Editorial illustration for Google launches cost-effective AI security model Gemini 3.5 Flash-Lite
Google's Gemini 3.5 Flash-Lite Cuts AI Security Costs
Google launches cost-effective AI security model Gemini 3.5 Flash-Lite
Google rolled out Gemini 3.5 Flash Cyber on Tuesday, a security-focused AI model built to hunt down and patch software vulnerabilities without the price tag of rival systems. The company pitched it directly against Anthropic's Mythos 5, the compute-heavy model powering Claude's security work under Project Glasswing, which costs twice as much to run as Claude Opus 4.8. Microsoft has already leaned on Mythos for its own patch cycles, and this month's Patch Tuesday turned out to be its largest yet after the company used AI to surface flaws at scale.
That scale is exactly what Google says its cheaper model can match. Built on Gemini 3.5 Flash and plugged into CodeMender, Google's security-focused coding agent, the new model is designed to run fast and often, letting automated agents comb through far more code paths than a slower, pricier system would allow. For now, access runs through CodeMender and stays limited to governments and select partners, not a public rollout.
The launch lands as competition over AI security tooling heats up beyond the usual US players. China's Z.ai has already claimed its own model can go toe to toe with Mythos, adding another front to a race that's increasingly about cost as much as raw capability.
Google is launching Gemini 3.6 Flash alongside a new security model dedicated to quickly finding and patching security vulnerabilities. In a blog post on Tuesday, Google describes Gemini 3.5 Flash Cyber as a “cost-efficient and highly capable alternative” to larger, more expensive AI systems, such as the one offered by Anthropic’s Mythos.
Why this matters
For teams weighing security tooling, price just became a real lever, not just a footnote. Google is explicitly positioning 3.5 Flash Cyber against Mythos on cost, not raw capability, which tells us where this market is headed: cheaper models that are good enough for high-volume, repetitive work like vulnerability scanning, while the expensive frontier models get reserved for harder problems. Folding Flash Cyber into CodeMender matters more than the pricing headline.
It signals Google wants security patching baked into developer workflows by default, not bolted on as a separate product. That's worth watching for founders building security tooling on top of foundation models, since the margin for a standalone product just got squeezed. We'd also flag the vagueness in "competitive performance" claims.
Google didn't publish hard benchmarks against Mythos in what we've seen so far, and that gap deserves scrutiny before anyone rearchitects a pipeline around it. Cheaper is good. Cheaper and unverified is a different conversation, and one we'll be pushing Google to answer with actual numbers.
Common Questions Answered
How does Google's Gemini 3.5 Flash-Lite compare in cost to Anthropic's Mythos 5 for security work?
Google's Gemini 3.5 Flash-Lite is positioned as a cost-effective alternative that runs at approximately half the price of Anthropic's Mythos 5, which powers Claude's security work under Project Glasswing. This significant cost difference makes Flash-Lite an attractive option for organizations looking to reduce expenses on AI-powered security tools without sacrificing essential vulnerability detection capabilities.
What is the primary purpose of Gemini 3.5 Flash Cyber according to Google's announcement?
Gemini 3.5 Flash Cyber is specifically designed to quickly find and patch software vulnerabilities in a cost-efficient manner. Google describes it as a highly capable alternative to larger, more expensive AI systems, making it ideal for high-volume, repetitive security work like vulnerability scanning.
Why does the market shift toward cheaper AI security models like Flash-Lite matter for enterprise teams?
The emergence of cost-efficient models like Gemini 3.5 Flash-Lite signals a market shift where price becomes a significant decision factor for security tooling, not just a minor consideration. This allows teams to deploy cheaper models for routine vulnerability scanning and repetitive security tasks, while reserving expensive frontier models for more complex security challenges.
How has Microsoft utilized Anthropic's Mythos model in its security operations?
Microsoft has already integrated Anthropic's Mythos model into its own patch cycles, with this month's Patch Tuesday representing the largest deployment yet. This demonstrates the model's effectiveness in identifying and addressing security vulnerabilities at scale.
Further Reading
- Introducing Gemini 3.6 Flash, 3.5 Flash-Lite, and 3.5 Flash Cyber - Google Blog
- Google Releases Three New AI Models - The New York Times
- Google Ships Three Gemini Flash Models as Its Flagship Slips - Unite.AI
- Google updates lightweight Gemini models, but flagship still delayed - Yahoo Finance
- Google launches three new Gemini models at once - Futu News