Google DeepMind has released two new Gemini models: a faster general-purpose model, 3.8 Flash, and a security-focused variant, 3.8 Flash Cyber, that only vetted defenders can use. The two models are built on the same underlying system but ship on different terms.
The general model, Gemini 3.8 Flash, is the third Flash-tier model Google has shipped in six weeks, and it holds the introductory pricing of the 3.7 release it builds on: $0.75 per million input tokens and $3.75 per million output tokens. Google says that rate expires on December 31, 2026 and then roughly doubles, to $1.50 and $7.50 per million. The company says developers who care most about running costs should stay on 3.7 Flash, which it will keep supporting for efficiency-first work.
Google says the new Flash model, part of its Gemini 3 family, beats larger and more expensive models on coding and agent benchmarks including DeepSWE, and scores 54.9 percent on HLE-Verified, a test of multi-step reasoning across technical and professional fields. The company also says the model "works harder" than its predecessor, running extra reasoning steps and tool calls that can burn more tokens on difficult problems. None of those benchmark results have been checked independently.
The security-tuned Gemini model, 3.8 Flash Cyber, is built for defensive work such as finding and fixing software flaws, and Google is limiting it to what it calls trusted defenders: government agencies, critical-infrastructure operators and software maintainers that apply through a new program called Fairwind. Google reports frontier-level results for the model on CyberGym, an industry benchmark for vulnerability discovery, and a 47.2 percent pass rate on the CWE-Bench patching test, close behind an unnamed larger competitor at 47.8 percent but at lower cost. It also says its Chrome security team saw 2.6 times more correct patches from the model than from larger commercial tools, and that one Google research team used it to find a critical vulnerability in under two hours. Because access is gated, outside researchers cannot yet test those claims.
Both releases run on a one-million-token context window, and Google describes 3.8 Flash as an update to the 3.7 architecture in the Gemini 3 line rather than a new design. Its published model card records a small drop in automated safety scores for non-English prompts and says the model did not cross any capability threshold in Google's Frontier Safety Framework. Google has not released a comparable card for the Cyber model, which leaves its safety testing and its real-world accuracy harder to judge from outside.













