The Information Machine
Following·since 2 Sep 2026·New·5 sources

Google Restricts Gemini 3.8 Flash Cyber to Vetted Governments and Partners

The gist

Google is restricting near-frontier cybersecurity AI capabilities to a vetted set of governments and infrastructure partners. Benchmark results and third-party testing suggest meaningful advantages in vulnerability detection and patching cost over competing models.

The full picture

Gemini 3.8 Flash Cyber, Google's cybersecurity-specialized AI model, is available exclusively through the Fairwind Program, which restricts access to approved governments and critical infrastructure operators. On the CWE-Bench patching benchmark, the model achieves 47.2% pass@1, close to a leading frontier model's 47.8%, at lower cost. On the CyberGym vulnerability discovery benchmark, it surpasses both its predecessor Gemini 3.5 Flash Cyber and significantly larger frontier models. An internal benchmark across 20 programming languages shows a success rate exceeding 70% in discovering vulnerabilities across complex codebases. Google's Chrome Security team found it produced 2.6 times more correct patches to Chrome vulnerabilities than comparable commercial models. Security firm Wiz reported 7.5% to 9.7% higher recall on its internal penetration testing benchmark at 2.3 to 5.2 times lower cost compared to other models. Google's Cloud Vulnerability Research team used the model to identify a critical vulnerability in under two hours, a task that typically takes months. Google is deploying the model internally to secure its own code. The Fairwind Program requires background checks on applicants to verify security history and ethical operations record, and prohibits partners from sharing, redistributing, or selling access to the frontier models. Organizations that do not qualify can use CodeMender with publicly available models and other Google AI Threat Defense products.

How it developed
2 September 2026

Google DeepMind introduces Gemini 3.8 Flash Cyber, describing it as its most capable cybersecurity model

Sources
The daily email

Want this in your inbox?

I send a short email each morning with the stories that moved. If you would rather just read here, that works too.

Subscribe free