
What happened
Google released Gemini 3.5 Flash Cyber, a new AI security model built on Gemini 3.5 Flash, designed to find and patch software vulnerabilities quickly and affordably. The model will first be available to governments and trusted partners through CodeMender, Google's security-focused coding agent. Google also launched Gemini 3.6 Flash with improvements in coding and multimodal performance, and introduced 3.5 Flash-Lite as a more cost-effective option in the 3.5 series.
Why it matters
Anthropic's Mythos 5, a powerful but expensive security model (costing twice as much as Claude Opus 4.8), has set a high bar for AI-driven vulnerability detection—Microsoft adopted it for security checks and achieved its largest Patch Tuesday this month after using AI to find vulnerabilities. Google's new model offers competitive performance at a fraction of the cost, allowing CodeMender to scan code "multiple times at high speed and low cost," which means more thorough vulnerability detection for organizations that cannot afford premium alternatives.
What to watch
On the CyberGym AI cybersecurity benchmark, 3.5 Flash Cyber achieved competitive performance against significantly larger models when invoked up to five times. In real-world testing on the V8 JavaScript Engine, it identified 55 unique confirmed issues, compared to 47 found by Gemini 3.5 Flash and 36 by Opus 4.6—and notably discovered 10 issues that no other model found.
Summaries like this, in your inbox every morning.
The launch of Gemini 3.5 Flash Cyber reflects intensifying competition in AI-powered security, particularly as Anthropic's Mythos 5 has raised the bar for vulnerability detection but at a prohibitively high cost. Mythos's adoption by Microsoft—and the resulting large volume of patched vulnerabilities in this month's Patch Tuesday—has made it clear that AI-driven security scanning can deliver real value, but only if the computational cost does not limit how frequently organizations can run it. Google's strategy targets this pain point directly: by making a smaller, cheaper model that CodeMender can invoke "multiple times at high speed and low cost," Google removes the economic barrier to repeated scanning.
The performance metrics Google cites show that the new model is genuinely competitive despite its lower cost. On the CyberGym benchmark, it matched larger models when called five times; on the V8 JavaScript Engine test, it found more vulnerabilities than both Gemini 3.5 Flash (55 vs. 47) and Claude Opus 4.6 (55 vs. 36), and crucially discovered 10 issues no other model found. This suggests that repeated invocations—enabled by low cost—may be more valuable than raw size, a finding that challenges the assumption that "bigger always means better" in security AI.
Google's broader model releases (Gemini 3.6 Flash and 3.5 Flash-Lite) fit into the same narrative: an emphasis on efficiency and cost-effectiveness across the product line. As China's Z.ai claims to offer competition to Mythos as well, the market for high-performance security AI is diversifying, and price-to-performance is becoming a key differentiator.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, LINE, or Slack.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Anthropic released Claude Opus 5.5 today and cut its price 20%, with input at $4 per million tokens and output…
Firecrawl announced it has raised $75 million in a Series B round led by Smash Ventures, with participation fr…
ASRock is shifting its business focus toward AI

Anthropic and OpenAI, which spent early September warning that model capabilities are outrunning the safeguard…

Jessica Wachter of Wharton and co-authors estimate hyperscaler spending will reach nearly 1.1兆ドル by 2027, and…

OpenAI released GPT-6 Sol and GPT-6 Luna on September 22, trained the same way as its top-tier GPT-6 Astra, an…
