Google launches Gemini 3.8 Flash and 3.8 Flash Cyber: third Flash release in six weeks targets reasoning, coding and cybersecurity
On September 2, 2026, Google announced Gemini 3.8 Flash and Gemini 3.8 Flash Cyber on its official blog. This is Google's third Flash release in just six weeks — 3.7 Flash launched only three weeks ago, and now 3.8 arrives with stronger reasoning and coding at the exact same introductory price as 3.7. Gemini 3.8 Flash is positioned as 'our most intelligent workhorse model,' delivering significant gains over 3.7 Flash in software engineering, agentic tasks and multi-step reasoning. Gemini 3.8 Flash Cyber is Google's most capable cybersecurity model, reaching frontier-level performance in vulnerability detection and automated patching, available only to trusted defenders through the new Fairwind Program. Both share the same foundational intelligence core, further accelerated by long-running agentic loops that recursively evaluate and refine the underlying models.
First, positioning and pricing. Gemini 3.8 Flash continues the Flash line's 'low price, high speed' approach: the official blog states it delivers 'our best reasoning and coding model yet at the same speed and low cost of 3.7,' with performance that often approaches far more expensive frontier models. On price, 3.8 Flash keeps 3.7 Flash's introductory rate — $0.75 per million input tokens and $3.75 per million output tokens — but that promo pricing expires on December 31, 2026, adjusting to $1.50 input and $7.50 output per million tokens from January 1, 2027. The cadence is a clear signal: Google is using 'more capability, same price' to pressure rivals like OpenAI on the volume-oriented Flash line. Google also notes that developers prioritizing compute efficiency can use lower effort levels to minimize token overhead, or keep relying on the fully supported 3.7 Flash.
On general capability, 3.8 Flash delivers an impressive report card. Official data shows that on DeepSWE v1.1, a benchmark measuring long-horizon software engineering, 3.8 Flash autonomously solves complex engineering problems end to end at a fraction of the cost, outperforming most larger frontier models. It scores 54.9% on HLE-Verifi. In specialized domains requiring advanced analysis and reporting, 3.8 Flash surpasses 3.7 Flash and other frontier models on Vals Finance Agent V2 and Harvey's Legal Agent Benchmark. Google attributes these gains to one core design choice: 3.8 Flash 'works harder.' On complex tasks it executes extra reasoning steps and calls tools iteratively, and at higher effort levels it will even use more tokens to maximize performance. The blog also showcases compelling demos: building a fully playable DOS version of Google Maps from a single prompt in Google Antigravity, and an interactive 3D topographic visualizer of famous sites built from real U.S. Geological Survey datasets.
The other headline is Gemini 3.8 Flash Cyber — Google's most capable cybersecurity model to date. It ships through the new Fairwind Program to trusted government authorities, critical-infrastructure operators and software maintainers, delivering frontier-level vulnerability discovery and automated patching. On CyberGym, the standard industry benchmark for autonomous vulnerability discovery, 3.8 Flash Cyber surpasses both 3.5 Flash Cyber and significantly larger frontier models. On Google's comprehensive internal benchmark spanning complex codebases in 20 programming languages, it shows an impressive leap over previous models. Google stresses that it invested in vulnerability fixing from the start, prioritizing it over offensive capabilities like exploitation: on CWE-Bench, run by Collinear and widely recognized as a challenging external benchmark for patching, 3.8 Flash Cyber reaches the Pareto frontier with a pass@1 of 47.2%, just below a leading frontier model's 47.8% — at a significantly lower cost. Defenders get near-frontier patching at Flash-level pricing.
What is most telling is Google's own dogfooding results. The Chrome Security team found that 3.8 Flash Cyber produced 2.6 times more correct patches to Chrome vulnerabilities than the best commercial models that are much larger. Cloud security firm Wiz measured +7.5 to +9.7 percentage points higher recall on its internal penetration-testing benchmark versus other leading frontier models, at 2.3x to 5.2x lower cost. Google's Cloud Vulnerability Research team used 3.8 Flash Cyber to find a critical foundational vulnerability in under two hours — research and discovery that usually takes months. On safety design, 3.8 Flash ships with safeguards against misuse in CBRN (chemical, biological, radiological, nuclear) and cyber-offense domains per Google's Frontier Safety Framework; 3.8 Flash Cyber carries a more permissive set of mitigations for cybersecurity and is therefore limited to trusted defenders needing comprehensive cyber capabilities. According to Gray Swan, the 3.8 family also made a significant leap in prompt-injection robustness. On the consumer side, 3.8 Flash is available to Google AI Pro and Ultra subscribers across the Gemini app, AI Mode in Google Search, and Gemini in Google Sheets.
For developers, enterprises and everyday users, this launch sends several clear signals. First, 'three Flashes in six weeks' shows Google is using the Flash line as its main weapon in an attrition war with rivals — every price-increase window is deliberately deferred, continuously raising the value-for-money bar with 'stronger at the same price.' Second, the Cyber variant follows a 'same model, different tiers' path similar to Anthropic's Mythos: wrapping the strongest capabilities into a dedicated program (Fairwind) for trusted defenders, addressing safety-regulator concerns while seeding Google's own security product ecosystem. Third, real-world numbers from Chrome, Wiz and the Cloud Vulnerability Research team show these models have evolved from 'good on lab benchmarks' to 'usable in real attack-defense work' — the human-efficiency ratio of the cybersecurity industry is being redefined. Worth watching next: which organizations gain access through Fairwind, the stability of 3.8 Flash in real long-running coding projects, and how OpenAI's GPT-5.x line responds to this dual-front competition on price and capability.
📌 Source: Google Official Blog (September 2, 2026) 'Introducing Gemini 3.8 Flash and 3.8 Flash Cyber' (https://blog.google/innovation-and-ai/models-and-research/gemini-models/3-8-flash-and-3-8-flash-cyber/). All figures, benchmark scores and statements are based on this official post.
🤔 Frequently Asked Questions
Q1: What is the difference between Gemini 3.8 Flash and 3.7 Flash?
3.8 Flash is Google's 'best reasoning and coding model yet,' significantly improved over 3.7 Flash in software engineering (beating most larger frontier models on DeepSWE v1.1), agentic tasks and specialized multi-step reasoning (54.9% on HLE-Verifi, Vals Finance Agent V2, Harvey's Legal Agent Benchmark), while keeping the same speed and introductory price. 3.7 Flash remains fully supported for efficiency-first workloads.
Q2: What is the pricing for the Gemini 3.8 family?
3.8 Flash matches 3.7 Flash pricing: an introductory rate of $0.75 per million input and $3.75 per million output tokens through December 31, 2026; from January 1, 2027 it adjusts to $1.50 input and $7.50 output per million tokens. It is available via the Gemini API, AI Studio, Android Studio and more.
Q3: Who can use Gemini 3.8 Flash Cyber?
3.8 Flash Cyber is available only to trusted defenders through the Fairwind Program — vetted government authorities, critical-infrastructure operators and software maintainers. Because it carries more permissive cyber mitigations, Google vets applicants; it is not open to general developers or the public.
Q4: How can ordinary users access 3.8 Flash now?
Developers can use it via the Gemini API (AI Studio, Android Studio) or agent-first tools like Google Antigravity; enterprises access it in Gemini Enterprise. For individuals, 3.8 Flash is available to Google AI Pro and Ultra subscribers across the Gemini app, AI Mode in Google Search, and Gemini in Google Sheets.
🛠️ Recommended Tools
- Text Summarizer - Quickly distill key points from Google announcements and benchmark deep-dives to stay on top of model capability shifts
- JSON Formatter - Organize and analyze API pricing and model parameter JSON data for clarity
- Timestamp Converter - Convert announcement timelines and promo deadlines (like the January 1, 2027 price change) for clearer API budget planning
Placed in a longer timeline, Gemini 3.8 Flash means far more than 'another new model.' It proves that a low-price, high-volume product line can carry frontier capability: beating most larger frontier models on DeepSWE v1.1 and reaching a Pareto-frontier pass@1 of 47.2% on CWE-Bench, while pricing anchors below one dollar per million tokens — 'capability for everyone' and 'cost control' are no longer an either-or choice. For developers, this means attempting long-horizon coding and agentic tasks at Flash prices that previously required flagship models. For the security industry, 3.8 Flash Cyber's real-world results in the hands of Chrome, Wiz and Google Cloud's vulnerability research team herald an AI-driven defense-efficiency revolution. To be sure, reliability behind high-frequency iteration, Fairwind's access bar, and the chain reaction on rivals like OpenAI still need time to play out. But one thing is already clear: Google is sharpening the Flash line into one of the most cutting weapons in AI competition, on a cadence of one release every two weeks.
Summary
On September 2, 2026, Google launched Gemini 3.8 Flash and Gemini 3.8 Flash Cyber — its third Flash release in six weeks. 3.8 Flash is the newest, most capable workhorse: it outperforms most larger frontier models on the DeepSWE v1.1 long-horizon software engineering benchmark, scores 54.9% on HLE-Verifi, beats prior models on Vals Finance Agent V2 and Harvey's Legal Agent Benchmark, and keeps 3.7 Flash's introductory price ($0.75/M input, $3.75/M output, moving to $1.50/$7.50 on January 1, 2027). 3.8 Flash Cyber ships to trusted defenders via the Fairwind Program: it surpasses 3.5 Flash Cyber and larger frontier models on CyberGym, and reaches a Pareto-frontier pass@1 of 47.2% on CWE-Bench vulnerability patching (versus 47.8% for a leading frontier model, at significantly lower cost). Chrome's security team found it produced 2.6x more correct patches than much larger commercial models; Wiz measured +7.5-9.7pp recall at 1/2.3 to 1/5.2 the cost; Google Cloud's vulnerability research team found a critical foundational vulnerability in under two hours — work that usually takes months. On safety, 3.8 Flash guards against CBRN and cyber-offense misuse per the Frontier Safety Framework, while 3.8 Flash Cyber's more permissive mitigations limit it to trusted defenders; prompt-injection robustness improved sharply per Gray Swan. Consumers get 3.8 Flash via Google AI Pro/Ultra (Gemini app, AI Mode, Sheets). The launch shows Google pushing its low-cost Flash line to new heights of frontier capability and real-world security impact — with a faster cadence, at the same price.