Gemini 3.8 Flash and Cyber: Faster Reasoning, Gated Security
Google's Gemini 3.8 Flash boosts coding and reasoning at 3.7 Flash's price; Gemini 3.8 Flash Cyber hunts vulnerabilities via a gated program.
Google's Gemini 3.8 Flash boosts coding and reasoning at 3.7 Flash's price; Gemini 3.8 Flash Cyber hunts vulnerabilities via a gated program.
Introduction
On September 2, 2026, Google announced two new models: Gemini 3.8 Flash and Gemini 3.8 Flash Cyber. The release is Google's third Flash-tier launch in six weeks, arriving three weeks after Gemini 3.7 Flash. Google describes Gemini 3.8 Flash as its "best reasoning & coding model yet," delivered at the same speed and low cost as 3.7 Flash. Gemini 3.8 Flash Cyber shares the same foundational model but is tuned specifically for vulnerability detection and automated patching. Unlike Google's earlier Flash releases, Cyber is not broadly available: access runs through Google DeepMind's new Fairwind Program, reserved for vetted defenders such as government authorities, critical infrastructure operators, and software maintainers. Together, the two releases continue Google's fast Flash-tier cadence while keeping the security-tuned variant behind an access program; Google's own benchmarks compare Cyber against an earlier Gemini 3.5 Flash Cyber.
Feature Overview
Gemini 3.8 Flash is positioned as Google's "most intelligent workhorse model," with gains over Gemini 3.7 Flash in software engineering, agentic tasks, and multi-step reasoning. On DeepSWE v1.1, a benchmark for long-horizon software engineering, Google says the model "outperforms most larger frontier models," though the company did not publish a numeric score for that claim. The one headline figure Google did publish is on HLE-Verified, where Gemini 3.8 Flash scored 54.9%. Google also says the model gained ground over 3.7 Flash and "other frontier models" on Vals Finance Agent V2 and Harvey's Legal Agent Benchmark, again without disclosing specific numbers — both claims should be read as Google's own assertions rather than independently confirmed results.
A notable design tradeoff sits behind these gains: Google says 3.8 Flash "works harder" than its predecessor. The model executes extra reasoning steps and calls tools iteratively, and it "might use more tokens to maximize performance, especially at higher effort levels." That means matching per-token pricing does not guarantee matching per-task cost. Google explicitly tells cost-sensitive developers to use lower effort levels or stay on Gemini 3.7 Flash, which "remains fully supported for efficiency-first workloads."
Gemini 3.8 Flash Cyber is tuned for vulnerability detection and automated patching. On the CyberGym benchmark, Google says the model reaches frontier-level autonomous vulnerability discovery, surpassing both Gemini 3.5 Flash Cyber and larger frontier models — again, no numeric score was published. Google does report one internal figure directly: across an internal benchmark spanning 20 programming languages, the model achieved a success rate exceeding 70%.
On CWE-Bench, a patching benchmark run by Collinear, Gemini 3.8 Flash Cyber posted a pass@1 score of 47.2%, compared with 47.8% for a leading frontier model. Google frames its position on this benchmark around cost-efficiency — describing it as Pareto-frontier standing — rather than claiming the higher raw score.
| Benchmark | Gemini 3.8 Flash / Cyber | Comparison |
|---|---|---|
| HLE-Verified | 54.9% | Gemini 3.8 Flash's own score |
| CWE-Bench pass@1 | 47.2% | 47.8% (leading frontier model) |
| Internal 20-language success rate | Above 70% | Gemini 3.8 Flash Cyber |
Google also reports several results from its own teams and from a Fairwind partner, framed as their findings rather than independent audits: its Chrome Security team says it found 2.6x more correct Chrome vulnerability patches than the best much-larger commercial models tested; the security firm Wiz reports 7.5–9.7% higher recall on its own internal penetration-testing benchmark at 2.3–5.2x lower cost; and Google Cloud Vulnerability Research says it found a critical foundational vulnerability in under two hours, work the team describes as usually taking months.
On safety, Gemini 3.8 Flash ships with CBRN and cyber-offense safeguards under Google's Frontier Safety Framework. Gemini 3.8 Flash Cyber ships with what Google calls "a more permissive set of mitigations," the stated reason its access is gated. Google also says 3.8 made what it calls a significant leap in prompt-injection robustness, as measured by Gray Swan, without publishing a score, and that it prioritized vulnerability fixing over offensive capabilities like exploitation when building the Cyber variant.
Usability Analysis
Pricing for Gemini 3.8 Flash is $0.75 per million input tokens and $3.75 per million output tokens — the same introductory price Google set for Gemini 3.7 Flash. Google describes this as introductory pricing rather than a confirmed permanent rate, so developers planning long-term workloads should watch for a standard-rate change later.
| Model | Input (per million tokens) | Output (per million tokens) |
|---|---|---|
| Gemini 3.7 Flash | $0.75 | $3.75 |
| Gemini 3.8 Flash | $0.75 | $3.75 |
Gemini 3.8 Flash is available to developers through the Gemini API in Google AI Studio, Android Studio, Google Antigravity, and Stitch. Enterprises can reach it through Gemini Enterprise, and consumers get access through Google AI Pro and Ultra subscriptions in the Gemini app, AI Mode in Google Search, and Gemini in Google Sheets. That spread mirrors how Google distributed Gemini 3.7 Flash, putting the model in front of individual developers, enterprise teams, and consumers on day one.
Gemini 3.8 Flash Cyber has a narrower path to real use. It is available only to what Google calls "trusted defenders" — government authorities, critical infrastructure operators, and software maintainers — who must apply through the Fairwind Program. That gating limits hands-on evaluation to a small pool of vetted organizations, which also means most of Google's performance claims about the Cyber variant can't currently be checked by outside researchers.
Pros and Cons
Pros:
- Gemini 3.8 Flash matches Gemini 3.7 Flash's introductory pricing while adding coding and reasoning gains on Google's HLE-Verified benchmark
- Wide same-day availability for 3.8 Flash across developer tools, enterprise platforms, and consumer surfaces
- Gemini 3.8 Flash Cyber shows an internal success rate above 70% across 20 programming languages
- Google reports real-world vulnerability-detection results from its Chrome Security and Cloud Vulnerability Research teams and from the security firm Wiz
- Google reports a significant leap in prompt-injection robustness for Gemini 3.8 Flash, as measured by Gray Swan
Cons:
- Gemini 3.8 Flash Cyber is gated behind the Fairwind Program, so most developers cannot access or independently test it
- The "works harder" reasoning mode can push token usage higher per task, so actual cost may exceed 3.7 Flash despite identical per-token pricing
- DeepSWE v1.1 and CyberGym claims lack a published numeric score, leaving those specific comparisons unverifiable by third parties
- On CWE-Bench, Gemini 3.8 Flash Cyber's 47.2% pass@1 trails a leading frontier model's 47.8%
Outlook
The pace behind these releases — Gemini 3.6 Flash, then 3.7 Flash, then 3.8 Flash and 3.8 Flash Cyber, all within six weeks — shows Google iterating on its mid-tier line faster than earlier in 2026. Ars Technica has observed that this cadence, without a new frontier-level Gemini Pro model since early 2026, makes a previously discussed Gemini 3.5 Pro look less likely to arrive soon; that is Ars Technica's own analysis, not a Google statement. If Flash-tier releases keep absorbing most of Google's near-term model investment, developers evaluating Gemini for reasoning-heavy or agentic workloads may find these updates more relevant than waiting on a new Pro-tier model.
For the Cyber variant, the Fairwind Program raises a broader question about how Google scales vulnerability-detection AI beyond a small set of vetted defenders. Results from Google's Chrome Security and Cloud Vulnerability Research teams, along with the security firm Wiz, point to real operational value, but wider access will mean balancing that value against the more permissive safety mitigations Google cites as the reason for keeping the model gated.
Conclusion
Gemini 3.8 Flash extends Google's Flash-tier reasoning and coding gains at the same introductory price as its predecessor, with the caveat that heavier reasoning effort can raise per-task token costs. Gemini 3.8 Flash Cyber shows promising internal vulnerability-detection results, tempered by a CWE-Bench score that trails a leading frontier model and by Fairwind Program gating that keeps it out of most developers' hands. Gemini 3.8 Flash suits developers and enterprises already building on Google's Flash tier. Gemini 3.8 Flash Cyber is relevant mainly to government agencies, critical infrastructure operators, and software maintainers who can qualify for Fairwind access.
Editor's Verdict
Gemini 3.8 Flash and Cyber: Faster Reasoning, Gated Security earns a solid recommendation within the Gemini space.
The strongest case for paying attention: Gemini 3.8 Flash matches Gemini 3.7 Flash's introductory pricing while adding coding and reasoning gains on Google's HLE-Verified benchmark. That alone raises the bar for what readers should expect in this space. Reinforcing that, wide same-day availability for 3.8 Flash across developer tools, enterprise platforms, and consumer surfaces — practical value rather than just headline appeal. The broader signal worth registering is straightforward: Gemini 3.8 Flash keeps Gemini 3.7 Flash's introductory per-token pricing while adding coding and reasoning gains, based on Google's HLE-Verified score and DeepSWE claims. On the other side of the ledger, one constraint is real rather than a marketing footnote: Gemini 3.8 Flash Cyber is gated behind the Fairwind Program, so most developers cannot access or independently test it. It should factor into any serious decision. Layered on top of that, the 'works harder' reasoning mode can push token usage higher per task, so actual cost may exceed 3.7 Flash despite identical per-token pricing — which narrows the set of teams for whom this is an obvious yes.
For Google Cloud and Workspace integrators, multimodal-first teams, and Gemini API adopters, this is a serious evaluation candidate, not just a curiosity to bookmark. For everyone else, the safer posture is to monitor coverage and revisit once the use cases that matter to your team are demonstrated in the wild.
Pros
- Gemini 3.8 Flash matches Gemini 3.7 Flash's introductory pricing while adding coding and reasoning gains on Google's HLE-Verified benchmark
- Wide same-day availability for 3.8 Flash across developer tools, enterprise platforms, and consumer surfaces
- Gemini 3.8 Flash Cyber shows an internal success rate above 70% across 20 programming languages
- Google reports real-world vulnerability-detection results from its Chrome Security and Cloud Vulnerability Research teams and from the security firm Wiz
- Google reports a significant leap in prompt-injection robustness for Gemini 3.8 Flash, as measured by Gray Swan
Cons
- Gemini 3.8 Flash Cyber is gated behind the Fairwind Program, so most developers cannot access or independently test it
- The 'works harder' reasoning mode can push token usage higher per task, so actual cost may exceed 3.7 Flash despite identical per-token pricing
- DeepSWE v1.1 and CyberGym claims lack a published numeric score, leaving those specific comparisons unverifiable by third parties
- On CWE-Bench, Gemini 3.8 Flash Cyber's 47.2% pass@1 trails a leading frontier model's 47.8%
References
Comments0
Key Features
1. Announced September 2, 2026 as Google's third Flash-tier release in six weeks, following Gemini 3.7 Flash three weeks earlier. 2. Gemini 3.8 Flash scores 54.9% on HLE-Verified and matches Gemini 3.7 Flash's introductory pricing of $0.75/$3.75 per million input/output tokens. 3. A 'works harder' reasoning behavior can use more tokens per task at higher effort levels, so per-task cost may exceed 3.7 Flash even at the same per-token price. 4. Gemini 3.8 Flash Cyber is a security-tuned variant for vulnerability detection and patching, gated behind Google DeepMind's new Fairwind Program. 5. Cyber variant posts an internal success rate above 70% across 20 programming languages and a 47.2% pass@1 on CWE-Bench, versus 47.8% for a leading frontier model. 6. Available via Gemini API (AI Studio, Android Studio, Antigravity, Stitch), Gemini Enterprise, and Google AI Pro/Ultra plans.
Key Insights
- Gemini 3.8 Flash keeps Gemini 3.7 Flash's introductory per-token pricing while adding coding and reasoning gains, based on Google's HLE-Verified score and DeepSWE claims.
- The model's 'works harder' reasoning behavior can consume more tokens per task at higher effort levels, so matching per-token pricing does not guarantee matching per-task cost.
- Google explicitly recommends cost-sensitive developers use lower effort levels or stay on Gemini 3.7 Flash, which remains supported for efficiency-first workloads.
- Gemini 3.8 Flash Cyber is restricted to the Fairwind Program, limiting access to government authorities, critical infrastructure operators, and software maintainers.
- On CWE-Bench, Gemini 3.8 Flash Cyber's 47.2% pass@1 trails a leading frontier model's 47.8%, so Google frames its position around cost-efficiency rather than raw accuracy.
- DeepSWE v1.1 and CyberGym claims come with no published numeric score, so those specific performance comparisons remain unverifiable outside Google's own statements.
- Google reports internal results from its Chrome Security and Cloud Vulnerability Research teams, plus the security firm Wiz, showing practical vulnerability-detection gains — none independently audited.
- The three-Flash-releases-in-six-weeks cadence, combined with no new frontier-level Gemini Pro since early 2026, has led Ars Technica to question the near-term prospects of a promised Gemini 3.5 Pro.
Was this review helpful?
Share
Related AI Reviews
Gemini Adds Optional Toggle to Remove AI Visible Watermarks
Google now lets users toggle off visible watermarks on Gemini-made media, while invisible SynthID and C2PA metadata remain embedded regardless.
Gemini 3.7 Flash: Google's New Coding, Agent Workhorse
Google's Gemini 3.7 Flash arrives just three weeks after 3.6 Flash, with stronger coding and agentic benchmarks at half its predecessor's price.
Gemini Robotics 2: Whole-Body Control for Humanoids
Google DeepMind's Gemini Robotics 2 ships three models enabling whole-body humanoid control, five-finger dexterity, and multi-robot teamwork.
Google Ships Gemini 3.6 Flash, Delays 3.5 Pro Again
Google released Gemini 3.6 Flash on July 21, 2026, plus 3.5 Flash-Lite and a security-tuned Flash Cyber variant, as flagship 3.5 Pro stays delayed.
