Introduction
On September 2, 2026, Google launched the Fairwind Program, a limited-access channel giving vetted governments and partners its most capable cyber defense models. The announcement, bylined by Four Flynn, VP of Security and Privacy, pairs Gemini 3.8 Flash Cyber with CodeMender, Google's code-security agent, so defenders can "generate verified, deployment-ready patches in minutes" instead of weeks — and inside their own secure cloud environment.
The detail that explains the whole program sits in the model announcement, not the program page. Gemini 3.8 Flash, released the same day and publicly available, ships with safeguards against chemical, biological, radiological and nuclear misuse and against cyber offense. Gemini 3.8 Flash Cyber, in Google's words, "ships with a more permissive set of mitigations for cybersecurity, and as such, is only available to trusted defenders." The gated model is the one with fewer guardrails. Fairwind is the vetting layer that substitutes for them.
Google says more than 650 partners globally are already participating.
Why the model is gated
Google DeepMind states the dual-use problem plainly on the program page: "Using frontier AI capabilities can help people to rapidly discover – and fix – critical vulnerabilities. But in the wrong hands, the same capabilities can become an equally powerful threat."
The stated logic is a head start rather than containment. Early access gives trusted defenders "a vital adaptation window to harden their systems before bad actors have a chance to exploit new capabilities" — an argument that the capability is coming regardless, so defenders should get it first.
Google also says it shaped the model's capabilities toward that end: it "invested in vulnerability fixing from the start, and prioritized it over offensive capabilities like exploitation." Partners are permitted only defensive dual-use work — authorized threat simulation, reverse engineering, and malware analysis for defensive and academic research. Creating malware is explicitly out.
This makes Fairwind a concrete instance of staged capability release, a recurring AI governance question: what to do when the same weights defend and attack. Google frames the program as provisional, saying it will collaborate "with industry, governments, and open-weight community leaders to strike the right balance between open access and robust security."
Who qualifies, and what they sign
Three prioritized groups:
- Governments and national cyber authorities — public-sector networks and citizen services.
- Critical infrastructure operators — healthcare, telecommunications, energy, financial networks.
- Core technology platforms — securing software foundations "for millions of downstream users at once."
Academic labs focused on defensive benchmarking may apply; students are directed to CodeMender on Google Cloud instead.
Google runs background checks on the applying organization to verify its security history and record of ethical operations. Accepted partners commit to user-level authentication with phishing-resistant MFA, access limited to internal cybersecurity, incident response or penetration testing teams, tracking of which employees use the model, and no sharing, redistributing or selling access. Applications go through a form; Google promises a response "as soon as we can" with no published turnaround.
One procurement-relevant detail: accessed as a managed model on the Gemini Enterprise Agent Platform, 3.8 Flash Cyber supports zero data retention.
This formalizes the posture Google took in July 2026, when Gemini 3.5 Flash Cyber shipped as a restricted CodeMender pilot rather than an API product. Fairwind turns that pilot into a standing program with published criteria.
What the model is claimed to do
All figures below are Google-reported unless noted:
| Measure | Result |
|---|---|
| CWE-Bench (patching, run by Collinear) | 47.2% pass@1, vs. 47.8% for Claude Fable 5 at significantly higher cost |
| Chrome Security team | 2.6x more correct Chrome patches than "the best commercial models that are much larger" |
| Internal multi-language benchmark | over 70% success rate discovering vulnerabilities across 20 programming languages |
| Google Cloud Vulnerability Research | one critical foundational vulnerability found in under 2 hours; Google says such work usually takes months |
| Wiz internal penetration-testing benchmark | +7.5–9.7% higher recall at 2.3–5.2x lower cost than other leading frontier models (reported by Wiz) |
| CyberGym (vulnerability discovery) | "frontier-level," surpassing 3.5 Flash Cyber and larger frontier models — no score published |
The CWE-Bench line is the one to read carefully. At 47.2% against 47.8%, the model is fractionally behind Claude Fable 5 on accuracy; Google's claim is the Pareto frontier — comparable results at materially lower cost — not a capability lead. The CyberGym result, which Google leads with, carries no number at all.
Separately, Google says the 3.8 line made "a significant leap in prompt injection robustness as measured by Gray Swan" — relevant because an agent reading untrusted code is exactly the setting where injection matters.
Partners on record
Five organizations gave attributed statements: Armadin (David Slater, Founder & Chief Architect), CrowdStrike (Daniel Bernard, Chief Business Officer), Palo Alto Networks (Charlie Sestito, Office of the CTO), Snowflake (Mayank Upadhyay, CSTO) and Wiz (Gal Nagli, Head of Threat Exposure).
The consistent theme is economics rather than raw capability. Snowflake ran a two-day trial on public repos and reported the model "held its own against much larger engines on critical and high severity findings… at Flash-style cost, cheap enough to run continuously rather than in occasional sweeps." Armadin likewise reported it "matched larger frontier models at a lower price." That is the same claim the CWE-Bench chart makes: parity at lower cost, run continuously instead of periodically.
The parts that are not gated
Google separated the model from the tooling. Any Google Cloud customer can run CodeMender with publicly available models on the Gemini Enterprise Agent Platform alongside AI Threat Defense; only the Cyber model requires approval.
The announcement also restated Google.org's grant-making: total cybersecurity funding now above $100 million globally, including $36 million across 35 cyber clinics that have supported more than 1,250 hospitals, public school districts and municipal utilities in the U.S. That is philanthropy for under-resourced defenders, not model access.
Conclusion
Fairwind is a distribution decision more than a technical one, and the precedent is worth noting: a frontier lab now runs background checks, mandates MFA, restricts which internal teams may hold a credential, and bans resale — closer to export control than to a developer signup. The justification is explicitly that the safest version of this capability is not the most restricted one, but the one that reaches defenders first.
What is still unpublished: the CyberGym score Google leads with, how long review actually takes, how the 650 partners distribute across the three tiers, and how a "more permissive set of mitigations" is bounded in practice.
Sources
- Google's Fairwind Program: Cyber defense tools for trusted partners — the launch announcement
- Fairwind Program — eligibility, vetting, governance, partner statements
- Introducing Gemini 3.8 Flash and 3.8 Flash Cyber — benchmarks and the Frontier Safety Framework note
- Google Ships Gemini 3.6 Flash at a Lower Price Than 3.5 — the earlier restricted Flash Cyber pilot