Google has released Gemini 3.8 Flash alongside a restricted cybersecurity variant, marking its third Flash model rollout in six weeks. The new software engineering model claims top leaderboard standing at a discounted rate, while navigating strict new European compliance timelines under the EU AI Act.
The release cadence for Google’s lightweight AI models has accelerated significantly. Following the debut of Gemini 3.8 Flash, the company now offers its third Flash model in just six weeks, as reported by Ars Technica. This aggressive rollout leaves the Pro product line untouched since early 2026, creating an unusual dynamic where the workhorse cheap model sits two versions ahead of the company flagship, according to TNW.
Pricing Pressures and Software Engineering Benchmarks
To keep wary businesses engaged amid fierce market competition, rivals have been cutting token prices. Google has structured introductory pricing for the new release through the end of the year, charging $0.75 per million input tokens and $3.75 output, against $1.50 and $7.50 afterwards.
Despite the lower cost at the current discounted rate, performance metrics for the new release show strong placement in specialized tasks. Gemini 3.8 Flash is now at the top of the DeepSWE leaderboard, which measures a model’s ability to solve complex software engineering problems. Google reportedly delayed the release of Gemini 3.5 Pro when its coding performance couldn’t match other models, but if these numbers reflect reality, even Google’s new Flash models are competing with the market leaders. However, computer use remains a stubborn weak spot for Google’s models. While Gemini 3.8 Flash is an improvement over 3.7 Flash in the OSWorld-2.0 test of agentic computer use, it is still far behind the market leader Claude Opus. In fairness, GPT is not great in this test either, and the computer use tool was originally added at version 3.5.
Gemini 3.8 Flash Cyber and Ecosystem Restrictions
Alongside the general workhorse version, Google introduced Flash Cyber, tuned for finding and fixing software vulnerabilities. This specialized cybersecurity model replaces the previous 3.5 version and targets high-stakes defense and infrastructure use cases, though it is noted that most users will never need to think about it.

Access to the cybersecurity variant is tightly controlled. Gemini 3.8 Flash Cyber is currently limited to trusted testers and governments, though Google does not say which governments. Google claims that the new cybersecurity model has demonstrated a substantial improvement over its previous models with internal testing. The model reportedly identified more vulnerabilities and issued working patches more often. Internal figures released by Google indicate substantial gains in security operations, including a 2.6x increase in patch accuracy for the Chrome security team, a critical vulnerability found by the Cloud team in just two hours, and statements from partners like Wiz and Palo Alto Networks attesting to the power of Gemini 3.8 Flash Cyber.
Gemini 3.8 Flash will be available across the Google ecosystem starting today. Like the past Flash release, users will need a Pro or Ultra subscription to access Gemini 3.8 Flash in the Gemini app, but they can always visit AI Studio to tinker with it for free.
European Compliance and Regulatory Timelines
Every rapid release into the European market brings immediate regulatory burdens for a product line that at launch was not available in Europe. Under Article 53 of the EU AI Act, every general-purpose model placed on the market carries technical documentation, a copyright policy, and a public training data summary. Google signed up willingly to these terms when it joined the general purpose AI Code of Practice on 30 July 2025, a week after Meta refused to do so.
The systemic risk tier carries a clock under Article 52. A model trained above 10 to the 25th floating-point operations must be notified to the Commission within two weeks. That compliance window is shorter than the gap between these releases, as Gemini 3.7 Flash arrived three weeks before this one. Whether any of them crosses the threshold is not public; Google has not said, and the presumption turns on training compute rather than on benchmark results. Flash models are by design smaller than the Pro line, and the Pro line has not moved since early 2026.
