Gemini 3.8 Flash is here. Who it is actually for.
Google shipped Gemini 3.8 Flash on 2 September 2026, plus a Cyber variant you cannot get. What changed against 3.7 Flash, and whether you will notice.
Google shipped a new Flash model on 2 September 2026. The name is Gemini 3.8 Flash. The API endpoint reads gemini-3.8-flash, and Google's own model list marks the entry "New Stable".
Gemini 3.7 Flash was twenty days old. We added that one to MultiChats on 14 August, the day after Google launched it. It already has a successor.
Here is what Google claims, and whether any of it reaches an ordinary conversation.
The claim, in Google's words
Google's announcement calls 3.8 Flash "our most intelligent workhorse model, delivering significant improvements from 3.7 Flash across software engineering, agentic tasks, and critical, multi-step reasoning in specialized domains".
The developer documentation is blunter. 3.8 Flash is "engineered for long-horizon software engineering, autonomous agents, and complex enterprise workflows". In the same list, 3.7 Flash is relabelled a "previous-generation Flash model".
Three results back it up. All are Google's own. None had been independently checked at the time of writing.
On DeepSWE v1.1, Google says the model "outperforms most larger frontier models in autonomously solving complex engineering problems end to end".
It scores 54.9% on HLE-Verified, which Google presents as evidence of multi-step reasoning "across STEM, humanities, and professional fields".
On Gray Swan, an adversarial testing suite, Google reports "a significant leap in prompt injection robustness".
Notice the shape of that list. Engineering, agents, robustness. Nothing about better answers to your questions.
"Long-horizon" translated
Strip the jargon and long-horizon describes one thing: how far a model gets through a task before it loses the plot.
A short task is a single answer. Summarise this page. Rewrite this email. A long-horizon task is forty steps, where step thirty depends on a constraint set at step four.
Autonomous agents are the consumer-facing version of that. You hand over a goal instead of a question. The model then plans its own steps, calls tools, reads what comes back and adjusts. Booking a trip. Working through an inbox.
Most attempts at this fail today, for a boring reason. The model drifts. It forgets an instruction from earlier, repeats a step it already did, or declares victory early. Reducing that drift is what 3.8 Flash is built for.
The security gain matters more than the benchmark
Prompt injection is the improvement here that a general reader should file away.
It works like this. A model reads a web page, a PDF or an email on your behalf. Buried in that text is a line addressed to the model rather than to you: ignore your instructions, do this instead. Sometimes the model obeys.
That is a curiosity while the model only talks. It stops being a curiosity the moment the model can act, which is the direction everything moved this year.
Hardening against injection is what makes the rest of the agent story shippable at all. A model that plans forty steps and can be hijacked at step three is worse than one that cannot plan.
About that second model, "Cyber"
Google announced two things in one post. The headline reads "Introducing Gemini 3.8 Flash and 3.8 Flash Cyber". The second model is absent from the public model list, and that absence is deliberate.
Google describes Cyber as "our most capable cybersecurity model with frontier-level performance in vulnerability detection and automated patching". Access runs through what the announcement calls a "new Fairwind Program". Google says the programme gives "trusted government authorities, as well as critical infrastructure operators and software maintainers" prioritised access.
So there is no consumer version. No app, no public API entry, no waitlist to join. If a headline about 3.8 Flash Cyber left you wondering what you were missing, the answer is a model for the people who patch national infrastructure.
So will you notice?
Honestly, on everyday questions, probably not.
Ask 3.7 Flash and 3.8 Flash for a recipe or a polite decline to an invitation. Expect two good answers that are hard to tell apart. Google is not claiming otherwise. Its own positioning is engineering and agents, start to finish.
The most telling detail is that Google did not retire the older model. 3.7 Flash "remains fully supported for efficiency-first workloads", per the same announcement. Companies retire models they consider beaten.
You will notice 3.8 Flash if your work looks like a chain. Long documents where a detail on page 60 changes the answer. Code spread across many files. That is a real group of people, though a minority of users.
Where you can reach it
Google says 3.8 Flash is available to Google AI Pro and Ultra subscribers across the Gemini app, AI Mode in Google Search, and Gemini in Google Sheets. For builders it lists AI Studio, Android Studio, the Gemini API, Google Antigravity, Stitch and Gemini Enterprise.
Google's announcement names no country restriction for the model, and neither does its model list. Two questions get merged constantly here. Is a Google feature available where you live? Is the model underneath that feature available? Those often have different answers.
One gap to flag. Google's model page carried no published context window for 3.8 Flash when we read it on 4 September 2026.
Where MultiChats stands today
Being precise about this, because it changes fast. As of 4 September 2026, the newest Gemini model in MultiChats is Gemini 3.7 Flash. Gemini 3.8 Flash is not in the picker yet.
We move quickly on Google releases and we expect to carry this one. Until the entry actually exists, we are not going to tell you it does. Check the model picker for the current answer. That is the only version that stays true.
What is there today: 60 models from 18 providers under one subscription. 21 of them are on the free plan, which runs on 50 messages every 24 hours. Pro is $20.99 a month, and the pricing section has the full ladder.
The short version
A new Flash model landed on 2 September. It holds together over longer chains of work and it is harder to hijack. Google published a locked-down cybersecurity sibling that you cannot use and probably should not want. For casual chat, 3.7 Flash was already good and remains so.
3.8 Flash is an agent release that happens to arrive in a chat box. Google described it that way itself. On this occasion the marketing is the accurate version.