Gemini 3.8 Flash 2026 explained: Flash Cyber and Fairwind

One core, two doors. Flash is public. Cyber stays inside Fairwind.

On 2 September 2026, Google DeepMind shipped two models at once: Gemini 3.8 Flash for everyday agents, and Gemini 3.8 Flash Cyber, which only enters through the Fairwind Program. It sat between Claude Fable 5.1 and GPT-6 Astra, so the headline was easy to miss.

The name to search is Gemini 3.8 Flash. The official blog describes one shared core and two doors: Flash on the public API and subscriptions, Cyber for governments, critical infrastructure, and software maintainers. Figures below come from that 2 September post and the Gemini 3.8 Flash model card.

A work table by a window
Read a twin release by who can use it, and which test produced the number.
9.22026 ship date
$0.75intro price / 1M input
54.9%HLE-Verified

Two names, one gate

Look at3.8 Flash3.8 Flash Cyber
Who gets itAPI, AI Studio, Enterprise, Pro/UltraFairwind trusted defenders
Safety valveCBRN and cyber-offense tightened to the frameworkLooser on cyber, hence the review
Price cardIntro $0.75 / $3.75; doubles 1 Jan 2027No separate public list

When the doors and scores start to blur, lay them on one page instead of flipping press notes.

How to read the official scores

Workhorse evals

DeepMind says 3.8 Flash beats most larger frontier models on DeepSWE v1.1 at lower cost; HLE-Verified is 54.9%; Vals Finance Agent V2 and Harvey’s Legal Agent also beat 3.7 Flash.

Defense evals

On CyberGym it beats 3.5 Flash Cyber and larger models. An internal vulnerability hunt across 20 languages tops 70%. CWE-Bench from Collinear reports pass@1 of 47.2% versus 47.8% for a leading frontier model, at lower cost.

One intelligence, two valves. A score is only valid behind its own door.

Field numbers need their own line

  1. 01
    Match the source

    The scores sit on the 2 September Google blog and the model card. Independent reruns are not in yet. Do not treat this as a composite crown.

  2. 02
    Then the field

    Chrome Security said 3.8 Flash Cyber produced 2.6 times more correct patches than the best larger commercial models. Wiz reported 7.5–9.7% higher pentest recall at 2.3–5.2× lower cost. Google’s cloud vulnerability team found a critical foundational flaw in under two hours, work that usually takes months.

  3. 03
    Log the regressions

    The model card says multilingual safety is 5.4 points worse than 3.7 Flash, with 1.1 points more unjustified refusals. The knowledge cutoff is mostly March 2026; some domains still stop at January 2025.

What it is
The next hop after 3.7 Flash: 1M context, 64K output, lifted by longer agent loops and cybersecurity training. DeepMind’s April 2026 Frontier Safety Framework review says it is unlikely to hit Tracked or Critical Capability Levels.
What it is not
A public offense kit. Flash Cyber’s looser cyber mitigations stay inside Fairwind. Gray Swan measured a clear jump in prompt-injection robustness; that is not a reason to drop a valve in production.

Keep the comparison on paper

Flash, Cyber, Fable, and Astra share one week. Write down who can call which model, which harness made the score, and when the price doubles. That beats chasing a single leaderboard.

Start a room