TLDRocket
Sign in

Google launches a cheaper alternative to large AI security models like Mythos

The Verge Emma Roth Covered by 19 sources

Google just launched a cheaper AI model built to hunt down and fix security bugs. It's meant to undercut pricier rivals like Anthropic's Mythos while still catching more flaws.

Based on reporting by The Verge, Emma Roth — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Google wants to make bug-hunting AI cheap enough to run constantly, not just occasionally. On Tuesday the company unveiled Gemini 3.5 Flash Cyber, a security-focused model it's pitching as a budget-friendly rival to heavyweight systems like Anthropic's Mythos. The pitch is simple: instead of paying a premium for one slow, thorough pass through your codebase, you get a fast, cheap model you can throw at the problem over and over.

Built on top of the existing Gemini 3.5 Flash, the new model is slotting into CodeMender, Google's automated coding agent that already scans for vulnerabilities and writes patches. According to Google, the economics here matter more than raw horsepower. Because 3.5 Flash Cyber is fast and inexpensive to run, CodeMender can call it repeatedly, checking far more code paths than it could with a single expensive model. More scans generally means more bugs caught before they become headlines.

For now, access is limited to governments and select partners, not the general public. That's a deliberate choice. Security tooling this powerful, especially anything that can autonomously find and patch vulnerabilities at scale, tends to get rolled out cautiously, both for liability reasons and because Google presumably wants field data before opening it up wider.

The bigger story is the strategy underneath the release. Anthropic and others have leaned into large, expensive models for security work, betting that depth beats speed. Google is betting the opposite: that cheap, repeatable scanning at volume finds more real-world problems than fewer, deeper passes from a costlier model. Whether that bet pays off will show up in whether CodeMender actually catches more vulnerabilities in production code, not in benchmark charts.

My take — AI-written commentary, not fact-checked reporting

I'll believe the 'cost-efficient alternative to Mythos' framing when someone outside Google runs a head-to-head, because right now it's a vendor grading its own homework. Still, the volume-over-depth approach to security scanning makes sense to me, cheap and repeated beats expensive and occasional in most real pipelines. The government-first rollout is the part worth watching; that's usually where AI security tools get their reputations made or broken.

Read more about this at: The Verge

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.