Google DeepMind announced the release of Gemini 3.8 Flash and Gemini 3.8 Flash Cyber on September 2, 2026, marking its third "Flash" model release in six weeks. Gemini 3.8 Flash is positioned as a general-purpose model, offering improvements in software engineering, agentic tasks, and multi-step reasoning. The Gemini 3.8 Flash Cyber variant is specifically designed for cybersecurity, focusing on vulnerability detection and automated patching.

Both models are built upon the same foundational intelligence, which Google DeepMind states has been refined through "long-running agentic loops that recursively evaluate and refine the underlying models." While sharing a core, the two variants differ in their safety envelopes and access protocols. Gemini 3.8 Flash is generally available for production use through the Gemini API, Google AI Studio, Antigravity, Android Studio, and Gemini Enterprise. In contrast, Gemini 3.8 Flash Cyber is not openly deployable; access is granted on a case-by-case basis via the new Fairwind Program. This program targets government authorities, critical infrastructure operators, and software maintainers.

Google DeepMind explained that Gemini 3.8 Flash is based on its predecessor, Gemini 3.7 Flash. The new model maintains the same specifications, including a 1-million-token context window, a 64,000-token maximum output, and support for text, image, audio, and video input with text output. It also retains tunable "thinking levels" (low, medium, high) to control latency and intelligence, with "medium" as the default. A notable change for users migrating from earlier versions is the discontinuation of the "minimal" thinking level, which will now return an API validation error if set.

The key improvement in Gemini 3.8 Flash stems from its enhanced diligence on complex tasks. The model executes additional reasoning steps and iteratively calls tools, which can lead to higher token consumption at elevated effort levels. Google's developer guide acknowledges that this approach prioritizes accuracy, suggesting that Gemini 3.7 Flash may be more suitable for workflows where compute efficiency is the primary concern.

On the DeepSWE v1.1 benchmark for long-horizon software engineering, Gemini 3.8 Flash reportedly outperforms many larger frontier models at a lower cost. It achieved a 54.9% score on HLE-Verified, indicating its capability in multi-step reasoning across STEM, humanities, and professional domains. The model also showed improved performance on benchmarks such as Vals Finance Agent V2 and Harvey's Legal Agent Benchmark.

Gemini 3.8 Flash Cyber demonstrates frontier-level performance in vulnerability detection and automated patching. On the CWE-Bench patching benchmark, it achieved a pass@1 score of 47.2%, closely approaching a leading frontier model's 47.8% but at a lower cost. Google's Chrome Security team found that 3.8 Flash Cyber produced 2.6 times more correct patches for Chrome vulnerabilities than larger commercial models. Security firm Wiz reported that the model achieved 7.5% to 9.7% higher recall on its internal penetration testing benchmark at 2.3 to 5.2 times lower cost compared to other leading models. Google's Cloud Vulnerability Research team used the model to identify a critical vulnerability in under two hours, a process that typically takes months.

Both Gemini 3.8 models include safeguards against misuse in chemical, biological, radiological, nuclear, and cyber offense domains, aligning with Google's Frontier Safety Framework. The models also show improved robustness against prompt injection attacks, as measured by the Gray Swan benchmark.

Gemini 3.8 Flash is available at an introductory price of $0.75 per million input tokens and $3.75 per million output tokens through December 31, 2026. Standard pricing of $1.50 per million input tokens and $7.50 per million output tokens will take effect on January 1, 2027. Consumers with Google AI Pro or Ultra subscriptions can access Gemini 3.8 Flash through the Gemini app, AI Mode in Google Search, and Gemini in Google Sheets.