Google has launched its Fairwind Program, a limited-access initiative for governments and trusted partners. The program gives them access to Google’s most advanced cyber defense capabilities. As a first step, it provides defenders with powerful Gemini models. These models help autonomously find and fix security vulnerabilities at scale.
As per the company:
Today, we’re launching our Fairwind Program to bring the best of Google’s AI and cyber defense capabilities to a trusted group of Google Cloud customers, government agencies, and cybersecurity partners, to help them proactively solve cyber risks at scale. As a first step, the Fairwind Program will give defenders access to powerful and advanced Gemini models to help them autonomously find and fix vulnerabilities, protecting critical infrastructure, public services, and national security.
The launch addresses a longstanding dilemma for cyber defenders. Previously, they faced a difficult choice. They could adopt enormous frontier models that were expensive to deploy and hard to control. Alternatively, they could use smaller open-weight models. However, those often struggled with complex vulnerability remediation.
Fairwind combines two key Google technologies. It pairs the company’s most advanced cyber model, Gemini 3.8 Flash Cyber, with its CodeMender harness. Together, these help defenders find, verify, and fix vulnerabilities at agentic scale. Because merely spotting weaknesses only creates fear, Google emphasizes autonomous fixing instead.
The speed advantage appears substantial. CodeMender with Gemini 3.8 Flash Cyber writes and validates code fixes. It does so at a fraction of the cost of traditional frontier models. Instead of taking weeks to fix vulnerabilities manually, defenders can now generate patches in minutes. Crucially, these deployment-ready patches remain within an organization’s secure cloud environment.
Google is staging access carefully across critical sectors. Governments and national cyber authorities receive priority to harden public-sector networks. Critical infrastructure operators across healthcare, telecommunications, energy, and financial networks also gain access. Additionally, core technology platforms can secure widespread software foundations affecting millions of users.
To ensure responsible use, participating organizations must agree to strict standards. Access is limited to internal cybersecurity, incident response, or penetration testing teams. Google recommends that organizations must also deploy protections like multi-factor authentication. According to Google, the program already includes more than 650 participating partners globally.
The initiative reflects Google’s broader cybersecurity commitment. Through Google.org, its latest funding brings total cybersecurity investment above $100 million globally. This includes $36 million supporting 35 cyber clinics. These clinics have provided free security support to over 1,250 hospitals, school districts, and municipal utilities in the US. Ultimately, Google argues the defender’s edge comes from shrinking the time between detecting and patching a flaw, keeping partners ahead of agentic-speed threats.
