Connect with us

NEWS

Google Releases Gemini 3.8 Flash and Locks the Cyber Build

Gemini 3.8 Flash is the third Flash drop in six weeks, priced like 3.7 but hungrier on tokens, with Cyber locked to Fairwind.

Published

on

Google released Gemini 3.8 Flash on September 2, 2026, its third Flash model in six weeks. A second variant, Gemini 3.8 Flash Cyber, goes only to trusted defenders in a new Fairwind Program.

The public model keeps 3.7 Flash’s intro token price. Google says it works harder, and may spend more tokens to do it. Gemini 3.1 Pro is still a preview. Flash Cyber ships with looser cyber safety rails, which is why it never gets a public API key.

A Third Flash Model in Six Weeks

Tulsee Doshi, senior director of product management, and Raluca Ada Popa, Gemini security lead at Google DeepMind, presented both variants on the company blog. They called 3.8 Flash the most intelligent workhorse in the line, built for long-horizon software engineering, agents, and multi-step work in specialist fields, at the same speed and list price as 3.7 Flash.

Google itself framed the drop as the third Flash release in only six weeks, landing three weeks after 3.7 Flash. Both of today’s builds share one core, the post said, then split on where they are allowed to run.

Logan Kilpatrick, a member of technical staff on Gemini and Google AI Studio, led with a coding score rather than a flagship Pro upgrade.

That 73.7% on DeepSWE v1.1 is the figure Google staff chose to put in front. Harnesses move, and a single leaderboard line is not a product review, but it is the claim the launch wanted in the room. Google’s cloud developer table, which uses a different set of tests, is less of a clean sweep.

3.8 FLASH VERSUS 3.7 FLASH, GOOGLE CLOUD TABLE

Evaluation 3.8 Flash 3.7 Flash
Terminal-bench 2.1 90.8% 81.6%
SWE-Bench Pro 61.6% 60.4%
SWE-Atlas 51.9% 48.0%
τ³-bench Banking 38.1% 30.9%
CharXiv (multimodal) 86.2% 84.5%
GDP.pdf 35.0% 34.0%
Humanity’s Last Exam 45.4% 45.7%

The same blog lists 54.9% on HLE-Verified, a different cut of that exam. On the cloud table, unverified HLE ticked down. Coding and agent rows moved up. Google also says 3.8 Flash beats 3.7 Flash and other frontier models on Vals Finance Agent V2 and Harvey’s Legal Agent Benchmark, without putting those scores in the developer table.

Consumers with Google AI Pro or Ultra get 3.8 Flash in the Gemini app, AI Mode in Search, and Gemini in Sheets. Developers get it in the Gemini API, Google AI Studio, Antigravity, and Gemini Enterprise. The model id is gemini-3.8-flash. It is generally available, not a preview.

The Same Sticker Price Hides a Heavier Token Bill

The pitch is familiar: frontier-ish coding at Flash money. The fine print is in Google’s own words. “3.8 Flash works harder,” the launch post said. On hard tasks it takes extra reasoning steps and calls tools again and again. “At times, the model might use more tokens to maximize performance, especially at higher effort levels.”

Google Cloud’s developer guide is blunter. It says 3.8 Flash delivers better accuracy and more reliable runs at the cost of higher token consumption than 3.7 Flash. Thinking levels (low, medium, high, with medium as the default) are the dial. For jobs where compute cost is the limit, the same page tells teams to stay on 3.7 Flash, which remains fully supported.

That is the cheap-model trick in one paragraph. The intro rate matches 3.7 Flash. The new build is designed to think longer. A shop that switches the model id and leaves effort on high can pay more for the same sticker.

GEMINI 3.8 FLASH TOKEN PRICE

  • Intro input: $0.75 per million tokens through December 31, 2026.
  • Intro output: $3.75 per million tokens in the same window, with thinking tokens billed as output.
  • Standard rate: $1.50 input and $7.50 output per million tokens from January 1, 2027, a clean doubling.
  • Escape hatch: 3.7 Flash stays on sale for teams that want the lighter token bill.

Rivals have been cutting token prices to keep businesses on the hook. Google’s move is to hold the intro rate through the end of the year and warn, in the same breath, that the new workhorse may chew more of those cheaper tokens. First-look coding sessions already split. Some people found everyday code work better. Others did not see an automatic step up on every harness, which is what you would expect when the official guide still points efficiency-first teams backward one version.

Gemini 3.1 Pro Remains a Preview

The Flash line is now the one that ships. Google Cloud’s family table still lists Gemini 3.1 Pro as gemini-3.1-pro-preview. Launch stage: Preview. Default thinking: high. Regions: Global only, not the multi-region footprint Flash already has.

GEMINI 3 FAMILY, CLOUD SPEC SHEET

Model Model ID Stage Default thinking Regions
Gemini 3.8 Flash gemini-3.8-flash GA Medium Global, multi-region
Gemini 3.7 Flash gemini-3.7-flash GA Medium Global, multi-region
Gemini 3.1 Pro gemini-3.1-pro-preview Preview High Global

Context window and max output match across the three rows: 1,048,576 input tokens and 65,536 output tokens. Inputs are text, image, audio, and video. Output is text. Flash is no longer the thin sibling on paper. It is the GA product with the same long context as Pro, a lower default thinking level, and a ship clock Pro does not have.

Google Cloud describes Flash as the primary agentic workhorse in the Gemini 3 family, sitting between deep-reasoning Pro models and high-throughput Flash-Lite. After three Flash drops in six weeks, that sentence reads less like positioning and more like the org chart. Temperature, top_k, and top_p are ignored. Teams coming from 3.6 or 3.7 have to swap thinking_budget integers for the thinking_level enum. The migration path is Flash to Flash. Nobody is being walked over to 3.1 Pro.

Why Is Gemini 3.8 Flash Cyber Locked Down?

Flash Cyber is the other half of the launch, and it is not a second API SKU. It replaces the 3.5 Flash Cyber gated build. Google says it is tuned for vulnerability detection and automated patching, and that it shares the same foundational intelligence as the public model. The split is safety, not size.

3.8 Flash Cyber ships with a more permissive set of mitigations for cybersecurity, and as such, is only available to trusted defenders who require a more comprehensive set of cyber capabilities.

Tulsee Doshi and Raluca Ada Popa, Google DeepMind launch post

The public 3.8 Flash keeps safeguards against misuse in chemical, biological, radiological, nuclear, and cyber-offense work, the same post said, under Google’s Frontier Safety Framework. Cyber gets a looser cyber rule set on purpose. That is the reason there is no self-serve key. It is also why a three-week public cadence and a government-only twin should not be read as one product with two names.

Google’s security numbers are almost all in-house or from named partners running private tests. Collinear’s CWE-Bench is the external patching board Google chose to cite.

FLASH CYBER SCORES GOOGLE PUT ON THE RECORD

Test Result Who ran it
Correct Chrome patches 2.6 times more than the best larger commercial models Chrome Security team
Critical foundational bug Found in less than 2 hours, work that Google says usually takes months Google Cloud Vulnerability Research
Internal discovery set Success rate exceeding 70% across 20 languages Google internal benchmark
CWE-Bench pass@1 47.2%, against 47.8% for a leading frontier model, at lower cost Collinear
Wiz pentest recall 7.5 to 9.7 percent higher recall, 2.3 to 5.2 times lower cost Wiz

CyberGym is called frontier-level against 3.5 Flash Cyber and larger models. Google did not print an absolute CyberGym number in the launch post. The company says it invested in fixing bugs rather than exploitation. That claim sits next to the other one: the cyber build is more permissive, so only “trusted defenders” may hold it.

Fairwind Puts a Badge on the Dual-Use Build

Fairwind is the access layer. Four Flynn, vice president for security and privacy, said the program is limited to governments and trusted partners and pairs Gemini 3.8 Flash Cyber with Google’s CodeMender harness, so defenders can find, verify, and fix bugs inside their own cloud. Flynn’s post says verified, deployment-ready patches can come in minutes instead of weeks of hand repair. That is Google’s timing, not an independent clock.

Google lists more than 650 participating partners globally. It does not publish a country list. The public model is global and multi-region. The cyber model is an application form.

WHO FAIRWIND SAYS IT WILL TAKE FIRST

  • Governments: National cyber authorities hardening public networks and citizen services.
  • Operators: Healthcare, telecoms, energy, and finance networks that cannot go down.
  • Platforms: Core software maintainers whose patches land on millions of downstream users.
  • House rules: Access limited to internal cyber, incident-response, or pentest staff, with multi-factor authentication.

Partners agree to those operational limits. Google says it will add partners over time and that it is trying to balance open access against security. The same Fairwind post leaves a side door open: any Google Cloud customer can run CodeMender on publicly available Gemini models in Gemini Enterprise, without the Cyber checkpoint. The gated weights are the scarce object. The harness is not.

Google.org’s wider cyber spend is now more than $100 million. A 2026 US impact note attached to the Fairwind launch cites $36 million for 35 cyber clinics and free help for over 1,250 hospitals, school districts, and municipal utilities. That money is adjacent to Fairwind, not a substitute for saying which governments hold the looser model.

Brussels Gets a Filing With Each Flash Launch

In the EU, a general-purpose model placed on the market is a compliance event, not a blog post. Article 53 of the AI Act requires technical documentation, a copyright policy, and a public summary of training content, plus information for downstream providers. Google is on the Commission’s published list of Code of Practice signatories. It signed on July 30, 2025. Meta does not appear on that list. The Code was published on July 10, 2025. The Commission and the AI Board have called it an adequate voluntary tool for showing compliance.

The systemic-risk tier is a shorter fuse. A model presumed to have high-impact capabilities (training compute above 10^25 floating point operations) must be notified to the Commission without delay, and in any event inside the two-week systemic risk notice window under Article 52. Google’s own gap between 3.7 Flash and 3.8 Flash was three weeks. That window is shorter than this cadence. Whether any Flash model crosses 10^25 is not public. Google has not said. Flash models are smaller than Pro by design, and the presumption turns on training compute, not on DeepSWE.

THE RELEASE AND FILING CLOCK

  1. July 10, 2025: The Commission publishes the General-Purpose AI Code of Practice.
  2. July 30, 2025: Google signs the Code; Meta is absent from the signatory list.
  3. August 2, 2025: GPAI provider duties under the AI Act enter application.
  4. September 2, 2026: Gemini 3.8 Flash goes GA; Flash Cyber opens only through Fairwind.
  5. December 31, 2026: The $0.75 / $3.75 intro rate expires.
  6. January 1, 2027: Standard API pricing becomes $1.50 / $7.50 per million tokens.

Article 53 still attaches to every GPAI model that is placed on the market, including a workhorse that Google is now shipping on a three-week rhythm. The Transparency and Copyright chapters of the Code are the paperwork track for that baseline. The Safety and Security chapter is only for the small set of systemic-risk models under Article 55. xAI signed only that last chapter and must show transparency and copyright compliance another way.

WHAT WE KNOW

  • Baseline duties: Documentation, copyright policy, and a public training-data summary apply to each GPAI model on the EU market.
  • Google’s posture: It is a Code of Practice signatory and is shipping Flash as a generally available global product, including multi-region.
  • Cyber distribution: Flash Cyber is request-only, with looser cyber mitigations and no public token price on the launch pages.

WHAT IS UNCONFIRMED

  • Compute tier: Google has not published training FLOP for 3.8 Flash or Flash Cyber, so the 10^25 presumption is untested in public.
  • Notice: There is no public record in the launch material of an Article 52 notification for this drop.
  • Governments: Fairwind does not name the states that hold the permissive cyber build.

Google still sells 3.7 Flash for teams that want the lighter token burn. The cyber build stays behind the Fairwind form, with looser rails and a partner list that stops at “more than 650” and a category of government.

Frequently Asked Questions

What Compute Level Makes a Model GPAI Under EU Guidance?

Commission guidelines treat a model as general-purpose AI when training compute exceeds 10^23 floating point operations and the model can generate language (text or audio), text-to-image, or text-to-video, and handle a wide range of distinct tasks. That 10^23 line is the identification test. The 10^25 line is a separate, higher presumption of systemic risk.

Can a Provider Fight the 10^25 Systemic Risk Label?

Yes. In the Article 52 notification, the provider may argue that even if training compute meets 10^25 FLOP, the model does not have capabilities matching the most advanced models, or that it does not present systemic risks for other reasons. The Commission can also designate a model as systemic risk on its own if it learns of one that was not notified.

Does Flash Cyber Have a Public Token Price?

Google has not published a public input or output price for Gemini 3.8 Flash Cyber on the launch pages. Access is an application to the Fairwind Program, not a self-serve API id like gemini-3.8-flash. The $0.75 / $3.75 intro rate is the public Flash price only.

Can You Use CodeMender Without Joining Fairwind?

Yes. Flynn’s Fairwind post says any Google Cloud customer can use CodeMender with publicly available models hosted on the Gemini Enterprise Agent Platform, together with Google’s AI Threat Defense tools. Fairwind is the gate for 3.8 Flash Cyber weights, not for the patching harness itself.

Which Frontier Lab Signed Only Part of the Code of Practice?

xAI signed up to the Safety and Security chapter only. The Commission’s signatory page says that means xAI must show it meets the AI Act’s transparency and copyright duties by other adequate means. Google, OpenAI, Anthropic, Amazon, Microsoft, and Mistral AI appear on the full signatory list.

Harry is the editor of COVER 365, an independent publication he owns and runs, and a journalist of ten years who moved from reporting into editing. Anything the site reviews has been used before it is judged. A phone, a car, a game or a piece of travel gear is tested in ordinary conditions, its measured results are set against the maker's specification sheet, and where the two disagree the article says which one to trust and why. No product gets a verdict Harry has not earned by using it. Off the test bench, the same rule of primary evidence applies: business stories come from filings and results, science from the published paper, sports from the governing body's records, and news from statements and transcripts rather than second hand accounts. Coverage runs across technology, auto, gaming, lifestyle and travel as well as news, business, science, sports and entertainment, for readers in every part of the world. Every figure is checked before publication and corrected publicly under a stated policy when wrong. Reader mail is answered at support@cover365.in.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending