“Google” introduced an AI model that almost no one will get: what does this say about the future?

"Google" introduced an AI model that almost no one will get: what does this say about the future?

This is “Gemini 3.5 Flash Cyber” – a specialized cybersecurity model designed to find, verify, and patch software vulnerabilities. However, what attracts the most attention is not its capabilities, but its distribution method: the model will not be available to the general market or regular business clients. Only governments and trusted partners will have access to it.

Read more Blind tennis? The World Championship in Vilnius will surprise even professionals

This is already the second such case in a few months – in April, “Anthropic” also acted similarly, introducing a model dedicated to cybersecurity. When two of the world’s largest AI laboratories decide that certain technologies are too dangerous for open access, it’s worth pausing to understand what’s really happening. And what’s happening is a fundamental breakthrough: AI has overturned decades of cybersecurity arithmetic.

KTU photo/Mantas Lukauskas

The Time Window That Became Negative

Cybersecurity has always been a race between attackers and defenders. Attackers look for vulnerabilities and create ways to exploit them, while defenders rush to patch them. For many years, this period was about a month – it’s no coincidence that Microsoft released security updates once a month, on the second Tuesday, for decades.

This year, this model collapsed. The annual report by Mandiant, a Google-owned cybersecurity company, based on over half a million hours of incident investigations, records an unprecedented metric: the average time from vulnerability discovery to exploitation has become negative – minus seven days. In other words, attacks on average begin a week before an official patch is released. Meanwhile, organizations on average patch critical vulnerabilities within 74 days, and almost half of system vulnerabilities found in large enterprises are never fixed at all.

The reason is AI. Models have learned to scan massive code arrays and find vulnerabilities faster and cheaper than any human security research team. Security experts estimate that AI can “disassemble” a published patch in less than an hour and turn it into a working attack tool against those who have not yet installed the update. Every security update also becomes an instruction for attackers.

Models You Won’t Get Publicly

The scale of this breakthrough is best illustrated by Anthropic’s experience. In April, the company introduced a model that, when given the sole task of finding a security vulnerability, independently discovered a 17-year-old critical bug in the FreeBSD operating system and wrote working exploit code itself. The oldest vulnerability found by the model had been hidden in the code for 27 years – in a system considered one of the security benchmarks.

Instead of releasing such a model to the market, Anthropic assembled a closed program where about 50 organizations – from Apple and Microsoft to the Linux Foundation – use this model to check the world’s most critical software. Over ten thousand high-severity vulnerabilities have already been found.

Google is taking a similar, but strategically different step. The strength of “Gemini 3.5 Flash Cyber” is not maximum power, but efficiency: the model is built using a lightweight “Flash” architecture and costs the same as a regular model, although it significantly outperforms it in specialized tasks. In a test with the Chrome browser engine code, it found 55 confirmed issues – more than significantly larger and more expensive competitors, including ten vulnerabilities that no other model had noticed. Internally, the model is already checking Chrome, Android, and cloud infrastructure code, and in one instance, it detected critical remote code execution vulnerabilities in public interfaces within two hours.

Nevertheless, both giants came to the same conclusion: a tool that finds vulnerabilities for defense is equally good at finding them for attack. Therefore, access is restricted, which raises a new and uncomfortable question – who decides which state and which organization is trustworthy?

Read more To live and study in Vilnius – a springboard to Europe

New Inequality in Digital Defense

Here lies the less noticeable, but long-term side of this story. If the most powerful defense tools are only available to the selected few, cybersecurity becomes a privilege dependent on relationships with a few US companies. Major states and corporations will gain access. But what about smaller states, municipalities, hospitals, medium-sized businesses – all those who are attacked most often and defend themselves most difficultly?

The situation is further complicated by last week’s context. Chinese laboratories are openly distributing increasingly powerful general-purpose models which, although not specialized for cybersecurity, will eventually acquire more and more of the same capabilities – but without any access restrictions. A paradoxical situation arises: specialized tools for defense are kept behind closed doors, while universal tools suitable for attacks spread freely online. In the security community, this tension is called a ticking clock – the question is no longer whether such capabilities will reach malicious actors, but when.

What This Means for Lithuania

For Lithuania, this topic is not theoretical. Last year, the National Cyber Security Centre registered almost three thousand cyber incidents, and its threat report directly states that malicious actors are increasingly using AI for attacks and that technical protection measures alone are no longer sufficient. At the same time, in Lithuania, with the entry into force of the new Cybersecurity Law, the circle of state-supervised organizations has increased almost fivefold – requirements are tightening precisely at a time when the pace of attacks is accelerating.

Practical conclusions for organizations are quite clear, though uncomfortable. First, the monthly update rhythm no longer matches reality – critical patches need to be deployed within days, not weeks, so automation is essential. Second, when the flow of vulnerabilities exceeds team capacity, prioritizing becomes the decisive ability: not patching everything in order, but first what is actually accessible to attackers. Third, AI must appear not only on the attack side but also on the defense side – from automated code review to anomaly monitoring. This is no longer a future investment, but a hygiene requirement.

At the state level, another question should be raised: how will Lithuania ensure access to the best defense tools when they are distributed not by market principles, but by trust? NATO and EU membership, close ties with the technology sector, and a strong cybersecurity reputation are real capital here. But it must be used consciously – to strive for Lithuanian institutions and critical infrastructure operators to be among those trusted partners who are granted access to such programs.

Defense Must Move at AI Speed

For a long time, cybersecurity was a field where technology changed quickly, but the rules of the game changed slowly. AI has changed the rules too. Vulnerabilities are found faster than we can patch them, patches become attack maps, and the most powerful tools are distributed behind closed doors.

The good news is that the same AI that accelerated attacks can also accelerate defense – Google and Anthropic programs show that machines are already finding and helping to patch vulnerabilities that humans have overlooked for decades. The bad news is that this advantage will not come automatically. It will go to those organizations and states that reorganize their defense to move at AI speed. Lithuania has repeatedly proven that it can be among the leaders in cybersecurity. Now, the most important thing is to leverage this groundwork once again – before the window of opportunity finally closes.

Read more «I feel cheated»: worried about Pikul and Dirkštys’ wedding tournament – UTMA washes its hands

Translated from

Leave a Reply

Your email address will not be published. Required fields are marked *