Google DeepMind launches Gemini 3.8 Flash and a cybersecurity version
The new model pushes deeper multi-step reasoning and tool use for coding agents, while the cyber-focused variant is limited to vetted defenders under a new access program called Fairwind.
Google DeepMind has released two new models, Gemini 3.8 Flash and a specialized version called Gemini 3.8 Flash Cyber. Both share the same underlying training but are aimed at different jobs: 3.8 Flash for general coding and agent tasks, and 3.8 Flash Cyber for finding and patching software vulnerabilities. The release is DeepMind’s third Flash-line model in six weeks, following Gemini 3.7 Flash. 3.8 Flash keeps 3.7 Flash’s price of $0.75 per million input tokens and $3.75 per million output tokens.
DeepMind says 3.8 Flash’s gains come from a model that works harder on difficult problems, taking extra reasoning steps and calling outside tools repeatedly instead of answering in one pass. That approach, an agentic loop that plans, acts, and checks its own work, can use more tokens per answer, so DeepMind is keeping 3.7 Flash available for tasks where cost matters more than accuracy. On DeepSWE v1.1, a benchmark for solving multi-step software engineering problems without human help, DeepMind says 3.8 Flash beats most larger frontier models at a fraction of the cost, and it scored 54.9% on HLE-Verified, a test of reasoning across STEM, humanities and professional subjects.
Cyber model reserved for vetted defenders
Gemini 3.8 Flash Cyber is available only through what DeepMind calls the Fairwind Program, limited to government cybersecurity authorities, critical infrastructure operators, and software maintainers. On CyberGym, an industry benchmark for finding software vulnerabilities, DeepMind says the model performs at a frontier level, beating both its predecessor, 3.5 Flash Cyber, and larger general-purpose models. On an internal test covering vulnerabilities across 20 programming languages, it found more than 70% of the flaws. On CWE-Bench, an external benchmark for patching vulnerabilities run by the company Collinear, 3.8 Flash Cyber scored 47.2% on its first attempt, close to a leading frontier model’s 47.8%, at what DeepMind describes as a lower cost.
DeepMind cites early results from partner security teams. Chrome’s security team says the model produced 2.6 times more correct patches for vulnerabilities than the best commercial models it tested, despite those models being much larger. The security firm Wiz reported 7.5 to 9.7 percentage points higher recall, the share of real vulnerabilities caught, at 2.3 to 5.2 times lower cost than other frontier models. Google’s Cloud Vulnerability Research team says it used 3.8 Flash Cyber to find a critical vulnerability in under two hours, a process DeepMind says normally takes months.
DeepMind says both models include safeguards against misuse in chemical, biological, radiological and nuclear weapons development and offensive cyber operations, under guidelines it calls its Frontier Safety Framework. The Cyber variant carries a more permissive set of mitigations, which is why DeepMind is restricting it to vetted defenders rather than releasing it broadly. Both new models also showed improved resistance to prompt injection, a technique where hidden instructions in text trick an AI system into acting against its user, based on testing by the security firm Gray Swan.
Gemini 3.8 Flash is rolling out through Google AI Studio, Android Studio, Gemini Enterprise, and the Gemini app for AI Pro and Ultra subscribers. Access to 3.8 Flash Cyber depends on approval through the Fairwind Program, which DeepMind has opened for applications. Whether outside organizations report results matching the benchmarks DeepMind and its partners have cited so far will depend on how that access rolls out.
Sources
- Introducing Gemini 3.8 Flash and 3.8 Flash Cyber Google DeepMind
This story was written by an automated desk from the sources above and published without a human editor in the loop. How that works, and what it means for you.