Google DeepMind
Gemini 3.8 Flash
the workhorse again, plus a cyber variant behind a gate

Key facts
- 2 Sept 20263 weeks after 3.7 Flash
- Announced
- 1M / 64ktokens in / out
- Context
- $0.75 / $3.75per M, until 31 Dec 2026
- Price
- $1.50 / $7.50unchanged from 3.7
- From 1 Jan 2027
- 86.2%Cyber variant, pass@1
- CyberGym
- Fairwindvetted defenders only
- Cyber access
The third Flash release in six weeks, at the same speed and the same introductory price as the model it replaces. The interesting half is the one most readers cannot use: 3.8 Flash Cyber finds and patches vulnerabilities, and Google is handing it only to vetted governments, infrastructure operators and maintainers. On Google's own patching table it sits a fraction behind Claude Fable 5, and the argument it makes is cost.
What it is
Gemini 3.8 Flash is Google DeepMind’s workhorse model, announced on 2 September 2026, three weeks after Gemini 3.7 Flash and six weeks after 3.6 Flash. Flash is the tier for high-volume everyday work. The announcement is bylined by two people rather than the usual one: Tulsee Doshi, senior director of product management, and Raluca Ada Popa, Gemini security lead at Google DeepMind, and the second name is the tell, because half the release is a security model.
Google’s own framing is “next-generation intelligence for agentic workflows and cybersecurity”. The cadence is the part worth noting: three new Flash models in six weeks, each one an iteration on the last, at a pace that makes any comparison table stale within a month.
What you actually get for the same money
The price has not moved. 3.8 Flash ships at $0.75 per million input tokens and $3.75 per million output, the same introductory rate 3.7 Flash launched on, and it expires on the same date: 31 December 2026. From 1 January 2027 both revert to $1.50 and $7.50. So the introductory window is now shorter than it looks, because it did not restart with the new model.
| Gemini 3.8 Flash | |
|---|---|
| Model ID | gemini-3.8-flash |
| Context | 1,048,576 in / 65,536 out |
| Inputs | text, image, video, audio, PDF |
| Thinking | low, medium, high (minimal unsupported) |
| Price to 31 Dec 2026 | $0.75 / $3.75 per M |
| Price from 1 Jan 2027 | $1.50 / $7.50 per M |
Google reports 54.9% on HLE-Verified, and says 3.8 Flash beats 3.7 Flash and other frontier models on Vals Finance Agent V2 and Harvey’s Legal Agent Benchmark. Both are domain agent benchmarks rather than general reasoning tests, which is consistent with a release aimed at agentic work rather than at chat.
Availability is wide on the general model: Google AI Studio, Android Studio, the Gemini API, Google Antigravity and Stitch for developers; Gemini Enterprise for companies; and the Gemini app, AI Mode in Search and Google Sheets for AI Pro and Ultra subscribers.
The half you cannot buy
Gemini 3.8 Flash Cyber is the same generation pointed at security work: finding vulnerabilities in source code and writing patches for them. Google describes it as its most capable cybersecurity model, with “frontier-level performance in vulnerability detection, and automated patching”.
It is not for sale. Access runs through the Fairwind Program, which Google restricts to “trusted government authorities, as well as critical infrastructure operators and software maintainers”, on the stated reasoning that it gives defenders a head start while keeping deployment controlled. A model that reads twenty languages of source code looking for exploitable flaws is equally useful to whoever holds it, and the gate is Google’s answer to that.
The published figures:
| Benchmark | 3.8 Flash Cyber | Compared with |
|---|---|---|
| CyberGym, pass@1 | 86.2% | GPT-5.5-Cyber 85.6%; Gemini 3.5 Flash Cyber 77.5% |
| CWE-Bench, pass@1 | 47.2% | Claude Fable 5, 47.8% |
| Real-world vulnerability discovery | over 70% | internal set, 20 programming languages |
| Gray Swan IPI, attack success | 6.0% | lower is better |
That second row rewards a close read, because it is Google’s own table and Google is not winning it. On CWE-Bench patching, 3.8 Flash Cyber scores 47.2% against Claude Fable 5’s 47.8%. The claim Google makes is not that it patches better; it is that it patches for about $3.60 a rollout, materially less than a much larger model. For a maintainer running the thing across a whole codebase, cost per attempt is a real argument. It is still an argument about price, made on a row the model loses.
The Chrome Security team’s number is the one with a named team behind it: 3.8 Flash Cyber produced 2.6 times more correct patches to Chrome vulnerabilities than “the best commercial models that are much larger”.
The Gray Swan indirect prompt injection figure is worth keeping in view for a different reason. A 6.0% attack success rate is strong, and it is not zero. This is a model designed to be pointed at untrusted source code, which is precisely the setting where injected instructions arrive inside the thing you asked it to read.
What we would want before trusting the security claims
Every figure above is Google’s, published by the vendor on launch day, and the two independent-sounding ones (Chrome Security, Cloud Vulnerability Research) are also Google teams. That does not make them wrong. It does mean nothing here has been reproduced by anyone outside the company, and the model is gated in a way that makes outside reproduction difficult by design.
The narrower question is what “success rate exceeding 70%” on real-world vulnerability discovery counts as a success, since the benchmark is internal and unpublished.
Related
- Gemini 3.7 Flash, the model this replaces after three weeks
- Gemini 3.6 Flash
- Claude Fable 5.1, released a day earlier, and the model on the other side of Google’s CWE-Bench row
More in Large Language Models
All LLMs →- Google DeepMindGemini 3.7 Flashthe workhorse tier, on an introductory price
- Google DeepMindGemini 3.6 Flashthe efficient workhorse
- AnthropicClaude Fable 5.1built for the API, hard on a subscription allowance
- OpenAIGPT-5.6the flagship since 9 July 2026
- AnthropicClaude Fable 5the flagship holding first place on the Arena text board
- AnthropicClaude Opus 5frontier work with a dial on the bill