On 21 July 2026, Google announced Gemini 3.6 Flash, 3.5 Flash-Lite and 3.5 Flash Cyber. Google split the Flash line into a stronger workhorse, a very fast low-cost tier and a cyber-specialised trusted-access model.
This release brief was checked against first-party material on 10 August 2026. The date above is the public announcement date, not the date a repository was created or a third-party provider added the model. Where access or weights arrived later, that distinction is recorded below.
Release record
| Field | Verified detail |
|---|---|
| Announcement | 21 July 2026 |
| Availability or weight release | 3.6 Flash and Flash-Lite on 21 July; Cyber through qualified access |
| Release type | three-model hosted agent and cybersecurity family rollout |
| Access | Google products, Gemini API and Vertex channels; Cyber access restricted; no open weights |
| Architecture | undisclosed Flash-family multimodal models optimised for efficiency and specialised cyber work |
| Maximum stated context | model-specific Gemini limits documented by Google |
What changed
The family gives production teams three different optimisation targets. Gemini 3.6 Flash improves coding, ML research and computer use while using fewer output tokens. Flash-Lite is reported at more than 350 tokens per second. Flash Cyber reserves higher-risk capability for defenders. A router can exploit those differences, but it also creates evaluation and audit obligations when tasks move among tiers.
The practical comparison is therefore not simply whether Gemini 3.6 Flash, 3.5 Flash-Lite and 3.5 Flash Cyber has the largest headline score. Teams need to ask whether its architecture, access terms, latency, tool behaviour and evaluation setup match the workload they actually intend to run. A model can lead one harness while losing on cost, refusal behaviour, multilingual quality or repeatability in another.
Benchmarks worth retaining
| Evaluation | Reported result | How to read it |
|---|---|---|
| DeepSWE | 49% versus 37% for 3.5 Flash | Coding improvement reported by Google |
| MLE Bench | 63.9% versus 49.7% | ML research task comparison |
| OSWorld | 83 versus 78.4 | Computer-use result in the launch table |
These are release-time results, not independently reproduced guarantees. Google compares 3.6 against 3.5 with reported token reductions and model-specific harnesses; Flash Cyber has different access and safety conditions from the general models. Scores should remain attached to the disclosed effort setting, agent harness, tool access, timeout, context-management policy and judge model. Moving a number into a procurement sheet without those conditions creates false comparability.
Architecture and access
Gemini 3.6 Flash, 3.5 Flash-Lite and 3.5 Flash Cyber is described as undisclosed Flash-family multimodal models optimised for efficiency and specialised cyber work with model-specific Gemini limits documented by Google of stated context. Its access position at verification time is Google products, Gemini API and Vertex channels; Cyber access restricted; no open weights. That wording matters: open weights, source-available weights, an API, a product preview and a research demonstration give adopters very different rights and different levels of reproducibility.
Before deployment, record the exact model identifier or checkpoint, inference stack, quantisation, reasoning setting, region, price schedule and supplier terms. If the release uses a custom licence, read the licence itself rather than relying on the word “open” in launch copy. If it is API-only, preserve the dated documentation and change-notice route because the served snapshot can change without a downloadable artefact.
What an evaluation should test next
For Gemini 3.6 Flash, 3.5 Flash-Lite and 3.5 Flash Cyber, a credible internal gate should include:
- a frozen set of representative tasks with pass, fail and abstain criteria;
- a matched baseline using the same tools, timeout, prompt budget and reviewer rubric;
- repeated runs to expose variance rather than reporting a single best attempt;
- latency, token use and total task cost alongside task success;
- adversarial, multilingual and long-context cases relevant to the real deployment; and
- rollback evidence showing the previous model can be restored safely.
The wider model change-control guide explains how to keep model, prompt, tool and corpus changes reconstructable. The AI dependency inventory guide covers the release and supplier records needed after deployment.
AIEngine verdict
This is a major efficiency-oriented family release. Treat 3.6, Lite and Cyber as separate controlled dependencies even if a Google product presents them under one Gemini experience.
This is a launch assessment, not a certification. Benchmark leadership is useful evidence of where to test; it is not authorization to place the model in a high-impact workflow without domain evaluation, security review and an accountable owner.
Primary sources
- Google Gemini Flash family announcement
- DeepMind Flash Cyber announcement
- Gemini API models documentation
Image provenance
Hero image: Google official Gemini release artwork. The locally served WebP is a crop of the first-party release or model-card asset recorded in the repository provenance manifest.



