Google has introduced Gemini 3.8 Flash alongside Gemini 3.8 Flash Cyber, splitting the same underlying model family into a broadly available general-purpose model and a more permissive cybersecurity variant restricted to trusted defenders.
The launch, announced on 2 September 2026, is aimed particularly at coding, long-running agent workflows and multi-step reasoning.
Contents
- What Gemini 3.8 Flash is
- Why there are two variants
- What Flash Cyber is designed to do
- Pricing and availability
- Prompt-injection robustness
- How to read Google's performance claims
What Gemini 3.8 Flash is
Google describes Gemini 3.8 Flash as its most capable Flash model for reasoning and coding so far. The Flash line is designed to balance capability, latency and cost rather than simply maximize performance at any price.
The company says 3.8 Flash improves on 3.7 Flash in software engineering, agentic tasks and complex multi-step reasoning. An agentic task is one in which the model repeatedly plans, acts, observes the result and decides what to do next instead of generating a single response.
That matters in coding because real development usually involves several dependent steps: inspecting a repository, choosing a change, editing files, running tests and repairing failures.
Why there are two variants
The two models share the same core intelligence but differ in the safeguards surrounding cybersecurity use.
Gemini 3.8 Flash is the broadly available model. Google says it includes safeguards designed to reduce misuse in areas including cyber offense and chemical, biological, radiological and nuclear risks.
Flash Cyber is intended for legitimate defensive security work that may require capabilities which would be inappropriate to expose without tighter access controls.
What Flash Cyber is designed to do
Google describes Flash Cyber as its most capable cybersecurity model, with capabilities in vulnerability discovery and automated patching.
It is not being offered as an unrestricted public model. Instead, Google is providing access through its Fairwind Program to selected government authorities, critical-infrastructure operators and software maintainers.
That distinction is important: a cybersecurity model can be useful for finding and fixing flaws, but the same technical capability may also be misused to identify exploitable weaknesses.
Pricing and availability
Google announced introductory pricing for Gemini 3.8 Flash of $0.75 per million input tokens and $3.75 per million output tokens through 31 December 2026. The company says pricing will rise from 1 January 2027 to $1.50 per million input tokens and $7.50 per million output tokens.
Gemini 3.8 Flash is available through the Gemini API and Google AI Studio, as well as selected Google developer and enterprise products. Google also says it is available to AI Pro and Ultra subscribers in the Gemini app, AI Mode in Google Search and Gemini in Sheets.
Flash Cyber has separate restricted access.
Prompt-injection robustness
Prompt injection is a security problem in which an AI agent encounters instructions embedded in a webpage, document or other content that attempt to override the user's real instructions.
For example, a malicious page could contain hidden text telling an agent to reveal confidential information or perform an unrelated action.
Google says Gemini 3.8 improves prompt-injection robustness in evaluations by Gray Swan. That is relevant to agentic systems because models that browse or process external content are exposed to instructions they did not receive directly from the user.
How to read Google's performance claims
Google reports strong results on software-engineering, agent and cybersecurity evaluations, including DeepSWE v1.1.
These should be interpreted as Google-reported benchmark results, not as a guarantee of performance in every production environment. Real-world results depend on tools, permissions, prompts, repository complexity and evaluation methodology.
The larger significance of the launch is architectural: frontier AI systems are increasingly being split into general-purpose and controlled-access variants when the same underlying capability has both beneficial and potentially harmful applications.
Primary source
- Google. Introducing Gemini 3.8 Flash and 3.8 Flash Cyber. 2 September 2026. https://blog.google/innovation-and-ai/models-and-research/gemini-models/3-8-flash-and-3-8-flash-cyber/