$ cat wiki/models/gemini-3-8-flash-cyber.md
Gemini 3.8 Flash Cyber
Spec
| Attribute | Value |
|---|---|
| Developer | Google DeepMind |
| Released | 2026-09-02 (restricted access only) |
| Announced | 2026-09-02 |
| Context window | unknown |
| Pricing | unknown — no public pricing; access is not sold |
| License | proprietary |
| Availability | Restricted — approved Fairwind Program partners only; usable inside CodeMender |
Context window is unknown rather than 1,048,576. Its general-purpose | |
| sibling Gemini 3.8 Flash carries that figure and this model is | |
| described as the same core model behind a different access envelope, but **no | |
| source read states a context window for the Cyber variant**, and inheriting one | |
| from a sibling is exactly the guess the schema forbids. The equivalent row on | |
Gemini 3.5 Flash Cyber reads unknown (Flash-family; likely 1M) — | |
| the hedge in that cell was already the wrong shape and is not repeated here. |
Pricing is unknown in the countable sense: there is no list price because
there is no self-serve route. Google's only cost statement is that CodeMender with
this model runs "at a fraction of the operating cost of traditional frontier
models" — a ratio with no numerator and no denominator
(source).
Release Date
2026-09-02, the same day as Gemini 3.8 Flash and 43 days after Gemini 3.5 Flash Cyber (2026-07-21).
Benchmarks
There are no published numbers for this model. That is the finding, not a gap in this page's research.
| Benchmark | Result |
|---|---|
| CyberGym | "frontier-level performance in autonomous vulnerability discovery", surpassing Gemini 3.5 Flash Cyber and significantly larger frontier models — no score published |
| Internal, 20 programming languages | success rate "exceeding 70%" — Google's own benchmark, not otherwise described |
| Set that against Gemini 3.5 Flash Cyber, which shipped six weeks | |
| earlier with an actual table: 55 Chrome V8 vulnerabilities found, against | |
| 47 for the base Flash and 36 for Claude Opus 4.6, and 10 issues found | |
| by Cyber that neither competitor found | |
| (source). |
The 3.5 Cyber release was more measurable than the 3.8 Cyber release. The claim "surpasses 3.5 Flash Cyber" is therefore made against a model whose numbers are public, by a model whose numbers are not — so the comparison cannot be checked in the direction it is offered. Whether that is deliberate — a capability whose score is itself sensitive — or simply a thinner announcement, nothing read says. It is recorded here because a benchmark that stops being published is a change in the record, and the record is what this wiki keeps.
Use Cases
- Autonomous vulnerability discovery at agentic scale
- Writing and validating code fixes inside CodeMender, run within the partner organisation's own secure cloud environment
- Producing "verified, deployment-ready patches in minutes" (source)
"Verified" and "validate" are the vendor's words. Nothing read describes what the verification consists of, who audits it, or what fraction of generated patches are wrong — which for a system that writes security patches is the number that decides whether it helps.
Access
Not openly deployable. The Fairwind Program is the only route, and it is granted case by case to trusted government and national cyber authorities, critical-infrastructure operators (healthcare networks, energy grids, financial systems, telecommunications) and software maintainers (source).
The approval criteria are not published. "Trusted" and "approved" are the whole of the stated test, which makes the gate an unauditable one — the same structural objection AI Governance already records against capability-gated release generally.
This is the third distinct gating mechanism recorded in four days, and the three are not variants of one design — see AI-Enabled Cyberattacks for the comparison:
- 2026-09-01 — Astra ships with the capability itself withheld (OpenAI)
- 2026-09-02 — this model ships whole, behind an access list (Google DeepMind)
- 2026-08-28 — GLM-5.3's weights ship, behind a licence requiring security review above a revenue threshold (Z.ai)
Compared To
- Gemini 3.5 Flash Cyber — the direct predecessor; published its benchmark table, where this one does not
- Gemini 3.8 Flash — the general-purpose sibling released the same day
- Astra — the other frontier model gated on cyber capability this week, by a different mechanism
- GLM-5.3 — gated on the same capability again, by a third mechanism