Google has introduced Gemini 3.5 Flash Cyber, its first lightweight AI model specifically optimized for cybersecurity tasks. Built on the Gemini 3.5 Flash architecture, the new model is designed to help security teams identify, validate, and patch software vulnerabilities more efficiently while maintaining the speed and cost advantages of Google’s Flash model family. Initially, the model will be available through a limited-access pilot for governments and trusted partners via Google’s CodeMender platform.

Image 56

The launch comes as organizations increasingly deploy AI to strengthen cyber defenses amid a surge in software vulnerabilities and sophisticated cyberattacks. Rather than targeting general-purpose AI workloads, Gemini 3.5 Flash Cyber is fine-tuned specifically for vulnerability discovery and remediation, enabling repeated low-cost scans of large codebases.

Gemini 3.5 Flash Cyber: Purpose-Built for Cybersecurity

Unlike standard AI models, Gemini 3.5 Flash Cyber has been trained specifically to assist with software security workflows.

Its primary capabilities include:

  • Finding software vulnerabilities.
  • Validating discovered security issues.
  • Recommending code fixes.
  • Assisting with automated patch generation.
  • Supporting large-scale security audits.

The model combines cybersecurity specialization with the low latency and lower operating costs of the Flash series, making it suitable for repeated security scans across complex software projects.

Key Features

FeatureBenefit
Cybersecurity-focused modelOptimized for vulnerability detection
Built on Gemini 3.5 FlashFast inference with lower costs
Automated code analysisFinds and validates software flaws
Patch assistanceHelps remediate vulnerabilities
CodeMender integrationSupports AI-powered security workflows

Strong Performance on Security Benchmarks

Google evaluated Gemini 3.5 Flash Cyber using CyberGym, a benchmark designed to assess AI agents on real-world software vulnerabilities.

According to Google:

  • The model achieved competitive performance against significantly larger AI models.
  • It outperformed standard Gemini Flash models on vulnerability discovery tasks.
  • It offers a favorable balance between cost, speed, and cybersecurity performance.

Finds More Vulnerabilities in Complex Codebases

Google also stress-tested the model on large and complex software projects, including browser engines.

One notable evaluation involved the V8 JavaScript Engine, where:

  • Gemini 3.5 Flash Cyber identified 55 confirmed vulnerabilities.
  • Standard Gemini 3.5 Flash found 47 issues.
  • Anthropic Claude Opus 4.6 identified 36 issues.
  • 10 vulnerabilities discovered by Flash Cyber were not found by the other tested models.

Benchmark Comparison

ModelConfirmed V8 Issues Found
Gemini 3.5 Flash Cyber55
Gemini 3.5 Flash47
Claude Opus 4.636

Available Through CodeMender Pilot

To reduce the risk of misuse, Google is not making Gemini 3.5 Flash Cyber broadly available at launch.

Instead, access is currently limited to:

  • Government organizations.
  • Trusted security partners.
  • Participants in the CodeMender pilot program.

Google says availability will expand over time while maintaining safeguards against offensive misuse of cybersecurity AI.

Part of Google’s Broader Gemini Expansion

The cybersecurity model was announced alongside two additional Gemini releases:

  • Gemini 3.6 Flash, focused on faster coding, multimodal capabilities, and improved reasoning.
  • Gemini 3.5 Flash-Lite, Google’s most affordable Flash-series model for cost-sensitive AI workloads.

Meanwhile, Google’s flagship Gemini 3.5 Pro remains in testing and has been delayed as the company continues to improve its coding performance before public release.

New Gemini Models Announced

ModelPrimary Focus
Gemini 3.6 FlashFaster, more capable general-purpose AI
Gemini 3.5 Flash-LiteLow-cost, high-speed AI workloads
Gemini 3.5 Flash CyberCybersecurity and vulnerability detection

Looking Ahead

With the launch of Gemini 3.5 Flash Cyber, Google is expanding its AI portfolio beyond general-purpose assistants into specialized enterprise models. By fine-tuning a lightweight Flash model for cybersecurity, the company aims to help defenders identify and remediate software vulnerabilities more efficiently while keeping inference costs low. Early benchmark results suggest the model can compete with significantly larger systems on vulnerability detection, making it a promising addition to AI-assisted security workflows.

As cyber threats continue to grow in scale and complexity, AI-powered security tools are becoming an increasingly important part of software development and enterprise defense. Google’s limited-access rollout through CodeMender reflects a cautious approach to balancing the benefits of advanced cybersecurity AI with the need to prevent misuse. If the pilot proves successful, Gemini 3.5 Flash Cyber could become a key component of automated vulnerability management for governments, enterprises, and software developers.

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.