Google Launches Fairwind to Give Selected Defenders AI Tools for Finding and Fixing Flaws
The program draws a line between broadly available code-security tooling and restricted access to Gemini 3.8 Flash Cyber, reflecting the dual-use risk of AI that can identify and repair software weaknesses.
Listen to this story
The audio brief
Story brief
3 key pointsFairwind formalizes Google’s restricted rollout of AI-assisted vulnerability remediation, replacing the earlier July Gemini 3.5 Flash Cyber pilot with Gemini 3.8 Flash Cyber plus CodeMender. Initial participants include national cyber authorities, critical-infrastructure operators and major technology platforms, with access confined to approved security teams and protected by controls such as multifactor...
- 01
Google says more than 650 partners participate globally, though initial Fairwind access is staged for high-impact defenders.
- 02
Selected organizations receive Gemini 3.8 Flash Cyber; all Google Cloud customers can use CodeMender with publicly available models.
- 03
The earlier Gemini 3.5 pilot reportedly found remote-code-execution and memory-corruption flaws in two hours.
Google has launched the Fairwind Program, a limited-access channel for governments and trusted partners to use AI systems that can find, verify and fix software vulnerabilities. The stakes lie in the handoff from detection to repair: Google is offering selected defenders its advanced Gemini 3.8 Flash Cyber model while keeping access bounded by operational controls.
Fairwind is open to selected Google Cloud customers, government agencies and cybersecurity partners. Google says it has more than 650 participating partners globally, and it is staging initial access for national cyber authorities, critical-infrastructure operators and core technology platforms.
One harness, two access paths
The restricted offering combines Gemini 3.8 Flash Cyber with CodeMender, Google’s harness for vulnerability work. Google says the combination can autonomously find weaknesses, validate them and produce code fixes. It further says those patches can be verified and ready to deploy within minutes inside an organization’s secure cloud environment; that is a company performance claim.
Who gets the advanced route—and under what conditions
- Initial priority goes to public-sector cyber authorities, operators of essential services and technology platforms whose software can affect many downstream users.
- Participants must limit access to internal cybersecurity, incident-response or penetration-testing teams, and use protections including multifactor authentication.
That split is central to the launch. Google says any Google Cloud customer can use CodeMender with publicly available models on the Gemini Enterprise Agent Platform. Fairwind therefore does not make vulnerability remediation exclusive to the selected group; it reserves access to the company’s advanced cyber model while leaving a broader, different model path available.
A restricted rollout becomes a named program
Google had already outlined a limited-access pilot in July for Gemini 3.5 Flash Cyber, a model it described as fine-tuned to find, validate and patch vulnerabilities through CodeMender. That earlier pilot was also limited to governments and trusted partners. Fairwind turns the restricted approach into a program built around Gemini 3.8 Flash Cyber and a defined set of participating organizations.
Google’s prior evidence for the 3.5 model came from its own systems and testing. The company said CodeMender with Gemini 3.5 Flash Cyber had been used on internal codebases including Chrome, Android, Cloud, Ads and YouTube. It also said a Cloud Vulnerability Research exercise identified remote-code-execution and memory-corruption vulnerabilities in two hours.
Speed is the promise; reliability is the open test
The appeal is straightforward: Google says Fairwind can generate verified patches in minutes, rather than the weeks required for manual remediation. The practical test for participants will be whether those proposed fixes remain safe and deployable across their own codebases and operating conditions.
Editorial analysis
Our Read
Our read: Fairwind is chiefly a distribution decision, not simply a new cyber model. Google is restricting Gemini 3.8 Flash Cyber to a defined set of partners with team-level access limits and multifactor authentication, while retaining a broader CodeMender option for Cloud customers using publicly available models. That creates a live test of whether Google can deliver its promised minutes-to-patch workflow in organizations beyond its own codebases. The evidence to watch next is partner experience with verified, deployment-ready fixes and whether Google expands the advanced-model program without changing its access controls.
Sources
- blog.googleProactive cyber defense for governments and enterprises
- deepmind.googledeepmind.google