Zendoric
← Back to the day · July 24, 2026

Google locks its cyberwarfare AI behind a state door: it creates exploits and only governments use it

🕒 Published on Zendoric: July 24, 2026 · 00:29

Gemini 3.5 Flash Cyber, Google DeepMind's new model, finds vulnerabilities, builds the exploit that proves them and writes the patch, all within hours. Google admits it is a dual-use weapon and only grants it to governments and trusted partners through a restricted-access pilot.

🎧 Listen to the analysis

By Zendoric · July 24, 2026.

Google DeepMind unveiled on July 21 Gemini 3.5 Flash Cyber, a specialized model built on the Flash 3.5 architecture and dedicated exclusively to cybersecurity. As Google itself describes it, the system scans code for vulnerabilities, generates an exploit —a program that proves the flaw is real and exploitable— within a controlled environment (sandbox), and then writes the patch that fixes it. All autonomously and, in the cases documented by Google, within roughly two hours. The model powers CodeMender, the company's security agent, which invokes it repeatedly to analyze different paths through the same code and consolidate a single vulnerability report.

The numbers Google provides are the selling point. In its internal Chrome vulnerability pipeline, Flash Cyber found 55 unique flaws, versus 47 for the standard 3.5 Flash model and 36 for Anthropic's Claude Opus, according to Google's own figures. In the internal Big Sleep evaluation, it outperformed both its base model and the larger 3.6 Flash. In one of the cited cases, the system generated a remote code execution (RCE, the ability to run arbitrary instructions on someone else's system) exploit that bypassed standard security mitigations.

It is precisely that step —not detecting the flaw, but demonstrating it with a working exploit— that has led Google to close off access. The company explicitly acknowledges that a model that only flags vulnerabilities is a defensive tool, but one that also builds the weapon to exploit them is dual-use by definition. That is why Flash Cyber is only available to governments and trusted partners through a limited-access pilot program, aimed at national cybersecurity agencies, military networks and critical-infrastructure operators. It is, by Google's own framing, the first frontier AI model built for offensive use and locked behind a state gate from birth.

The launch also included Gemini 3.6 Flash, general-purpose and priced at $1.50 per million input tokens (the minimum unit of text the model processes), and Gemini 3.5 Flash-Lite, a lightweight version designed for high-volume use. Google mentioned Gemini 4 in passing, with no date. Striking, by contrast, is the absence of Gemini 3.5 Pro, the large reasoning model the sector has been expecting for months: Google has not explained the delay, and each Flash launch without its Pro sibling fuels more speculation than answers.

Our reading is that Flash Cyber inaugurates a new category with few precedents: an AI capability that a company considers too dangerous to sell openly, but too valuable not to share with the State. It is not just another cybersecurity benchmark —of the kind that, as we have been noting, many are already saturated and no longer discriminate—; here the maker itself is deciding, unilaterally, who may wield a real offensive tool. That shifts the debate from technical capability to governance: who audits access, which governments enter the pilot, and what happens when that same technology, with fewer scruples, is replicated by an actor with no export controls.

In the short term, the risk is twofold: on the one hand, automating the search for exploits also speeds up anyone who wants to misuse it if the access perimeter fails; on the other, concentrating this capability in state hands reinforces an asymmetry of power between governments with access to the AI frontier and everyone else. In the long term, however, if the promise holds —patching critical-infrastructure vulnerabilities faster than an attacker can exploit them—, the balance between attack and defense tips in favor of whoever protects, not whoever attacks. That is exactly the kind of defensive advance we need so that the transition toward a more automated and abundant society is not built on vulnerable power grids, hospitals and financial systems. The condition, as always, is that the governance of this selective access measures up to the capability Google has just acknowledged creating.

🔗 Related on Zendoric

Sources & references