Google's cheap Gemini 3.8 Flash matches bigger models, but gates the cyber version
Google released Gemini 3.8 Flash and a security-focused variant called Gemini 3.8 Flash Cyber, the third Flash update in six weeks. The general model is pitched as a cheap workhorse, and the price is the headline: $0.75 per million input tokens and $3.75 per million output tokens during an introductory period that runs to the end of 2026, after which it doubles. Google says the model beats most larger frontier models on DeepSWE v1.1, a long-horizon software engineering benchmark, and scores 54.9% on HLE-Verified for multi-step reasoning. It also tops finance and legal agent benchmarks from Vals and Harvey. The pitch is straightforward: agent-grade capability at a small model's cost.
The more interesting release is Flash Cyber. Google reports it clears 70% on internal real-world vulnerability benchmarks across 20 programming languages, and 47.2% pass@1 on CWE-Bench patching at a fraction of the cost of rivals. The Chrome Security team says it produced 2.6 times more correct patches than commercial alternatives. Unlike the general model, which ships through AI Studio, the Gemini app, and Google Cloud, Flash Cyber is gated behind a new Fairwind Program limited to vetted defenders, government bodies, and critical infrastructure operators. The same capability that finds bugs to fix can also find them to exploit, which is why Google is keeping the strongest version restricted.
Why it matters
If you run coding or security agents, a model this cheap that matches larger ones changes what you can afford to run continuously. But the strongest bug-finding version is gated, so defenders who don't qualify for Fairwind will not get the tool that attackers building on their own models are already assembling.