Google launches Gemini 3.5 Flash Cyber to patch vulnerabilities fast, cheaply
An AI security model built on Gemini 3.5 Flash aims to let agents scan more code paths at low cost.

Google is launching Gemini 3.5 Flash Cyber, an AI security model built on Gemini 3.5 Flash. It will be available first to governments and trusted partners through CodeMender, Google’s security-focused coding agent.
Google is rolling out Gemini 3.5 Flash Cyber, an AI model designed for one job: quickly finding and patching security vulnerabilities. In a blog post on Tuesday, Google positions it as a “cost-efficient and highly capable alternative” to larger, more expensive AI security systems, including the one offered by Anthropic’s Mythos.
The punchline is how Google wants security teams to use it. CodeMender, Google’s security-focused coding agent, can call Gemini 3.5 Flash Cyber “multiple times at high speed and low cost,” so the AI can scan more code paths and increase the odds of catching vulnerabilities that might slip past narrower review.
This is a strategic move in an area where the constraints are never abstract. Security work is expensive in the literal sense. Even when an organization has smart engineers, vulnerability discovery and remediation take time, and time translates into operational cost. The faster you can iterate on fixes and the more surface area you can review, the less you rely on humans alone to chase every potential flaw across complex codebases.
Where this gets interesting is the pricing and performance tradeoff Google is implicitly betting on. Larger AI security models are powerful, but they are also more expensive to run and harder to scale across day-to-day workflows. By building a dedicated security model on top of Gemini 3.5 Flash, Google is aiming for a setup where you can run more scans, more frequently, without the same cost shock that comes with repeatedly invoking heavier models. In other words: not just “better AI,” but a different operating model for how security agents behave.
The distribution plan also matters. Google says Gemini 3.5 Flash Cyber will be available first to governments and trusted partners via CodeMender. That sequencing is typical for high-stakes security tooling, where access is controlled and the early rollout is channeled through environments Google considers appropriate for sensitive use. For decision-makers, that signals this is not a casual consumer launch. It is a targeted push into organizations that are under pressure to improve security posture while still meeting compliance and procurement realities.
There is also a subtle shift in how teams may think about vulnerability workflows. Instead of treating vulnerability scanning as a one-time event, CodeMender can repeatedly invoke the model at “high speed and low cost.” When a tool can be run multiple times, it changes expectations: teams can afford broader coverage, more iterative patching, and more frequent reassessment as code changes. Security becomes less like a gate and more like a continuous background process.
Second-order implications for execs and boards: this competitive landscape is starting to look like a race to the cheapest marginal security scan that still finds real issues. If “multiple times” at low cost becomes the default pattern, then AI security models could compress the gap between what large organizations can do today and what smaller teams can realistically afford tomorrow. That is the kind of shift that can change vendor comparisons, budgeting cycles, and how security ROI is reported internally.
For peers evaluating AI security spend, the core question is no longer only whether a model can detect vulnerabilities. It is whether you can operationalize detection and remediation at scale. Gemini 3.5 Flash Cyber is built to be called repeatedly through CodeMender, which suggests Google is targeting the day-to-day bottlenecks: coverage, speed, and cost. If this works as advertised, it could force every security team to rethink what “affordable” continuous scanning means, and it could raise the bar for other providers whose offerings depend on expensive, one-off deep scans.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Technology

By 2035, data centers could use 4x more electricity than today
A new build pipeline through 2033 may consume power on par with India, forcing operators to plan for scarcity now.
Frozen-fiber tech couples light and sound 1,000x more strongly than standard glass
A glass capillary frozen into a fiber lets photonic systems trade energy waste for tighter light-sound linkage.
Nvidia publishes Vera AI server CPU specs, posting SPEC CPU 2026 integer lead over AMD
The company released a white paper with SPEC CPU 2026 results, placing Vera ahead of AMD's Epyc 9755 for integer performance.
