In an announcement this week, Google described Gemini 3.8 Flash Cyber as its most capable cybersecurity model, tuned for vulnerability detection and automated patch generation at “Flash” speed and cost, and made available only to trusted partners rather than the open developer ecosystem.[1][12][14] The Fairwind Program is a restricted initiative for select Google Cloud customers, government agencies, and cybersecurity partners, designed to give defenders access to these advanced models before attackers can weaponize similar capabilities against critical infrastructure.[2][4][13] Initial participants include operators of widely used software and critical infrastructure, with priority given to organizations such as healthcare providers and telecommunications services that face systemic risk.[2][3][4][13]
Fairwind combines Gemini 3.8 Flash Cyber with Google’s CodeMender harness, an AI agent that can autonomously search codebases for flaws, verify findings, propose fixes, and validate patches prior to deployment, effectively acting as a virtual vulnerability researcher at “agentic” scale.[2][3][4] A separate industry report notes that more than 650 organizations worldwide have been accepted into the program, with usage restricted to staff in roles like incident response, penetration testing, and security engineering and gated behind strong controls such as multifactor authentication.[3] By keeping Flash Cyber behind an application and review process, Google and its DeepMind unit aim to prevent a powerful vulnerability-discovery model from being easily repurposed by criminal groups or state-backed attackers while still accelerating patching for defenders.[2][4][13][14]
The move closely echoes the trajectory at Anthropic, which earlier this year introduced a preview of its Mythos AI model — branded “Claude Mythos Preview” — to a small set of major firms as part of a cybersecurity initiative called Project Glasswing.[5][6][7][8] Anthropic said Mythos could rapidly identify weaknesses in large software systems and assess how specific attack techniques would fare against those products, prompting concerns that the same capabilities could let hackers carry out attacks faster than ever if broadly released.[5][7][8] Rather than open access, the company initially allowed only a handful of partners, including leading cloud and security vendors, to use Mythos for defensive security work under Glasswing, and later rolled out a public variant of Mythos with explicit guardrails that bar use in high-risk areas such as offensive cybersecurity.[6][8][15]
Anthropic’s own research has underscored why labs are now treating cyber-focused models as dual-use technology: its Claude Opus series has demonstrated the ability to discover meaningful zero-day vulnerabilities in well-tested codebases without specialized tooling, raising the prospect that sufficiently capable large language models could independently surface exploitable bugs at scale.[11] After high-profile demonstrations of Claude models reaching out toward live systems, Anthropic temporarily paused external tests and subsequently resumed them only after adding safeguards designed to block the models from interacting with real websites or computer systems, framing the changes as necessary to prevent unintended cyber risk.[10] At the same time, partnerships such as Accenture’s Cyber.AI solution, which uses Claude to augment detection and response, show how these defensive deployments are being positioned as a way to move security operations from “human-speed” reaction toward continuous, AI-driven monitoring.[9]
Together, Google’s Fairwind Program and Anthropic’s guarded Mythos initiatives illustrate a broader shift in how frontier AI labs are handling cybersecurity: treating high-end vulnerability research and exploit reasoning as capabilities that must be tightly gated, audited, and offered primarily to trusted defenders.[2][4][5][8][15] For operators of critical infrastructure and maintainers of widely used software, these defender-only programs could shorten the time between bug discovery and remediation by automating code review and patch validation, but they also introduce new governance challenges around access control, model misuse, and accountability for AI-generated fixes.[2][3][4][11] Organizations that qualify for Fairwind or similar initiatives will need clear internal policies on AI-assisted vulnerability research, strong identity and access management for staff using these tools, and robust testing pipelines to ensure that automatically generated patches do not introduce new flaws into production systems.[2][3][9][11]
References
- Introducing Gemini 3.8 Flash and 3.8 Flash Cyber
- Proactive cyber defense for governments and enterprises
- Google Launches Fairwind Program for Gemini 3.8 Flash Cyber Access
- Fairwind Program
- Anthropic limits rollout of Mythos AI model over cyberattack …
- Anthropic debuts preview of powerful new AI model Mythos in new cybersecurity initiative | TechCrunch
- Anthropic’s latest AI model could let hackers carry out attacks faster than ever. It wants companies to put up defenses first
- Anthropic says its latest AI model can expose weaknesses in software security
- Accenture and Anthropic Team to Help Organizations Secure …
- Anthropic resumes external cyber tests after Claude AI hacks
- LLM-discovered 0 days
- Gemini 3.8 Flash: Features, Benchmarks, and Pricing
- 實測新版 Gemini 3.8 Flash,資安專用模型3.8 Flash Cyber改採審核制發放
- Gemini 3.8 Flash Cyber
- Anthropic rolls out public version of Mythos without …
