Google opens Fairwind Program: Gemini 3.8 Flash Cyber writes and tests security patches on its own
The Fairwind Program hands governments, hospitals and infrastructure operators an AI agent that finds software flaws and ships a verified fix in minutes.

Key points
- Google launched the Fairwind Program, giving 650+ vetted partners early access to Gemini 3.8 Flash Cyber, a specialised AI model built to find and fix software vulnerabilities.
- The system pairs the model with CodeMender, a tool that writes and tests code patches automatically inside a customer's own cloud.
- Access is limited to governments, critical infrastructure operators such as hospitals and energy grids, and core technology platforms.
- Google.org's cybersecurity funding now tops $100 million globally, including $36 million for 35 cyber clinics helping over 1,250 US hospitals, schools and utilities.
- Any Google Cloud customer can still use CodeMender with publicly available models through the Gemini Enterprise Agent Platform.
Google is opening a side door to its best cyber-defence AI, and only a select guest list is getting a key.
The company announced the Fairwind Program, a limited-access scheme that puts its newest security model, Gemini 3.8 Flash Cyber, in the hands of governments, big infrastructure operators and a short list of trusted partners. The goal is blunt: find the holes in their software, then patch them, without waiting weeks for a human engineer.
What does the Fairwind Program actually do?
It hunts for bugs in code and writes the fix itself. The model works alongside a tool Google calls CodeMender, an AI agent (software that carries out multi-step tasks on its own) that drafts a patch, tests it, and hands back something ready to deploy.
Google says the whole loop runs inside the customer's own secure cloud. That matters for a hospital or a power company that cannot ship its source code off to a third party.
The pitch, in plain terms: instead of a security team spending three weeks arguing about a fix, the agent produces a verified patch in minutes. Google claims it does this at a fraction of the running cost of larger frontier models, the giant general-purpose AIs like the ones behind ChatGPT.
Who gets in?
Not you, unless you run something critical. Google is staging access to three groups:
| Group | Examples | Why they qualify |
|---|---|---|
| Governments | National cyber agencies | Protect public-sector networks |
| Critical infrastructure | Hospitals, telecoms, energy, banks | Keep essential services running |
| Core tech platforms | Widely used software vendors | One fix protects millions downstream |
More than 650 partners are already signed up worldwide. Each one has to agree to strict rules: only in-house security, incident response or penetration testing staff can touch the tools, and multi-factor authentication (a login that requires a second check, like a code on your phone) is mandatory.
Why limit it at all?
Because the same agent that patches a flaw can, in the wrong hands, be pointed at finding flaws to exploit. Google frames the limited rollout as an "adaptation window" for defenders to harden systems before attackers catch up. That is a polite way of saying: we do not want this loose on the open internet yet.
Smaller Google Cloud customers are not locked out entirely. They can still run CodeMender with publicly available models on the Gemini Enterprise Agent Platform, paired with Google's AI Threat Defense product. It is a step down from the specialised cyber model, but the plumbing is the same.
What does this mean for ordinary people?
If your hospital, school or local utility uses one of these partners, the software running your medical records or your water bill should get patched faster. That is the practical upside. You will not see the AI. You will, hopefully, see fewer breach notifications in your inbox.
Google also used the announcement to flag its wider security spending. Through Google.org, its charitable arm, total cybersecurity funding has passed $100 million. The 2026 US Cybersecurity Impact Report details $36 million going to 35 cyber clinics that have helped more than 1,250 hospitals, public school districts and municipal utilities with free hands-on security support.
What happens next?
Google says the program will expand as partners and use cases grow, with input from open-weight AI communities (groups that build models anyone can download and inspect). Translation: today it is a walled garden. Tomorrow, if the patches hold up in the real world, the walls may come down a little.
For now, the defender's clock is the thing to watch. Attackers already move at machine speed. Fairwind is Google's bet that defenders can too.



