Google DeepMind released Gemini 3.8 Flash and a companion model, Gemini 3.8 Flash Cyber, on September 2. This is Google’s third Flash-tier update in six weeks, and it keeps the same pricing as the prior version while improving reasoning, coding, and multi-step agentic performance. Read the official announcement.
The two models share a core architecture but differ in access and safety mitigations. Gemini 3.8 Flash is generally available today through the Gemini API, Google AI Studio, Antigravity, Android Studio, and Gemini Enterprise, priced at $0.75 per million input tokens and $3.75 per million output tokens. Gemini 3.8 Flash Cyber, by contrast, is restricted to vetted defenders — government authorities, critical infrastructure operators, and software maintainers — who apply through a new access program Google calls Fairwind, and it’s tuned specifically for finding and patching vulnerabilities rather than more general-purpose use.
A fast cadence, and a deliberate split on cyber capability
The pace here is the real story: three Flash-tier releases in six weeks is unusually rapid even by current industry standards, and it comes right after reports questioned whether Google was slowing down following a leadership transition at DeepMind. Shipping a genuinely improved low-cost model this quickly, while still gating the riskier cybersecurity variant behind a vetting program, is a reasonable way to keep pushing capability without just handing offensive security tooling to anyone with an API key.
On raw capability, Google’s own benchmarks show 3.8 Flash outperforming larger, pricier frontier models on long-horizon software engineering tasks at a fraction of the cost — a claim that, if it holds up under independent testing, would be a genuinely useful option for teams running high-volume agentic workloads who don’t need the biggest, most expensive model for every task. The split approach to the cyber-focused variant also mirrors what OpenAI and Anthropic have both done with their own most capable models this same week, suggesting an emerging industry norm: ship the general-purpose model broadly, and gate the sharpest dual-use capabilities behind a trusted-access program rather than skipping the capability altogether.
For developers, the practical news is a workhorse-tier Gemini model at unchanged pricing but noticeably better agentic and coding performance — worth testing against whatever you’re currently running for cost-sensitive production traffic.
Leave a comment