Google 'valuemaxxes' with AI security model response to Anthropic Google released its first security AI model, Gemini 3.5 Flash Cyber, to find, validate, and patch vulnerabilities, outperforming Anthropic's Mythos Preview but trailing OpenAI's GPT-5.5-Cyber in provider-reported tests. The model is integrated with Google's code security agent CodeMender and restricted to governments and trusted partners, following Anthropic's approach. Tulsee Doshi, senior director of product management at Google DeepMind, said the model offers 'valuemaxxing' for enterprises due to lower cost per token. Google released its first security AI model in response to Anthropic's Claude Mythos. Google's 3.5 Flash Cyber is tuned to find, validate, and patch vulnerabilities better than Gemini’s mainline Flash models. Google is also taking a leaf from Anthropic's book https://www.sdxcentral.com/news/anthropic-bug-hunter-launched-with-all-star-cast-and-good-old-us-patriotism/ by limiting the large language model LLM to governments and trusted partners via Google code security agent CodeMender. Tulsee Doshi, senior director of product management at Google DeepMind, explained that 3.5 Flash Cyber replicated vulnerabilities at a lower price per token than larger AI models, giving it "valuemaxxing" credentials for enterprises looking to cut down on tricky token expenses. CyberGym tests results put it above Mythos Preview, but lower than OpenAI's own GPT5.6 Sol security model and Anthropic's Mythos 5. OpenAI tops the charts with its GPT‐5.5‐Cyber; note these scores were provider-reported and have not been independently verified. According to a DeepMind blog https://deepmind.google/blog/introducing-gemini-3-5-flash-cyber/ , CodeMender invokes 3.5 Flash Cyber multiple times, helping AI agents analyze "vastly" more code paths to find and validate vulnerabilities. These sub-agents then output a single report. "Thanks to its speed and affordability, 3.5 Flash Cyber can be easily integrated into frequent scans, time-sensitive launch processes, or commit scanning pipelines at scale," Google added. The model is Google's first security-centric model since 2023's Sec-PaLM https://www.sdxcentral.com/news/new-google-cloud-generative-ai-products-aim-to-reduce-security-risks-address-talent-gap/ , which integrated Google's security intelligence and Mandiant’s intelligence https://www.sdxcentral.com/analysis/how-ai-mandiant-shape-googles-cloud-security-strategy/ on vulnerabilities, malware, threat indicators, and behavioral threat actor profiles. The release follows Cisco's launch of a small language model SLM family also catering for vulnerability tracking. Dubbed Antares https://www.sdxcentral.com/news/cisco-security-ai-aces-openai-but-anthropic-thats-a-mythos-mystery/ , the models tested higher than Google's Gemma and Gemini models, but tested lower than some OpenAI LLMs and Anthropic's Claude Opus 4.6. As this title gleaned, Cisco's Antares batch was not tested against Mythos, despite it having access to the model, a privilege it shares with Google.