Google Gates Its Most Permissive Cyber Model Behind Fairwind
Security / news
Google Gates Its Most Permissive Cyber Model Behind Fairwind
The Fairwind program pairs Gemini 3.8 Flash Cyber with the CodeMender patching agent for more than 650 vetted partners, and on Google's own benchmark the model still trails a frontier competitor on one of three tests.
Google opened the Fairwind Program on Sept. 2, giving vetted governments and named partners access to Gemini 3.8 Flash Cyber, a version of its cybersecurity model with fewer safety restrictions than the public release, paired with its CodeMender patch-generation agent, according to Google's announcement. Access requires multi-factor authentication and is limited to a participant's internal cybersecurity, incident response or penetration testing teams.
Google Vice President of Security and Privacy Four Flynn wrote that the goal is verified, deployment-ready patches produced "in minutes rather than weeks." More than 650 partners are already participating globally, Google said, including CrowdStrike, Palo Alto Networks, Snowflake, Wiz and Armadin.
The benchmark where the gated model does not win
Google's own figures, reported by byteiota and flagged there as vendor-reported rather than independently verified, show Gemini 3.8 Flash Cyber ahead on two of three named tests and essentially tied on the third.
| Benchmark | Gemini 3.8 Flash Cyber | Comparison |
|---|---|---|
| CyberGym Pass@1 | 86.2 percent | Not disclosed |
| CWE-Bench Pass@1 | 47.2 percent | 47.8 percent (top frontier model) |
| Real-world, 20 languages | 71.0 percent | Not disclosed |
| Gray Swan prompt injection | 6.0 percent attack success rate | Lower is better |
On CWE-Bench, the model Google is gating behind vetted access scores 0.6 percentage points below an unnamed frontier competitor, not above it. Google's pitch for Fairwind rests on speed and cost rather than raw accuracy: Wiz, one of the named partners, reported 7.5 to 9.7 percentage points higher recall at 2.3 to 5.2 times lower cost using the model, and Google's own vulnerability research team said it used the pairing to find a Chrome security bug in about two hours, a different flaw from the actively exploited zero-day the Chrome team patched separately this week.
What it costs outside the vetted program
Google Cloud customers who are not part of Fairwind can still reach CodeMender with publicly available models through its Gemini Enterprise Agent Platform, at an introductory rate of $0.75 per million input tokens and $3.75 per million output tokens, byteiota's report says. That pricing is due to expire Dec. 31, 2026, after which Google has not said what the model will cost.
The dollar figures attached to the announcement
Google tied Fairwind to $100 million in cumulative Google.org cybersecurity funding, including $36 million already committed to 35 cyber clinics that Google says serve more than 1,250 hospitals, school districts and municipal utilities in the U.S. None of that funding is contingent on Fairwind participation, and Google's announcement does not say how the clinic total was counted or over what period the $100 million was spent.
The gating logic behind Fairwind is itself a tell: Google's public Gemini 3.8 Flash carries safeguards against chemical, biological, radiological and nuclear misuse and against offensive cyber use, under its own Frontier Safety Framework, and the Cyber variant deliberately relaxes the second category. That trade, more capability in exchange for vetted access rather than open availability, is a bet that gating beats patching every disclosed flaw in public, the same bet regulators are testing from the other direction in this month's Patch Tuesday cycle, and it leaves outside researchers unable to independently reproduce any of the four benchmark figures Google published.
Sources: Google, "Google's Fairwind Program: Cyber defense tools for trusted partners", Sept. 2, 2026; byteiota, Sept. 2026; Cybersecurity Insiders, Sept. 3, 2026.
Sources
More in Security
- 01Cisco and Acronis Share a CISA Deadline, Not a Severity ScoreOne flaw needs no password and no user interaction, the other needs an attacker already logged in, and CISA gave federal agencies the same three days to fix both.
- 02Bransys ELD App Shipped With Hardcoded Login CredentialsCISA disclosed three flaws Sept. 17 in the trucking compliance app, including a hardcoded password a researcher says exposed live location and engine data from every connected truck on a subset of fleets.
- 03MikroTik Patches RouterOS Flaws Attackers Exploited FirstPoland's national CERT says attackers began exploiting the chained flaws on Sept. 2, a day before MikroTik shipped a fix, and more than 122,500 routers were still reachable a week later.
- 04Attackers Exploit a JFrog Artifactory Bug in Four DayswatchTowr says attackers began minting administrator tokens by abusing a default empty join key, CVE-2026-82329, within days of JFrog's own patch shipping.