# Google gates Gemini 3.8 Flash Cyber behind vetted access scheme

> Google launched a restricted cyber-defence AI model via new Fairwind Program.

*Google pairs a security-tuned model with its CodeMender agent, but only lets vetted defenders in.*

By Behzad Hosseini · FeaturedDaily
Canonical: https://featureddaily.com/news/google-gates-gemini-3-8-flash-cyber-behind-vetted-access-scheme

**What happened:** Google made Gemini 3.8 Flash generally available on 2 September 2026 and launched a specialised sibling, Gemini 3.8 Flash Cyber, for security defenders.

**The details:** Cyber is a post-trained version of the same base model with fewer restrictions on advanced security work. It searches code for vulnerabilities, verifies findings, generates fixes and validates patches before deployment. Google pairs it with its CodeMender agent harness through a new access scheme called the Fairwind Program.

**Who's affected:** Fairwind is application-only. It's open to government agencies, Google Cloud customers and security partners, with priority given to critical-infrastructure operators and maintainers of widely used software. Members must restrict access to security staff and enforce protections like multi-factor authentication. More than 650 organisations are already in.

**The catch:** No self-serve option exists for the Cyber variant. Anyone on Google Cloud can still use CodeMender, but only with public models, not the restricted one.

**The numbers:** Google's internal tests show over 70% vulnerability discovery across 20 languages and 2.6 times more correct patches than competing models. On a Collinear patching benchmark it hit 47.2% pass@1, close to a leading frontier model's 47.8%, at much lower cost.

**Why it matters:** Google is betting that gated, agentic-scale defence tools help vetted defenders outpace attackers without handing the same capability to everyone.

**The context:** Google now joins Anthropic and OpenAI in restricting its strongest cyber model to a vetted programme. Anthropic gated Claude Mythos 5 via Project Glasswing in April; OpenAI did the same with GPT-5.6-Cyber through Daybreak.

**What's next:** Fairwind membership will determine who gets access to Google's most capable vulnerability-hunting tools, as the company expands the programme beyond its initial 650-plus organisations.

Details from [Google's announcement](https://blog.google/innovation-and-ai/technology/safety-security/fairwind-program/) and [Security Boulevard's coverage](https://securityboulevard.com/2026/09/google-launches-fairwind-program/).

## Key takeaways

- Gemini 3.8 Flash Cyber needs Fairwind Program approval, no self-serve
- Over 650 organisations already in the programme
- Finds bugs 70%+ of the time across 20 languages, Google says

## Sources

- [Google's Fairwind Program: Cyber defense tools for trusted partners](https://blog.google/innovation-and-ai/technology/safety-security/fairwind-program/) — Google, 2026-09-02
- [Google Launches Fairwind Program for Gemini 3.8 Flash Cyber Access](https://securityboulevard.com/2026/09/google-launches-fairwind-program/) — Security Boulevard, 2026-09
