Google’s Gemini 3.5 Flash Cyber Signals a New Era of AI-Driven Cybersecurity

AI just took another step towards becoming an important player in digital defense. Google DeepMind announced the release of the new Gemini 3.5 Flash Cyber – an AI model that is designed to identify and fix software vulnerabilities long before any attacker tries to use them. This is probably one of the most interesting news to come out of the field of applying artificial intelligence for the benefit of cybersecurity.

While the release is still limited to governments and partners of Google, the implications of this announcement affect literally everybody both those working with security and ordinary customers who want their software to be safe.

What is Gemini 3.5 Flash Cyber?

Gemini 3.5 Flash Cyber is an AI model optimized for cybersecurity purposes and released as a part of CodeMender product suite. CodeMender is an AI-powered tool that is capable of detecting vulnerabilities in code and fixing them automatically, developed and presented by Google in late 2025.

This model is fine-tuned for one specific purpose only – analyzing huge chunks of code fast and accurately enough to find security flaws in it. As Google puts it, the main advantage of this model is its efficiency. It is smaller and faster than the heavy AI models designed to be used for cybersecurity. Because of that, CodeMender is able to call it repeatedly to analyze more code paths in less time.

Better Than Rival AI Models

According to Google, Gemini 3.5 Flash Cyber outperformed not only general-purpose models of the company itself, but also competing AI models in terms of discovering vulnerabilities in the code. In one test, involving the V8 JavaScript engine (the one that powers Google Chrome browser), the specialized model found 55 confirmed unique vulnerabilities while the general-purpose Gemini model was able to detect only 47 and a competing AI model managed to find only 36 of them. Moreover, it managed to find several vulnerabilities that none of other AI models was able to detect.

In addition to synthetic benchmarks, the AI has proven to be useful in real-world scenarios, for instance, when working with complex browser engines. Google claims that, as a result of one experiment, AI created a remote-code-execution exploit that is able to bypass modern security methods, such as ASLR and W^X.

A Carefully Limited Release

Because of the potential danger of this technology, Google decided to take a cautious approach to its deployment. Instead of releasing the Gemini 3.5 Flash Cyber as an accessible product, the company started with a limited access pilot program targeting only selected governments and partners of Google.

Google security executives noted that there is a potential double-edged nature of the technology that allows defenders to discover and fix vulnerabilities faster, but, if misused, could allow attackers to exploit these vulnerabilities. This careful approach reflects the tendencies that can be seen across the entire AI industry. Similar vulnerability discovery AI models were tested recently in other major AI labs. They all faced the same challenge – how to provide a head start to defenders without giving a new weapon to attackers.

Why This News Is Important For You

At first glance, it might seem that this news is relevant only for big companies and government agencies. In reality, however, the consequences will be felt by a lot more people.

With the help of AI, software vulnerabilities will be identified and fixed in various software components that everybody is using every day. With the maturation of this type of technologies, it is reasonable to assume that they will find their place in commercial cybersecurity products and services that will be used by enterprises and consumers.

From the point of view of individual users, this means that the era of pure manual vulnerability hunting is coming to its end. And AI will make it possible to discover more vulnerabilities in a shorter period of time. This raises an additional concern since, in the age of AI, exploitation of those vulnerabilities will probably occur much faster too. So the knowledge of basic digital hygiene becomes especially valuable in the current situation.

Bigger Picture: Double-Edged Nature of AI in Digital Defense

Gemini 3.5 Flash Cyber is a part of the bigger trend that is changing the cybersecurity landscape right now. More and more often AI is used to help defenders to fix vulnerabilities faster than they can be exploited, but at the same time, it can be used to create a new type of threat. Google’s cautious and limited release of this technology reflects a wide industry recognition of the fact that this kind of technology requires some limitations before widespread use.

The thing that we know for sure is that the era of manual vulnerability hunting is coming to an end. More and more often AI models are discovering flaws in software faster and better and in some cases, they are discovering issues that remained unknown for years. And with the expansion of pilot projects into wide deployment, the safety of software will be greatly improved – if the technology won’t be misused.

What comes next

Google promised that access to Gemini 3.5 Flash Cyber will be expanded in the future along with the wide-scale release of CodeMender’s capabilities as a part of Gemini Enterprise Agent Platform. For now, the pilot is strictly limited, but the future of this technology is obvious. AI will play an important role in securing software.

And while this technology will mature in the future, it is still necessary to pay attention to practical and everyday digital security. Such things as choosing safe software and understanding the basics of digital privacy are especially important. All of this and many other topics are discussed in detail on TheTweaks where you can learn how to protect yourself from digital threats in your daily life.