Introducing Gemini 3.8 Flash and 3.8 Flash Cyber
Google has introduced Gemini 3.8 Flash, a faster, lower-cost model designed for long-running coding and agentic workflows, alongside Gemini 3.8 Flash Cyber, a cybersecurity-focused variant for trusted defenders. Both models share the same foundational intelligence and use extended agentic loops to evaluate and refine their work.
The release follows Gemini 3.7 Flash by three weeks and marks Google’s third Flash launch in six weeks. Gemini 3.8 Flash is available at the same introductory price as its predecessor: $0.75 per million input tokens and $3.75 per million output tokens.
A Flash model built for complex work
Gemini 3.8 Flash is positioned as Google’s most intelligent workhorse model, with improvements in software engineering, autonomous agents and multi-step reasoning across specialized fields.
On the DeepSWE v1.1 long-horizon software engineering benchmark, Google says the model outperforms most larger frontier models while operating at a fraction of their cost. It also surpasses Gemini 3.7 Flash and other frontier models on Vals Finance Agent V2 and Harvey’s Legal Agent Benchmark. On HLE-Verified, which measures reasoning across STEM, humanities and professional subjects, Gemini 3.8 Flash achieves 54.9%.
The model’s performance comes partly from doing more work on difficult tasks. At higher effort levels, it may execute additional reasoning steps, make repeated tool calls and use more tokens to improve its results. Developers focused primarily on compute efficiency can select lower effort levels or continue using Gemini 3.7 Flash, which Google says remains supported.
Google’s examples include a playable DOS version of Google Maps, a 3D castle game and scientific visualizations built with real U.S. Geological Survey datasets. In Google AI Studio, Gemini 3.8 Flash can also generate an interactive Three.js hardware visualizer with explorable device layers.
Cybersecurity capabilities for trusted defenders
Gemini 3.8 Flash Cyber is designed specifically for vulnerability discovery and automated patching. It is available through Google’s new Fairwind Program to trusted government authorities, critical infrastructure operators and software maintainers.
On CyberGym, an industry benchmark for autonomous vulnerability discovery, the model demonstrates frontier-level performance and surpasses Gemini 3.5 Flash Cyber as well as significantly larger frontier models. In an internal evaluation spanning complex codebases and 20 programming languages, it achieved a success rate above 70%.
For automated fixes, Gemini 3.8 Flash Cyber reached a 47.2% pass@1 score on Collinear’s CWE-Bench, close to a leading frontier model’s 47.8% result while being offered at a significantly lower cost.
Google says its teams are already applying the model to real security work. Chrome’s security team found that it produced 2.6 times more correct vulnerability patches than the best commercial models that are much larger. Google’s Cloud Vulnerability Research team also used it to find a critical foundational vulnerability in less than two hours.
Access and safeguards
Gemini 3.8 Flash includes safeguards covering cyber offense and chemical, biological, radiological and nuclear risks. The Cyber variant uses more permissive cybersecurity mitigations, which is why Google is limiting it to trusted defenders through Fairwind.
Both models also show improved robustness against prompt injection, according to measurements from Gray Swan.
Developers can access Gemini 3.8 Flash through Google AI Studio, the Gemini API, Android Studio, Google Antigravity and Stitch. Enterprises can use it in Gemini Enterprise, while Google AI Pro and Ultra subscribers can access it through the Gemini app, AI Mode in Google Search and Gemini in Google Sheets.

Comments (0)
to join the discussion
No comments yet
Be the first to share your thoughts!