Google has introduced the Fairwind Program, a limited access initiative that gives select governments, Google Cloud customers, and cybersecurity partners early access to its most capable AI-driven cyber defense tools. The program pairs Google’s specialized security model, Gemini 3.8 Flash Cyber, with its CodeMender harness to let defenders find, verify, and patch vulnerabilities autonomously rather than simply flagging them for human triage.
According to Google, the combination is designed to solve a tradeoff defenders have long faced: large frontier models that are costly and hard to control across enterprise codebases, versus smaller open-weight models that struggle with complex remediation and require teams to build their own tooling. Google says CodeMender with Gemini 3.8 Flash Cyber can generate verified, deployment-ready patches in minutes, inside an organization’s own secure cloud environment, at a fraction of the cost of running traditional frontier models for the same task.
Who gets access
Google says it is staging initial access to three categories of partners it considers most critical to societal resilience:
- Governments and national cyber authorities, to harden public-sector networks and citizen-facing services against targeted intrusions
- Critical infrastructure operators in healthcare, telecommunications, energy, and financial services, to reduce risk of operational disruption
- Core technology platforms, where a single fix can uplift security for large numbers of downstream users at once
Google states that more than 650 partners globally are already participating. Organizations that join agree to operational safeguards, including restricting tool access to internal cybersecurity, incident response, or penetration testing staff, and enforcing multi-factor authentication.
Broader availability and next steps
Access to Gemini 3.8 Flash Cyber itself is being prioritized for Fairwind participants, but Google notes that any Google Cloud customer can already use CodeMender with publicly available models on the Gemini Enterprise Agent Platform, combined with its AI Threat Defense offerings, to start automating vulnerability remediation today.
Google frames Fairwind as an extension of its existing zero-trust architecture and built-in account protections, and says the program will evolve based on partner feedback as it works with industry, governments, and the open-weight model community to balance broader access against the risk of these capabilities being misused.
For security teams, the practical takeaway is that autonomous, agentic patching is moving from research demos toward production use inside regulated and critical-infrastructure environments, a shift worth tracking closely as adoption expands beyond this initial partner group.
