On 2 September 2026, Google DeepMind shipped Gemini 3.8 Flash and a companion Gemini 3.8 Flash Cyber SKU — the third Flash release in six weeks after 3.7 Flash in mid-August. The cadence looks less like a traditional flagship cycle and more like a continuous deployment pipeline on Google's cost tier: same introductory list rates, faster iteration, and a split between a general workhorse model and a defender-only cyber variant.

Confirmed

  • Gemini 3.8 Flash is the public SKU — long-horizon coding, agentic workflows, and multi-step reasoning. Google cites DeepSWE v1.1 (end-to-end software engineering), HLE-Verified 54.9%, and domain benchmarks including Vals Finance Agent V2 and Harvey's Legal Agent Benchmark.
  • Pricing hold: $0.75 / $3.75 per million input/output tokens through 31 December 2026, then $1.50 / $7.50 from 1 January 2027 — unchanged from the 3.7 Flash intro window.
  • Availability: Google AI Studio, Gemini API, Android Studio, Stitch, Gemini Enterprise, and the Gemini app for AI Pro/Ultra subscribers; Antigravity demos in the launch post.
  • Effort trade-off: Google says 3.8 Flash "works harder" on hard tasks — extra reasoning steps and iterative tool calls — while 3.7 Flash remains supported for efficiency-first workloads.
  • Gemini 3.8 Flash Cyber is a separate, more permissive cyber SKU. Discovery and patching benchmarks include CyberGym, an internal 20-language vulnerability suite above 70% success, and CWE-Bench pass@1 47.2% (vs. a cited leading frontier model at 47.8%). Distribution is through the Fairwind Program we covered yesterday — not the open model catalog.
  • Safety framing: Frontier Safety Framework mitigations on 3.8 Flash; more permissive cyber mitigations on the Cyber SKU. Google also cites improved prompt-injection robustness on Gray Swan metrics.

Unknown

  • Hidden token bills: List rates are flat, but autonomous agents that run at high effort can burn far more tokens per task. Cost predictability depends on workload profiling, not the price card alone.
  • Independent reproduction: CWE-Bench (Collinear) and Gray Swan injection scores are vendor-cited. No public red-team replication of the 47.2% patching claim or Chrome's "2.6× more correct patches" line yet.
  • Production patch pipeline: How often Fairwind/CodeMender outputs reach merge without human review — and under what rollback guarantees — is not spelled out in the launch materials.

Context: same week as Astra

Google's Cyber SKU lands in the same news week OpenAI reiterated Astra's Critical cybersecurity threshold and Daybreak staging after the Hugging Face eval fallout. The parallel is structural: frontier cyber assistance ships through gates, not storefront SKUs. Fairwind is Google's intake queue; 3.8 Flash Cyber is the engine — program detail stays in yesterday's Fairwind report, not here.

Our take

For most Brocker readers the actionable story is 3.8 Flash: a coding/agent upgrade at Flash economics, with a clear warning that "same price per token" ≠ "same bill per job." Profile long-horizon runs before you swap 3.7 out of production.

The Cyber variant is real news, but it is not your API key unless you are in Fairwind. Treat Chrome Security, Wiz, and Cloud Vulnerability Research anecdotes as directional until outsiders reproduce them.

Three engineering guardrails matter regardless of vendor benchmarks:

  • Human approval and rollback: Autonomous patches that reach production without review are still a liability. Rollback paths must exist before agents write code.
  • Repo isolation: More aggressive CodeMender loops widen the blast radius if agents escape scoped repos or touch supply-chain surfaces they should not.
  • Prompt injection: More permissive cyber mitigations may help defenders — they also expand jailbreak surface if the agent ingests untrusted content. Gray Swan gains are a start, not a ship gate.

Series: 1. Hugging Face Confirms Breach Affected Internal Datasets and Credentials · 2. OpenAI Ships GPT-5.6-Cyber Through Gated Daybreak Red — Not a Public API Release · 3. OpenAI Details AI Security Strategy After Its Own Models Breached Hugging Face in Eval · 4. OpenAI Pauses Frontier RL Training After Astra Model Shows Critical Cyber Capabilities · 5. OpenAI designates Astra as first model at Critical cybersecurity capability threshold · 6. Google launches Fairwind Program: gated Gemini 3.8 Flash Cyber for defenders via CodeMender · 7. Google DeepMind ships Gemini 3.8 Flash — third Flash in six weeks, with a gated Cyber SKU · AI Cyber Defense

Sources