Google shipped its third Flash model in six weeks on Wednesday, which tells you plenty about the pace of the current AI market. The more interesting release, though, is the one you cannot simply sign up for. Alongside Gemini 3.8 Flash, a faster, cheaper workhorse aimed at coders and autonomous agents, Google introduced Gemini 3.8 Flash Cyber, a model built specifically to find software vulnerabilities and patch them. It is being handed out only to people the company has decided to trust.
The headline numbers on the general model are a snapshot of where the price war has settled. Gemini 3.8 Flash holds the same introductory price as its three-week-old predecessor, 75 cents per million input tokens and 3.75 dollars for output, while claiming to approach the quality of far larger and more expensive frontier models on long-horizon coding and multi-step reasoning benchmarks. Google's own framing is telling: for anyone who cares mostly about cost, the older 3.7 Flash "remains fully supported." The frontier is now advancing in three-week increments, and last month's model is already the budget option.
Flash Cyber is the part worth slowing down for. On CyberGym, an industry benchmark for autonomously discovering vulnerabilities, Google says it beats models many times its size, and on an internal test spanning 20 programming languages it finds flaws more than 70 percent of the time. Google's own Cloud team used it to surface a critical vulnerability in under two hours, work that normally takes months, while the Chrome security team reports it produced 2.6 times more correct patches than the best larger commercial models.
A tool that is expert at finding security holes is, by definition, dual-use, because the same skill that closes a flaw can open it. Google's answer is a deliberate asymmetry. It says it invested in vulnerability fixing "from the start" and prioritized it "over offensive capabilities like exploitation," then wrapped the whole thing in a gate. The general 3.8 Flash ships with safeguards against chemical, biological and cyber-offense misuse. Flash Cyber ships with what Google calls a "more permissive" set of cyber mitigations, and is available only through a new Fairwind Program to vetted government authorities, critical-infrastructure operators and software maintainers.
That structure is an implicit admission about where this technology sits. If the model were purely defensive there would be little reason to restrict it, so the restriction concedes that the capability could just as easily arm an attacker, and that the only real control is who holds the key. It also raises the obvious question the announcement does not answer: defenders get a vetting process and an application form, while anyone building a comparable tool on open-weight models gets neither, and asks no one for permission. Google is betting that giving well-resourced defenders a decisive head start is the safer path, and that speed and cost, the same two levers driving every other Flash release, are what turn a head start into a durable advantage. Whether the people without an invitation stay behind is the part no benchmark measures.