
Google has introduced Gemini 3.8 Flash and Gemini 3.8 Flash Cyber, its latest models focused on software engineering, agentic tasks, multi-step reasoning, vulnerability detection and automated patching. Gemini 3.8 Flash is designed for general-purpose workloads, while Gemini 3.8 Flash Cyber focuses on defensive cybersecurity.
The release comes three weeks after Gemini 3.7 Flash and is the third Flash release from Google in six weeks. Both models use the same foundational intelligence and long-running agentic loops designed to recursively evaluate and refine the underlying models.
Gemini 3.8 Flash
Gemini 3.8 Flash brings improvements over Gemini 3.7 Flash across software engineering, agentic tasks and multi-step reasoning in specialized domains. The coding and reasoning improvements are driven by model-development changes, including rigorous training in cybersecurity, while the model is designed for long-horizon coding and autonomous agents.

On the DeepSWE v1.1 Long-Horizon Software Engineering benchmark, Gemini 3.8 Flash outperforms most larger frontier models in autonomously solving complex engineering problems end to end, at a fraction of the cost.

The model also records higher results than Gemini 3.7 Flash and other frontier models on benchmarks covering specialized professional domains:
- Vals Finance Agent V2: Gemini 3.8 Flash outperforms Gemini 3.7 Flash and other frontier models.
- Harvey’s Legal Agent Benchmark: Gemini 3.8 Flash also outperforms Gemini 3.7 Flash and other frontier models.
- HLE-Verified: The model scores 54.9%, covering multi-step reasoning across STEM, humanities and professional fields.



On complex tasks, Gemini 3.8 Flash can execute additional reasoning steps and make iterative tool calls, which can increase token usage, particularly at higher effort levels. Developers can use lower effort levels to reduce token overhead, while Gemini 3.7 Flash remains supported for efficiency-first workloads.
Gemini 3.8 Flash Cyber
Gemini 3.8 Flash Cyber focuses on defensive cybersecurity tasks, including autonomous vulnerability discovery and automated patching. It shares the foundational intelligence of Gemini 3.8 Flash while incorporating cybersecurity-focused training, with the model retaining the Flash series’ speed and cost profile for iterative use.
Vulnerability discovery
On CyberGym, the standard industry benchmark for finding vulnerabilities, Gemini 3.8 Flash Cyber demonstrates frontier-level performance in autonomous vulnerability discovery, surpassing Gemini 3.5 Flash Cyber and significantly larger frontier models.

Google also evaluated the model on an internal benchmark designed to capture real-world defensive needs beyond the C/C++ codebases represented in CyberGym. The benchmark covers complex codebases across 20 programming languages, with Gemini 3.8 Flash Cyber achieving a success rate of more than 70%.

Automated patching
Gemini 3.8 Flash Cyber also focuses on fixing software vulnerabilities. Google says vulnerability fixing was prioritized from the beginning over offensive capabilities such as exploitation.
On CWE-Bench, an external vulnerability-patching benchmark run by Collinear, Gemini 3.8 Flash Cyber achieves a 47.2% pass@1 score, compared with 47.8% for a leading frontier model, at a significantly lower cost.

Google also evaluated the model on real-world security workloads:
- Google Chrome Security: The model produced 2.6 times more correct patches for Chrome vulnerabilities than the best commercial models tested, which were much larger.
- Wiz: The model achieved 7.5–9.7% higher recall on an internal penetration-testing benchmark while costing 2.3–5.2 times less than other leading frontier models.
- Google Cloud Vulnerability Research: The model identified a critical foundational vulnerability in less than two hours, compared with research and discovery processes that usually take months.
Safety
Gemini 3.8 Flash includes safeguards against misuse involving Chemical, Biological, Radiological, and Nuclear (CBRN) applications and cyber offense, while supporting beneficial use cases under Google’s Frontier Safety Framework.
The key safety measures across the Gemini 3.8 models include:
- CBRN and cyber safeguards: Gemini 3.8 Flash includes protections against misuse involving CBRN applications and cyber offense.
- Cybersecurity mitigations: Gemini 3.8 Flash Cyber uses a more permissive set of cybersecurity mitigations for comprehensive defensive cybersecurity capabilities.
- Prompt injection protection: The Gemini 3.8 models have improved robustness against prompt injection, based on measurements from Gray Swan.

Pricing
Gemini 3.8 Flash is priced as follows:
| Period | Input tokens | Output tokens |
|---|---|---|
| Through December 31, 2026 | $0.75 per 1M | $3.75 per 1M |
| From January 1, 2027 | $1.50 per 1M | $7.50 per 1M |
Availability
For developers, Gemini 3.8 Flash is available through:
- Google Antigravity for agent-first workflows
- Gemini API through Google AI Studio and Android Studio
- Stitch for generating user interfaces
- Google’s developer documentation
For enterprises, Gemini 3.8 Flash is available through Gemini Enterprise.
For consumers, the model is available to Google AI Pro and Ultra subscribers through the Gemini app, AI Mode in Google Search and Gemini in Google Sheets.
Gemini 3.8 Flash Cyber is being provided through Google’s new Fairwind Program, with prioritized access for trusted government authorities, critical infrastructure operators and software maintainers.
