Google ships Gemini 3.8 Flash and a security-tuned variant
Gemini 3.8 Flash went on general release on 2 September, alongside a restricted Flash Cyber model built for finding software vulnerabilities.
Google released Gemini 3.8 Flash, its low-cost AI model for everyday work, on 2 September 2026, according to the company's blog and 9to5Google. It came three weeks after version 3.7. Google also released Gemini 3.8 Flash Cyber, a security version for trusted partners only, which Google says produced 2.6 times more correct patches for Chrome bugs than much larger models.
- 54.9%Gemini 3.8 Flash score on the HLE-Verified reasoning test
- $0.75per million input tokens until 31 December 2026
- 650+partners in Google's Fairwind Program
- 70%+of flaws found in Google's internal 20-language test
What happened
Gemini 3.8 Flash is the third Flash model Google has released in about six weeks. Google calls it its most intelligent workhorse model, meaning the model it expects people to use for most ordinary tasks. The company says it improves on 3.7 Flash in software engineering, agent tasks, where the model carries out several steps on its own, and multi-step reasoning in specialised subjects. Google says it often comes close to more expensive frontier models. The one exact score in Google's text is 54.9 percent on HLE-Verified, a hard reasoning test that covers science, the humanities and professional fields.
Google gives an introductory price of 0.75 US dollars per million input tokens and 3.75 dollars per million output tokens, the same introductory price 3.7 Flash had. That offer ends on 31 December 2026. From 1 January 2027 the price doubles to 1.50 and 7.50 dollars. Developers can use the model through Google AI Studio, the Gemini API, the Antigravity coding tool, Android Studio and Stitch, a tool for designing user interfaces. Paying subscribers can also use it in the Gemini app, AI Mode in Search and Gemini in Google Sheets.
Gemini 3.8 Flash Cyber is not available to the public. Google offers it only through a new scheme called the Fairwind Program, aimed at government cyber agencies, operators of critical infrastructure such as hospitals, telecoms, energy and finance, and software maintainers. Google says Fairwind has more than 650 partners. Inside the program the model is paired with CodeMender, a Google tool that finds, checks and fixes security flaws. Google says partners must limit access to their security teams and use protections such as multi-factor authentication.
The engineering behind it
Google explains the gains with a simple idea: 3.8 Flash works harder. On a difficult task it runs extra reasoning steps and calls tools again and again, for example running code, reading the result and trying a fix. This usually gives better answers, but it uses more tokens, which are the small pieces of text a model reads and writes and the unit it is billed in. Google says developers can choose a lower effort level to use fewer tokens. In practice, this turns cost into a setting the developer must manage.
The Cyber version shares the same base model but has looser safety limits in the security area, so that it can study and repair flaws that the normal model would refuse to discuss. That is why Google restricts who can use it. Google says it focused the model on fixing vulnerabilities rather than on exploitation, which means actually using a flaw to break into a system. The ordinary 3.8 Flash keeps safeguards against cyber attacks and against chemical, biological, radiological and nuclear misuse under Google's Frontier Safety Framework.
The security numbers come from Google and its partners, not from independent tests. Google says its Chrome Security team found the Cyber model produced 2.6 times more correct patches for Chrome flaws than the best commercial models, which are much larger. The security company Wiz reported 7.5 to 9.7 percent higher recall on its own penetration-testing benchmark at 2.3 to 5.2 times lower cost. Recall here means the share of real flaws the model managed to find. Google also says the model found more than 70 percent of flaws in an internal test across 20 programming languages.
What it means in Nepal
The sources say nothing specific about Nepal. What they do show is that the cheaper models are becoming more capable, and that a developer anywhere with an internet connection and an API key can use them. For a student project, the main skills are practical ones: writing clear instructions, deciding how much reasoning effort a task needs, and estimating the cost in tokens before running a large job. These habits matter more as prices change, because the introductory price ends on 31 December and the regular price is twice as high.
The Cyber model points to how security work is changing. If a model can suggest patches in minutes, the human job moves towards checking those patches. Someone still has to read the change, understand the original flaw, write a test that proves the fix works and confirm that nothing else broke. Those are skills any student can practise now with open-source projects. They also depend on basics that no model replaces: knowing how memory, networks and operating systems actually behave.
A careful reader should also notice how the claims are framed. Every security result in this story comes from Google or a partner in its program, and the Cyber model is closed to outside testers. Reading a vendor announcement, separating measured results from marketing, and waiting for independent checks is part of engineering judgement. It is a habit worth building early, because new model releases now arrive every few weeks.
What to study if this interests you
Artificial Intelligence, ENCT 351, in the sixth semester of BCT, introduces search, reasoning, learning and the basics of neural networks, which explain what a model like Gemini is doing when it reasons step by step. The course has a full guide on this site. BEI students take a course of the same name in their fifth semester.
For the security side, Network and Cyber Security, ENCT 463, in the eighth semester of BCT, covers how attacks work and how systems are defended. Software Engineering, ENCT 352, in the sixth semester, teaches testing, version control and code review, the skills needed to check whether a machine-written patch is correct. Operating System, ENCT 254, in the fourth semester, explains memory management and process isolation, which is where many of the flaws these models look for are found.
Words in this story
- Token
- A small piece of text, often part of a word, that a language model reads or writes and that providers use to set prices.
- Patch
- A change to a program's code that fixes a bug or a security flaw.
- Penetration testing
- Authorised testing in which experts attack a system on purpose to find weaknesses before criminals do.
- Recall
- The share of real problems that a detection tool manages to find, out of all the problems that exist.
Where this comes from
- 9to5Google, 2 Sep 2026
- Google (The Keyword blog), 28 Sep 2026
- Google (The Keyword blog), launch post, 2 Sep 2026
- Google (The Keyword blog), Fairwind Program, 2 Sep 2026
Written in our own words; no sentence is copied from these reports. Researched with AI assistance on 11 October 2026; no member of faculty has reviewed it yet. If you spot a mistake, call 01-5091616 and we will correct it and say so.




