Google launches a cyber-defence programme for critical infrastructure
Fairwind gives more than 650 vetted government and infrastructure partners access to an automated vulnerability-fixing pipeline built on a restricted cyber model.
- Security & misuse
- Notable
Google announced Fairwind, a limited-access programme giving more than 650 vetted government agencies, critical-infrastructure operators and cybersecurity partners early access to its most advanced automated vulnerability-remediation tools. The pairing at the centre of the programme combines a restricted cyber-specialised model, Gemini 3.8 Flash Cyber, with CodeMender, Google’s fix-generation harness, which the company said could take a discovered vulnerability through verification to a deployment-ready patch in minutes rather than the weeks such fixes normally take.
Access is confined to organisations Google has separately vetted — national cyber authorities, operators in sectors such as healthcare, telecommunications, energy and finance, and existing Google Cloud customers and security partners — rather than released as a general product or research artefact. Google framed the launch alongside a wider funding commitment: its Google.org cybersecurity giving passed $100 million in total, including $36 million directed at 35 US “cyber clinics” that the company said support more than 1,250 hospitals, school districts and municipal utilities that otherwise lack dedicated security staff.
The announcement landed within days of OpenAI’s own pledge of $1 billion in cyber-defence support for frontline defenders, making early September 2026 a moment when two of the largest frontier labs pushed defensive-cyber-AI programmes in quick succession rather than treating offensive-capable models purely as a risk to be contained. Both companies framed the moves as addressing a structural imbalance — that AI-assisted attack tooling was becoming easier to access than AI-assisted defence — though neither published independent data on how much the tools reduce real-world remediation time outside the vetted partner group, and access to both programmes remains restricted rather than open for outside scrutiny.
In the commentary
What people were saying around this time — external links, from the record's commentary rail.