Google announced the Fairwind Program, an initiative that offers advanced artificial intelligence capabilities to selected governments, companies, and cybersecurity partners. The goal is to detect and fix software vulnerabilities more quickly, before attackers can take advantage of them.
The proposal combines Gemini models with specialized tools to automate part of the work that can normally take weeks. The idea? Move from simply discovering flaws to fixing them and verifying that the solution is ready to deploy.
AI to find and fix vulnerabilities
The program integrates Gemini 3.8 Flash Cyber, Google’s cybersecurity-focused model, with CodeMender, a tool designed to analyze code, identify weaknesses, and propose fixes.
According to Google, this combination can generate verified, deployment-ready patches within minutes, inside an organization’s secure environment. This represents an important shift for teams that typically review large amounts of code manually.
Detecting a vulnerability is only the first step. The real defensive advantage appears when an organization can fix it before someone exploits it.
The company also highlights that Gemini 3.8 Flash Cyber aims to provide specialized reasoning at a lower operating cost than other frontier models. In simple terms, it seeks to deliver advanced capabilities without requiring the same level of infrastructure or budget.
What CodeMender brings to the table
CodeMender works as a layer that allows the model to participate in the complete remediation process. This includes:
- Analyzing code for vulnerabilities.
- Proposing changes to fix them.
- Validating that the patches resolve the problem.
- Preparing fixes for deployment in the organization’s environment.
Automation does not eliminate the need for specialists. Rather, it can help them focus on the highest-risk cases, review changes generated by AI, and make the final decisions.
A program focused on critical systems
Google is initially giving access to organizations whose security has a broad impact on society. These include:
- Governments and national cybersecurity authorities.
- Critical infrastructure operators in sectors such as healthcare, energy, telecommunications, and finance.
- Technology platforms that support services used by millions of people.
For a public institution, a vulnerability can affect citizen services. In a hospital, it could interrupt essential systems. In a telecommunications or energy company, an intrusion can create consequences that go far beyond a locked screen.
That is why reducing the time between discovering a flaw and fixing it has become a priority. Attackers also use automation and AI tools to move faster. Defense, then, needs to respond with comparable capabilities.
More than 650 organizations are participating
Google says the Fairwind Program already has more than 650 partners worldwide. Access is aimed at a trusted group of Google Cloud customers, government agencies, and specialized security partners.
Participation includes operational requirements. Access to these capabilities must be limited to employees on internal cybersecurity, incident response, or penetration testing teams. Organizations must also use protective measures such as multifactor authentication.
These conditions are intended to reduce the risk of misuse. A tool capable of finding and fixing vulnerabilities also requires strict controls, activity logs, and human oversight. Speed alone does not guarantee secure defense.
Broader access to other Google tools
Although Google is prioritizing access to Gemini 3.8 Flash Cyber for program participants, the company says that any Google Cloud customer can work on code security through CodeMender and publicly available models in the Gemini Enterprise Agent Platform.
It also mentions AI Threat Defense, a set of solutions designed to complement these capabilities. The strategy aims to create an ecosystem in which companies of different sizes can adopt AI tools without having to build all the necessary infrastructure from scratch.
Google expands its cybersecurity investment
Fairwind is part of Google’s broader strategy to strengthen digital security. The company says its zero-trust architecture systems and AI-based defenses protect billions of accounts every day.
Through Google.org, Google also says its global cybersecurity funding has surpassed $100 million. In the United States, its program has allocated $36 million to 35 cybersecurity clinics, which have provided practical support to more than 1,250 hospitals, public school districts, and municipal services.
The move reflects a reality that no longer belongs only to large technology companies: cybersecurity affects any organization that stores data, operates services, or depends on software. AI can help close that gap, as long as it is used with controls, verification, and clear goals.
Fairwind’s promise is concrete: find flaws earlier, fix them faster, and help governments and companies maintain an advantage over threats that are also advancing at automated speed. The challenge will be proving that this autonomy can scale without sacrificing oversight or trust.
Original source
https://blog.google/innovation-and-ai/technology/safety-security/fairwind-program
