Google launches Gemini 3.8 Flash, plus a cybersecurity variant restricted to vetted defenders
The third Flash update in three months ships at introductory pricing of $0.75/$3.75 per million input/output tokens through the end of the year, while Gemini 3.8 Flash Cyber -- reserved for governments, critical-infrastructure operators, and software maintainers in Google's new Fairwind Program -- finds real vulnerabilities across 20 languages 71% of the time.
Google released Gemini 3.8 Flash on September 2, 2026 -- the third Flash-tier update in three months, arriving three weeks after Gemini 3.7 Flash -- with gains in agentic coding and long-running, multi-step tasks, according to Google DeepMind's own model page. It's generally available now across the Gemini app, AI Studio, the Gemini API, and Google Antigravity.
A second, gated version built for defenders
Alongside it, Google introduced Gemini 3.8 Flash Cyber, a specialized version for vulnerability discovery and automated patching that's available only through a new Fairwind Program restricted to governments and national cyber authorities, operators of critical infrastructure like healthcare and energy networks, and maintainers of widely-used software platforms -- gated behind mandatory multi-factor authentication, background verification, and a ban on redistributing access. Google's own figures put it at a 71% real-world vulnerability-discovery rate across 20 programming languages, and Chrome's security team reported it produced 2.6 times more correct patches than larger commercial models it was tested against, per 9to5Google's reporting.
Pricing for the general Flash 3.8 model is introductory through December 31, 2026, at $0.75 per million input tokens and $3.75 per million output tokens, doubling to $1.50 and $7.50 on January 1, 2027, per Google's own published rate card.
A cybersecurity model that's simultaneously cheap enough for wide use and gated specifically to keep it out of the wrong hands is a strange combination on paper, and it's the same trade-off this site keeps flagging in AI procurement generally: the sticker price on an API call describes almost nothing about who's allowed to use the capability behind it, under what oversight, or what it's actually worth to the org paying for it. A pricing page is not a governance policy, even when a vendor ships both on the same day.