Gemini 3.8 Flash Cyber Matches Frontier Patch Accuracy at Flash Cost — Locked Behind Fairwind Access
Google shipped two new models on September 2: Gemini 3.8 Flash (general availability) and Gemini 3.8 Flash Cyber (restricted access). It is the third Flash-tier release in six weeks, and the fourth Flash model in under four months.
Gemini 3.8 Flash
3.8 Flash is priced identically to 3.7 Flash at launch: $0.75 per million input tokens, $3.75 per million output tokens. Introductory pricing runs through December 31, 2026. Standard rates take effect January 1, 2027: $1.50 input, $7.50 output.
On Artificial Analysis, the model scores 59 on the Intelligence Index and sits on the intelligence-per-dollar Pareto frontier. On the general agentic benchmarks, 3.8 Flash outperforms 3.7 Flash on DeepSWE v1.1 (long-horizon software engineering), Vals Finance Agent V2, and Harvey’s Legal Agent Benchmark. HLE-Verified sits at 54.9%, up from 3.7 Flash’s position. The model was added to Arena’s Agent Arena, Code Arena, and Text Arena on launch day.
Gray Swan’s prompt injection benchmark shows measurable improvement in injection robustness over the 3.7 generation.
Gemini 3.8 Flash Cyber
The Cyber variant is available only to organizations approved through Google’s Fairwind Program — a new access-controlled tier for vetted security defenders. Pricing is not separately published; Fairwind approval is required before pricing is disclosed.
Benchmark results against the public patching and vulnerability discovery benchmarks:
| Benchmark | 3.8 Flash Cyber | Reference | Note |
|---|---|---|---|
| CWE-Bench pass@1 (Collinear) | 47.2% | 47.8% (larger frontier) | Pareto frontier on cost |
| CyberGym (vuln discovery) | SOTA | 3.5 Flash Cyber | Surpasses previous gen and larger models |
| Internal 20-lang benchmark | >70% | — | Vuln discovery across C, Go, Rust, and 17 others |
| Gray Swan IPI | Leading | Prior generation | Prompt injection robustness |
Third-party deployment results:
- Chrome Security team: 2.6x more correct patches to Chrome vulnerabilities compared to best commercial models that are larger.
- Wiz: +7.5 to 9.7% higher recall on internal penetration testing benchmark, at 2.3 to 5.2x lower cost than leading frontier models.
- Google Cloud Vulnerability Research: used 3.8 Flash Cyber to find a critical foundational vulnerability in under two hours. Research and discovery for that class of vulnerability normally takes months.
CWE-Bench is worth unpacking. It tests automated patching capability across the Common Weakness Enumeration taxonomy, run by Collinear. A 47.2% pass@1 against 47.8% for the leading model means 3.8 Flash Cyber is within one point of the best-available alternative while running at Flash-tier speed and cost. The cost differential is what the Wiz and Chrome numbers confirm in practice — you get near-frontier patching throughput at a fraction of the compute spend.
The Fairwind Program access model mirrors how Google has handled other sensitive capability tiers: controlled distribution to security teams, academic researchers, and government-adjacent defenders, with expanded rollout contingent on track record. The 3.5 Flash Cyber predecessor followed the same path before broader availability.
3.8 Flash Cyber is available on Vertex AI under the Fairwind access track starting September 2.