Google ships Gemini 3.8 Flash with a cybersecurity-only sibling

laptop screen displaying colorful code

Google released two models on Wednesday: Gemini 3.8 Flash, aimed at software engineering and autonomous tasks, and Gemini 3.8 Flash Cyber, a restricted variant built for vulnerability detection and patching. The launch comes three weeks after Gemini 3.7 Flash and is the third Flash-generation release this quarter.

Gemini 3.8 Flash

Pricing holds at $0.75 per million input tokens and $3.75 per million output tokens, matching the predecessor’s introductory rate. The model is available to Google AI Pro and Ultra subscribers through the Gemini app, AI Mode in Google Search, Gemini in Google Sheets, and to developers via the Gemini API and AI Studio.

On the DeepSWE v1.1 long-horizon software engineering benchmark, Google says 3.8 Flash outperforms most larger frontier models at lower cost. It scores 54.9% on HLE-Verified, a benchmark covering reasoning across STEM, humanities, and professional fields.

The performance gains come from an architectural change that pushes the model to iterate through reasoning chains and invoke tools multiple times on complex problems. That approach can increase token consumption when the effort setting is high. Developers who want to control costs can dial down the effort setting or keep using Gemini 3.7 Flash.

Gemini 3.8 Flash Cyber

The Cyber variant is not generally available. Access is gated to participants in Google’s new Fairwind Program, which targets government authorities, critical infrastructure operators, and software maintainers.

On CyberGym, an industry benchmark for autonomous vulnerability discovery, the Cyber model outperforms both its predecessor and larger frontier models, according to Google. On CWE-Bench, a patching benchmark, it achieves a pass@1 rate of 47.2%, compared with 47.8% for a leading frontier model, at lower cost.

Google says it is already deploying the Cyber model internally. The Chrome Security team’s testing found the model generated correct vulnerability patches at a rate 2.6 times higher than competing commercial models of greater size. Google’s Cloud Vulnerability Research team also reported the model surfaced a critical foundational vulnerability in under two hours, work the team said ordinarily takes months.

Context

Prior reporting indicated Google was testing 3.8 Flash internally against Anthropic’s Opus model using Jetski, Google’s internal coding tool, with engineers preferring the new model. Google has also increased investment in reinforcement learning since the start of the year. Koray Kavukcuoglu, who became CEO of Google DeepMind last month after co-founder Demis Hassabis stepped aside, has signaled he wants to accelerate the pace of execution.

Stay on top of AI & Automation with BizStack Newsletter
BizStack  —  Entrepreneur’s Business Stack
Logo