Gemini 3.8 Flash and 3.8 Flash Cyber (Sep 2, 2026)
Google Sep 2 2026 primary: Gemini 3.8 Flash on developer/enterprise/Pro/Ultra; Flash Cyber gated via Fairwind. Resolves the 2026-09-02 unverified cluster. Benches and intro pricing are Google's own claims.
Gemini 3.8 Flash and 3.8 Flash Cyber (Sep 2, 2026)
Generated by Grok Bot research on 2026-09-03. WebSearch + WebFetch + native X. Treat as raw material — review before promoting.
Filer: /clipping-file → /clipping-promote → /ingest-pending into vault/threads/artificial-intelligence. Bounded 9am ET idle X pull. This resolves yesterday’s overnight clip (research-clip://x-ai-overnight-lab-drops-2026-09-02), which treated Gemini 3.8 Flash timing as news-cluster chatter and did not cite it. Do not re-file Fable/Mythos 5.1, reward-seeker / Hacker-Opus, Astra Critical, or DeepMind agentic video from that source.
Summary
On 2 September 2026 Google published that Gemini 3.8 is two variants sharing a foundation: 3.8 Flash, aimed at software engineering, agents, and multi-step reasoning and available on developer, enterprise, and Gemini Pro/Ultra consumer surfaces; and 3.8 Flash Cyber, gated through Fairwind. Same-day official X from @GoogleDeepMind and @GeminiApp matches that split. This is now a primary-source launch, not the unverified cluster from the 2026-09-02 overnight pass. Every capability number below is Google’s own claim. Flash introductory API pricing is $0.75/M input and $3.75/M output through 31 December 2026, then $1.50/$7.50. Flash Cyber benches (internal 20-language vulnerability set, CWE-Bench, Chrome tests) are not independently reproduced here; cross-model harness comparability remains open.
Findings
Two variants, one foundation
Google’s Sep 2 2026 model post states Gemini 3.8 has two variants that share a foundation. Flash is the generally available line: Google says it improves software engineering, agents, and multi-step reasoning, and that it is available via developer, enterprise, and Pro/Ultra consumer surfaces. Flash Cyber is the cyber-specialized line, gated via Fairwind. The same post says Flash and Cyber have different mitigations. Do not treat them as the same deployed model.
The DeepMind launch post (2026-09-02) repeats the product split in text: 3.8 Flash improvements across SWE, agentic tasks, and multi-step reasoning; Cyber described as Google’s most capable cyber variant. That post has an animated GIF attached. Claims in this clipping come from the post text and from fetched official pages only. The GIF was not inspected and is not described. x_video: false because load-bearing claims are not from media.
Flash: availability, Google-claimed capability, introductory price
Google’s blog reports 54.9% HLE-Verified for Flash. That is a Google-reported score, not a third-party rerun in this pass. The same post says Flash may use more tokens. @GeminiApp (2026-09-02) says Flash is available to Pro/Ultra and claims more reliable comprehensive responses for advice, text analysis, and complex coding. A follow-up DeepMind post says Flash is rolling out via Antigravity/API, with Cyber gated via Fairwind.
Introductory API pricing on the blog: $0.75 per million input tokens and $3.75 per million output tokens through 31 December 2026, then $1.50 / $7.50. The cheap intro rate expires; do not stamp $0.75/$3.75 as the durable list price. Token-heavier generations (Google’s own “may use more tokens” note) can eat the intro discount in practice. Consumer Pro/Ultra availability is a surface, not evidence that the same meter applies there.
Flash Cyber: Google-reported benches, not an independent bake-off
All of the following are Google-reported on the Sep 2 blog, not reproduced here:
- >70% success on an internal 20-language vulnerability benchmark.
- CWE-Bench pass@1 47.2% versus a leading frontier model at 47.8%. Google does not name that frontier model in the fetched post. The gap is 0.6 points; treat it as a near-tie on Google’s own comparison, not as a demonstrated lead.
- Chrome tests: 2.6× more correct patches than larger commercial models (unnamed).
Official X in the same window restates overlapping but not identical claims: expert vulnerability detection and autonomous patching; deployable fixes in minutes inside an org cloud; CyberGym lead and 2.6× more valid fixes in Chrome tests. Keep the blog’s “correct patches vs larger commercial models” wording and the X “CyberGym lead / valid fixes” wording as two Google claims, not one merged result. Cross-model harness, effort level, tool access, and patch-validity criteria are not independently checked. Do not compare these numbers to other labs’ cyber benches (including OpenAI’s Astra / ExploitBench material from yesterday’s clip) as if they share a harness.
Fairwind gating
Flash Cyber is gated via Fairwind. The Fairwind program page (fetched) says vetted governments, healthcare, telecom, and core platforms get access to Flash Cyber and CodeMender. Google says over 650 partners. Governance on that page: use restricted to defensive / academic dual-use tasks; phishing-resistant MFA; access controls; no redistribution; due diligence. Google also claims zero data retention for the managed Enterprise Agent Platform. Those are program rules and Google statements, not an audit. @GoogleDeepMind frames Fairwind as trusted authorities / essential providers.
Model card not fetched
WebSearch discovered https://deepmind.google/models/model-cards/gemini-3-8-flash/. WebFetch timed out. Do not cite that URL as a retrieved source in Findings. No model-card numbers, limits, or safety text are used here.
Accounts with nothing in-window; xAI miss
No original posts from @AnthropicAI, @OpenAI, or @karpathy in this window. xAI was inaccessible; record as a miss, not as “xAI said nothing.” News-cluster stories were discovery only and are not cited (same rule as yesterday’s overnight clip).
Contradictions and open questions
- Yesterday vs today: the 2026-09-02 overnight clip left Gemini 3.8 Flash timing as unverified cluster chatter. Official blog + DeepMind/GeminiApp X now confirm a Sep 2 launch. That cluster item is resolved as a primary; do not keep “unverified” on the launch itself.
- CWE-Bench near-tie vs “most capable cyber variant”: Google reports 47.2% pass@1 vs 47.8% for an unnamed leading frontier model on the blog, while the launch post calls Cyber the most capable cyber variant. Those two Google lines do not automatically agree.
- Harness comparability: CWE-Bench, the internal 20-language set, Chrome tests, CyberGym (X only), and other labs’ cyber evals are not shown to share protocol, tools, or patch-accept criteria. Stamp Google-reported, not cross-lab rank.
- 2.6× wording split: blog = 2.6× more correct patches than larger commercial models in Chrome tests; X = CyberGym lead and 2.6× more valid fixes in Chrome tests. Same-day Google, not proven identical metrics.
- Introductory pricing expiry: $0.75/$3.75 holds only through 31 December 2026, then $1.50/$7.50 per the blog. Pair with “may use more tokens.”
- “Fixes in minutes” is an X claim (2095196708254658820), not a numbered result on the fetched blog.
- Model card timeout: safety, limits, and eval appendices on
deepmind.google/models/model-cards/gemini-3-8-flash/were not retrieved. - Fairwind 650 partners / zero retention / dual-use-only: Google program claims; no partner list or independent retention audit in this pass.
- CodeMender is named on the Fairwind page as an access item next to Flash Cyber; this clipping has no other CodeMender primary.
- Animated GIF on the root launch post: not used. Do not infer capability from unseen media.
Provenance
Method: Grok Bot / WebSearch / WebFetch / native X (not Parallel)
Generated: 2026-09-03
Rounds: 1 of 3 (early-exit — bounded 9am ET idle X pull; official blog + Fairwind + native X closed the 2026-09-02 unverified-cluster item; no recap blogs)
URLs fetched: 2 successful, 1 failed
Fetch notes: Google blog and Fairwind program page retrieved via WebFetch. Model-card URL discovered by WebSearch; WebFetch timed out — recorded as a miss, not cited in Findings. Root X post 2095175498967949359 has an animated GIF; claims taken from post text and fetched official pages only; media not described. News clusters used for discovery only, never cited. Grokipedia not used.
Web sources:
- Introducing Gemini 3.8 Flash and Gemini 3.8 Flash Cyber (Google, Sep 2, 2026) — two-variant launch; Flash SWE/agents/reasoning; intro $0.75/$3.75 through 2026-12-31 then $1.50/$7.50; 54.9% HLE-Verified; may use more tokens; Cyber via Fairwind; Google-reported >70% internal 20-language vuln bench, CWE-Bench 47.2% vs 47.8%, Chrome 2.6× correct patches; different mitigations; Flash on developer/enterprise/Pro/Ultra
- Fairwind program (Google DeepMind) — vetted governments/healthcare/telecom/core platforms; Flash Cyber + CodeMender; Google says 650+ partners; defensive/academic dual-use, phishing-resistant MFA, access controls, no redistribution, due diligence; zero-retention claim for managed Enterprise Agent Platform
- Gemini 3.8 Flash model card (DeepMind) — not fetched (WebFetch timed out); listed only as a failed fetch
X sources:
- X post by @GoogleDeepMind (2026-09-02) — launch: Flash SWE/agentic/multi-step; Cyber most capable cyber variant; animated GIF attached (text used, media not described)
- X post by @GoogleDeepMind (2026-09-02) — Flash via Antigravity/API; Cyber gated via Fairwind
- X post by @GeminiApp (2026-09-02) — Flash on Pro/Ultra; more reliable comprehensive responses (advice, text analysis, complex coding)
- X post by @GoogleDeepMind (2026-09-02) — expert vulnerability detection / autonomous patching
- X post by @GoogleDeepMind (2026-09-02) — deployable fixes in minutes inside org cloud
- X post by @GoogleDeepMind (2026-09-02) — CyberGym lead; 2.6× more valid fixes in Chrome tests
- X post by @GoogleDeepMind (2026-09-02) — Fairwind for trusted authorities / essential providers
- none from @AnthropicAI, @OpenAI, or @karpathy (no original posts in window)
- xAI inaccessible — miss, not a none-found
Grokipedia:
- not used