Gemini 3.8 Flash and 3.8 Flash Cyber: Same Intro Price, a Model That Works Harder

Google logoGoogleImportant3 septembre 2026Modèles
Ce qui s’est passé
Google launched Gemini 3.8 Flash at 3.7 Flash's $0.75/$3.75 intro price, plus a gated Gemini 3.8 Flash Cyber for trusted defenders via the new Fairwind Program.
Pourquoi c’est important
3.8 Flash beats 3.7 across coding and agentic benchmarks but 'works harder' — higher effort can burn more tokens — while 3.8 Flash Cyber posts frontier CWE-Bench/CyberGym results behind an access gate.
Que faire
Benchmark 3.8 Flash against 3.7 on your own agent workloads before Dec 31; security teams should start a Fairwind application if they want Cyber access.

Verdict: a capability upgrade, not a recommendation flip. Gemini 3.8 Flash matches the $0.75/$3.75 intro pricing of the Gemini 3.7 Flash we still recommend for efficiency-first workloads — but Google says it "works harder," so per-task token burn, not headline price, is the real cost question. Neither 3.8 variant is a directory entity yet (both are filed as candidates), so there are no verdict flips today. The gated Gemini 3.8 Flash Cyber is the bigger story for security teams: a frontier cyber model at Flash-tier cost that you qualify for rather than buy.

Google shipped its third Flash-tier model in six weeks, and this one is aimed squarely at the workhorse slot Gemini 3.7 Flash has held since mid-August. Gemini 3.8 Flash arrives at the same introductory price — $0.75 per million input and $3.75 per million output tokens, good through Dec 31, 2026 before rising to $1.50/$7.50 — and Google is explicit about the trade-off: on complex tasks the model "works harder," executing extra reasoning steps and calling tools iteratively, which can mean more tokens consumed at higher effort levels (Google, 2026).

Launched alongside it, Gemini 3.8 Flash Cyber is Google's most capable cybersecurity model, gated to trusted defenders through the new Fairwind Program — a direct capability successor to the CodeMender-gated Gemini 3.5 Flash Cyber we currently rate Caution.

What happened

Gemini 3.8 Flash is built on the same shared core as the Cyber variant and posts material gains over 3.7 Flash across software engineering, agentic tasks, and multi-step reasoning (Google, 2026):

  • DeepSWE v1.1 (long-horizon software engineering): outperforms most larger frontier models end-to-end "at a fraction of the cost."
  • Specialized domains: leads 3.7 Flash and other frontier models on Vals Finance Agent V2 and Harvey's Legal Agent Benchmark; 54.9% on HLE-Verified.
  • Token caveat: at higher effort levels the model may use more tokens; lower effort levels trim the overhead, and Google keeps 3.7 Flash "fully supported for efficiency-first workloads."
  • Availability: Gemini API via Google AI Studio, Gemini Enterprise, Google Antigravity, Android Studio, plus the Gemini app for AI Pro/Ultra subscribers, AI Mode in Search, and Gemini in Google Sheets.

Gemini 3.8 Flash Cyber is a defender-first model — Google says patching was prioritized over exploitation (Google, 2026):

  • CyberGym: surpasses both 3.5 Flash Cyber and "significantly larger frontier models" on autonomous vulnerability discovery.
  • 20-language internal benchmark: exceeds 70% success on real-world vulnerability discovery across complex codebases.
  • CWE-Bench: pass@1 of 47.2% against a leading frontier model's 47.8% — at significantly lower cost.
  • In production at Google: Chrome Security measured 2.6x more correct patches than much larger commercial models; Wiz saw +7.5–9.7% recall at 2.3–5.2x lower cost; Cloud Vulnerability Research found a critical foundational vulnerability in under two hours.
  • Access: restricted to trusted government authorities, critical-infrastructure operators, and software maintainers via the Fairwind Program — there is no public API.

Both models ship with CBRN and cyber-offense safeguards per Google's Frontier Safety Framework; the Cyber variant carries a more permissive cyber mitigation set, which is exactly why it is gated. Google also reports a significant prompt-injection robustness jump on the Gray Swan benchmark (Google, 2026).

Why it matters

The 3.8 Flash launch reframes the choice we gave readers when 3.7 Flash became our recommended Flash-tier pick: same price, better benchmarks, but a model explicitly optimized to spend more tokens when the task is hard. For token-metered agent workloads, headline price-per-token is no longer the whole cost equation — per-task token burn is. That keeps 3.7 Flash a legitimate efficiency pick while 3.8 Flash is the capability upgrade path.

For security teams, 3.8 Flash Cyber closes the gap the GPT-5.6-Cyber and Mythos-class gated models opened: a frontier cyber model at Flash-tier cost. But like every model in this class, it is not something you can buy — you have to qualify.

What changes for you

  • Cost-sensitive 3.7 Flash users: don't switch on headline benchmarks alone. Run your own agent workloads on 3.8 Flash and compare per-task token burn before the Dec 31 intro pricing expires.
  • Coding and agent builders: 3.8 Flash is live in the Gemini API today — benchmark it against 3.7 Flash on your longest-horizon tasks.
  • Security teams: the only route to 3.8 Flash Cyber is a Fairwind Program application; plan around a qualification process, not a price sheet.

Que faire

  1. 1 Benchmark Gemini 3.8 Flash against 3.7 Flash on your own long-horizon tasks and compare per-task token burn, not just per-token price.
  2. 2 If you need frontier defensive cyber capability, apply for Fairwind Program access — there is no public API for 3.8 Flash Cyber.

Outils et modèles concernés

Gemini 3.8 FlashGemini 3.8 Flash CyberGemini 3.7 FlashGemini 3.5 Flash Cyber

Ne ratez plus jamais une mise à jour

Le récap hebdomadaire — uniquement les changements de verdict et les actions urgentes. Sans remplissage.

En vous abonnant, vous acceptez notre Politique de confidentialité. Désabonnement à tout moment.