Google has launched Gemini 3.8 Flash alongside a cybersecurity version restricted to governmental use.
Google has introduced Gemini 3.8 Flash and Gemini 3.8 Flash Cyber, marking the company's third Flash release in six weeks, with the cyber model available only to trusted testers and government entities. According to the EU AI Act, every general-purpose model launched in the market must meet documentation, copyright, and training data requirements, and any systemic risk model must be reported to the Commission within a two-week timeframe.
Gemini 3.8 Flash is Google's latest offering, as reported by Ars Technica, and it consists of two versions: a general model referred to as a workhorse, and Flash Cyber, which is designed to identify and address software vulnerabilities. Flash Cyber replaces version 3.5.
The Pro line has not been updated since early 2026, with TNW noting that the less expensive model is now two versions ahead of the flagship offering. The pricing for Gemini 3.8 Flash is introductory until the end of the year, set at $0.75 per million input tokens and $3.75 for output, compared to the future prices of $1.50 and $7.50, respectively. Competitors have been lowering token prices to attract cautious businesses.
In Europe, each release is subject to compliance requirements. Article 53 mandates that technical documentation, a copyright policy, and a public summary of training data be provided for each general-purpose model that enters the market. Google has agreed to these terms voluntarily, joining the General Purpose AI Code of Practice on July 30, 2025, shortly after Meta declined to do so.
The systemic risk classification has a time constraint; any model that is trained using more than 10 to the 25th floating-point operations must be reported to the Commission within two weeks, as stipulated by Article 52. This timeframe is shorter than the interval between the releases, with Gemini 3.7 Flash launching three weeks prior to this version.
It is not publicly stated if any of these models exceed the threshold, as Google has not disclosed this information, and the assumption relies on training resources rather than benchmark performance. Flash models are intentionally designed to be smaller than the Pro series.
The situation with the cyber variant presents a different issue. Flash Cyber is limited to trusted testers and governmental bodies, though Google has not specified which governments are included.
Additionally, there are concerns regarding performance. Google's own data indicate that Flash is trailing behind Claude Opus in terms of agentic computer usage, even a year after TNW reported on the computer use tool introduced with version 3.5.
The security assertions come only from internal measures, claiming a 2.6x increase in patch accuracy for the Chrome team and a critical vulnerability identified within two hours, both assessed by Google.
This reveals the complexity of the issue; each release comes with its own European compliance responsibilities, even though the product line was not initially available in Europe at the time of its launch.
Other articles
Google has launched Gemini 3.8 Flash alongside a cybersecurity version restricted to governmental use.
Google has launched Gemini 3.8 Flash and Flash Cyber. Each general-purpose model available in the EU market is subject to Article 53 obligations, while the cyber model is restricted.
