On September 2, 2026, Google launched Gemini 3.8 Flash (general) and Gemini 3.8 Flash Cyber (defenders-only via the new Fairwind Program). Same foundational intelligence, different mitigations and access. Chrome-team claim: 2.6× more correct patches than larger commercial models (company-attributed). Intro Flash price $0.75 / $3.75 per million tokens through December 31, 2026. Flash Cyber is not a generally available API SKU.

What the video shows

NONE. No YouTube from the last 14 days was verified with a title that honestly covers both the 3.8 Flash public drop and the Fairwind / Flash Cyber access gate. Prefer no embed; revisit only if Google or a careful trade channel posts a Fairwind-explicit segment.

What’s new

Google’s own post is the clean primary: third Flash release in a short window, two named variants, shared core, different deployment boundaries. 3.8 Flash is positioned for long-horizon coding and autonomous agents, with company claims of large gains over 3.7 Flash on software-engineering and specialized agent benchmarks. 3.8 Flash Cyber is positioned for autonomous vulnerability discovery and patching, with more permissive cybersecurity mitigations — which is exactly why Google restricts who may use it.

Fairwind is the access product. Google’s get-started bullets put developers, enterprises, and consumers on Flash paths (Antigravity, Gemini API / AI Studio, Gemini Enterprise, Gemini app for Pro/Ultra, etc.). Cyber is a separate apply-for-access line for trusted government authorities plus critical infrastructure operators and software maintainers.

Do not drag Friday’s Meta Muse Spark 1.3 brief back into the lead. Same-week model noise is background at most; this piece stays on Google’s dual-SKU and the Fairwind gate.

Evidence

Product split (Google blog). Gemini 3.8 Flash: general intelligent workhorse; same intro price as 3.7 Flash at $0.75 / $3.75 per million tokens. Gemini 3.8 Flash Cyber: “most capable cybersecurity model” for vulnerability detection and automated patching, “available to trusted defenders through our new Fairwind Program.” Google states both are powered by the same foundational intelligence; Cyber ships with a more permissive cyber mitigation set and is therefore limited to trusted defenders who need broader cyber capability. Standard 3.8 Flash ships with stronger safeguards against cyber offense (and CBRN) per Google’s Frontier Safety Framework language.

Company-reported cyber results (attribute). Google says Chrome Security found 3.8 Flash Cyber produced 2.6 times more correct patches to Chrome vulnerabilities than the best commercial models that are much larger; Wiz reported higher recall on an internal pen-test benchmark at lower cost; Google Cloud Vulnerability Research used the model to find a critical foundational vulnerability in less than two hours (company narrative). On external-ish benches Google cites CyberGym leadership for vuln discovery and CWE-Bench pass@1 of 47.2% near a leading frontier model at 47.8% with lower cost framing — all still vendor-presented numbers.

Price clock (Flash). Footnote on Google’s post: introductory price expires December 31, 2026; from January 1, 2027, $1.50 / $7.50 per million input/output tokens apply. That schedule is for the public Flash listing language — not a published Fairwind Cyber rate card in the same post.

Secondary trade press. 9to5Google and SiliconANGLE repeat the dual launch and Fairwind gate; SiliconANGLE adds color on CodeMender as a harness and early Fairwind participants. Prefer Google’s eligibility wording when secondary counts or logos get ahead of the primary post.

What this does not prove

  • It does not prove Flash Cyber is generally available via the Gemini API. Fairwind application is the documented front door.
  • It does not prove the 2.6× Chrome result is an independent public bake-off. It is a Google-attributed Chrome Security finding.
  • It does not prove Cyber is “safer” in every sense. Google describes more permissive cyber mitigations for defenders — capability gating, not a universal safety halo.
  • It does not prove you should rip out existing vuln tooling tomorrow. Launch claims are starting evidence; production IR still needs human verification and change control.
  • It does not reopen the Muse Spark 1.3 story. Different vendor, already covered Friday.

Why it matters

Access policy is becoming part of the model card. Google is not only shipping a faster Flash; it is drawing a bright line between a public coding workhorse and a cyber-capable twin that only vetted defenders should hold. That pattern — also visible across the industry’s various “verified defender” programs — is the operational takeaway for CISOs and platform owners: which SKU are you actually allowed to call, under what contract, with which mitigations stripped?

For builders, 3.8 Flash’s intro pricing and agentic positioning are the near-term levers. For security teams, Fairwind eligibility and CodeMender-style harness talk matter more than a leaderboard screenshot. For editors, the failure mode is a headline that says “Google launches cyber Gemini” without saying who can run it.

What to watch next

  1. Fairwind admissions and refusals — who gets in, what contractual controls look like, whether a public Cyber model ID ever appears.
  2. Independent patch/vuln evaluations outside Google-relayed Chrome / Wiz / internal benches.
  3. Jan 1, 2027 price step-up for Flash — whether intro rates stick in promo form or hard-cut.
  4. Mitigation documentation — clearer public detail on what “more permissive cyber mitigations” allow and forbid in practice.

Bottom Line

Gemini 3.8 Flash is the public workhorse with a dated intro price. Gemini 3.8 Flash Cyber is the real cyber sibling — and Fairwind is who gets it. Same core intelligence story from Google; different gate, different mitigations. Do not architect as if Cyber were a checkbox in AI Studio for everyone.

Sources