STACKDUST
AR
Official Google artwork for the Gemini 3.8 Flash and 3.8 Flash Cyber launch

Google Launches Gemini 3.8 Flash and 3.8 Flash Cyber: Frontier-Level Coding at 3.7 Prices, a Cyber Model Behind the Fairwind Gate


On September 2, 2026, Google launched Gemini 3.8 Flash — its third Flash release in six weeks, following 3.7 Flash — positioning it as its best reasoning and coding model yet at 3.7’s speed and price. The more consequential half of the announcement is its sibling: Gemini 3.8 Flash Cyber, Google’s most capable model for vulnerability discovery and automated patching, which will not be sold to everyone. Access runs exclusively through the new, limited Fairwind Program for trusted defenders.

The Core Model: “Works Harder”

The stated design idea behind the 3.8 jump: the model works harder — extra reasoning steps and iterative tool-calling on complex tasks, even at the cost of more tokens at higher effort levels. If compute is the constraint, lower effort levels trim token overhead, and 3.7 Flash remains fully supported for efficiency-first workloads.

The disclosed numbers from Google:

  • DeepSWE v1.1 (long-horizon software engineering): 3.8 Flash outperforms most larger frontier models in autonomously solving complex engineering problems end to end, at a fraction of the cost.
  • HLE-Verified: 54.9% on multi-step reasoning across STEM, humanities, and professional domains.
  • Vals Finance Agent V2 and Harvey’s Legal Agent Benchmark: outperforms 3.7 Flash and other frontier models on professional financial and legal analysis.

The launch demos telegraph the positioning: a full 3D game built from a single prompt in Google Antigravity, a playable DOS version of Google Maps, and interactive topographic cross-sections built on real USGS datasets.

Pricing: Introductory Through Year-End

The introductory price is $0.75 per million input tokens and $3.75 per million output — identical to 3.7’s introductory rate. The planning-relevant catch: it expires December 31, 2026, after which the price becomes $1.50/$7.50 starting January 1, 2027 — a doubling of both rates. The model is generally available now in Google AI Studio and the Gemini Enterprise Agent Platform as gemini-3.8-flash, plus Antigravity, Android Studio, Stitch, and the Gemini app for AI Pro/Ultra subscribers (see our earlier frontier API pricing guide for the broader picture).

3.8 Flash Cyber: Cyber Capability Behind a Credential Gate

This is where the story intersects with OpenAI’s Astra announcement a day earlier: frontier cyber capability is no longer being shipped to the public.

Gemini 3.8 Flash Cyber shares the same foundational intelligence but ships with a deliberately more permissive mitigation set in the cyber domain — which is precisely why it is gated behind the Fairwind Program, open to governments and national cyber authorities, critical infrastructure operators, and core technology platforms and software maintainers. The disclosed numbers:

  • CyberGym: frontier-level autonomous vulnerability discovery, surpassing 3.5 Flash Cyber as well as significantly larger frontier models.
  • An internal benchmark spanning 20 programming languages: a success rate exceeding 70% discovering real-world vulnerabilities across complex codebases.
  • CWE-Bench (run by Collinear) for automated patching: 47.2% pass@1 versus 47.8% for a leading frontier model — on the Pareto frontier at a much lower cost.

Beyond benchmarks, Google disclosed internal production use: Chrome Security found the model produced 2.6× more correct patches for Chrome vulnerabilities than the best, much larger commercial models; Wiz measured +7.5–9.7% higher recall on their internal pentesting benchmark at 2.3–5.2× lower cost; and Google’s Cloud Vulnerability Research team found a critical foundational vulnerability in under 2 hours — work that normally takes months.

Safety: One Thread Ties Both Releases

Both models ship with safeguards under Google’s Frontier Safety Framework covering CBRN and cyber offense, plus a disclosed jump in prompt-injection robustness on Gray Swan’s benchmarks — directly relevant if you build agents that read untrusted web content. The difference: Cyber carries a more permissive mitigation set by design, and that is exactly why it sits behind Fairwind.

What Developers Should Do Now

  • Migrating to 3.8 Flash is nearly free in 2026 — but budget 2027 against the doubled price ($1.50/$7.50), and watch effort levels, because the extra “diligence” shows up as a token bill on complex tasks.
  • Stay on 3.7 Flash for cost-sensitive workloads — Google explicitly committed to continuing support.
  • Advanced cyber capability is no longer buy-on-demand: if your organization relies on model-driven vuln discovery, start Fairwind paperwork early — limited programs fill.
  • For security teams concretely: CWE-Bench numbers and the “critical vuln found in 2 hours” datapoint indicate model-assisted patching is maturing from research curiosity into operational tooling — plan its place in your defense pipeline as an accelerator, not a replacement for your security team.

The Takeaway

On its own, 3.8 Flash is an excellent routine upgrade: more intelligence at the same price — a trade everyone understands. The strategic news is the sibling: with Fairwind, Google formally joins the access-gated cyber-model era that OpenAI’s Astra and Anthropic’s Mythos are shaping. If you build defensive tooling, get used to a new idea: the capability is coming — but with a credential key.

Sources


Next ArticleMeta Ships Muse Spark 1.3: an Agentic Coding Model That Uses ~25% Fewer Tokens on Long TasksPrevious ArticleGitSpawn: A Single Flaw Lets Untrusted Repositories Run Host Code in AI Coding Agents