Fairwind Program and Flash Cyber
On 2 September 2026 Google launched the Fairwind Program, a limited-access program for governments and trusted partners, and with it Gemini 3.8 Flash Cyber, a cybersecurity variant of Gemini 3.8 Flash that is available only to program members. The program pairs the model with Google's CodeMender harness to find, verify and fix vulnerabilities; Google reports more than 650 participating partners worldwide.
Why it matters
Access to a cyber-capable model is gated by who the user is, not by price: members agree to operating standards (access only for internal security teams, multi-factor authentication). The atlas already holds comparable programmes from Anthropic (Project Glasswing) and OpenAI (Daybreak).
About the program. Initial access is staged to governments and national cyber authorities, critical infrastructure operators (healthcare, telecommunications, energy, finance) and core technology platforms. Participants commit to limiting access to employees in internal cybersecurity, incident-response or penetration-testing teams and to using multi-factor authentication. Any Google Cloud customer can use CodeMender with publicly available models on the Gemini Enterprise Agent Platform. Google.org puts its total cybersecurity funding above $100 million. About the model. Gemini 3.8 Flash Cyber is called Google's 'most capable cybersecurity model', available to trusted defenders; its mitigations for cybersecurity are more permissive, which is why it is outside public access. Google's figures: on CyberGym it surpasses 3.5 Flash Cyber and significantly larger models (no number given); on an internal benchmark spanning 20 programming languages its success rate exceeds 70%; on Collinear's CWE-Bench its pass@1 is 47.2% against 47.8% for a leading frontier model, at a significantly lower cost; Chrome Security got 2.6 times more correct patches than from the best commercial models; Wiz measured 7.5-9.7% higher recall at 2.3-5.2 times lower cost; Cloud Vulnerability Research found a critical vulnerability in less than 2 hours. Google says fixing vulnerabilities was prioritised over exploitation. What the record does not claim. All figures are Google's own; the partner list and the quotations were not in the page text, so the make-up of the '650 partners' was not checked. The date, 2 September 2026, stands on both Google posts.