On 21 July Google announced three new Flash models - the fast 3.6 Flash, the cheap 3.5 Flash-Lite, and the specialized 3.5 Flash Cyber for finding and patching holes in code. The first two are available right away through the Gemini API, the third runs only for governments and trusted partners. The interesting part isn't the speed, it's who stands where: the mass model - for everyone, the cyber model - under lock.
- On 21 July 2026 Google released Gemini 3.6 Flash, 3.5 Flash-Lite and 3.5 Flash Cyber.
- 3.6 Flash is the workhorse - per Google's data it spends 17% fewer output tokens than 3.5 Flash.
- 3.5 Flash Cyber (for cyber vulnerabilities) is given only to governments and trusted partners through the CodeMender tool.
Who's for whom. That's the question I was left with after Google released three models at once.
The numbers are theirs, measuring their own model - I take them with a grain of salt. But the move is clear and smart. The mass model gets cheaper and lighter, so it fits everywhere - in apps, in search, on the phone. The cyber model, the one that finds holes in code, they keep under lock.
Here's what I read into that split. The ability to find vulnerabilities is a double-edged sword - the same model that patches a hole can also open one. Google apparently decided that this gift doesn't get handed out at the general counter. Whether 'trusted partners' is a strong enough barrier, I don't know. But at least they admit there's something worth guarding.
We got used to every new model being 'faster, cheaper, for everyone'. Here, for the first time from a big company, we see a clear line - this I give out broadly, that I hold back. And that line - what you give and what you keep - is the news. More important than one more percentage point on some benchmark.