US Edition
Your source for latest news
TechnologyArtificial intelligence

Google releases a cybersecurity AI model it says is too capable for public release

Gemini 3.8 Flash Cyber found and patched software vulnerabilities far faster than rival models in Google's own tests, but the company is restricting access to vetted governments and infrastructure operators, citing the model's dual-use risk.

PT
By PressTemps Technology DeskPublished Today, 09:46 ET · 6 min read
Google releases a cybersecurity AI model it says is too capable for public release
The Google DeepMind offices at 6 Pancras Square in London. Photo: Gciriani / Wikimedia Commons, CC BY-SA 4.0
What to know
Google DeepMind released Gemini 3.8 Flash and a security-specialized sibling, Gemini 3.8 Flash Cyber, on September 2, 2026.
Google's Chrome Security team found 3.8 Flash Cyber produced 2.6 times more correct vulnerability patches than larger commercial rival models.
Access to Flash Cyber is restricted to vetted governments, critical-infrastructure operators and software maintainers through a new program called Fairwind, now covering more than 650 organizations.
Using Gemini-assisted triage, Chrome fixed 1,072 security bugs across its two most recent release milestones, more than the previous 23 milestones combined.

Google DeepMind released a new pair of artificial intelligence models this week that illustrate a widening split in how the industry is choosing to deploy AI for cybersecurity: one model built for broad commercial use, and a more capable sibling deliberately withheld from the public because of what the company itself calls its "dual-use" potential to help attackers as easily as defenders.

The general-purpose model, Gemini 3.8 Flash, and a specialized variant called Gemini 3.8 Flash Cyber were both introduced on September 2 in a post on Google's official blog. While the standard model is available immediately to consumers and developers, the cybersecurity version is restricted to a newly created vetting program called Fairwind, open only to government agencies, critical-infrastructure operators and software maintainers that Google has approved in advance.

The numbers

Gemini 3.8 Flash arrived just three weeks after its predecessor, 3.7 Flash, continuing an unusually rapid release cadence for Google's mid-tier model line. It processes up to 1 million tokens of input and generates up to 64,000 tokens of output, according to the model's official documentation, and is priced at an introductory rate of $0.75 per million input tokens and $3.75 per million output tokens through the end of the year, after which both rates double.

The Cyber variant's numbers are aimed less at price-conscious developers than at security teams. On CyberGym, an industry benchmark for autonomous vulnerability discovery, Google says the model outperforms both its predecessor and larger general-purpose frontier models. On an internal test spanning 20 programming languages, it found real-world vulnerabilities with better than 70 percent success, and on a standard patch-quality benchmark called CWE-Bench it produced a correct fix 47.2 percent of the time on its first attempt. Perhaps the most concrete figure came from Google's own Chrome Security team, which found in production testing that 3.8 Flash Cyber generated 2.6 times as many correct vulnerability patches as the best larger commercial models it was tested against. A separate Chrome security blog post disclosed that the browser's engineering team, now using Gemini models to automate vulnerability discovery, triage and patching, fixed 1,072 security bugs across its two most recent release milestones alone, more than the total fixed across the previous 23 milestones combined.

How Google got here

The Cyber line traces back to a narrower predecessor, Gemini 3.5 Flash Cyber, which Google introduced in July as its first attempt at a security-specialized model gated behind a limited-access program. That earlier release reflected a problem the company has been wrestling with publicly for months: an AI system capable of finding software flaws faster than human researchers is, by definition, also capable of helping someone exploit them. Google's response has been to build the model's training and safeguards around defensive tasks specifically, rather than releasing a general-purpose vulnerability-hunting tool to anyone with an API key.

"With Gemini 3.8 Flash Cyber, we focused specifically on equipping defenders with expert capabilities that give them an advantage over attackers," said Raluca Ada Popa, Google DeepMind's Gemini Security Lead, in comments accompanying the launch. "This is why we have invested in vulnerability fixing from the start, and prioritized it over offensive capabilities like exploitation."

"In cybersecurity, attackers need only find one significant flaw over millions of lines of code. Defenders have to remove every one." — Raluca Ada Popa, Gemini Security Lead, Google DeepMind

Who is affected, and how rivals are responding

For most developers and consumers, the immediate change is simply a faster, cheaper coding and reasoning model: Gemini 3.8 Flash is live now in the Gemini app for Google AI Pro and Ultra subscribers, inside Google Sheets and AI Mode, and available to programmers through Google Antigravity, AI Studio and the Gemini API, as an early rundown of the release noted. The Cyber model's effects will be felt differently and more narrowly: Google says it is already working with more than 650 organizations worldwide, including cybersecurity vendors, through the Fairwind Program, and that access will continue to be prioritized for government authorities and operators of critical infrastructure such as utilities and telecommunications networks, rather than opened to the general public.

Software users benefit indirectly. Chrome's security team has folded Gemini-assisted triage directly into its bug-fixing pipeline, using what the company describes as multiple cooperating AI agents, one drafting a candidate patch, another critiquing it, a third writing tests, to push more fixes into stable releases faster than manual review alone could manage. The approach is being closely watched by the broader software industry as a test case for whether AI-assisted patching can be scaled without introducing new classes of errors.

Google's decision to gate its most capable cyber model is not happening in isolation. Rival AI labs have taken similar steps in the same window: Anthropic has restricted its own top-tier security-oriented model to trusted-access programs, and OpenAI has said its forthcoming Astra model, built to meet what the company calls a "critical cybersecurity capability" threshold under its internal safety framework, will likewise be limited to vetted testers rather than sold broadly, according to reporting on the parallel announcements. Taken together, the moves mark a shift from AI companies competing purely on raw model capability toward a newer competition over how responsibly, and to whom, that capability gets distributed.

Outside commentary on the Google release has focused less on whether the technology works, Google's own benchmark claims have gone largely unchallenged so far, and more on the harder question the industry has not yet resolved: whether restricting access to "trusted defenders" can meaningfully slow attackers who have their own resources to build comparable tools, or whether it mainly slows down the defenders who most need the help. Coverage of the launch has noted that Google has not published detailed criteria for who qualifies for Fairwind access, leaving smaller software maintainers and independent security researchers uncertain whether they will ever receive it.

What happens next

Google has not said when, if ever, it plans to widen public access to Flash Cyber, and the model card for the mainstream Gemini 3.8 Flash makes no mention of the security variant at all, underscoring how deliberately the two products have been kept on separate tracks. In the near term, the more consequential test may play out inside Chrome itself, where the security team's public commitment to publish ongoing vulnerability-fix statistics gives outside researchers a rare, semi-continuous window into whether AI-assisted patching is holding up at scale or merely shifting where errors occur. Standard pricing for the mainstream model takes effect on January 1, 2027, and rival frontier-safety disclosures from Anthropic and OpenAI are expected to invite direct comparisons of how each company is managing the same underlying risk: increasingly capable AI systems that are, by their creators' own admission, exactly as useful to attackers as to the defenders they are designed to help.

More on this story

All Technology