CourionAI
EN
Newsletter
← All news
google 3 min read

Google's Gemini 3.8 Flash Keeps the Old Price, and Brings a Cyber Twin

Google DeepMind released Gemini 3.8 Flash on 2 September at $0.75 per million input tokens, unchanged from 3.7 Flash. A separate Cyber variant for vulnerability finding and patching goes only to vetted defenders.

Two identical lightning bolts side by side, the left one free and the right one enclosed inside a heavy shield outline

Google DeepMind put out Gemini 3.8 Flash last Wednesday, its third Flash release in six weeks. The pitch is unusually plain: the same speed and the same price as 3.7 Flash, with better reasoning and coding. Input costs $0.75 per million tokens, output $3.75, and that is an introductory rate that expires on 31 December 2026. From 1 January those figures double to $1.50 and $7.50.

Google reports gains on long-horizon software engineering, meaning tasks where a model has to keep working through a problem over many steps rather than answering in one shot. It scores 54.9% on HLE-Verified, a hard multi-subject reasoning test, and Google says 3.8 Flash beats larger and more expensive models on DeepSWE v1.1. There is an honest caveat in Google’s own post: 3.8 Flash “works harder”, running extra reasoning steps and calling tools repeatedly, which means it can burn more tokens than 3.7 Flash on the same job. Google explicitly tells developers who care most about cost to stay on 3.7 Flash or dial the effort level down.

The second model is the interesting one. Gemini 3.8 Flash Cyber is tuned for finding software vulnerabilities and writing patches for them, and it is not generally available. Access runs through a new Fairwind Program aimed at government bodies, critical infrastructure operators and software maintainers. Google says it deliberately prioritised fixing flaws over exploiting them. Some concrete results: Chrome’s security team reported 2.6 times more correct patches than from much larger commercial models, and Google’s cloud vulnerability team says it found a critical foundational bug in under two hours, work that would normally take months. On CWE-Bench, an external patching benchmark, it scores 47.2% against a leading frontier model’s 47.8%, at a fraction of the cost.

The pattern behind the split. Two labs in two days have now shipped a public model plus a gated cyber sibling. The reason is that the same skill reads both ways: a model good enough to find the hole in your code is good enough to find the hole in someone else’s. Rather than choose between shipping it to everyone or nobody, both companies have carved out a middle tier with an application form. Google also reports a large jump in resistance to prompt injection, the trick where instructions hidden in a web page or document hijack a model that is reading it. That is arguably the more useful safety improvement for ordinary users, since prompt injection is the failure mode you are most likely to actually meet.

What this means for you. If you use the Gemini app on a Pro or Ultra plan, 3.8 Flash is already there, and in AI Mode in Search and in Google Sheets. For most everyday questions you will not notice. If you build with the API, note the calendar: the price you sign up for today doubles in January, so budget on the 2027 number rather than the current one. And if you run infrastructure that people depend on, the Fairwind Program is open to applications, which is a genuinely new option that did not exist a year ago.

Sources

Source: https://blog.google/innovation-and-ai/models-and-research/gemini-models/3-8-flash-and-3-8-flash-cyber/

Next story

OpenAI Ships GPT-6 Astra, and Calls It Its First Critical Cyber Model

OpenAI released GPT-6 Astra on 3 September with a 1.1 million token context window at $10 per million input tokens and $50 per million output. It is the first model the company says meets its Critical cybersecurity threshold.

A large eight pointed star built from concentric printed rings with a small closed padlock at its centre