Alphabet has released three new Gemini models, including a cybersecurity-focused system designed to identify and patch software vulnerabilities. Gemini 3.5 Flash Cyber will initially be made available through a limited-access pilot for governments and trusted partners, rather than through a broad public launch.
The release also includes Gemini 3.6 Flash and Gemini 3.5 Flash-Lite, reflecting Googleβs push to improve the efficiency and affordability of its AI portfolio while expanding its capabilities in coding, multimodal tasks, and agent-based workflows. Google is positioning the updates as part of a wider effort to make powerful AI systems more practical to operate at scale.
The announcement highlights two increasingly important priorities in the AI market: cost and cybersecurity. Google is betting that smaller, more targeted models can make AI cheaper to deploy across high-volume workloads, while Gemini 3.5 Flash Cyber signals its intent to compete in the fast-growing market for AI-powered software security tools.
Google Targets Performance, Scale and Software Security
Built on Gemini 3.5 Flash and fine-tuned to find, validate, and patch software vulnerabilities, Gemini 3.5 Flash Cyber is Googleβs new lightweight cybersecurity model.
Google said the model is designed for large and complex codebases, where detecting deeper flaws can require assessing a huge number of possible code paths. Rather than relying on a single, expensive call to a larger model, CodeMender can invoke Gemini 3.5 Flash Cyber repeatedly, allowing sub-agents to assess more paths before producing a final report. The company said this makes it suitable for frequent scans, commit-scanning pipelines, and time-sensitive launches.
That focus on making advanced capabilities usable at scale runs through Googleβs wider release. Gemini 3.6 Flash improves coding, multimodal, and knowledge-work performance while using up to 17% fewer tokens than its predecessor. Gemini 3.5 Flash-Lite is aimed at high-volume workloads and smaller tasks within AI agent systems, extending the companyβs push to lower the cost of AI deployment. The lower cost of running these models also allows systems such as Gemini 3.5 Flash Cyber to be used more frequently to continuously search for vulnerabilities.
In tests on Googleβs V8 JavaScript engine, Gemini 3.5 Flash Cyber found 55 confirmed unique issues under a fixed number of invocations, compared with 47 for mainline Gemini 3.5 Flash and 36 for Claude Opus 4.6, according to Google.
Google said these capabilities help defenders find and address critical flaws before they are exploited while limiting broader misuse. The company added that the model is already being used across internal codebases, including Chrome, Android, Cloud, Ads, and YouTube. Its Cloud Vulnerability Research team said it used the system to uncover remote code execution vulnerabilities in public APIs and a memory corruption flaw in a production service within two hours.
As a result of these capabilities, the model will initially be available only to governments and trusted partners through CodeMender under a limited-access pilot. Google said the approach is intended to give defenders an earlier opportunity to find and fix critical flaws while limiting the potential for misuse.
A Growing Race for AI Security and Efficiency
Googleβs move arrives as enterprise and public sector interest in AI security continues to grow. Anthropicβs Mythos helped accelerate that attention by showing how models could be applied to finding flaws across large bodies of source code while also raising questions about how those systems should be controlled.
For Illia Martyn, founder at SkillCanvas.ai, the release marks Googleβs entry into the AI cybersecurity arena alongside Anthropic: βThis is the answer to Anthropicβs Mythos, which recently found 23 thousand potential vulnerabilities across a thousand open-source projects and can put together working exploits. Itβs also the only one of the three that Google isnβt opening up to the public: governments and vetted partners only, closed pilot.β
That decision to offer a limited release to a select group also mirrors Mythos. But where the two diverge could be where Googleβs new cybersecurity model gains an advantage:
βSo what Googleβs leading with is price, not a top model.β
By building on Flash, Google claims 3.5 Flash Cyber offers a cost-efficient and highly capable alternative to larger, more expensive cybersecurity models. Mythos, on the other hand, is extremely compute-intensive and expensive to run.
Google is not alone in pursuing this AI cybersecurity strategy at a different price point. Microsoft last week released Project Perception, an AI security framework designed to find flaws in source code while allowing organizations to use different models for the task, potentially reducing costs.
Anthropic said it is working to make Mythos much more efficient before any general release, and its recently released Claude Opus 5 runs at βhalfβ the price of its restricted version of Mythos Fable 5.
Googleβs Cybersecurity Push Takes Shape
Googleβs wider Gemini releases come as competition in AI cybersecurity grows, with companies looking to turn increasingly capable models into tools that can identify software flaws before they are exploited. The challenge is not just building a model that can find vulnerabilities, but making it affordable enough to deploy repeatedly across vast and constantly changing codebases.
That is where Google is positioning Gemini 3.5 Flash Cyber. By building the model on its smaller Flash architecture, the company says CodeMender can make repeated calls across more code paths without the cost associated with relying on a larger model for every task. Google argues that this approach can make frequent scanning and validation more feasible for enterprises and public sector organizations.
For Google, the next test is whether it can convert Flash Cyberβs efficiency into real-world adoption. The initial pilot will show whether a lower-cost, specialized model can give defenders the ability to search more software, more often, while still discovering the most sensitive vulnerabilities that stronger, more expensive models can find.