Google's Fairwind Program Wants to Cut Vulnerability Patching From Weeks to Minutes — And 650 Organizations Already Signed Up
Google DeepMind’s new Fairwind Program pairs its Gemini 3.8 Flash Cyber model with CodeMender, the company’s automated vulnerability-patching technology, to compress a fix cycle that traditionally takes weeks into minutes. Access is limited to trusted organizations — government cyber authorities, critical-infrastructure operators in healthcare, telecom, energy, and financial services, and core technology platforms — that agree to restrict use to internal security teams, enforce multi-factor authentication, and meet Google’s onboarding requirements. More than 650 partners are already participating, including CrowdStrike, Palo Alto Networks, Snowflake, and Wiz, and Google frames the launch as part of a wider commitment: over $100 million in Google.org cybersecurity funding globally, including $36 million distributed across 35 “cyber clinics” supporting hospitals, schools, and municipal utilities. On the same day, Gemini 3.8 Flash Cyber reported over 70% success on internal vulnerability-discovery tests across 20 languages, 47.2% pass@1 on the CWE-Bench patching benchmark, and 2.6 times more correct patches than commercial alternatives on Chrome’s own security team’s testing.
The urgency behind that pace is quantified elsewhere. BCG’s August cybersecurity research found nearly 89% of surveyed organizations experienced an AI-enabled attack in the past year, with 35% reporting significant financial or operational impact — yet only 41% have formal AI governance policies, and fewer than 20% have deployed shadow-AI monitoring or prompt-injection detection. Government is already a proving ground for the alternative: Alberta’s Ministry of Technology and Innovation used Claude Code to scan 466 million lines of code across 3,400 repositories in about 20 hours, work it estimates would have taken 6.5 years manually, with every generated patch still reviewed by human engineers before shipping.
Fairwind is a bet that patching speed, not just detection, is where AI closes the gap BCG’s numbers describe — provided the human-review step both companies build in stays intact as the pace increases.