Google has released **Gemini 3.8 Flash**, a new general-purpose model aimed at software engineering, agentic workflows and multi-step reasoning, together with **Gemini 3.8 Flash Cyber**, a more permissive cybersecurity variant available only through a restricted access program.
The general model is available through the Gemini API, Google AI Studio, Gemini Enterprise and selected consumer surfaces. Google says the introductory API price remains the same as Gemini 3.7 Flash: $0.75 per million input tokens and $3.75 per million output tokens. The company has already published a future step-up to $1.50 input and $7.50 output per million tokens from January 1, 2027, so buyers should treat today’s price as explicitly temporary rather than a permanent rate.
A material update to the Gemini surface
Google positions 3.8 Flash as its strongest Flash release so far for reasoning and coding while retaining the speed and cost profile of the previous generation. The important change for users is not one benchmark number but the combination of broader agentic use, long-horizon coding and a low-cost API tier. Google also says developers can lower the model’s effort level when token efficiency matters more than maximum reasoning depth.
The benchmark claims in Google’s launch material are first-party results and should be treated accordingly. They are useful for understanding what Google optimized, but they do not substitute for independent workload testing. The company reports gains across software-engineering, finance, legal-agent and general reasoning evaluations, while also acknowledging that the model may spend more reasoning steps and tokens on difficult tasks.
Cyber capabilities are deliberately separated
Gemini 3.8 Flash Cyber is not simply another public API SKU. Google is limiting access through its Fairwind Program to trusted government authorities, critical-infrastructure operators, software maintainers and other approved defenders. The model is tuned for vulnerability discovery and patching and uses a more permissive cybersecurity safety profile than the general Flash model.
That separation is significant. Instead of exposing the strongest cyber behavior through the same general endpoint, Google is pairing capability with an access-control layer. The company says the public model still includes safeguards for cyber misuse and other high-risk domains, while the Cyber version is reserved for vetted defensive use.
What changes for Gemini users
For ordinary Gemini users, the practical update is the arrival of 3.8 Flash across the Gemini API, AI Studio, Gemini Enterprise and the Gemini app for eligible subscribers. For security teams, the more consequential development is the restricted Cyber branch and its explicit access model.
Because AiToolMap’s canonical Gemini review was refreshed on September 1, this release creates an immediate material-update trigger: the review should be rechecked for model availability, current pricing, safety boundaries and product-surface wording. The existing review should remain canonical until that update passes the normal evidence and publication gates.