3 min Devops

Google Gemini 3.8 Flash is a better, more autonomous coder

Google Gemini 3.8 Flash is a better, more autonomous coder

Google is introducing Gemini 3.8 Flash, a new AI model designed to deliver improved performance in software development, autonomous agents, and complex reasoning tasks. At the same time, Gemini 3.8 Flash Cyber is being released, a specialized version for detecting and fixing vulnerabilities.

Gemini 3.8 Flash follows shortly after version 3.7. Google is keeping the introductory price the same: $0.75 per million input tokens and $3.75 per million output tokens. With this move, the company aims to make the performance of larger models available within the more affordable Flash segment.

A key area of focus is software development, where an AI model works autonomously on a task for an extended period. According to Google, Gemini 3.8 Flash outperforms several larger models on DeepSWE v1.1, a benchmark for complex software engineering.

However, this improved performance may come at the expense of efficiency. For complex tasks, Gemini 3.8 Flash performs additional reasoning steps and may repeatedly call on external tools. This can increase token usage. Developers can set a lower effort level when cost or computing capacity is a greater priority. Gemini 3.7 Flash will also remain available.

Focused on autonomous agents

With Gemini 3.8, Google places a strong emphasis on models that not only generate answers but can also independently execute sequences of actions. According to the company, both new variants have been improved with long-term agentic loops, in which models are repeatedly evaluated and refined.

Google has also tested Gemini 3.8 Flash on financial and legal agent tasks. On HLE-Verified, a benchmark for complex reasoning tasks across various disciplines, the model achieved a score of 54.9 percent.

Cyber variant identifies and fixes vulnerabilities

Gemini 3.8 Flash Cyber focuses specifically on defensive cybersecurity. The model can independently search for vulnerabilities in software and then develop patches.

On CyberGym, a benchmark for autonomous vulnerability detection, Google reports that the model outperforms Gemini 3.5 Flash Cyber and several larger models. In an in-house test using codebases in twenty programming languages, Gemini 3.8 Flash Cyber reportedly found more than 70 percent of the vulnerabilities presented.

For automatically fixing vulnerabilities, Google used the external CWE-Bench. There, the model achieved a pass@1 score of 47.2 percent, compared to 47.8 percent for what Google calls a leading frontier model. The company does not specify which competing model was used for this comparison.

Google is now also applying the technology to its own software. The Chrome Security team reportedly generated 2.6 times as many correct patches with Gemini 3.8 Flash Cyber as with larger commercial models. The Cloud Vulnerability Research team also used the model to find a critical vulnerability within two hours.

Access to cyber model is limited

Gemini 3.8 Flash Cyber will not be made generally available. Through the new Fairwind Program, Google is granting access to selected government organizations, critical infrastructure operators, and software maintainers.

This restriction is related to the cyber model’s expanded capabilities. The standard Gemini 3.8 Flash includes measures designed to limit offensive cyber use. In the Cyber version, these restrictions are less stringent, allowing security researchers to conduct more in-depth analyses.

Gemini 3.8 Flash will be available through the Gemini API, Google AI Studio, Android Studio, and Gemini Enterprise, among other platforms. The Cyber variant is accessible only through the Fairwind Program.