# Google opens Fairwind for faster cyber defense

> Google is giving selected defenders restricted access to Gemini 3.8 Flash Cyber and CodeMender, while its benchmark claims still need independent testing.

_Source: Google official announcement, cross-checked with independent coverage surfaced by Google News · 2026-09-03 · 5 min read · Verified against primary sources_

Canonical: https://iyu.app/e/google-fairwind-cyber-defense

## The 60-second version

Google is giving selected defenders restricted access to an AI system that can find, verify, and help patch software vulnerabilities.

**Key points**

- Fairwind pairs Gemini 3.8 Flash Cyber with the CodeMender repair harness.
- Google reports strong results, but the benchmark figures are self-reported and context-dependent.
- Access is limited to trusted organizations and internal security teams with controls such as MFA.

**Verdict.** The important test is safe reduction of patch time in real codebases, not a headline score.

## Full explainer


### What changed — Fairwind narrows the gap between finding and fixing

Google has launched Fairwind, a limited-access program that gives selected governments, critical-infrastructure operators, and software maintainers access to Gemini 3.8 Flash Cyber with the CodeMender harness. The aim is not simply to list vulnerabilities, but to help defenders verify and repair them inside a secure cloud environment.

- **650+** — participating partners named by Google
- **20** — programming languages in an internal test
- **47.2%** — CWE-Bench pass@1 reported by Google


### How it works — An agentic repair loop, not an autopatch button

The model can inspect a codebase, reason about a weakness, propose a patch, and validate the result. CodeMender is the surrounding harness: the important promise is a checked patch that can be reviewed and deployed, rather than an untested code fragment.

- **Access:** Limited to trusted defenders, including government and critical infrastructure partners.
- **Workflow:** Find a weakness, verify it, write a repair, then validate the patch.
- **Guardrails:** Internal security teams, incident responders, or penetration testers; MFA required.


### What the numbers mean — The evidence is promising, but it is still vendor evidence

Google reports frontier-level results on CyberGym, more than 70% success on an internal multi-language benchmark, and 47.2% pass@1 on CWE-Bench versus 47.8% for a leading frontier model. These figures describe Google’s tests and selected comparisons; they are not a guarantee for every production codebase.

> **⚑ Caveat:** The benchmark scores and claims about speed, cost, and patch quality are reported by Google. Independent replication, deployment context, and the review burden still matter.


### Why it matters — The defender’s clock is the real battleground

As coding agents make attacks faster, a vulnerability that takes weeks to repair is a widening window of exposure. Fairwind’s practical bet is that a smaller, cheaper model can run more repair iterations while keeping access restricted. That could help organizations reduce patch latency, but it also concentrates powerful cyber capability behind an eligibility gate.

> The meaningful metric is not how many flaws an AI can name; it is how safely a team can close them.


## Primary sources

- [Google: Fairwind Program](https://blog.google/innovation-and-ai/technology/safety-security/fairwind-program/)
- [Google: Gemini 3.8 Flash and Flash Cyber](https://blog.google/innovation-and-ai/models-and-research/gemini-models/3-8-flash-and-3-8-flash-cyber/)
- [Independent coverage (Google News result: VentureBeat)](https://news.google.com/rss/articles/CBMivAFBVV95cUxNMHpNUnplNkRkbUhZNFNRbXpENzJfdzFKelp1akdHeEhWMXRJZTVfU0R6clE5WUc2S2U0N2E0ZGZCaFlMczNybUdTdUc0UmtvQXF0dDVGWUlzUmxJN3NZNENaY2dVLW4wREtCTFF3YzAyUGJ4WUhFT2tfYUZNVE0yZDhqaDFkZUtJd3BnZVFhaW1COHBDRG12OXZHVVFyejBLSDNQWmU0UjNFUWRVZ0tGdll2SUxaM1FscHVHTg?oc=5)

---
_Published by iyu (https://iyu.app) — the day's AI news, checked against primary sources and rewritten in plain language. Free to quote with attribution and a link to the canonical URL._
