On September 2, 2026, Google announced Gemini 3.8 Flash and Gemini 3.8 Flash Cyber, a security-focused edition. The standard model is designed to spend more effort on long-horizon software engineering, agent tasks and multi-step professional reasoning. Cyber applies the same family of capabilities to vulnerability discovery and patching, with access restricted to trusted defenders.
Gemini 3.8 Flash targets long-horizon work
Google says Gemini 3.8 Flash improves over 3.7 Flash in software engineering, agent work and multi-step reasoning. In the company's DeepSWE v1.1 long-horizon software engineering evaluation, 3.8 Flash scored 73.7%, up from 65.3% for 3.7 Flash; it reported 54.9% on HLE-Verified. These are Google's published results and describe the model's direction, not a guarantee for every repository or conversation.
The key design choice is that the model can take more reasoning steps and call tools iteratively on complex tasks. Google warns that higher effort can consume more tokens. Developers who prioritize latency or cost can lower the effort level or continue using the fully supported Gemini 3.7 Flash. The benefit may come from doing more work, not from every request becoming faster and cheaper.
Where can you use it?
Developers can start with the Gemini API, Google AI Studio, Google Antigravity, Android Studio and Stitch, while enterprises can access it through Gemini Enterprise. For consumers, Gemini 3.8 Flash is available to Google AI Pro and Ultra subscribers in the Gemini app, AI Mode in Google Search and Google Sheets. Exact features and rollout timing can still vary by account, region and product surface.
Ars Technica notes that switching to 3.8 Flash in the Gemini app requires Pro or Ultra, while developers can experiment in AI Studio. A model being announced does not mean every access point is open without conditions; users should check their interface and plan.
Pricing stays flat for now, with a deadline
Gemini API uses the same introductory pricing as 3.7 Flash: $0.75 per million input tokens and $3.75 per million output tokens through December 31, 2026. From January 1, 2027, Google's listed regular prices are $1.50 per million input tokens and $7.50 per million output tokens. High-effort long tasks may consume more output tokens, so teams should estimate costs from their own request sizes, caching and tool calls.
Cyber is not a hidden switch for regular accounts
Gemini 3.8 Flash Cyber is offered through the new Fairwind Program to trusted defenders, including government authorities, critical infrastructure operators and software maintainers. Google says the model prioritizes vulnerability discovery and automated patching over exploitation. Its Chrome Security team reported 2.6 times more correct patches than much larger commercial models in internal testing. These are Google's internal-use and evaluation claims, not a reproducible guarantee for public users.
In security, stronger capabilities also raise misuse risks. Google says standard 3.8 Flash retains safeguards for CBRN and cyber offense, while Cyber uses a more permissive but governed boundary and is limited to approved defensive teams. Cyber is not a consumer Pro tier and a model name alone does not grant vulnerability research access.
What matters for users?
For developers, the most useful test is a long-running task that repeatedly reads project state and calls tools, rather than a few short prompts. If cost matters, track effort levels and token usage together. For consumers, the value is potentially deeper reasoning on complex research, reports and coding tasks, but Google's benchmarks still need to be tested against your data, permissions and error rates. Flash Cyber is better understood as a controlled security capability for professional defenders, not a consumer chat tier.
Google's announcement: Introducing Gemini 3.8 Flash and 3.8 Flash Cyber
