Google Launches Gemini 3.8 Flash and Flash Cyber AI Models
Google has announced two new versions of its advanced Gemini 3.8 Flash artificial intelligence model: the standard Gemini 3.8 Flash and Gemini 3.8 Flash Cyber. The new models are designed for agent-based tasks, software development, complex reasoning, vulnerability detection, and automated cybersecurity defense.
The standard Gemini 3.8 Flash is positioned as Google’s general-purpose model for AI agents, coding, software engineering, and multi-step inference. Gemini 3.8 Flash Cyber is optimized for identifying, prioritizing, and fixing software vulnerabilities at scale.
Google CEO Sundar Pichai said on X that Gemini 3.8 Flash represents a “big leap forward”. Google says the model improves on Gemini 3.7 Flash and performs strongly across software engineering, agent workflows, and multi-step reasoning. On the DeepSWE coding benchmark, it reportedly outperformed several large frontier models while operating at a significantly lower cost.
Pichai described Gemini 3.8 Flash Cyber as Google’s most capable cybersecurity model to date. The company says it delivers leading performance in vulnerability discovery and automated patching, achieving 86.2% on the CyberGym cybersecurity benchmark and 47.2% on CWE-Bench, which measures AI-assisted vulnerability remediation.
According to Google’s internal testing, Gemini 3.8 Flash Cyber detected vulnerabilities across 20 programming languages with a success rate of more than 70%. Gemini 3.8 is Google’s third Flash model release in six weeks, following the launch of Gemini 3.7 Flash.
Gemini 3.8 Flash Delivers More Advanced Reasoning
Gemini 3.8 Flash is now available through Gemini Enterprise. Developers can access the model through the Gemini API using Google AI Studio, Google Antigravity, Android Studio, and Stitch for user-interface generation.
The model is priced at $0.75 per million input tokens and $3.75 per million output tokens. This matches the introductory pricing for Gemini 3.7 Flash. Users can adjust the model’s reasoning and computation levels based on their preferred balance of quality, cost, and response speed.
For applications that prioritize efficiency, developers can reduce token usage or continue using Gemini 3.7 Flash, which Google says remains well suited to efficiency-focused workloads. In a Google blog post, senior product director Tulsee Doshi and Gemini security lead Raluca Ada Popa explained that Gemini 3.8 Flash is designed to work more intensively on complex tasks.
Gemini 3.8 Flash may use additional tokens to complete more inference steps and maximize performance. The model supports a 1-million-token context window and up to 64,000 output tokens. It can process text, images, audio, video, and PDF files, making it suitable for multimodal AI applications.
Google evaluated Gemini 3.8 Flash across coding, multimodal reasoning, computer use, long-context processing, general knowledge, and scientific analysis. The company says the model also performs well on specialized professional tasks, including finance and legal research.
For example, Gemini 3.8 Flash reportedly outperformed its predecessor and other frontier AI models on the Vals Finance Agent V2 benchmark and the Harvey legal benchmark. It also achieved 54.9% on the Humanity’s Last Exam Verified benchmark, which measures advanced reasoning across mathematics, science, humanities, and other academic fields.
Google demonstrated Gemini 3.8 Flash using its Antigravity platform to build a 3D game from a simple prompt. The game included puzzles, adaptive storytelling, and Nano Banana-generated images and textures in a fantasy setting featuring a wizard exploring a castle.
In other demonstrations, Gemini 3.8 Flash created a functional DOS-style version of Google Maps with interactive locations, directions, and Street View features. It also built a 3D device visualizer that used sliders to separate hardware components for inspection. Another example generated topographic maps of well-known geographic locations using U.S. Geological Survey datasets, complete with cross-sections, 2D projections, and scientific descriptions.
According to Arena.ai, Gemini 3.8 Flash debuted at 14th place in Agent Arena, ranking above DeepSeek-V4-Pro and well ahead of Gemini 3.7 Flash, which ranked 32nd. The model also entered Text Arena in seventh place, ahead of Claude Opus 5 and Gemini 3.7 Flash.
Gemini 3.8 Flash reportedly improved performance in several areas, including multi-turn conversations, writing, literature, language understanding, long-context prompts, difficult instructions, coding, software and IT support, business, management, and financial operations.
Gemini 3.8 Flash Cyber Is Already Protecting Google’s Code
Google will initially provide Gemini 3.8 Flash Cyber to trusted defenders through its Fairwind program. The initiative prioritizes government agencies, critical infrastructure operators, and other organizations seeking advanced AI-powered cybersecurity capabilities. Eligible organizations can apply for access.
Google says Gemini 3.8 Flash Cyber received specialized cybersecurity training and includes improved protection against prompt injection attacks. The model is designed to autonomously discover vulnerabilities, analyze large codebases, recommend fixes, and automate security patching.
According to Google, the goal is to give cybersecurity defenders expert-level assistance and help them respond more effectively to attackers, malicious AI agents, and human hackers. The company says it has prioritized vulnerability remediation and defense rather than offensive exploitation capabilities.
Gemini 3.8 Flash Cyber includes more permissive cybersecurity safeguards than standard AI models. As a result, access is currently limited to selected partners. Google says the model also includes protections for sensitive areas involving chemical, biological, radiological, and nuclear threats.
Google is already using Gemini 3.8 Flash Cyber to protect its own software. The company reports that the model generated 2.6 times more accurate patches for Chrome vulnerabilities than a much larger commercial AI model.
Wiz, which Google acquired for $32 billion earlier this year, reported that Gemini 3.8 Flash Cyber achieved 7.5% to 9.7% higher recall for real-world vulnerabilities in internal penetration-testing benchmarks. The company also found that the model operated at 2.3 to 5.2 times lower cost than leading frontier AI models.
Google’s Cloud Vulnerability Research team also used Gemini 3.8 Flash Cyber to identify critical vulnerabilities in the model itself within two hours. Google said similar investigations and discoveries would typically take several months.
Raluca Ada Popa said AI agents are becoming highly capable at discovering and exploiting software vulnerabilities. While AI models can scan enormous codebases, the cost and volume of findings can overwhelm security teams. Attackers need to find only one serious flaw, while defenders must address every significant vulnerability.
Doug Turner, director of engineering at Chrome, described the recent increase in reported software flaws as a potential “vulnerability apocalypse.” He said the number of vulnerabilities reported through Chrome’s vulnerability research program rose sharply following the rapid development of generative AI.
Turner also highlighted a vulnerability found by Gemini 3.8 Flash Cyber in Chromium and Chrome that had existed for 13 years. The subtle issue had been reviewed by dozens or even hundreds of engineers without being reported. Google says Gemini 3.8 Flash Cyber could help developers identify similar issues and create more effective security patches.
Source: venturebeat.com


