Google announced the launch of Fairwind, a limited-access program that enables governments, Google Cloud customers, and trusted cybersecurity partners to use advanced capabilities to find and fix software vulnerabilities at scale. The company says the first phase focuses on protecting critical infrastructure, public services, and national security.
The program combines the Gemini 3.8 Flash Cyber model, which Google describes as its most advanced cybersecurity model, with the CodeMender tool. According to the company, this combination can help defense teams discover and validate vulnerabilities, write software fixes, and verify their validity, rather than merely flagging the existence of a flaw.
What changes in practice?
Google says CodeMender with Gemini 3.8 Flash Cyber can produce documented, deployment-ready patches within minutes inside an organization’s secure cloud environment, in cases that previously required weeks to complete manually. It also says that running the specialized model is intended to provide advanced security reasoning capabilities at a lower operating cost than leading general-purpose AI models, while keeping the remediation process within the organization’s environment.
This does not mean that the program is open to all users. Google has begun providing access to groups it considers essential to the resilience of the digital society, including:
- Governments and national cybersecurity authorities, to strengthen public-sector networks and citizen services.
- Critical infrastructure operators in the healthcare, telecommunications, energy, and financial sectors.
- Core technology platforms that provide widely used software and whose security can raise the level of protection for a large number of their users.
Access restrictions and operational responsibility
Google requires participating organizations to follow strict operational standards, including limiting use of the capabilities to employees of the organization’s cybersecurity, incident response, or penetration-testing teams, along with implementing safeguards such as multifactor authentication. The company says the program includes more than 650 participating partners worldwide, without naming those partners in the text.
Fairwind represents a different approach from traditional vulnerability-discovery tools: the value Google highlights lies not only in finding the flaw, but in reducing the time between its discovery, remediation, and validation of the fix. This is important for organizations that manage large-scale systems or services that cannot wait through lengthy review and patching cycles, but it does not eliminate the need for review by specialized teams before changes are introduced into production environments.
Options available outside the program
Google explains that other Google Cloud customers can use CodeMender with publicly available models hosted on the Gemini Enterprise Agent Platform, alongside the company’s solutions within AI Threat Defense. Priority access to Gemini 3.8 Flash Cyber, however, remains, according to the announcement, with Fairwind program customers.
Google links the initiative to a broader commitment to cyber resilience, saying that its global cybersecurity funding through Google.org has exceeded $100 million. It also released its 2026 report on the impact of cybersecurity in the United States, citing $36 million in funding for 35 cyber clinics that provided free, practical support to more than 1,250 hospitals, public school districts, and municipal facilities. The effectiveness of automated fixes and the program’s actual expansion scope remain points requiring independent evaluation as broader usage results become available.