Gemini 3.8 Flash and Flash Cyber: Pricing, Benchmarks, and Who Gets Access
Google released Gemini 3.8 Flash and 3.8 Flash Cyber on September 2. Pricing stays at the 3.7 Flash introductory rate of $0.75/$3.75 per million tokens, but it expires December 31, 2026 and doubles. The cyber variant ships only to vetted Fairwind Program organizations.
Google released two models on September 2, 2026: Gemini 3.8 Flash and Gemini 3.8 Flash Cyber1. The launch follows 3.7 Flash from three weeks earlier and marks the third Flash release in six weeks1.
What stands out is how differently the two are distributed. Gemini 3.8 Flash ships broadly — the Gemini API, the Gemini app, AI Mode in Google Search. Gemini 3.8 Flash Cyber goes only to organizations vetted through the Fairwind Program, which launched the same day12. Both run on the same foundational intelligence1.
The price holds, but only through year-end
Gemini 3.8 Flash costs the same as 3.7 Flash: $0.75 per million input tokens and $3.75 per million output tokens1.
That is an introductory price, and it expires on December 31, 20261. A footnote on the announcement page states that $1.50 input and $7.50 output apply starting January 1, 20271. The structure is identical to the one used for Gemini 3.7 Flash, which was also half price through year-end and doubles in the new year. If you are budgeting API spend annually, the model name changed but the January 1, 2027 cutover did not.
On performance, Google positions 3.8 Flash as its “most intelligent workhorse model,” claiming significant improvements over 3.7 Flash across software engineering, agentic tasks, and multi-step reasoning in specialized domains1. The one figure stated in the announcement text is 54.9% on HLE-Verified, which Google describes as evidence of multi-step reasoning across STEM, humanities, and professional fields1. On DeepSWE v1.1 (long-horizon software engineering), Google says 3.8 Flash outperforms most larger frontier models; on quantitative and professional benchmarks such as Vals Finance Agent V2 and Harvey’s Legal Agent Benchmark, it says the model outperforms 3.7 Flash and other frontier models1. The announcement text gives no scores for any of them1.
It is designed to spend more tokens
Google attributes the performance gains less to raw capability than to a design choice: 3.8 Flash “works harder”1. On complex tasks it executes extra reasoning steps and calls tools iteratively. As a result, the announcement states plainly that the model might use more tokens to maximize performance, especially at higher effort levels1.
This is the part a price-per-token comparison misses. If the same job consumes more tokens, the bill can rise even when the unit price holds. Google acknowledges this and points to two options for efficiency-first workloads: use lower effort levels, or stay on 3.7 Flash, which remains fully supported1. Measuring token consumption and accuracy on your own workload before switching is the sensible path.
Choosing who receives the cyber variant
Gemini 3.8 Flash Cyber is built for vulnerability detection and automated patching1. Google offers the following figures from its own evaluations.
On an internal benchmark spanning complex codebases in 20 programming languages, the model exceeds a 70% success rate at discovering vulnerabilities1. On CWE-Bench, an external patching benchmark run by Collinear, it reaches 47.2% pass@1 against a leading frontier model’s 47.8% — close enough that Google calls it “on the Pareto frontier” given the significantly lower cost1. Internally, Google says its Chrome Security team found the model produced 2.6 times more correct patches than the best commercial models that are much larger, and its Cloud Vulnerability Research team found a critical foundational vulnerability in under two hours, work that usually takes months1. Security company Wiz reported 7.5–9.7% higher recall on its internal penetration testing benchmark at 2.3–5.2x lower cost than other leading frontier models1.
Google states it has invested in vulnerability fixing from the start and prioritized it over offensive capabilities like exploitation1. Even so, this model is distributed nothing like 3.8 Flash.
Fairwind as the gate
The Fairwind Program launched the same day as a limited-access program for governments and trusted partners2. It targets a trusted group of Google Cloud customers, government agencies, and cybersecurity partners, and pairs Gemini 3.8 Flash Cyber with the CodeMender harness2. Google says defenders can generate verified, deployment-ready patches in minutes within their own secure cloud environment, instead of spending weeks on manual fixes2.
Staged access covers three categories: governments and national cyber authorities; critical infrastructure operators across healthcare, telecommunications, energy, and financial networks; and core technology platforms securing widely used software foundations2. Participating organizations agree to operational standards, including limiting access to employees on internal cybersecurity, incident response, or penetration testing teams, and deploying protections such as multi-factor authentication2. Google says there are more than 650 participating partners globally2.
Google frames the reasoning as giving defenders an “adaptation window” to harden their systems before bad actors can exploit new capabilities2. The safety treatment differs between the two models as well: 3.8 Flash ships with safeguards against misuse in CBRN (chemical, biological, radiological, and nuclear) and cyber offense domains, while 3.8 Flash Cyber ships with a more permissive set of mitigations for cybersecurity1. That is precisely why it is restricted to trusted defenders who need a more comprehensive set of cyber capabilities1.
Google Cloud customers outside Fairwind can still use CodeMender with publicly available models hosted on the Gemini Enterprise Agent Platform to secure their code2. What is gated is the Cyber model, not the patching machinery itself.
The Flash Cyber line, and another announcement the same week
This is not the first cyber-focused Flash model. The line began with the Gemini 3.6 Flash, 3.5 Flash-Lite, and Flash Cyber release on July 21, and even then Flash Cyber was not generally available — it went to governments and trusted partners through a pilot program built around CodeMender. What is new is that the access arrangement now has a name and stated participation terms in the Fairwind Program. The Flash line also moves quickly: agentic video understanding shipped for 3.7 Flash, 3.6 Flash, and 3.5 Flash-Lite just a day earlier, on September 1.
In broader context, “release a highly capable cyber model only to vetted recipients” appeared twice this week. On September 1, OpenAI said its upcoming Astra model had reached the Critical cybersecurity threshold under its Preparedness Framework, and that access to advanced cyber capabilities would initially go to a small group after release. The two companies reached that conclusion through different reasoning and different processes, but the conclusion — do not hand capable models to everyone — is the same.
For teams running security operations, the practical difference sits in the access terms. Models like the Cyber variant are no longer something you obtain by reading a price sheet and signing up. Applying, passing review, and deciding which internal teams get access has become the first piece of work in evaluating adoption.
Sources
- Introducing Gemini 3.8 Flash and 3.8 Flash Cyber - Google official blog (September 2, 2026)
- Proactive cyber defense for governments and enterprises - Google official blog, Fairwind Program announcement (September 2, 2026)
Was this article helpful?
Thank you!
Received. Thank you!