· via Google AI blog
Google's Fairwind Program gives governments early access to Gemini 3.8 Flash Cyber and CodeMender
Google has launched Fairwind, a limited-access program offering its Gemini 3.8 Flash Cyber model and CodeMender harness to governments and enterprises for autonomous vulnerability discovery and patching.

Google has launched the Fairwind Program, a limited-access initiative that gives governments, critical infrastructure operators and vetted enterprise customers early use of the company's most advanced security AI. According to the Google AI blog, the program combines a purpose-built cyber model, Gemini 3.8 Flash Cyber, with Google's CodeMender harness, letting defenders detect, verify and repair vulnerabilities with a high degree of autonomy.
The middle ground Google is targeting
Google describes a trade-off that has slowed AI adoption in defense work: full-size frontier models can be expensive to run and difficult to govern across large enterprise codebases, while smaller open-weight models often cannot handle difficult remediation tasks and leave teams to assemble their own tooling and infrastructure. Fairwind is Google's attempt to occupy the space between those two options, offering specialized security capability without frontier-model costs.
The company claims the pairing delivers the reasoning needed to write and validate code fixes at a fraction of the operating cost of conventional frontier models. Where manual remediation can take weeks, Google says the tooling can produce verified, deployment-ready patches in minutes, running inside the customer's own secured cloud environment. These performance claims come from Google and have not been independently verified.
Who gets in first
Access is being staged toward the organizations Google considers most central to societal resilience:
- Governments and national cyber authorities, to harden public-sector networks and citizen-facing services against targeted intrusions.
- Critical infrastructure operators, covering healthcare, telecommunications, energy and financial networks against operational disruption.
- Core technology platforms, where securing widely deployed software can improve security for large numbers of downstream users at once.
The blog states that more than 650 partners worldwide are already participating.
Conditions for participation
Because the capabilities involved are powerful, joining the program comes with strict operational standards. Participating organizations must restrict access to staff on their internal cybersecurity, incident response or penetration testing teams, and must deploy protections such as multi-factor authentication. Google says the program will evolve alongside partner needs and that it will work with industry, governments and open-weight community leaders to balance broad access against security.
Not exclusive to Fairwind
Gemini 3.8 Flash Cyber access is prioritized for program participants, but Google notes that any Google Cloud customer can already use CodeMender with publicly available models hosted on the Gemini Enterprise Agent Platform, alongside the company's AI Threat Defense product line.
A funding footnote
Alongside the launch, Google says its total cybersecurity funding through Google.org has passed $100 million globally. Its 2026 US Cybersecurity Impact Report details $36 million directed to 35 cyber clinics, which have provided free hands-on security support to more than 1,250 hospitals, public school districts and municipal utilities in the United States.
Why it matters
Google's core argument is that the defender's advantage now lies in how quickly a flaw moves from detection to patch, and that agent-driven tooling can compress that window from weeks to minutes at a moment when offensive AI operates at comparable speed. By handing these capabilities to well-run defensive teams first, Google is effectively trying to buy society time to harden systems before equivalent tools spread to attackers.
The design also raises structural questions. Security capability of this grade is being allocated by a single vendor under restricted terms, which concentrates influence over who gets protected and when, even as Google frames the program as a contribution to global cyber resilience. For Google Cloud, Fairwind is also a commercial wedge: the most capable cyber model sits behind a gated program, while the broader patching tooling is open to anyone already on the platform.
- #google-cloud
- #cybersecurity
- #gemini
- #vulnerability-management
- #ai-agents