LIVE
+++ Pentagon Adds ChatGPT and Grok to GenAI.mil Platform +++ US Justice Department backs OpenAI in NYT copyright case +++ OpenAI delays Astra after the Hugging Face breach +++ OpenAI Hit With 30 New Tumbler Ridge Shooting Suits +++ Nvidia to buy Hugging Face for $12.93 billion +++ Microsoft: more memory chips won't fix AI bottleneck ++++++ Pentagon Adds ChatGPT and Grok to GenAI.mil Platform +++ US Justice Department backs OpenAI in NYT copyright case +++ OpenAI delays Astra after the Hugging Face breach +++ OpenAI Hit With 30 New Tumbler Ridge Shooting Suits +++ Nvidia to buy Hugging Face for $12.93 billion +++ Microsoft: more memory chips won't fix AI bottleneck +++
All news ›
AI IN LIFE AI IN LIFENEWS
DAILY
DE EN
MODELS

Google launches Gemini 3.8 Flash and a Cyber variant

The general-purpose model starts at $0.75 per million input tokens, while the security-tuned Cyber version stays limited to vetted defenders.

Google launches Gemini 3.8 Flash and a Cyber variant

Symbolic image: in a night-shift operations center, a person tracks abstract analysis graphics across several screens while indicator lights blink on server racks behind glass.

Google released Gemini 3.8 Flash for general reasoning and coding on September 2, 2026, alongside Gemini 3.8 Flash Cyber, a security variant handed only to vetted defenders through its Fairwind Program.

At a glance

  • Introductory pricing through Dec. 31, 2026: $0.75 per million input tokens, $3.75 per million output tokens.
  • After that, rates rise to $1.50 input and $7.50 output per million tokens.
  • HLE-Verified: 54.9 percent. CWE-Bench patching: 47.2 percent pass@1.
  • Google claims a success rate above 70 percent finding real vulnerabilities across 20 programming languages.
  • Chrome security reports 2.6 times as many correct patches as commercial rivals.

Google introduced Gemini 3.8 Flash and Gemini 3.8 Flash Cyber on September 2, 2026. The split matters: the general model ships broadly, while Flash Cyber is gated behind the Fairwind Program and reserved for vetted defenders, government authorities and critical infrastructure operators.

Pricing

Gemini 3.8 Flash launches at $0.75 per million input tokens and $3.75 per million output tokens. Those are introductory rates that hold through Dec. 31, 2026. Both figures then double, to $1.50 and $7.50.

Where it runs

The announcement lists Google Antigravity, AI Studio, Android Studio, the Gemini API, Gemini Enterprise, AI Mode in Search and Google Sheets. Inside the Gemini app, access starts with Pro and Ultra subscribers.

The benchmark claims

Google reports 54.9 percent on HLE-Verified and 47.2 percent pass@1 on CWE-Bench patching. It puts real-world vulnerability discovery above a 70 percent success rate across 20 programming languages, and says the Cyber model clears its 3.5 Flash Cyber predecessor on CyberGym. Prompt-injection robustness is credited to Gray Swan testing.

What partners report

Chrome's security team is cited as seeing 2.6 times as many correct patches as commercial competitors. Security vendor Wiz reportedly gained 7.5 to 9.7 percent in recall at 2.3 to 5.2 times lower cost. A Google Cloud Vulnerability Research team says it surfaced a critical flaw in under two hours, against a normal timeline of months.

The unverified part

Every figure above comes from Google's own post. Independent coverage from other newsrooms could not be retrieved for this piece, and no third party has published a check of the benchmark setups. The announcement also does not state the model's context window.

◈ AI-GENERATED REPORT · SOURCES LINKED

FAQ

How much does Gemini 3.8 Flash cost?

Through Dec. 31, 2026 it is $0.75 per million input tokens and $3.75 per million output tokens. Afterward the rates go to $1.50 and $7.50.

Who can use Gemini 3.8 Flash Cyber?

Access runs through the Fairwind Program and is limited to vetted defenders, government authorities and critical infrastructure operators, for defensive work only.

How well does the model find security flaws?

Google cites a success rate above 70 percent on real vulnerabilities across 20 programming languages and 47.2 percent pass@1 on CWE-Bench patching. None of it is independently verified.