Gemini 3.8 Flash Launches with Restricted Cybersecurity Variant
View original source →Google released Gemini 3.8 Flash to general availability on September 2 at competitive pricing, while simultaneously revealing the Fairwind Program — a restricted track that makes a hardened cybersecurity version of the model available exclusively to qualified security researchers and defenders.
Key Points:
• Gemini 3.8 Flash: general availability at $0.75 per million input tokens and $3.75 per million output tokens.
• Gemini 3.8 Flash Cyber (Fairwind Program): restricted to qualified security defenders; achieved 70%+ vulnerability discovery across 20 programming languages; 2.6x more correct patches to Chrome vulnerabilities than the leading commercial models tested; 47.2% pass@1 on CWE-Bench.
• CWE-Bench is a standardized test of whether an AI can correctly identify and fix real-world classes of software vulnerabilities — 47.2% pass@1 means the model got nearly half of tested vulnerabilities right on the first attempt.
• The Fairwind Program requires organizations to qualify as trusted security defenders before access is granted — Google's acknowledgment that a model capable of finding vulnerabilities is equally capable of being used to exploit them.
A model that generates 2.6x more correct security patches than commercial alternatives is a material force-multiplier for understaffed security teams. Gating the cybersecurity version behind a trusted-defender program creates a governance model that purely commercial distribution would not achieve.
Why It Matters: The 2.6x patch quality improvement over commercial alternatives represents a significant capability advantage for security teams, while the restricted access model establishes a governance precedent for dual-use AI capabilities.