Skip to main content
AI Safety & Governance

Google Launches Gemini 3.8 Flash Cyber Model, Fully Deployed Internally for Code Security Protection

On September 2 local time, Google announced the launch of the Gemini 3.8 Flash Cyber model, making it available to the first group of trusted security teams through the Fairwind program.

Google launches Gemini 3.8 Flash Cyber, fully deployed internally for code security protection

On September 2 local time, Google announced the launch of the Gemini 3.8 Flash Cyber model, making it available to the first group of trusted security teams through the Fairwind program.

Google said that on CyberGym, an authoritative industry benchmark for vulnerability discovery, Gemini 3.8 Flash Cyber demonstrated top-tier autonomous vulnerability-discovery capabilities. It not only surpassed its predecessor, 3.5 Flash Cyber, but also outperformed several much larger frontier models.

Google launches Gemini 3.8 Flash Cyber, fully deployed internally for code security protection

Google evaluated Gemini 3.8 Flash Cyber using more comprehensive internal benchmarks. The tests required the model to discover various types of security vulnerabilities in complex codebases spanning 20 programming languages. The results showed that the model represents a major advance over Google's previous models, with its vulnerability-discovery success rate exceeding 70%.

Google launches Gemini 3.8 Flash Cyber, fully deployed internally for code security protection

Google said that its core objective in developing Gemini 3.8 Flash Cyber was to give defenders professional-grade capabilities, enabling them to gain the upper hand against attackers. For this reason, Google focused on vulnerability remediation from the outset and prioritized this capability over offensive techniques such as vulnerability exploitation.

In the CWE-Bench test, Gemini 3.8 Flash Cyber remained on the Pareto Frontier: its Pass@1 accuracy reached 47.2%, close behind the leading frontier model's 47.8%. At the same time, its inference cost was significantly lower, achieving an excellent balance between performance and cost.

Google launches Gemini 3.8 Flash Cyber, fully deployed internally for code security protection

Google said that Gemini 3.8 Flash includes comprehensive safety mechanisms. While supporting compliant, beneficial use cases, it strictly guards against misuse in the areas of chemical, biological, radiological, and nuclear weapons (CBRN), as well as cyberattacks.

By contrast, Gemini 3.8 Flash Cyber moderately relaxes policy-based blocking restrictions in the cybersecurity domain, so it is available only to compliant security teams that require more comprehensive cyber defense and offense capabilities.

Google has now fully deployed Gemini 3.8 Flash Cyber internally for code security protection. The following are specific deployment examples:

The Chrome security team found in its evaluation that, for security vulnerabilities in the Chrome browser, 3.8 Flash Cyber generated 2.6 times as many valid patches as leading commercial models, even though those leading commercial models have significantly more parameters.

Evaluations by security firm Wiz showed that, in its internal benchmark, Gemini 3.8 Flash Cyber achieved a 7.5%-9.7% higher recall rate than other leading frontier models, while its inference cost fell significantly to between 1/5.2 and 1/2.3 of the original cost.

Using the 3.8 Flash Cyber model, Google's cloud vulnerability research team successfully discovered a critical underlying architecture vulnerability in less than 2 hours. Previously, researching and investigating vulnerabilities of this kind typically took several months.