# Fairwind Program

> Source: https://aiwiki.ai/wiki/fairwind_program
> Updated: 2026-10-01
> Fact-checked: 2026-10-01
> Categories: AI Safety, AI in Cybersecurity, Google, Google DeepMind
> License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/) - attribute to "AI Wiki (aiwiki.ai)"
> Cite as: AI Wiki. "Fairwind Program." aiwiki.ai, 1 Oct 2026. https://aiwiki.ai/wiki/fairwind_program
> From AI Wiki (https://aiwiki.ai), the free encyclopedia of artificial intelligence. Reuse freely with attribution.

The **Fairwind Program** is a limited-access cybersecurity program run by [Google](https://aiwiki.ai/wiki/google) and [Google DeepMind](https://aiwiki.ai/wiki/google_deepmind) that gives vetted defenders, such as government cyber authorities, critical-infrastructure operators and major technology platforms, early access to Google's most cyber-capable [Gemini](https://aiwiki.ai/wiki/gemini) models. Google launched it on September 2, 2026, with [Gemini 3.8 Flash Cyber](https://aiwiki.ai/wiki/gemini_3_8_flash_cyber) paired with its CodeMender code-security agent, and said it had more than 650 participating partners worldwide at launch.[1][3] On September 30, 2026, Google began the rollout of its frontier model [Gemini 4 Argon](https://aiwiki.ai/wiki/gemini_4_argon) through the program, releasing it "without cyber guardrails" to trusted defenders before any wider availability.[4]

Google presents Fairwind as a way to give defenders "a critical head start against cyber threats" while keeping dual-use models away from attackers. Members must accept usage terms that limit who inside an organization can use the models and which tasks are allowed, and applicants go through due-diligence checks.[2] Outside coverage has compared the program to [Anthropic](https://aiwiki.ai/wiki/anthropic)'s [Project Glasswing](https://aiwiki.ai/wiki/project_glasswing).[14]

## Overview

| Item | Details (as of October 1, 2026) |
| --- | --- |
| Operator | Google (program page hosted by Google DeepMind)[1][2] |
| Launched | September 2, 2026[1] |
| Launch announcement | "Proactive cyber defense for governments and enterprises," by Four Flynn, Google's Vice President, Security and Privacy[1] |
| Tagline | "Keeping defenders one step ahead"[2] |
| Partners | More than 650 worldwide, per Google[1][2] |
| Priority applicants | Governments and national cyber authorities; critical infrastructure operators; core technology platforms[1][2] |
| Models offered | Gemini 3.8 Flash Cyber (from September 2, 2026); Gemini 4 Argon for "a set of" partners (from September 30, 2026)[2][3][4] |
| Associated tooling | CodeMender code-security agent[1][2] |
| Permitted use | Defensive and academic research dual-use tasks only[2] |
| Application | Online interest form; Google reviews applications on a rolling basis[2] |

## Background

Fairwind followed a smaller pilot that Google announced in July 2026. On July 21, 2026, Google announced Gemini 3.5 Flash Cyber, a version of [Gemini 3.5 Flash](https://aiwiki.ai/wiki/gemini_3_5_flash) fine-tuned for finding and fixing vulnerabilities, and said that "given the dual-use nature of this technology" the model would be "exclusively available to governments and trusted partners via CodeMender soon as part of a limited-access pilot program."[5]

CodeMender itself entered preview for Google Cloud customers on July 22, 2026. Google Cloud describes it as a managed code-security agent that scans code for vulnerabilities, checks whether they can be exploited, and proposes tested fixes, and says it can run on Google's generally available models through Gemini Enterprise Agent Platform.[6]

## Launch

Google announced Fairwind on September 2, 2026, in a post on its company blog by Four Flynn and in the same-day launch of [Gemini 3.8 Flash](https://aiwiki.ai/wiki/gemini_3_8_flash) and Gemini 3.8 Flash Cyber, written by Tulsee Doshi and Raluca Ada Popa.[1][3] Flynn framed the program as an answer to a choice defenders had faced between "enormous frontier models that could be expensive to deploy and difficult to control" and "smaller open-weight models that might struggle with complex vulnerability remediation."[1]

Flynn described Fairwind as "a limited access program for governments and trusted partners to use our most advanced cyber defense capabilities," aimed at "a trusted group of Google Cloud customers, government agencies, and cybersecurity partners."[1] The first offering combined Gemini 3.8 Flash Cyber, which Google called its most advanced cyber model at the time, with the CodeMender harness "to help defenders find, verify, and fix vulnerabilities at agentic scale."[1] Google said the pairing could produce "verified, deployment-ready patches in minutes" inside an organization's own cloud environment, instead of the weeks manual fixes could take.[1]

The Gemini 3.8 launch post explained why the Cyber variant was restricted: standard 3.8 Flash "ships with safeguards against misuse" in chemical, biological, radiological and nuclear (CBRN) domains and cyber offense, while 3.8 Flash Cyber "ships with a more permissive set of mitigations for cybersecurity, and as such, is only available to trusted defenders who require a more comprehensive set of cyber capabilities."[3] The post said Fairwind would provide "trusted government authorities, as well as critical infrastructure operators and software maintainers with prioritized access."[3]

Google released its 2026 Google.org US Cybersecurity Impact Report alongside the launch. Flynn wrote that Google.org's cybersecurity funding had passed $100 million globally, including $36 million for 35 cyber clinics that had given free security support to more than 1,250 U.S. hospitals, public school districts and municipal utilities.[1]

## Eligibility and application

The launch post says Google is "staging initial access to government and enterprise partners most critical to society's resilience"; the program page says it prioritizes access for governments and partners "most critical to societal resilience." Both name three priority groups:[1][2]

| Priority group | Purpose stated by Google |
| --- | --- |
| Governments and national cyber authorities | Defending public-sector networks and citizen services against targeted intrusions |
| Critical infrastructure operators | Protecting essential services, including healthcare, telecommunications, energy and financial networks, from operational disruption |
| Core technology platforms | Securing widely used software foundations for millions of downstream users |

The program page also says Google welcomes applications from "academic labs that focus on defensive benchmarking," and recommends that students use CodeMender on Google Cloud instead.[2] Google says it vets all applicants for "a proven track record of ethical operations and research," runs background checks on applying organizations covering their security history and ethical record, and reviews applications and adds partners over time. It gives no fixed processing time, saying only that it "will review and respond to eligible partners who meet our criteria as soon as we can."[2]

Organizations that do not qualify are pointed to CodeMender running on publicly available models and to Google's other AI Threat Defense products.[1][2]

## Governance and usage terms

The program page lists four sets of controls:[2]

| Control | What Google says |
| --- | --- |
| Restricted dual-use tasks | Partners may carry out only dual-use tasks "for defensive and academic research purposes," such as authorized threat simulation, reverse engineering and malware analysis. Malicious tasks such as creating malware are not permitted. |
| Best-practice security | Participants agree to user-level authentication, phishing-resistant multi-factor authentication and applicable access controls. Access to Gemini 4 Argon may be granted only to internal cybersecurity, incident response or penetration testing teams, and organizations must track employee access and use. |
| Managed access | Partners may not share, redistribute or sell access to Google's frontier models. |
| Due diligence | Google runs background checks on applying organizations. |

The September 2 launch post described the same employee limit for the Flash Cyber phase: participants agree to restrict access to "employees within their internal cybersecurity, incident response, or penetration testing teams" and to deploy protections such as multi-factor authentication.[1] The program page says that when Gemini 4 Argon is accessed directly as a managed model on Gemini Enterprise, it supports zero data retention.[2]

## Models and tools

| Offering | Added | Description from Google |
| --- | --- | --- |
| [Gemini 3.8 Flash Cyber](https://aiwiki.ai/wiki/gemini_3_8_flash_cyber) | September 2, 2026 | Cyber-specialized variant of Gemini 3.8 Flash with "frontier-level performance in vulnerability detection and automated patching," available only through Fairwind[3] |
| [Gemini 4 Argon](https://aiwiki.ai/wiki/gemini_4_argon) | September 30, 2026 | Google's new frontier model, given to trusted defenders and internal Google teams "without cyber guardrails"; the program page says "a set of Fairwind Program partners get exclusive access" to it[2][4] |
| CodeMender | Paired with Fairwind models from launch | Code-security agent that partners can use with Fairwind models; the program page says it spares defenders from building "their own harnesses"[1][2] |

According to the program page, Gemini 4 Argon can be used "as a standalone model or together with CodeMender."[2] As of October 1, 2026, the program page presents Gemini 4 Argon as the program's model and mentions Gemini 3.8 Flash Cyber only in benchmark comparisons, although the September 2 posts had named Flash Cyber as the launch model.[1][2][3]

## Gemini 4 Argon rollout

Google announced Gemini 4 Argon on September 30, 2026, in a post by [Koray Kavukcuoglu](https://aiwiki.ai/wiki/koray_kavukcuoglu). The post said the model "is rolling out to a set of trusted cyber defenders through our Fairwind Program."[4] Kavukcuoglu wrote that "safely releasing frontier capabilities at this level requires a phased approach" and that Google was "actively engaged in the U.S. government's voluntary process for pre-release model access while we gradually expand access."[4] For "trusted defenders and our own internal teams at Google," the post said, Google would release Argon "without cyber guardrails so they can leverage its full frontier-level cybersecurity defense capabilities."[4]

Google named one partner deployment. Wiz was using Argon through its Scan for Good initiative, which Google describes as "a program dedicated to protecting critical public infrastructure for free by finding and remediating high-risk exposures." Google said the model found a critical vulnerability exposing sensitive personal information in healthcare software used by hospitals worldwide, one that "previous frontier models had missed."[4]

Google's launch-day posts described the first cohort in slightly different terms. [Demis Hassabis](https://aiwiki.ai/wiki/demis_hassabis) wrote that Google was "rolling it out responsibly starting with government and trusted cyber defenders through our Fairwind Program today, before wider availability soon."[7] The Google DeepMind account said Argon was "rolling out today to a set of trusted testers through our Fairwind Program,"[8] and Google's main account said it was going to "an initial cohort of cyber defenders" while Google iterates on guardrails.[9] According to the Argon post, broader release would follow, "starting with paid API customers and Google AI Ultra subscribers."[4]

## Reported performance

The first two rows are Google's own internal benchmarks, published on the program page and in launch posts, and have not been independently replicated. The CWE-bench figures come from Collinear AI's public leaderboard, which Collinear says Artificial Analysis independently evaluated and published.

| Evaluation | Gemini 4 Argon | Gemini 3.8 Flash Cyber | Notes |
| --- | ---: | ---: | --- |
| Real-world vulnerability discovery (Google internal, 20 languages, pass@1) | 85.8% | 71.0% | Google internal benchmark[2][4] |
| Wiz penetration test benchmark (pass@1) | 70.9% | 58.2% | Wiz internal black-box benchmark[2][4] |
| CWE-bench v1 (pass@1) | 68% | n/a | Argon tied with Grok 4.7 and GPT-6 Astra; Claude Opus 5.5 at 67%[2] |
| CWE-bench v0, run by Collinear (pass@1) | n/a | 47.2% | Google compared it with 47.8% for an unnamed "leading frontier model"; Collinear's v0 leaderboard lists that score for Claude Fable 5[3][18] |

The Argon post says Argon "ties for first place" on CWE-bench v1 at 68%, building on 3.8 Flash Cyber's results on CWE-bench v0.[4] The program page also shows a chart from Gray Swan's indirect [prompt injection](https://aiwiki.ai/wiki/prompt_injection) benchmark in which Argon had the lowest attack success rate shown, 0.7% at 15 attempts.[2]

## Named partners

Google's launch post and program page show the logos of eleven organizations among the more than 650 partners: Accenture, Armadin, the Center for Internet Security, CrowdStrike, Datadog, McKinsey & Company, Menlo Security, Palo Alto Networks, Robinhood, Snowflake and Wiz.[1][2] The launch post also carried testimonials from five of them about Gemini 3.8 Flash Cyber:[1]

| Organization | Speaker | Summary of comments |
| --- | --- | --- |
| Armadin | David Slater, founder and chief architect | Said the model "matched larger frontier models at a lower price and with best-in-class latency" in Armadin's evaluations |
| CrowdStrike | Daniel Bernard, chief business officer | Said Fairwind "brings the industry together to accelerate vulnerability discovery and remediation" |
| Palo Alto Networks | Charlie Sestito, director, Office of the CTO | Said early testing found the model "exceptionally fast" and above its model class on several cybersecurity tasks, including vulnerability hunting |
| Snowflake | Mayank Upadhyay, CSTO | Described a two-day trial on Snowflake's public repositories in which the model "held its own against much larger engines" at a cost low enough to run continuously |
| Wiz | Gal Nagli, head of threat exposure | Said the model performed better than larger frontier models in Wiz's web exploitation, penetration testing and bug bounty evaluations |

## Comparison with other trusted-access programs

Fairwind is one of several programs that frontier AI developers set up in 2026 to give cyber-capable models to vetted defenders before or instead of releasing them to the public.

| Program | Developer | Started | Who gets access | What it provides |
| --- | --- | --- | --- | --- |
| Fairwind Program | Google | September 2, 2026[1] | Vetted organizations, prioritizing governments, critical infrastructure and core technology platforms; more than 650 partners[1][2] | Gemini 3.8 Flash Cyber and, for some partners, Gemini 4 Argon without cyber guardrails, usable with CodeMender[2][4] |
| [Project Glasswing](https://aiwiki.ai/wiki/project_glasswing) | Anthropic | April 7, 2026[10] | Twelve launch partners plus more than 40 organizations that build or maintain critical software at launch[10] | Use of [Claude Mythos Preview](https://aiwiki.ai/wiki/claude_mythos) for defensive security work, with up to $100 million in usage credits; Anthropic has since widened the program and moved members to later Mythos models[10] |
| [Cyber Verification Program](https://aiwiki.ai/wiki/anthropic_cyber_verification_program) | Anthropic | April 16, 2026, with Claude Opus 4.7[17] | Security professionals and organizations that apply[11][17] | A "free application-based program for Opus and Sonnet" that lifts default blocks on high-risk dual-use cyber activity; prohibited uses stay blocked[11] |
| Trusted Access for Cyber | [OpenAI](https://aiwiki.ai/wiki/openai) | February 5, 2026 (pilot)[12] | Individuals who verify their identity, enterprises through OpenAI, and an invite-only tier for more permissive models[12] | An "identity and trust-based framework" for high-risk cyber work, introduced with GPT-5.3-Codex, plus $10 million in API credits[12] |

The programs differ in scope. Glasswing began as a fixed coalition around a single unreleased model.[10] OpenAI's and Anthropic's verification schemes adjust safeguards on models that are otherwise available to the public, and OpenAI's also verifies individual users.[11][12] Fairwind combines restricted models with organization-level vetting and limits on which internal teams may use them.[2] Some organizations appear in more than one: CrowdStrike and Palo Alto Networks were Glasswing launch partners and are also named Fairwind partners, and Google itself was a Glasswing launch partner.[2][10]

## Reception

Coverage at launch mostly restated Google's announcement. Cybersecurity Insiders presented Fairwind as an effort to help government agencies and partners find and fix vulnerabilities proactively, and noted the U.S. Cybersecurity Impact Report released with it.[13] Writing for Barchart, Ruchi Gupta called it "a Project Glasswing-style initiative" and set the launch against investor worries that Google was behind Anthropic and OpenAI in the frontier model race.[14] GIGAZINE reported the program's partner count and its operating standards, such as limiting use to internal security staff and requiring multi-factor authentication.[15]

When Argon launched, The Next Web led with the fact that "cyber defenders get it first," and reported Google's participation in the U.S. government's voluntary pre-release access process. It also cited Bloomberg's report that some Google employees doubted how well the model handled real work, which Google disputed.[16]

## References

1. Four Flynn. "Proactive cyber defense for governments and enterprises." Google (The Keyword), September 2, 2026. https://blog.google/innovation-and-ai/technology/safety-security/fairwind-program/
2. Google DeepMind. "Fairwind Program." Accessed October 1, 2026. https://deepmind.google/fairwind-program/
3. Tulsee Doshi and Raluca Ada Popa. "Introducing Gemini 3.8 Flash and 3.8 Flash Cyber." Google (The Keyword), September 2, 2026. https://blog.google/innovation-and-ai/models-and-research/gemini-models/3-8-flash-and-3-8-flash-cyber/
4. Koray Kavukcuoglu. "Gemini 4 Argon: our next era of frontier intelligence." Google (The Keyword), September 30, 2026. https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-4-argon/
5. Tulsee Doshi. "Introducing Gemini 3.6 Flash, 3.5 Flash-Lite, and 3.5 Flash Cyber." Google (The Keyword), July 21, 2026. https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-6-flash-3-5-flash-lite-3-5-flash-cyber/
6. Michael Gerstenhaber and Clemens Viernickel. "Now in preview: Find and fix software vulnerabilities with CodeMender." Google Cloud Blog, July 22, 2026. https://cloud.google.com/blog/products/identity-security/find-and-fix-software-vulnerabilities-with-codemender
7. Demis Hassabis (@demishassabis). Post on X, September 30, 2026. https://x.com/demishassabis/status/2105417239432200636
8. Google DeepMind (@GoogleDeepMind). Post on X, September 30, 2026. https://x.com/GoogleDeepMind/status/2105388084154056939
9. Google (@Google). Post on X, September 30, 2026. https://x.com/Google/status/2105388148729553195
10. Anthropic. "Project Glasswing: Securing critical software for the AI era." April 7, 2026. https://www.anthropic.com/glasswing
11. Anthropic. "Real-time cyber safeguards on Claude Opus and Sonnet." Claude Help Center. Accessed October 1, 2026. https://support.claude.com/en/articles/14604842-real-time-cyber-safeguards-on-claude-opus-and-sonnet
12. OpenAI. "Introducing Trusted Access for Cyber." February 5, 2026. https://openai.com/index/trusted-access-for-cyber/
13. Naveen Goud. "Google launches Fairwind Cybersecurity Program to strengthen Government and Partner defenses." Cybersecurity Insiders, September 3, 2026. https://www.cybersecurity-insiders.com/google-launches-fairwind-cybersecurity-program-to-strengthen-government-and-partner-defenses/
14. Ruchi Gupta. "Google Unveils Gemini 3.8 Flash and Fairwind Program: How to Play GOOGL Stock Here." Barchart via Yahoo Finance, September 6, 2026. https://finance.yahoo.com/technology/ai/articles/google-unveils-gemini-3-8-140002406.html
15. "Google releases 'Gemini 3.8 Flash,' with prices to double from 2027." GIGAZINE, September 3, 2026. https://gigazine.net/gsc_news/en/20260903-gemini-3-8-flash-cyber/
16. Ana Maria Constantin. "Google unveils Gemini 4 Argon, and cyber defenders get it first." The Next Web, September 30, 2026. https://thenextweb.com/news/google-gemini-4-argon-cyber-defenders-fairwind
17. Anthropic. "Introducing Claude Opus 4.7." April 16, 2026. https://www.anthropic.com/news/claude-opus-4-7
18. Collinear AI. "CWE-bench: a cybersecurity benchmark by Collinear AI." Accessed October 1, 2026. https://cwe-bench.com/

