Introducing Gemini 3.8 Flash and 3.8 Flash Cyber
Sep 2, 2026, 9:18 AM · Google DeepMind

DeepMind's Gemini 3.8 post is a vendor scoreboard: same introductory price as 3.7, more tokens if you let it 'work harder,' and Cyber locked behind Fairwind.
Why it matters
Google DeepMind's blog introduces Gemini 3.8 Flash, called its best reasoning and coding model yet at 3.7's speed and cost, as the third Flash release in six weeks. Introductory API pricing is $0.75 per million input tokens and $3.75 per million output, the same as 3.7; that rate expires December 31, 2026, then $1.50 / $7.50. A second variant, 3.8 Flash Cyber, is for vulnerability detection and automated patching, available to trusted defenders through the new Fairwind Program.
Google says 3.8 Flash outperforms most larger frontier models on DeepSWE v1.1 long-horizon software engineering, beats 3.7 and other frontier models on Vals Finance Agent V2 and Harvey's Legal Agent Benchmark, and scores 54.9% on HLE-Verified. The model 'works harder' — extra reasoning steps, iterative tool calls — and 'might use more tokens,' especially at higher effort. Developers who care about efficiency are told to turn effort down or stay on 3.7. Cyber claims: frontier-level on CyberGym; over 70% success on an internal multi-language vulnerability benchmark; CWE-Bench pass@1 of 47.2% versus 47.8% for a leading frontier model at lower cost. Chrome security saw 2.6 times more correct patches than the best larger commercial models; Wiz reports +7.5–9.7% recall at 2.3–5.2x lower cost; Cloud vulnerability research found a critical issue in under two hours. 3.8 Flash has CBRN and cyber-offense safeguards; Cyber is more permissive and gated. Gray Swan is cited for prompt-injection robustness.
The Signal Desk read
Vendor blog: every benchmark is Google's chosen board, every customer quote a launch partner. DeepSWE, Harvey, Vals, HLE-Verified, CyberGym, CWE-Bench — the pattern is Flash punching into expensive-model columns at a promotional token price that dies on New Year's Day 2027. The honest line is the token warning. 'Works harder' is how you keep the sticker at $0.75 / $3.75 while the bill rises.
Cyber is the more interesting SKU. Fairwind, governments and trusted partners, more permissive mitigations, patching prioritized over exploitation — that is a dual-use product with an access list. Chrome's 2.6x patch figure and the two-hour Cloud find are internal. Treat them as existence proofs that Google is using the model on Google, not as a market-wide superiority claim.
Signal Desk's read: six weeks, three Flash models, and still no 3.5 Pro is a cadence strategy. Ship the cheap workhorse that eats coding and agent evals, gate the dangerous twin, and tell efficiency-sensitive customers 3.7 is still supported. That splits the user base on purpose: pay more tokens for diligence, or keep the old model. Fairwind is how Google does 'responsible' capability without putting a cyber model in AI Studio.
The Antigravity demos (wizard castle, DOS Maps, USGS topography) are launch theater. DeepSWE is the number developers will actually chase.
Context
Google has been iterating Flash on a few-week clock while frontier Pro sits still. 3.8 is meant to be the agentic coding default in Antigravity, AI Studio, Gemini Enterprise, and the Gemini app for Pro/Ultra subscribers, with Cyber as a separate defender channel.
Who feels it
- API developers
- Same unit price as 3.7, higher token burn at high effort. Measure dollars per task, not dollars per million tokens.
- Defenders
- Fairwind is the door. Cyber is not a general-availability model, by design.
- Efficiency-sensitive apps
- Google left 3.7 up. That is an admission 3.8's diligence is a cost center.
What to watch
- January 1, 2027 price jump versus whatever Flash lands before then.
- Independent DeepSWE and CWE-Bench replications, not the blog tables.
- Fairwind membership criteria and whether Cyber leaks beyond it.
Companies: Google