Google ships Gemini 3.8 Flash, gating its cyber model behind Fairwind
Two threads run through Wednesday's AI news: capability is arriving faster than the guardrails around it, and the people building the guardrails are picking who gets access. Google released its third Flash model in six weeks and put its most capable cybersecurity variant behind an invitation-only program. A few hours earlier, the US government told a federal court that restricting model training would hurt the country.
Google released Gemini 3.8 Flash and Gemini 3.8 Flash Cyber today, roughly three weeks after 3.7 Flash — and the company is keeping the cyber variant on a short leash. Both models share the same core, and Google says the coding and reasoning gains came in part from training in the demanding domain of cybersecurity. 3.8 Flash is priced the same as its predecessor, at an introductory $0.75 per million input tokens and $3.75 per million output tokens through the end of the year, and it lands near the top of third-party coding and agentic benchmarks — 73.7% on DeepSWE v1.1 and 59 on the Artificial Analysis Intelligence Index, within a few points of models that cost five to six times more. Flash is no longer the cheap-compromise tier; it's the tier Google expects most agent builders to default to.
The more interesting decision is what Google is not releasing widely. Flash Cyber beats previous models and larger frontier models on CyberGym, and clears 70% success on Google's internal benchmark spanning 20 programming languages — but it ships through the new Fairwind Program, a limited-access arrangement for governments and vetted enterprise partners, with more than 650 organizations on the roster. Participants agree to restrict access to internal security, incident-response, and penetration-testing staff, and to run multi-factor authentication. Google paired it with CodeMender, which writes and validates patches inside a customer's own cloud environment rather than shipping code out.
That's a deliberate mirror of OpenAI's Astra play from earlier this week — strong cyber capability, restricted distribution, defenders first. We covered that reasoning in OpenAI pauses Astra over possible 'Critical' cyber capability. The difference is packaging: Google is selling the defensive side as a product with a partner program attached, while OpenAI framed Astra as a risk it had to contain. Neither lab is arguing that the cyber capability shouldn't exist; both are arguing about who holds the keys. Expect that framing to harden into the industry default — the open-weights question gets decided by access lists, not by model cards.
The Trump administration filed a statement of interest backing OpenAI in the New York Times copyright lawsuit. US attorneys argued that while fair use hinges on the facts of each case, it would be "problematic — and legally incorrect" to impose broad copyright liability that would generally make model training impermissible without licensing, and called LLM training consistent with the "creative 'progress'" that copyright is meant to serve. The filing lands days after the White House published a national AI legislative framework, and while the president is pursuing his own defamation suit against the Times.
A statement of interest doesn't decide anything, but it does tell the court where the executive branch stands, and that position now lines up with the entire AI industry's most consequential legal defense. It also puts the administration in the odd posture of backing OpenAI's fair-use argument while separately suing the paper that's bringing this one. For publishers watching a string of training-data cases move toward settlement, the government weighing in on the defendant's side raises the odds that whatever comes out of this litigation looks like a licensing regime rather than a ban.
The US Army awarded $192 million to Palantir and Anduril to move TITAN from prototype into production. Palantir took $127 million and Anduril $65 million to build eight AI-powered mobile ground stations over the next 18 months; Anduril, the lead hardware systems architect on the program since inception, will handle the ruggedized vehicle-mounted integration. The Army says another production order is anticipated in fiscal 2027.
TITAN is a targeting node — software that ingests sensor feeds and shortens the path from detection to a strike decision. Moving it into production means the Army is done treating battlefield AI as an experiment, and the 18-month delivery window means the question of how much human judgment sits in that loop is now a fielding question rather than a lab question.
What to watch: whether Fairwind's access list holds once enterprises outside the first 650 start asking for the same patching capability — restricted distribution is easy to announce and hard to defend.
Should advanced cyber models be sold only to vetted defenders, or does gating them just widen the gap between organizations that can afford defense and everyone else? Tell us in the comments.
Sources: Google DeepMind — Introducing Gemini 3.8 Flash and 3.8 Flash Cyber · Google — Proactive cyber defense for governments and enterprises · 9to5Google — Gemini 3.8 Flash launch and introductory pricing · Hacker News discussion · The Verge — Trump administration backs OpenAI in NYT suit · Reuters — US government backs OpenAI in New York Times copyright case · The Hill — Trump admin backs OpenAI fair use argument · Tectonic Defense — Army awards Palantir and Anduril $192M for TITAN · GovCon Wire — Palantir, Anduril win $192M in Army TITAN production orders · US Army — Army announces move to production for TITAN