Gemini 3.8 Flash Holds 3.7 Pricing, Adds a Gated Cyber Model
Google's 3.8 Flash keeps 3.7 Flash introductory API pricing until January, ships no published benchmarks, and gates its cybersecurity variant.
Google shipped Gemini 3.8 Flash roughly three weeks after 3.7 Flash, and the introductory API pricing is unchanged — but only until January.
The release also introduces a variant you cannot call with an API key. Here is what changes for anyone already running 3.x in production.
The pricing window is the actionable part
According to the release analysis, the introductory API pricing for 3.8 Flash remains the same as it was for 3.7 Flash, and Google has indicated this pricing will change in January. The write-up frames that as a window for developers to integrate and test the new model without an immediate cost increase.
That framing is right as far as it goes, and it is worth being precise about what it does not say: no replacement rate has been published, and the analysis does not state whether the January change is an increase, a restructure, or tier-specific. Plan the migration test now; do not put a number in next year's budget yet.
The model also continues to support customizable effort levels, which the source describes as a trade-off between quality, cost and latency — the mechanism that lets you serve a fast, cheap response for one task and a slower, higher-quality one for another.
What Google targeted
The stated focus is narrow and worth reading literally: long-running agents, multi-step reasoning, and software engineering tasks. The analysis characterizes this as a deliberate move away from chatbot benchmarks toward code generation, debugging, and orchestrating complex tasks.
One caveat for anyone deciding whether to switch: the source publishes no benchmark figures at all — no scores, no latency measurements, no head-to-head against 3.7 Flash. The claim of improvement is directional, not quantified. Treat it as a reason to run your own eval on the free-pricing window, not as evidence the eval will pass.
A cybersecurity variant behind a gate
The more structurally interesting item is Gemini 3.8 Flash Cyber, described as a specialized variant fine-tuned for cybersecurity use cases — specifically vulnerability discovery and automated patching.
Access is not public. The source says it is being made available to trusted defenders through a new channel called Google's Fairwind Program, and reads the gating as a deliberate pattern: controlling release to mitigate misuse while still reaching security professionals who use it for defense.
The practical consequence for builders is a change in procurement, not just capability. If the most capable model for your security workload sits behind a verification process, an API key stops being sufficient, and access becomes something with a lead time and an approval step.
What to do this week
- If you run 3.7 Flash in production: run your agent and code-gen evals against 3.8 Flash now, while the rate is still the old one. The January change removes the free part of this comparison.
- If you were counting on stable Flash pricing: flag January to whoever owns the budget, with the caveat that the new rate is not published.
- If you do security work: the Fairwind application is the gating item, and it is worth starting before you need the model.
What to watch: whether Google publishes the January rates before the window closes, and whether the gated-variant pattern extends to other high-stakes domains. The analysis expects it will, but that is a forecast rather than an announcement.
More from DangMua