Google's relentless Flash cadence continues: on September 2, 2026, the company launched Gemini 3.8 Flash, its third Flash-family release in six weeks, calling it the "best reasoning & coding model yet" while keeping the speed and price of its predecessor. The announcement came with a second, more unusual debut: Gemini 3.8 Flash Cyber, a cybersecurity-specialized variant that Google will only release to vetted defenders through its new, limited-access Fairwind Program.

The headline deal: frontier-leaning output at Flash pricing
The core pitch is arithmetic every engineering team can appreciate. Gemini 3.8 Flash posts gains on long-horizon reasoning and coding benchmarks at the same introductory price as 3.7 Flash:
- Pricing: $0.75 per million input tokens and $3.75 per million output tokens.
- Adaptive effort: when you raise the reasoning-effort setting on hard tasks, the model works harder and spends more tokens rather than forcing you to jump to a larger, costlier model.
- No forced migration: Gemini 3.7 Flash remains available and supported.
The post was signed by Tulsee Doshi (Senior Director of Product Management for Gemini) and Raluca Ada Popa (Gemini Security Lead at DeepMind) — a pairing that signals security was central to this launch, not an afterthought.
Three Flash drops in six weeks
For context on the pace: 3.7 Flash landed roughly three weeks ago with a million-token context at economical rates, and 3.6 Flash arrived weeks before that. Three meaningful releases in about a month and a half changes how teams should think about model selection — it is no longer an annual architecture decision but a monthly review. The encouraging part of this particular cycle is that Google raised capability while holding the introductory price flat, which gives finance teams one less variable to model while the frontier race continues.
To demonstrate the model in action, Google showcased two projects built inside its Google Antigravity development environment: a DOS-style retro game running on Google Maps data, and a 3D wizard-castle level whose textures were generated with Nano Banana image capabilities mid-build. The intended message is that the model now plans, executes, and verifies multi-stage engineering work end-to-end — closer to a junior engineer taking a ticket than a text generator.
What the benchmarks actually say
Google's claims rest on an unusually practical set of evaluations this time:
- DeepSWE v1.1 — long-horizon software engineering tasks requiring multi-step fixes across tangled code.
- Vals Finance Agent V2 — agentic financial workflows.
- Harvey's Legal Agent Benchmark — the legal-agent evaluation built by the legal-AI firm Harvey.
- HLE-Verified: 54.9% on the human-verified version of Humanity's Last Exam.
A necessary caveat: these are first-party numbers. Independent, broad replication will take weeks, and rival labs cherry-pick their own highlight reels. The honest position is that 3.8 Flash looks like a genuine price-performance step for coding workloads, but your own eval suite remains the final arbiter.

Flash Cyber and Fairwind: the security story
The most consequential part of the announcement is not the general model. Gemini 3.8 Flash Cyber is described by Google as its most capable cybersecurity model, and it will not appear in the public API. Instead it ships exclusively through the Fairwind Program, a limited-access initiative for governments and trusted partners announced the same day by Four Flynn, Google's VP of Security and Privacy.
The claimed results:
- Surpasses larger frontier models on CyberGym's frontier autonomous vulnerability-discovery evaluation.
- Over 70% success on an internal benchmark spanning 20 programming languages.
- CWE-Bench (Collinear): 47.2% pass@1 versus 47.8% for the leading frontier model — at significantly lower cost.
- With Chrome Security: 2.6x more correct patches than the best commercial models.
- With Wiz: +7.5–9.7% recall at 2.3–5.2x lower cost.
- Google Cloud's vulnerability research team used it to find a critical foundational vulnerability in under two hours.
The reasoning behind the restricted release is straightforward: a model that autonomously finds and exploits unknown flaws is exactly the tool you do not want circulating freely.
What this means for you
- Cost planning just got easier: teams already running 3.7 Flash for coding and agentic work can upgrade in place — same input/output rates, better task completion.
- For enterprises weighing security tooling: Fairwind is a new procurement path for government security teams and critical-infrastructure operators, but access requires vetting as a trusted partner; there is no published country list yet.
- For product builders outside the US: the general model is available immediately through Google AI Studio and the Gemini API, so international teams can ship against it today.
- Effort-based billing note: "working harder" means more output tokens on difficult prompts. Per-token price is flat, but heavy reasoning settings will still move your invoice.
Quick comparison: where 3.8 Flash fits
| Criterion | Gemini 3.8 Flash | Gemini 3.7 Flash | Large frontier models |
|---|---|---|---|
| Input price / M tokens | $0.75 | $0.75 (intro) | Several times higher |
| Deep reasoning | Best in Flash family | Very good | Highest overall |
| Latency | Fast (Flash class) | Fast | Slower |
| Best for | Coding & everyday agents | Light, cost-sensitive work | Research-grade complexity |
We previously covered how Gemini 3.7 Flash brought a million-token context to an economical tier; 3.8 continues that trajectory of pushing quality down the price curve. Google has also been expanding the surrounding agent infrastructure — see our explainer on Gemini managed agents for how background-task agents change application architecture.
Honest limitations
- All headline numbers come from Google's own announcement; treat them as directional until independent evals land.
- The higher-effort mode increases token consumption — cost-per-task on hard problems may not drop as much as per-token price suggests.
- Flash Cyber is not a product you can buy; any vendor claiming to sell "Gemini cyber capabilities" commercially is misrepresenting the program.
- Long-term support horizons for 3.7 Flash are unstated.
Frequently asked questions
What is the difference between Gemini 3.8 Flash and Gemini 3.8 Flash Cyber?
3.8 Flash is the general-purpose model available through the Gemini API for commercial and coding use. Flash Cyber is a cybersecurity specialist — autonomous vulnerability discovery and patching — restricted to governments and trusted defenders via the Fairwind Program.
How much does Gemini 3.8 Flash cost?
$0.75 per million input tokens and $3.75 per million output tokens at the introductory price, identical to 3.7 Flash's launch pricing, per Google's official announcement.
Is upgrading from 3.7 Flash worth it?
For coding and long-horizon agent tasks, most likely yes: same price, measurably better results on software-engineering evaluations. For light or extremely cost-sensitive workloads, the difference may not justify touching a stable production setup on day one.
Can organizations in the Middle East access Flash Cyber?
Not directly. Fairwind is a limited-access program for governments and vetted partners; there is no commercial storefront and no published country list, so eligible Gulf security institutions would need to engage Google through the program itself.
Does Gemini 3.8 Flash support Arabic?
Yes, as part of the Gemini family's multilingual API support, with general improvements in following long, complex instructions. As always with code-adjacent Arabic tasks, run your own evaluation set before committing.
Bottom line
Gemini 3.8 Flash is Google's clearest 2026 statement yet: the price-performance frontier is collapsing downward, fast. Builders get near-frontier coding quality at commodity rates starting today, while the sharpest security capabilities are deliberately locked behind a trusted-defender gate. Audit your model routing this week — there is likely money on the table. For a wider view of options, browse our tested AI tools directory.
Primary source: Google's official announcement on blog.google, September 2, 2026; pricing and benchmark figures as stated in the announcement.