Gemini 3.8 Flash explained: Google's 2026 dual drop and Fairwind

Google shipped public Flash and Fairwind-gated Flash Cyber on 2 September. The story is one core, two access envelopes — not another empty leaderboard.

On 2 September 2026, Google introduced Gemini 3.8 Flash and Gemini 3.8 Flash Cyber: two variants on one shared core, split by safety envelope rather than model size. The official post is by Tulsee Doshi and Google DeepMind’s Raluca Ada Popa.

This is the third Flash drop in six weeks, three weeks after 3.7 Flash. Public Flash keeps 3.7’s introductory price. Flash Cyber is not on a price sheet: it goes to vetted defenders through the new Fairwind program. MarkTechPost called the split one core, two access envelopes.

What shipped Public Flash evals Fairwind Cyber

Two variants, one core

Google says both releases share the same foundational intelligence, refined by long-running agentic loops that recursively evaluate the models. Some coding and reasoning gains are credited to hard cybersecurity training. Weights stay closed; there is no self-hosted path.

01

Gemini 3.8 Flash

The public workhorse for software engineering, agent work, and multi-step reasoning. Gemini API, AI Studio, Antigravity, Android Studio, Gemini Enterprise, and the Gemini app for Pro / Ultra.

02

Gemini 3.8 Flash Cyber

Built for vulnerability discovery and automated patching. Cyber mitigations are more permissive, so it is not sold on the public API.

03

Fairwind

Priority access for government authorities, critical-infrastructure operators, and software maintainers. The Fairwind note also pairs the model with CodeMender for find, verify, and fix.

How to read the public Flash numbers

  1. 1

    The price sheet

    Same intro rate as 3.7 Flash: $0.75 per million input tokens and $3.75 per million output through 31 December 2026. From 1 January 2027 the rate becomes $1.50 / $7.50.

  2. 2

    Scores in prose

    HLE-Verified is 54.9%. DeepSWE v1.1, Vals Finance Agent V2, and Harvey’s Legal Agent are relative wins; the announcement does not publish absolute scores for those benches.

  3. 3

    It “works harder”

    On complex tasks it takes extra reasoning steps and calls tools iteratively; higher effort can burn more tokens. Google says keep 3.7 when compute is the constraint. MarkTechPost notes MINIMAL effort is not supported on 3.8.

54.9%
HLE-Verified (public Flash)
0.75
Intro input $ / 1M tokens
47.2%
CWE-Bench pass@1 (Cyber)

Flash Cyber: find, then patch

Google says it prioritized fixing over exploitation. On CyberGym it claims frontier-level discovery versus 3.5 Flash Cyber and larger models, with no absolute figure. An internal bench across 20 languages reports a success rate above 70%.

Item Public figure How to read it
CWE-Bench (Collinear) 47.2% pass@1 vs 47.8% for a leading frontier model Pareto claim, not first place
Chrome Security 2.6× more correct patches than the best, much larger commercial models Google team figure
Wiz internal pentest +7.5–9.7 pp recall at 2.3–5.2× lower cost Partner bench, not a public board

Google’s own line: 3.8 Flash works harder — extra reasoning steps and iterative tool calls, sometimes more tokens at higher effort.

Same core, different envelope
The split is mitigations and who may use them, not two weight files. Public Flash blocks CBRN and cyber offense; Cyber’s cyber mitigations are looser, so it is gated.
Fix over exploit
The post stresses patches and validation, not exploit development. Cloud Vulnerability Research says it found a critical foundational bug in under two hours, work that usually takes months.
Closed weights
MarkTechPost: no self-hosted or on-prem path. Context window listed as 1,048,576 tokens; max output 65,536.

When the team needs one sketch

After the post, groups usually want one picture: public price and HLE, Cyber’s CWE-Bench, and the Fairwind gate. No extra meeting suite. Open a short space on tidemeet or see how to create a space. For a closed flagship split the same week, read Claude Fable 5.1; for another eval design from the same lab, see DeepMind’s double-blind enclave.

# axis
flash-public → fairwind-cyber → no-self-host

Questions

Is this the same as the on-site DeepMind double-blind eval post?

No. That piece is about an evaluation protocol. This one is the 2 September product split: public Flash and Fairwind-gated Flash Cyber.

Who can use Flash Cyber?

It is not sold on a public price sheet. Google says Fairwind is for governments, critical-infrastructure operators, and software maintainers, case by case.

Is 3.8 always cheaper than 3.7?

The intro unit price matches 3.7, but Google says the new model works harder and can spend more tokens at high effort. Keep supported 3.7 Flash when compute is tight.

What does this have to do with a temporary meeting tool?

No product tie. If you only need one sketch of the two envelopes, temporary meeting tools says when a short browser space is enough.

Create a free space