Alphabet has released three new Gemini models, including a cybersecurity-focused system designed to identify and patch software vulnerabilities. Gemini 3.5 Flash Cyber will initially be made available through a limited-access pilot for governments and trusted partners, rather than through a broad public launch.
The release also includes Gemini 3.6 Flash and Gemini 3.5 Flash-Lite, reflecting Google's push to improve the efficiency and affordability of its AI portfolio while expanding its capabilities in coding, multimodal tasks, and agent-based workflows. Google is positioning the updates as part of a wider effort to make powerful AI systems more practical to operate at scale.
The announcement highlights two increasingly important priorities in the AI market: cost and cybersecurity. Google is betting that smaller, more targeted models can make AI cheaper to deploy across high-volume workloads, while Gemini 3.5 Flash Cyber signals its intent to compete in the fast-growing market for AI-powered software security tools.
Google Targets Performance, Scale and Software Security
Built on Gemini 3.5 Flash and fine-tuned to find, validate, and patch software vulnerabilities, Gemini 3.5 Flash Cyber is Google's new lightweight cybersecurity model.
Google said the model is designed for large and complex codebases, where detecting deeper flaws can require assessing a huge number of possible code paths. Rather than relying on a single, expensive call to a larger model, CodeMender can invoke Gemini 3.5 Flash Cyber repeatedly, allowing sub-agents to assess more paths before producing a final report. The company said this makes it suitable for frequent scans, commit-scanning pipelines, and time-sensitive launches.
That focus on making advanced capabilities usable at scale runs through Google's wider release. Gemini 3.6 Flash improves coding, multimodal, and knowledge-work performance while using up to 17% fewer tokens than its predecessor. Gemini 3.5 Flash-Lite is aimed at high-volume workloads and smaller tasks within AI agent systems, extending the company's push to lower the cost of AI deployment. The lower cost of running these models also allows systems such as Gemini 3.5 Flash Cyber to be used more frequently to continuously search for vulnerabilities.
In tests on Google's V8 JavaScript engine, Gemini 3.5 Flash Cyber found 55 confirmed unique issues under a fixed number of invocations, compared with 47 for mainline Gemini 3.5 Flash and 36 for Claude Opus 4.6, according to Google.
Google said these capabilities help defenders find and address critical flaws before they are exploited while limiting broader misuse. The company added that the model is already being used across internal codebases, including Chrome, Android, Cloud, Ads, and YouTube. Its Cloud Vulnerability Research team said it used the system to uncover remote code execution vulnerabilities in public APIs and a memory corruption flaw in a production service within two hours.
As a result of these capabilities, the model will initially be available only to governments and trusted partners through CodeMender under a limited-access pilot. Google said the approach is intended to give defenders an earlier opportunity to find and fix critical flaws while limiting the potential for misuse.
A Growing Race for AI Security and Efficiency
Google's move arrives as enterprise and public sector interest in AI security continues to grow. Anthropic's Mythos helped accelerate that attention by showing how models could be applied to finding flaws across large bodies of source code while also raising questions about how those systems should be controlled.




