Skip to content

Google releases Gemini 3.6 Flash and 3.5 Flash-Lite, unveils restricted Flash Cyber security model

· by Pondero Newsdesk

The short version

Google and Google DeepMind launched three Gemini models on July 21, 2026. Gemini 3.6 Flash cuts output-token usage by 17 percent and prices output at $7.50 per million tokens, while a government-only Flash Cyber variant outperformed Claude Opus 4.6 in V8 vulnerability testing.

Google releases Gemini 3.6 Flash and 3.5 Flash-Lite, unveils restricted Flash Cyber security model

A government-only Gemini security model found 55 confirmed V8 vulnerabilities against 36 for Claude Opus 4.6 in testing, while Gemini 3.5 Pro missed its launch deadline for the third consecutive month. Google and Google DeepMind released three models on July 21, 2026: a restricted Flash Cyber variant available only to governments and trusted partners, Gemini 3.6 Flash priced at $7.50 per million output tokens, and a cheaper Flash-Lite tier at $2.50.

What

Gemini 3.5 Flash Cyber is not available to the public. Fine-tuned for vulnerability discovery and built into Google's CodeMender agent, it is accessible only to governments and trusted partners through a limited-access pilot. Per Google DeepMind's blog, the model found 55 confirmed vulnerabilities in testing on Google's V8 JavaScript engine, compared with 47 for standard 3.5 Flash and 36 for Anthropic's Claude Opus 4.6. Ten of the 55 vulnerabilities were not found by either competing model.

Gemini 3.6 Flash replaces 3.5 Flash as the standard workhorse for developers on the Gemini API. Per Google's blog announcement, the new model produces 17 percent fewer output tokens on equivalent tasks and is priced at $1.50 per million input tokens and $7.50 per million output tokens. It is available through Google AI Studio, the Gemini API, and enterprise Gemini tiers.

Gemini 3.5 Flash-Lite targets cost-sensitive, high-throughput workloads at $0.30 per million input tokens and $2.50 per million output tokens, and Google describes it as the fastest model in the 3.5 series at 350 output tokens per second.

Why it matters

If you are on 3.5 Flash today, 3.6 is a drop-in swap: output price drops to $7.50 per million tokens and the model generates fewer tokens per task. Seventeen percent fewer output tokens at constant volume means lower API bills on output-heavy jobs such as agentic loops and long-form document generation. Flash-Lite's $2.50 output price gives high-volume classification or extraction pipelines a cheaper tier below 3.6 Flash.

The Flash Cyber benchmark is harder to evaluate without DeepMind's full testing methodology, but 55 confirmed V8 vulnerabilities against 36 for Claude Opus 4.6 is a specific, named comparison from a primary source. Security operations teams at government agencies and qualified enterprises will likely treat that figure as a reason to request pilot access. For everyone else, commercial availability is not on the schedule yet.

The absent announcement is also notable. Gemini 3.5 Pro, which Google originally targeted for June 2026, remains unreleased per TechCrunch. Three delays have kept the high-end reasoning slot open for Claude Sonnet 5 and competing frontier models. Google has not provided a new target date.

What to watch next

Watch for Google to open Flash Cyber enrollment criteria and disclose what "trusted partner" status requires. At the Pro tier, each month of further delay cedes the high-end API market to Anthropic and OpenAI.

Sources