Google's Fairwind Program Gates Its Least-Restricted Cyber Model

Google launched Fairwind on September 2, 2026: vetted partners get Gemini 3.8 Flash Cyber — the variant that ships with deliberately looser safety mitigations.

by HowAIWorks Team
On this page

Introduction

On September 2, 2026, Google launched the Fairwind Program, a limited-access channel giving vetted governments and partners its most capable cyber defense models. The announcement, bylined by Four Flynn, VP of Security and Privacy, pairs Gemini 3.8 Flash Cyber with CodeMender, Google's code-security agent, so defenders can "generate verified, deployment-ready patches in minutes" instead of weeks — and inside their own secure cloud environment.

The detail that explains the whole program sits in the model announcement, not the program page. Gemini 3.8 Flash, released the same day and publicly available, ships with safeguards against chemical, biological, radiological and nuclear misuse and against cyber offense. Gemini 3.8 Flash Cyber, in Google's words, "ships with a more permissive set of mitigations for cybersecurity, and as such, is only available to trusted defenders." The gated model is the one with fewer guardrails. Fairwind is the vetting layer that substitutes for them.

Google says more than 650 partners globally are already participating.

Why the model is gated

Google DeepMind states the dual-use problem plainly on the program page: "Using frontier AI capabilities can help people to rapidly discover – and fix – critical vulnerabilities. But in the wrong hands, the same capabilities can become an equally powerful threat."

The stated logic is a head start rather than containment. Early access gives trusted defenders "a vital adaptation window to harden their systems before bad actors have a chance to exploit new capabilities" — an argument that the capability is coming regardless, so defenders should get it first.

Google also says it shaped the model's capabilities toward that end: it "invested in vulnerability fixing from the start, and prioritized it over offensive capabilities like exploitation." Partners are permitted only defensive dual-use work — authorized threat simulation, reverse engineering, and malware analysis for defensive and academic research. Creating malware is explicitly out.

This makes Fairwind a concrete instance of staged capability release, a recurring AI governance question: what to do when the same weights defend and attack. Google frames the program as provisional, saying it will collaborate "with industry, governments, and open-weight community leaders to strike the right balance between open access and robust security."

Who qualifies, and what they sign

Three prioritized groups:

  • Governments and national cyber authorities — public-sector networks and citizen services.
  • Critical infrastructure operators — healthcare, telecommunications, energy, financial networks.
  • Core technology platforms — securing software foundations "for millions of downstream users at once."

Academic labs focused on defensive benchmarking may apply; students are directed to CodeMender on Google Cloud instead.

Google runs background checks on the applying organization to verify its security history and record of ethical operations. Accepted partners commit to user-level authentication with phishing-resistant MFA, access limited to internal cybersecurity, incident response or penetration testing teams, tracking of which employees use the model, and no sharing, redistributing or selling access. Applications go through a form; Google promises a response "as soon as we can" with no published turnaround.

One procurement-relevant detail: accessed as a managed model on the Gemini Enterprise Agent Platform, 3.8 Flash Cyber supports zero data retention.

This formalizes the posture Google took in July 2026, when Gemini 3.5 Flash Cyber shipped as a restricted CodeMender pilot rather than an API product. Fairwind turns that pilot into a standing program with published criteria.

What the model is claimed to do

All figures below are Google-reported unless noted:

MeasureResult
CWE-Bench (patching, run by Collinear)47.2% pass@1, vs. 47.8% for Claude Fable 5 at significantly higher cost
Chrome Security team2.6x more correct Chrome patches than "the best commercial models that are much larger"
Internal multi-language benchmarkover 70% success rate discovering vulnerabilities across 20 programming languages
Google Cloud Vulnerability Researchone critical foundational vulnerability found in under 2 hours; Google says such work usually takes months
Wiz internal penetration-testing benchmark+7.5–9.7% higher recall at 2.3–5.2x lower cost than other leading frontier models (reported by Wiz)
CyberGym (vulnerability discovery)"frontier-level," surpassing 3.5 Flash Cyber and larger frontier models — no score published

The CWE-Bench line is the one to read carefully. At 47.2% against 47.8%, the model is fractionally behind Claude Fable 5 on accuracy; Google's claim is the Pareto frontier — comparable results at materially lower cost — not a capability lead. The CyberGym result, which Google leads with, carries no number at all.

Separately, Google says the 3.8 line made "a significant leap in prompt injection robustness as measured by Gray Swan" — relevant because an agent reading untrusted code is exactly the setting where injection matters.

Partners on record

Five organizations gave attributed statements: Armadin (David Slater, Founder & Chief Architect), CrowdStrike (Daniel Bernard, Chief Business Officer), Palo Alto Networks (Charlie Sestito, Office of the CTO), Snowflake (Mayank Upadhyay, CSTO) and Wiz (Gal Nagli, Head of Threat Exposure).

The consistent theme is economics rather than raw capability. Snowflake ran a two-day trial on public repos and reported the model "held its own against much larger engines on critical and high severity findings… at Flash-style cost, cheap enough to run continuously rather than in occasional sweeps." Armadin likewise reported it "matched larger frontier models at a lower price." That is the same claim the CWE-Bench chart makes: parity at lower cost, run continuously instead of periodically.

The parts that are not gated

Google separated the model from the tooling. Any Google Cloud customer can run CodeMender with publicly available models on the Gemini Enterprise Agent Platform alongside AI Threat Defense; only the Cyber model requires approval.

The announcement also restated Google.org's grant-making: total cybersecurity funding now above $100 million globally, including $36 million across 35 cyber clinics that have supported more than 1,250 hospitals, public school districts and municipal utilities in the U.S. That is philanthropy for under-resourced defenders, not model access.

Conclusion

Fairwind is a distribution decision more than a technical one, and the precedent is worth noting: a frontier lab now runs background checks, mandates MFA, restricts which internal teams may hold a credential, and bans resale — closer to export control than to a developer signup. The justification is explicitly that the safest version of this capability is not the most restricted one, but the one that reaches defenders first.

What is still unpublished: the CyberGym score Google leads with, how long review actually takes, how the 650 partners distribute across the three tiers, and how a "more permissive set of mitigations" is bounded in practice.

Sources

Frequently Asked Questions

A limited-access program launched September 2, 2026 that gives vetted governments, critical infrastructure operators and core technology platforms exclusive access to Gemini 3.8 Flash Cyber, usable standalone or inside Google's CodeMender patching harness.
Google says 3.8 Flash Cyber ships with a more permissive set of mitigations for cybersecurity under its Frontier Safety Framework. The public 3.8 Flash carries CBRN and cyber-offense safeguards that the Cyber variant deliberately relaxes, so access is vetted instead.
Governments and national cyber authorities, critical infrastructure operators in healthcare, telecommunications, energy and finance, and core technology platforms. Academic labs doing defensive benchmarking may also apply; students are pointed to CodeMender on Google Cloud instead.
Background checks on the organization, user-level authentication with phishing-resistant MFA, access limited to internal cybersecurity, incident response or penetration testing teams, tracking of employee access and use, and no sharing, redistributing or selling access.
On CWE-Bench, run by Collinear, Google reports 47.2% pass@1 against 47.8% for Claude Fable 5 at significantly higher cost. Google's Chrome Security team reported 2.6x more correct Chrome patches than from much larger commercial models.
Yes. Any Google Cloud customer can run CodeMender with publicly available models on the Gemini Enterprise Agent Platform alongside AI Threat Defense. Only the Gemini 3.8 Flash Cyber model itself requires Fairwind approval.

Continue Your AI Journey

Explore our glossary and model catalog to deepen your understanding.