
Google has placed its most capable cybersecurity model behind an approval process, limiting access to organisations it trusts to find and fix software weaknesses.
Available through the company’s new Fairwind Program, Gemini 3.8 Flash Cyber prioritises government agencies, essential service providers, and major technology platforms.
Announced in early September, the programme gives selected organisations tools to repair vulnerable systems before attackers exploit them. Google says more than 650 partners are participating globally, with CrowdStrike, Palo Alto Networks, and Snowflake among those featured.
Who Can Access the Model?
Access extends to approved organisations across healthcare, telecommunications, energy. and financial services, alongside national cybersecurity authorities and companies maintaining widely used software.
Applicants undergo background checks covering their security history and record of ethical operations. Once approved, organisations must limit model access to internal security teams, track employee use, and require protections including phishing-resistant multifactor authentication.
Partners also cannot share, resell, or redistribute access. Permitted activities include authorised attack simulations, malware analysis, and reverse engineering for defensive or academic research purposes.
What Makes the Gemini 3.8 Flash Cyber More Powerful?
Gemini 3.8 Flash Cyber is designed to identify software flaws and generate fixes automatically. Google says it achieved a 71% success rate on an internal vulnerability discovery test spanning 20 programming languages, compared with 46.6% for Gemini 3.5 Flash Cyber.
The company also reports practical results inside its own products. Its Chrome security team found that the new model produced 2.6 times as many correct security patches as the larger commercial models used for comparison.
Through Fairwind, the model can work with CodeMender, Google’s software security agent, to find, verify and repair vulnerabilities. Google says this combination can generate validated patches in minutes within an organisation’s secure cloud environment.
“To outpace automated threats, defenders need model performance that operates at the speed of the attack,” said Charlie Sestito, a director in Palo Alto Networks’ Office of the CTO, in a testimonial published by Google.
Why Google Is Restricting Access
The Cyber model comes with more permissive cybersecurity safeguards than standard Gemini 3.8 Flash. Google says this allows approved defenders to perform more extensive security work, with access restricted to trusted organisations that need those capabilities.
The risk of misuse already has practical examples. In May, Google’s threat intelligence team reported identifying a criminal actor with an exploit targeting a previously unknown software vulnerability. The team believed AI had helped develop the exploit and said its intervention may have prevented a planned mass exploitation campaign.
For organisations seeking advanced AI security tools, Fairwind makes access dependent on Google’s assessment of their work and security record. The company says it plans to expand participation, while other Google Cloud customers can already use CodeMender with publicly available models.
