Google shipped two new models this week from the same underlying foundation, and deliberately restricted access to one of them. Gemini 3.8 Flash is available to anyone, priced at 0.75 dollars per million input tokens and 3.75 dollars per million output tokens. Gemini 3.8 Flash Cyber, described by Google as its most capable cybersecurity model to date, is available only to a curated set of what the company calls trusted defenders, through a newly launched initiative called the Fairwind Program. The split is deliberate, and it says something significant about how seriously frontier labs now treat the dual-use risk baked into their own most capable systems.
What Flash Cyber can actually do
Flash Cyber is built specifically for autonomous vulnerability discovery, security research, and automated patching, and Google’s own published benchmarks back up the “most capable” claim with real numbers. On CyberGym, the standard industry benchmark for vulnerability discovery, Flash Cyber demonstrates what Google calls frontier-level performance, surpassing both its own predecessor, 3.5 Flash Cyber, and significantly larger frontier models. Google says it also cleared 70 percent or better on an internal benchmark testing vulnerability discovery across 20 different programming languages, a genuinely broad span for a single security-focused model to handle well, and posted 47.2 percent pass@1 on CWE-Bench, a benchmark tracking common weakness enumeration categories. Perhaps most concretely, Google claims Flash Cyber delivers 2.6 times more correct patches to real Chrome vulnerabilities than leading commercial alternatives, a specific, testable claim rather than a vague capability assertion.
The model is paired with CodeMender, Google’s own harness for validating and deploying fixes, letting defenders generate verified, deployment-ready patches in minutes inside their own secure cloud environment, according to Google’s own announcement, a dramatic compression compared to the weeks manual vulnerability remediation can typically take at enterprise scale.
Why access is deliberately restricted
The Fairwind Program already works with more than 650 partners globally, according to Google, and access is prioritized for four categories: governments and cyber authorities protecting public networks, critical infrastructure operators in healthcare, telecom, energy, and finance, maintainers of core technology platforms with wide-reaching software ecosystems, and approved cybersecurity teams conducting authorized defensive research. Applicants have to clear Google’s eligibility and due-diligence requirements, and organizations are expected to demonstrate a legitimate defensive use case while maintaining operational controls like multi-factor authentication and limited internal access before they’re granted entry.
Google’s own framing of the tradeoff is unusually direct for a product announcement: the same autonomous vulnerability-discovery capability that helps a defender patch a critical flaw before an attacker finds it could, in the wrong hands, help an attacker find that same flaw first. Restricting Flash Cyber to a vetted defender population is Google’s attempt to tilt that balance meaningfully toward defense, a real, structural bet that giving capable defenders a head start matters more than the theoretical efficiency loss from not releasing the model broadly.
Part of a broader industry pattern, not an isolated move
Google isn’t alone in reaching this conclusion. The Hacker News reported that Google, Anthropic, and OpenAI have each separately unveiled cyber-focused AI models, safeguards, and restricted-access programs around the same period, a pattern that reflects genuine, converging industry consensus rather than one company’s isolated caution. Anthropic has similarly held back its own cybersecurity-capable Mythos model under a program called Project Glasswing specifically because of its capacity to autonomously discover zero-day vulnerabilities, restricting access to a trusted coalition rather than releasing it broadly. This deliberate access-gating for cyber-capable models is also the direct product context behind the 117-company joint letter on AI cyber defense published just days before Flash Cyber’s release, in which OpenAI, Anthropic, Google, and more than a hundred other companies warned that AI-enabled cyberattacks will become significantly more widespread and sophisticated in the coming months.
Read together, these releases and that letter tell a consistent story: frontier labs increasingly believe the cyber-offense capability of their most advanced models has crossed a threshold serious enough to warrant genuinely restricted release, not just a safety disclaimer attached to an otherwise open product.
The general-purpose sibling tells its own story
Standard Gemini 3.8 Flash, released alongside Flash Cyber, is itself a genuinely capable general-purpose model, debuting at number 7 in Text Arena, ahead of Claude Opus 5, with real gains over its 3.7 Flash predecessor across multi-turn conversation, writing, coding, and business and financial reasoning tasks. On DeepSWE v1.1, a long-horizon software engineering benchmark, 3.8 Flash reportedly outperforms most larger frontier models at solving complex engineering problems end to end, at a fraction of the cost those larger models charge. That both models, the openly available Flash and the tightly restricted Flash Cyber, share the same foundational intelligence underscores that the restriction on Flash Cyber isn’t because Google lacks confidence in the underlying model’s quality. It’s a deliberate, calculated choice about who should have first access to a specific, high-risk capability.
What this signals about where the industry is heading
Google has been explicit that the Fairwind Program is a first step, not a finished framework, saying it will evolve access and product offerings alongside partner and user needs, and that it intends to collaborate with industry, governments, and the open-weight community to strike what it calls the right balance between open access and robust security. That language suggests the current restricted-access model isn’t necessarily permanent, but it also signals that Google doesn’t yet see a clear, safe path to opening Flash Cyber’s capabilities more broadly. For any organization not yet inside a program like Fairwind, Google’s public guidance points toward using CodeMender with its publicly available models on the Gemini Enterprise Agent Platform, combined with dedicated tools like AI Threat Defense, a meaningfully less capable but still genuinely useful path to some of the same defensive benefit.
See Google’s own Fairwind Program announcement for the complete eligibility criteria and technical detail.




