Twikup logo
Twikup
Google Expands Gemini Cybersecurity Power as AI Agents Tackle Complex Threats

Google Expands Gemini Cybersecurity Power as AI Agents Tackle Complex Threats

By Akshay SatijaEditor in ChiefSeptember 19, 2026Updated September 19, 20265 min read
Today
#Google Gemini#Gemini AI#Gemini 3.8 Flash Cyber#Google DeepMind#AI Cybersecurity#Artificial Intelligence#Cybersecurity#AI Security

Reader highlight

Key Takeaways

1

Google’s Gemini 3.8 Flash Cyber is designed to autonomously discover vulnerabilities and generate validated patches.

2

The Fairwind Program gives selected governments and trusted organisations access to advanced Gemini cybersecurity capabilities.

3

Google says the technology is being deployed with safeguards because advanced cybersecurity AI has potential for both defensive and harmful uses.

Gemini 3.8 Flash Cyber Targets Vulnerability Detection

Google introduced Gemini 3.8 Flash Cyber in September 2026 as its most capable cybersecurity model.

According to Google, the model is specifically designed for defenders and can identify vulnerabilities across complex software codebases. It can also generate validated code fixes after discovering security weaknesses.

Google says the model was evaluated on CyberGym, an industry benchmark for autonomous vulnerability discovery. Gemini 3.8 Flash Cyber recorded an 86.2% Pass@1 result on the benchmark, according to Google's published results.

The company also tested the model against an internal benchmark covering complex codebases written in 20 programming languages. Google says the model achieved a success rate above 70% on that evaluation.

Google Wants AI to Find and Fix Vulnerabilities Faster

One of the main goals behind the technology is to reduce the time between discovering a security weakness and fixing it.

Google's Fairwind Program combines Gemini 3.8 Flash Cyber with its CodeMender system. The company says this combination can help defenders find, verify and fix vulnerabilities at scale.

Instead of relying entirely on manual security reviews, AI agents can analyse code, identify potential weaknesses and generate patches for security teams to review and deploy.

Google says CodeMender with Gemini 3.8 Flash Cyber can generate verified, deployment-ready patches in minutes within an organisation's secure cloud environment.

Fairwind Program Gives Trusted Defenders Early Access

Google launched the Fairwind Program on September 2, 2026.

The limited-access initiative provides advanced cyber defence capabilities to selected government agencies, critical infrastructure operators, technology platforms and other trusted partners.

Google says the programme is intended to help organisations proactively identify and address cyber risks before attackers can exploit vulnerabilities.

Participating organisations must follow operational standards established by Google. These include restricting access to appropriate cybersecurity, incident-response or penetration-testing teams and using protections such as multi-factor authentication.

Google says more than 650 partners are participating globally.

Gemini Is Already Being Used for Google’s Own Security

Google DeepMind has also described how its cybersecurity models are being used internally.

In July 2026, Google introduced Gemini 3.5 Flash Cyber, a model designed to find, validate and patch vulnerabilities.

Google said the model was being used with CodeMender to identify and fix vulnerabilities across internal codebases, including Chrome, Android, Cloud, Ads and YouTube.

The company also reported that its Cloud Vulnerability Research team used Gemini 3.5 Flash Cyber to identify remote-code-execution vulnerabilities in public APIs and a memory-corruption vulnerability in a production service.

These examples show Google's focus on using AI as a defensive cybersecurity tool rather than simply as a general-purpose coding assistant.

AI Cybersecurity Models Carry Dual-Use Risks

Advanced cybersecurity AI can have both defensive and offensive applications.

Google acknowledges this issue in its deployment approach. Gemini 3.8 Flash Cyber is therefore being made available through the Fairwind Program to trusted defenders rather than being offered broadly without restrictions.

Google says its latest models include safeguards against misuse involving cyber offence, while the cybersecurity-specific model has more permissive mitigations because it is intended for organisations that need advanced security capabilities.

This approach reflects the challenge facing AI developers as models become increasingly capable of carrying out complex tasks autonomously.

Google Is Expanding AI-Powered Cyber Defence

The Fairwind Program is part of Google's broader cybersecurity strategy.

The company says it wants to give governments, critical infrastructure operators and technology companies access to advanced AI tools that can help strengthen digital systems.

Google is also combining Gemini models with CodeMender and other security technologies to automate parts of vulnerability discovery and remediation.

The objective is to help security teams respond faster as software environments become larger and more complex.

What This Means for the Future of Cybersecurity

The development of Gemini 3.8 Flash Cyber shows how AI is moving deeper into practical cybersecurity workflows.

AI systems can already analyse large amounts of code, identify potential vulnerabilities and generate fixes. As these capabilities improve, organisations could increasingly use AI agents to support vulnerability research, software testing and security remediation.

However, the same capabilities also create new security concerns if powerful cyber tools are misused.

Google's decision to restrict access to Gemini 3.8 Flash Cyber through the Fairwind Program reflects its effort to balance advanced capabilities with controlled deployment.

Bottom Line

Google is expanding Gemini's role in cybersecurity through models designed to autonomously discover vulnerabilities and generate software patches.

Gemini 3.8 Flash Cyber and the Fairwind Program represent Google's latest effort to give trusted defenders more powerful AI-based security tools.

The technology could help organisations identify and fix vulnerabilities faster, while Google's controlled-access approach aims to reduce the risks associated with increasingly capable cybersecurity AI.

Sources

Google is giving its Gemini models a bigger role in cybersecurity. Gemini 3.8 Flash Cyber is designed to autonomously discover vulnerabilities and generate validated fixes, while the Fairwind Program provides selected defenders with controlled access to these advanced capabilities.

Source

Google

Frequently Asked Questions

FAQ

What is Gemini 3.8 Flash Cyber?

Gemini 3.8 Flash Cyber is Google's specialised cybersecurity AI model designed to detect software vulnerabilities and generate automated patches.

What is Google's Fairwind Program?

The Fairwind Program is a limited-access initiative that gives selected governments, critical infrastructure operators and trusted technology partners access to Google's advanced cybersecurity AI capabilities.

Can Gemini 3.8 Flash Cyber find vulnerabilities automatically?

Yes. Google says the model is designed for autonomous vulnerability discovery and can analyse complex codebases to identify security weaknesses.

Can Gemini automatically fix security vulnerabilities?

Google says Gemini 3.8 Flash Cyber can generate validated code fixes after discovering vulnerabilities when used with its CodeMender system.

Why is access to Gemini 3.8 Flash Cyber restricted?

Google describes advanced cybersecurity AI as dual-use technology, meaning capabilities designed for defence could potentially be misused. The company therefore limits access to trusted defenders through the Fairwind Program.

Twikup on WhatsApp

Essential stories, sent directly to you.

Follow the Twikup channel for breaking news and important updates—without another crowded inbox.

Follow Twikup