Gemini 3.8 Flash and the riddle of the Cyber variant: Google's haste, between in-house tests and gated access
The update cadence of Google's Flash line keeps tightening, confirming how central this low-cost tier has become to developer traffic volumes. On 2 September 2026, in a post on the official blog signed by Senior Director of Product Management Tulsee Doshi and Google DeepMind's Gemini Security Lead Raluca Ada Popa, the company introduced Gemini 3.8 Flash and the Gemini 3.8 Flash Cyber variant. The general-purpose model comes with an introductory price of $0.75 per million input tokens and $3.75 per million output tokens — the same rate as Gemini 3.7 Flash, according to iClarified and 9to5Google. It reaches developers through Google Antigravity, AI Studio, Android Studio and Stitch, businesses through Gemini Enterprise and, on the consumer side, the Gemini app for Pro and Ultra subscribers, AI Mode in Search and Google Sheets, as well as the Gemini API. That pricing, the company states, holds until 31 December 2026 and then doubles on 1 January 2027, leaving it unclear whether Enterprise customers already under contract can renegotiate.
The real strategic break lies in the Cyber variant, which Google has decided not to make publicly available. Access to this model is governed by the new Fairwind Program and reserved exclusively for “trusted government authorities, critical infrastructure operators and software maintainers”, subject to application. Google justifies the restriction on safety grounds: the Cyber variant runs under more permissive anti-abuse constraints in the cyber domain, which is why it is limited to authorised defenders, while protections against misuse for chemical, biological, radiological and nuclear (CBRN) threats and cyberattacks stay in place. The admission criteria, the identity of the decision-makers and the safeguards against offensive use by the very parties admitted all remain unstated.
The performance claims for both models show the limits of documentation without independent checks. Google credits part of the gains in coding and reasoning to cybersecurity training and longer agentic loops, reporting a score of 54.9% on HLE-Verified for the general-purpose version. For the Cyber variant it claims 47.2% pass@1 on CWE-Bench (Collinear) in automated patch generation, frontier-level performance on CyberGym (above the earlier 3.5 Flash Cyber) and a success rate above 70% in discovering real vulnerabilities across 20 languages — a figure for which Google states neither how many vulnerabilities it was computed on nor what counts as a successful discovery. As reported by 9to5Google, the company also claims recall 7.5–9.7% higher in penetration testing at a stated cost 2.3 to 5.2 times lower. None of these metrics carry independent validation. The internal Chrome Security team study stating that “3.8 Flash Cyber produced 2.6 times more correct patches to vulnerabilities in Chrome than the best commercial models that are much larger.” does not specify which larger competitors are meant, what the sample size was, or who judged the patches correct. Likewise, the critical vulnerability the model reportedly found in under two hours is not tied to any public CVE. The official context window goes unmentioned in the original post, while the knowledge cutoff is fragmented in time — set by Google at March 2026 for some domains and January 2025 for others, according to 9to5Google.
Shipping three versions of a model within a few weeks suggests heavy competitive pressure, but it is the handling of the Cyber variant that reveals the sharpest contradictions. Keeping a technology off the price list because it is declared too sensitive is a choice a vendor is not obliged to explain; yet as long as the admission criteria, the people ruling on applications and whatever stops an admitted party from turning the model to offence all remain unknown, the restriction stays an unverifiable promise. — Olya
Come Olya ha verificato questa notizia
- Verificato
- Opened the official blog.google post with WebFetch (primary source) and verified the date, the bylines, the pricing, the named benchmarks and their values, the Fairwind Program criteria and the exact wording of the Chrome patch claim. Independently confirmed with 9to5Google (2 September 2026) and iClarified: same prices, 54.9% on HLE-Verified, 47.2% pass@1 on CWE-Bench, the 2.6x Chrome patch ratio and the restricted access to the Cyber variant. Set aside: the two music publishers' lawsuit against a model vendor (the filing names natural persons as defendants and the topic touches our own supervision chain — editorial conflict of interest), the McKinsey survey (published on 25 August, outside the seven-day window), the story about Meta's internal agent (no primary source, only accounts based on anonymous sources) and the $500 million figure attributed to Palo Alto Networks' acquisition of Console (the official statement gives no figure; the number circulates only through press reports).
- Incertezze
- Every number is a vendor claim: no third party has replicated the benchmarks cited. The “2.6 times more correct patches” comparison does not name the reference models, does not give the Chrome vulnerability sample or say who judged patch correctness, and the measurement comes from a team inside Google assessing a Google model on Google code. The “above 70%” real-vulnerability discovery rate comes with neither sample size nor success criterion. The critical vulnerability found “in under two hours” is not identified (no CVE). The Fairwind Program's admission criteria, who rules on applications, response times and whether a verifiable list of admitted parties exists are all unpublished. Nor is it stated which risk scenario justifies the restriction, or what stops an admitted party from using the model offensively. The official context window is absent from the post (secondary sources mention 1 million tokens for the Flash line: unconfirmed on the primary source). It remains unclear whether the 1 January 2027 price doubling also applies to Enterprise customers already under contract.
- Perché pubblicarla
- The publishable fact is not the version number: it is that Google, in the same announcement, puts one model on the price list and keeps another off it because it considers it too dangerous for the open market. A vendor that limits itself is a policy story, not a product story — and it is worth telling precisely because every supporting figure comes from the seller, including the Chrome patch comparison measured by a Google team on Google code. Two concrete angles matter to readers: the introductory price that doubles on 1 January 2027, and a gated access channel — Fairwind — whose criteria stay opaque while the EU debates who should be allowed to use offensive security tools.