A cheaper, terser Flash
Google released Gemini 3.6 Flash on July 21, 2026, alongside a smaller sibling, 3.5 Flash-Lite. Google's own post cites Artificial Analysis figures showing 3.6 Flash uses about 17 percent fewer output tokens than 3.5 Flash on its Intelligence Index, and cites third-party firm Datacurve reporting reductions of up to 65 percent on some coding benchmarks such as DeepSWE. [1]
3.6 Flash is priced at $1.50 per million input tokens and $7.50 per million output tokens. On coding and agentic benchmarks Google reports gains over 3.5 Flash, including DeepSWE at 49 percent versus 37 percent and OSWorld-Verified at 83.0 percent versus 78.4 percent. It ships with computer-use support and is available through the Gemini API, Google AI Studio, Gemini Enterprise and the Gemini app. [1]
Atlas interpretation: The pitch is efficiency rather than a capability jump. Google's own benchmark gains are framed against its prior Flash model rather than rivals, and the token-reduction numbers describe cost to run a given task rather than a higher ceiling on what the model can do. That is consistent with a workhorse-tier refresh aimed at the token bill, not a new frontier claim. [1]
A vulnerability-hunting sibling kept off the open market
The third model in the announcement, 3.5 Flash Cyber, is a lightweight variant tuned to find, validate and patch software vulnerabilities. It runs inside CodeMender, Google DeepMind's automated vulnerability-repair agent, which calls the model multiple times per analysis to examine more execution paths than a single expensive call would allow. Google DeepMind reported that on the V8 JavaScript engine, 3.5 Flash Cyber found 55 unique confirmed issues, against 47 for mainline 3.5 Flash and 36 for Anthropic's Claude Opus 4.6. [2][3]
The Hacker News reported that in testing, 3.5 Flash Cyber produced exploits described as 100 percent reliable remote code execution against Chrome and Safari targets that bypassed Address Space Layout Randomization and Write XOR Execute protections. Access is restricted to a limited-access pilot program for governments and trusted partners through CodeMender, with Google citing dual-use risk as the reason and describing guardrails that keep the model's other capabilities disabled outside defensive use. [3][2]
Atlas interpretation: That restriction is the part of the announcement that departs from a routine model refresh. Google is not selling 3.5 Flash Cyber the way it sells the other two models in the same post; it is gating a model whose stated benchmark, producing working exploits against hardened browser targets, is also a capability an attacker would want. The Hacker News places the release alongside comparable vulnerability-discovery work from other AI labs, which suggests the gating is now a category-wide response to that dual-use problem rather than a one-off policy for this model. [3]
Sources
- Introducing Gemini 3.6 Flash, 3.5 Flash-Lite, and 3.5 Flash Cyber
Google · Jul 21, 2026
- Introducing Gemini 3.5 Flash Cyber
Google DeepMind · Jul 21, 2026
- Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Vulnerabilities
The Hacker News · Jul 21, 2026