All posts

Blog

Google launches Gemini 3.8 Flash and 3.8 Flash Cyber, its third Flash model in six weeks

FindAmNow
googlegeminicoding-agentscybersecurityantigravity

Google introduced Gemini 3.8 Flash and Gemini 3.8 Flash Cyber on 2 September 2026, its third Flash release in six weeks, with the same introductory API price as 3.7 Flash and a restricted Cyber variant for trusted defenders.

Google announced Gemini 3.8 Flash and Gemini 3.8 Flash Cyber on 2 September 2026 as its third Flash release in six weeks, following Gemini 3.7 Flash from three weeks earlier. In the company blog, Tulsee Doshi and Raluca Ada Popa call Gemini 3.8 “our best reasoning & coding model yet, at the same speed and low cost of 3.7.” Both variants share that core. Google says they are accelerated by long-running agentic loops that recursively evaluate and refine the models, with coding and reasoning gains driven in part by cybersecurity training.

Two Flash variants, same introductory price

Gemini 3.8 Flash is the workhorse. Google says it improves on 3.7 Flash across software engineering, agentic tasks, and multi-step reasoning in specialized domains. The Gemini API introductory price matches 3.7 Flash at $0.75 per million input tokens and $3.75 per million output tokens. That rate expires on 31 December 2026; from 1 January 2027 the listed price is $1.50 per million input tokens and $7.50 per million output tokens.

Gemini 3.8 Flash Cyber is the cybersecurity variant for vulnerability detection and automated patching. Access for trusted defenders is through Google’s new Fairwind Program, which the post says will prioritize government authorities, critical infrastructure operators, and software maintainers.

The Gemini 3.8 Flash model card, published 2 September 2026, lists a context window of up to 1M tokens for text, images, audio, and video, and 64K tokens of text output. It describes the model as based on Gemini 3.7 Flash, with customizable effort levels for quality, cost, and latency, and notes that the model may use more tokens at higher effort levels.

Coding, agents, and extra work on hard tasks

Google says 3.8 Flash “works harder”: on complex tasks it runs extra reasoning steps and calls tools iteratively. For compute-constrained applications, developers can use lower effort levels or keep using Gemini 3.7 Flash, which “remains fully supported for efficiency-first workloads.”

On DeepSWE v1.1 (long-horizon software engineering), Google says 3.8 Flash outperforms most larger frontier models at a fraction of the cost. It also cites gains versus 3.7 Flash and other frontier models on Vals Finance Agent V2 and Harvey’s Legal Agent Benchmark, and a 54.9% score on HLE-Verified for multi-step reasoning across STEM, humanities, and professional fields.

Ars Technica independently recorded the third-Flash-in-six-weeks framing, the two variants, and the introductory and post-2026 API prices.

Flash Cyber: discovery, patches, and Google’s own code

Google reports frontier-level autonomous vulnerability discovery on CyberGym versus 3.5 Flash Cyber and larger models. On an internal benchmark spanning 20 programming languages, it says the model exceeds a 70% success rate. Patching is prioritized over exploitation. On Collinear’s CWE-Bench, 3.8 Flash Cyber is described as on the Pareto frontier, with a pass@1 of 47.2% against a leading frontier model at 47.8%, at significantly lower cost.

The Chrome Security team found 3.8 Flash Cyber produced 2.6 times more correct patches for Chrome vulnerabilities than the best commercial models that are much larger. Wiz reported +7.5–9.7% higher recall on an internal penetration-testing benchmark at 2.3–5.2x lower cost than other leading frontier models. Google’s Cloud Vulnerability Research team used the model to find a critical foundational vulnerability in less than two hours.

Safety differs by variant. 3.8 Flash ships with safeguards against misuse in CBRN and cyber offense under Google’s Frontier Safety Framework. 3.8 Flash Cyber has a more permissive cybersecurity mitigation set and is limited to trusted defenders. Google also says Gemini 3.8 models improved prompt-injection robustness as measured by Gray Swan.

Where to get it

Developers can use 3.8 Flash in Google Antigravity, the Gemini API via Google AI Studio and Android Studio, and Stitch for UIs. Enterprises get it in Gemini Enterprise. Google AI Pro and Ultra subscribers get 3.8 Flash in the Gemini app, AI Mode in Google Search, and Gemini in Google Sheets. Fairwind applicants apply through the announcement post.

Source: Introducing Gemini 3.8 Flash and 3.8 Flash Cyber (Google, 2 September 2026). Also used: Gemini 3.8 Flash model card (Google DeepMind, 2 September 2026); Ars Technica (2 September 2026).

Source