Google Built a Vulnerability-Hunting AI and Locked It Behind a Government-Only Pilot


Google DeepMind released Gemini 3.5 Flash Cyber on July 21, a specialized security model built on top of Gemini 3.5 Flash and fine-tuned to find, validate, and patch software vulnerabilities — and unlike the two other models announced the same day, it isn't going to the public.
Access is limited to governments and trusted partners through Google's CodeMender program, as part of what the company calls a limited-access pilot with no public API, no published pricing, and no self-serve signup. Google says the model has already been running internally across Chrome, Android, Cloud, Ads, and YouTube codebases, and cites a benchmark where it found 55 confirmed issues in V8 JavaScript engine testing against 36 for Claude Opus — though that comparison relies on Google's own unpublished vulnerability set rather than an independently reproducible test.
Google frames the restriction as intentional rather than a rollout delay. In DeepMind's announcement, security lead Raluca Ada Popa and VP Four Flynn described the approach as tied directly to the model's dual-use risk: a system this effective at discovering exploitable bugs is equally useful to whoever gets to run it, so the company is controlling distribution from launch rather than relying on usage guardrails after the fact.
The move puts Flash Cyber in the same emerging category as Anthropic's approval-gated Mythos models — frontier-adjacent capability that labs are choosing to build but not ship broadly. It's a notable shift from Google's usual API-first playbook, and one of the clearer signals yet that offensive-security capability is now advancing fast enough that even its developers don't trust open distribution.


