A Flash model designed to stay busy
Gemini 3.8 Flash launched on September 2 with a 1,048,576-token input limit and up to 65,536 output tokens. It accepts text, images, video, audio and PDFs, while its documented toolset includes code execution, function calling, Search and Maps grounding and preview computer-use support.
Google is aiming it squarely at long-horizon software engineering and autonomous agent workflows. Rather than presenting efficiency as the sole virtue of a Flash-class model, the company says 3.8 can perform extra reasoning steps and iterate on tool calls when a problem warrants it.
That behavior complicates the price comparison with Gemini 3.7 Flash.
The API rate is unchanged for now
The introductory rate remains $0.75 per million input tokens and $3.75 per million output tokens through December 31, 2026. Google's published pricing then doubles on January 1, 2027 to $1.50 and $7.50 respectively.
Until then, two jobs charged at the same token rate can still produce different totals. Google warns that Gemini 3.8 Flash may use more tokens at higher effort settings. Developers who value compute efficiency above the extra reasoning can lower effort or continue using 3.7 Flash.
An early Artificial Analysis measurement cited by The Verge found the cost per evaluated task roughly 40 percent above 3.7 Flash, driven in part by greater output-token use and additional turns in agentic evaluations. It is one benchmark result, not a general rule for API bills, but it illustrates the distinction Google itself is making.
Cyber gets a different access model
Gemini 3.8 Flash Cyber shares the underlying intelligence but is tuned for vulnerability discovery and automated remediation. Google says it gives this version a more permissive set of cybersecurity mitigations, which is why ordinary Gemini and API users do not simply get access to it.
Instead, Flash Cyber is being distributed through Fairwind, a restricted program prioritizing governments, national cyber authorities, critical-infrastructure operators, software maintainers and other trusted security partners.
Google reports frontier-level results on CyberGym and says an internal evaluation spanning complex codebases in 20 programming languages produced a vulnerability-discovery success rate above 70 percent. On CWE-Bench, which measures patching, Google reports 47.2 percent pass@1 compared with 47.8 percent for a leading frontier model, while emphasizing a lower rollout cost.
The model is already being pointed at Google's own software
Chrome's security team found that 3.8 Flash Cyber generated 2.6 times as many correct vulnerability patches as much larger commercial models, according to Google. Its Cloud Vulnerability Research team says the model helped uncover a critical foundational vulnerability in under two hours.
Wiz supplied another partner result: on an internal penetration-testing benchmark, it recorded 7.5 to 9.7 percentage points higher recall while reporting a 2.3 to 5.2 times lower cost than other leading frontier models.
Those numbers deserve the usual qualification. They are launch results supplied by Google and participating partners, and several depend on private benchmarks that outside teams cannot independently reproduce from the announcement alone.
Regular 3.8 Flash is going almost everywhere
Developers can use Gemini 3.8 Flash through the Gemini API and Google AI Studio, with integrations also announced for Antigravity, Android Studio and Stitch. Enterprise customers get it through Gemini Enterprise.
Google AI Pro and Ultra subscribers can access it in the Gemini app, AI Mode in Search and Gemini in Google Sheets.
Fairwind is deliberately different. Google says the program already has more than 650 partners and requires operational controls around who can use the advanced cyber tooling. It has not announced a date for unrestricted public access to Gemini 3.8 Flash Cyber.