Google released Gemini 3.8 Flash on 2 September alongside a second model it is not selling to everyone: Gemini 3.8 Flash Cyber, gated behind a programme called Fairwind and open only to trusted government authorities, critical infrastructure operators and software maintainers.
The workhorse
Google calls 3.8 Flash its “most intelligent workhorse model”, aimed at software engineering, agentic tasks and multi-step reasoning. It reports 54.9% on HLE-Verified, and says the model beats its 3.7 predecessor and larger frontier models on DeepSWE v1.1, the Vals Finance Agent V2 evaluation and Harvey’s legal agent benchmark.
Those comparisons are Google’s own. The company names the benchmarks but not, in most cases, the competing scores.

The price doubles at New Year
Introductory pricing is $0.75 per million input tokens and $3.75 per million output. On 31 December 2026 that becomes $1.50 and $7.50 — a straight doubling, disclosed in the launch post rather than buried in a later notice.
Anyone modelling unit economics on the launch price has four months before the number they planned around changes underneath them. That is the most consequential line in the announcement and the easiest one to skim past.
The cyber model is the third this week
Flash Cyber is described as Google’s “most capable cybersecurity model with frontier-level performance in vulnerability detection and automated patching”. Google reports it finds real-world vulnerabilities at above 70% across 20 programming languages, and scores 47.2% Pass@1 on CWE-Bench against a leading model’s 47.8% — behind on accuracy, ahead on cost.
Partners supply the sharper numbers: Chrome’s security team reports 2.6 times more correct patches, Wiz reports 7.5 to 9.7% higher recall at 2.3 to 5.2 times lower cost, and Google Cloud’s vulnerability research group says a critical flaw that normally takes months surfaced in under two hours.
Every one of those figures comes from Google or a Google partner. None has been independently reproduced.

A pattern, not a coincidence
3.8 Flash ships with mitigations against chemical, biological, radiological and nuclear misuse and against cyber offence, under Google’s Frontier Safety Framework. Flash Cyber carries deliberately “more permissive” mitigations — which is the entire reason it is gated.
That is the third vendor in seven days to ship an offensive-capable cyber model behind an access programme rather than an API key. OpenAI classified Astra at its Critical cybersecurity level on 1 September and restricted it to early testers. CrowdStrike launched SafeMind with an offensive model the same day, available through Project QuiltWorks.
Three companies, three gates, no shared standard for what qualifies someone to pass through one.
What to watch
Whether anyone outside these programmes can check the claims. A capability that only vetted parties can access is also a capability only vetted parties can evaluate.