SAN FRANCISCO: Google on July 21 released three new artificial intelligence (AI) models, including Gemini 3.6 Flash, its most powerful, and Gemini 3.5 Flash Cyber, which is fine-tuned for cybersecurity.
Google is aiming to compete with rivals such as Anthropic and OpenAI on cutting-edge models and on cybersecurity, an area in which the two startups have forged ahead this year with powerful systems that can identify security vulnerabilities in software.
Gemini Flash 3.6 improves on the capabilities of Google’s previous version of Flash, which performed strongly on benchmarks like coding and finance tasks, according to AI leaderboards. The new model is also cheaper for users.
Gemini 3.5 Flash Cyber can find and patch security vulnerabilities at a lower cost than other larger models, the company said. The third model, Gemini 3.5 Flash-Lite, is designed for tasks like managing AI “agents,” which are bots that can act autonomously to function like digital personal assistants.
The new Flash models were built “to meet the sweet spot of efficiency and quality,” Tulsee Doshi, a senior director of product management on Google’s Gemini team, said in a statement.
Google has also been working on a flagship AI model called Gemini 3.5 Pro, which is expected to be its highest performing system. The Silicon Valley company had said in May that Pro would be rolled out in June, but it remains unavailable. Google said Pro was still in testing and would be made “broadly available as soon as it’s ready.”
Since OpenAI’s ChatGPT chatbot kicked off the AI boom in 2022, Google has poured money and effort into leading the race. Its Gemini AI models soon ranked among the top AI tools.
But in recent months, Google has been upstaged by advanced new models from Anthropic and OpenAI, as well as new models from Chinese startups such as Moonshot AI. This month, Meta, the owner of Facebook and Instagram, also released a model that crept ahead of Gemini’s capabilities, according to several leaderboards.
Cybersecurity has increasingly been a focus for AI models. The systems can find flaws in software and fix them more rapidly than humans, but they can also be used to exploit vulnerabilities and carry out cyberattacks.
In April, Anthropic released a cybersecurity-focused model called Mythos, which it said could create a cybersecurity “reckoning.” To prevent the powerful model from falling into the wrong hands, the company made it only available to a small group of organisations so they could defend against cyberattacks. Anthropic later released Fable, a model with similar capabilities and guardrails meant to prevent it from being used for hacking.
OpenAI soon introduced its own cybersecurity model and made it available to only a limited group of organisations to prepare their defences, before rolling it out more broadly. (The New York Times has sued OpenAI and Microsoft, claiming copyright infringement of news content related to AI systems. The two companies have denied those claims.)
Google said it was taking a similar approach with Gemini 3.5 Flash Cyber. In testing, the model found 55 problems in a complex piece of open-source code known as V8 JavaScript Engine, including 10 vulnerabilities that no other model had uncovered before, the company said.
“The model will be exclusively available to governments and trusted partners,” Doshi said. “This will give front-line defenders a head start in finding and fixing critical vulnerabilities before they can be exploited, while mitigating against broader misuse.”
Google said the new Flash models would be available for a lower cost than its previous offerings. The systems use 17% fewer tokens, which are the units of measurement for AI use, than earlier models. That means developers will spend less money to complete the same tasks. – ©2026 The New York Times Company
This article originally appeared in The New York Times.
