AssuredBox

Google DeepMind Launches Gemini 3.8 Flash and 3.8 Flash Cyber for AI Agents and Secure Code

Google DeepMind Launches Gemini 3.8 Flash and 3.8 Flash Cyber for AI Agents and Secure Code

RELEASED DATE: 2 September 2026

8 Minutes Read

[Source: Made by Assuredbox Team.]

Google DeepMind has introduced Gemini 3.8 Flash and Gemini 3.8 Flash Cyber, two new versions of its Gemini family designed around a clear direction: making AI agents more capable while helping defenders find and fix software vulnerabilities faster. The new models arrive only three weeks after Gemini 3.7 Flash, making this the third Flash release from Google in just six weeks. Google describes Gemini 3.8 Flash as its best reasoning and coding model yet, while Gemini 3.8 Flash Cyber is being positioned as its most capable cybersecurity model for vulnerability discovery and automated patching.

The two models share the same underlying foundational intelligence, but they are designed for different deployment environments. Gemini 3.8 Flash is the broadly available workhorse model for coding, agentic workflows and complex multi-step reasoning, while Gemini 3.8 Flash Cyber is being provided through a restricted program for trusted defenders because it has more permissive cybersecurity safeguards.

Gemini 3.8 Flash Is Built for Longer AI Agent Work

The biggest theme behind Gemini 3.8 Flash is not simply that it can answer questions more accurately. Google is pushing it toward tasks where an AI has to work through a problem over many steps, use tools repeatedly and continue refining its own output.

According to Google, 3.8 Flash delivers significant improvements over 3.7 Flash in software engineering, agentic tasks and difficult multi-step reasoning, while keeping the same speed and introductory pricing as the previous model. Google says the model can execute additional reasoning steps and make iterative tool calls when a task requires more effort. Developers can also choose lower effort levels when token efficiency matters more than maximum performance.

That distinction matters because AI agents behave very differently from traditional chatbots. A chatbot may generate a piece of code in one response, but an agent can inspect a repository, identify a bug, modify several files, run tests, examine the result and make another change. The more reliably a model can handle that loop, the more useful it becomes as a software engineering system rather than just a coding assistant.

Stronger Coding Performance at Flash-Level Cost

Google says Gemini 3.8 Flash performs strongly on long-horizon software engineering tasks and can outperform a number of larger frontier models on DeepSWE v1.1 while operating at a much lower cost. The company also highlights improvements in specialized professional workflows, including finance and legal agent evaluations, along with a 54.9% result on HLE-Verified, a benchmark covering multi-step reasoning across STEM, humanities and professional domains.

Google is also emphasizing that the improvements are not limited to benchmark scores. The company has demonstrated 3.8 Flash generating interactive projects and applications through tools such as Google Antigravity and Google AI Studio. Examples shown by Google include a playable game, a functional DOS-style version of Google Maps, a topographic visualization using real datasets and an interactive hardware visualizer built with Three.js.

These demonstrations point toward a broader shift in Google's AI strategy. Instead of focusing only on text generation, the company increasingly wants Gemini to function as an execution layer that can take an objective and turn it into a working result.

Gemini 3.8 Flash Cyber Takes a Different Approach

Alongside the general-purpose model, Google DeepMind has launched Gemini 3.8 Flash Cyber, specifically designed around cybersecurity tasks. Google describes it as its most capable cybersecurity model, with frontier-level performance in autonomous vulnerability discovery and automated patching.

The model is available through the new Fairwind Program, which gives prioritized access to trusted defenders such as government authorities, critical infrastructure operators and software maintainers. That restricted rollout is deliberate because a model capable of finding security flaws at scale can be valuable to defenders while also creating serious misuse concerns when placed in unrestricted hands.

Finding Vulnerabilities Automatically

One of the most interesting claims from Google is the performance of Gemini 3.8 Flash Cyber on CyberGym, an industry benchmark focused on autonomous vulnerability discovery. Google says the model surpasses Gemini 3.5 Flash Cyber as well as significantly larger frontier models in that evaluation.

Google also tested the model against an internal benchmark covering complex codebases across 20 programming languages. In that evaluation, the company says Gemini 3.8 Flash Cyber achieved a success rate above 70%. While internal benchmarks should naturally be interpreted with some caution, the result illustrates what Google is trying to achieve: moving AI security analysis beyond a narrow set of programming languages and toward larger, messier real-world software environments.

The Model Is Focused on Fixing Code Too

Detecting a vulnerability is only half the security problem. Developers still have to understand the issue, write a patch, test it and make sure the fix does not introduce another problem.

Google says Gemini 3.8 Flash Cyber was deliberately optimized for vulnerability fixing, with an emphasis on defensive capabilities rather than offensive exploitation. On the external CWE-Bench evaluation run by Collinear, Google reports a 47.2% pass@1 score, close to a leading frontier model's 47.8%, while being offered at significantly lower cost.

That is potentially important for software teams because automated patching can shorten the gap between discovering a vulnerability and actually closing it. In large codebases, that gap can become a major security problem when hundreds or thousands of issues have to be triaged manually.

Google Is Already Using 3.8 Flash Cyber

Google says the cybersecurity model is already being used internally to protect its own software. According to the company, Chrome's security team found that Gemini 3.8 Flash Cyber produced 2.6 times more correct vulnerability patches than the best commercial models tested by the team, while Google's Cloud Vulnerability Research team used it to identify a critical foundational vulnerability in less than two hours.

Google also cites results from Wiz, which reported higher recall on its internal penetration-testing benchmark at a lower cost compared with other leading frontier models. These figures are Google's reported results and partner findings, so they should be understood as evidence of the model's current performance rather than proof that every security workflow will see the same improvement.

Why Google Made Cybersecurity a Separate Model

The split between Gemini 3.8 Flash and Gemini 3.8 Flash Cyber says a lot about where AI development is heading.

A general-purpose model needs to be helpful without making dangerous capabilities too easy to misuse. A cybersecurity-focused model, however, needs enough freedom to inspect vulnerable code and help defenders act quickly. Google therefore chose to provide the more permissive cyber capabilities through a trusted-access program instead of making them universally available.

The models also come with different safety configurations. Google says standard 3.8 Flash includes safeguards covering CBRN and cyber offense, while 3.8 Flash Cyber uses more permissive cybersecurity mitigations and is consequently restricted to trusted defenders. Google also reports a significant improvement in prompt-injection robustness across the 3.8 models.

Pricing Keeps Gemini 3.8 Flash Competitive

For developers, another important part of the launch is pricing. Gemini 3.8 Flash is available at the same introductory price as Gemini 3.7 Flash: $0.75 per million input tokens and $3.75 per million output tokens. Google says that introductory pricing runs through the end of 2026, after which the listed rates increase to $1.50 per million input tokens and $7.50 per million output tokens.

Keeping the price unchanged while increasing capability is significant because agentic systems can consume large amounts of tokens. An AI agent may need to reason, inspect files, call tools and repeatedly revise its work, so the economics of each model can matter almost as much as its benchmark score.

Who Can Use the New Gemini Models?

Gemini 3.8 Flash is available to developers through Google Antigravity, the Gemini API in Google AI Studio and Android Studio, as well as to enterprise users through Gemini Enterprise. Google also says the model is available to Google AI Pro and Ultra subscribers in the Gemini app, AI Mode in Google Search and Gemini in Google Sheets.

Gemini 3.8 Flash Cyber has a much narrower distribution. Access is being provided through the Fairwind Program to trusted government authorities, critical infrastructure operators and software maintainers. That means most developers will interact with Gemini 3.8 Flash rather than the cybersecurity-specific model.

Another Sign That AI Is Moving Toward Agents

The release of Gemini 3.8 Flash comes at a time when almost every major AI company is trying to move beyond simple conversational assistants. The goal is increasingly to create systems that can operate inside software environments, use tools, maintain context and complete tasks that may take much longer than a single interaction.

Google's own framing of 3.8 Flash reflects that change. The company isn't presenting it simply as a faster chatbot. It is calling it a workhorse model for agentic workflows and emphasizing long-horizon coding, iterative tool use and complex reasoning.

At the same time, 3.8 Flash Cyber shows another side of the same trend. As agents become better at understanding and changing code, cybersecurity becomes both an opportunity and a risk. A system that can autonomously identify a vulnerability and write a correct patch could dramatically improve defensive security, but the same underlying capability is precisely why access controls and safety systems are becoming more important.

Google's latest release therefore feels less like a routine model-number update and more like another step toward an AI environment where models are expected to act, reason, inspect, modify and improve, rather than simply generate an answer. Gemini 3.8 Flash is aimed at bringing that capability to developers and businesses at scale, while Gemini 3.8 Flash Cyber shows how far the same technology can be pushed when the objective is securing real-world software.

More Related POSTS

Grok Bot is SpaceXAI’s new always-on AI agent that can use apps, remember tasks, work with tools and run jobs autonomously with its own computer.

Anthropic launches Fable 5.1 and Mythos 5.1, bringing stronger coding, scientific research and AI agent capabilities with new safety controls.

Google is moving Gemini Developer API users from standard API keys to auth keys, with a September 30, 2026 deadline to avoid service interruption.

AI has designed functional new bacteriophages in a major biology breakthrough, raising new possibilities for medicine, antibiotics and biosecurity.

OpenAI is ending its Cursor partnership after SpaceX acquired Cursor. Here’s what happened, the November 2026 transition, and what developers need to know.