Google announced Gemini 3.8 Flash and Gemini 3.8 Flash Cyber on 2026-09-02, the third Flash release in roughly six weeks. Google positions 3.8 Flash as its workhorse model, delivering gains over 3.7 Flash in software engineering, agentic tasks and multi-step reasoning in specialized domains while holding the same speed and price point. Reported results include 54.9 percent on HLE-Verified and a success rate above 70 percent on an internal benchmark spanning 20 programming languages, alongside improved standing on DeepSWE v1.1.
Pricing is unchanged from the 3.7 Flash introductory rate: 0.75 dollars per million input tokens and 3.75 dollars per million output tokens. Google states plainly that this is an introductory price which expires on 2026-12-31, after which the rate becomes 1.50 dollars per million input and 7.50 dollars per million output on 2027-01-01. Anyone modelling 2027 inference budgets on current Flash pricing should note the doubling is already published rather than speculative.
The second model, Gemini 3.8 Flash Cyber, is the more consequential release from a governance standpoint. Google describes it as its most capable cybersecurity model, with frontier-level performance in vulnerability discovery and automated patching, citing a 47.2 percent pass-at-1 rate on CWE-Bench patching and 2.6 times more correct vulnerability patches on a Chrome Security evaluation, plus frontier-level results on CyberGym. It is not generally available. Access runs through a new Fairwind Program that prioritizes trusted government authorities, critical infrastructure operators and software maintainers, with an application portal.
Google also reports significant improvement on Gray Swan prompt-injection robustness relative to earlier versions. The pattern across this release is now familiar across the frontier labs in the same week: a broadly available general model shipped alongside a gated cyber variant, with the capability that would most excite an attacker held behind a vetted-defender program.