In partnership with

AI made PMs faster. Multiplayer mode is still broken.

A PM can summarize research, draft a PRD, and mock up a prototype before lunch. The hard part starts when the team has to decide what actually gets built.

Jira Product Discovery gives product teams one place to capture insights, prioritize ideas with consistent frameworks, and build living roadmaps stakeholders can rally around.

And because it’s connected to Jira, the context behind every decision stays with the work—so developers and their agents know not just what to build, but why.

AI helps PMs move faster. Jira Product Discovery helps the whole team build with confidence.

For much of the artificial intelligence boom, the competition has been relatively easy to understand.

Companies built increasingly capable models. Benchmarks improved. Context windows expanded. Prices fell. Developers gained access to capabilities that would have seemed extraordinary only a few years earlier.

The assumption underneath much of this progress has been that better AI eventually becomes more accessible. Capabilities that begin inside expensive frontier models gradually move into smaller, faster and cheaper systems.

Google’s latest Gemini release suggests that this pattern is continuing, but with an important complication.

Google recently introduced Gemini 3.8 Flash, a model designed for long-running agentic workflows, coding and professional tasks. Alongside it, the company introduced Gemini 3.8 Flash Cyber, a specialized cybersecurity model capable of autonomously discovering vulnerabilities and generating patches.

The first model is being broadly offered to developers and enterprises. The second is not.

Gemini 3.8 Flash Cyber is initially available to trusted defenders through Google’s Fairwind Program, a limited-access initiative for governments and trusted partners.

That distinction may ultimately prove more consequential than another improvement on an AI benchmark.

We may be entering an era in which the central divide in artificial intelligence is no longer simply between those who have access to powerful AI and those who do not. Instead, it may increasingly be between different levels of capability, with access determined by what a model can do, who wants to use it and how much risk accompanies that use.

Intelligence is Becoming Cheaper

One of the most important trends in artificial intelligence has been the declining cost of useful intelligence.

Frontier models remain expensive to develop but the cost of using increasingly capable models has fallen considerably. Smaller models can now perform tasks that once required the largest systems available.

Gemini 3.8 Flash illustrates that trajectory.

Google says the model substantially improves on Gemini 3.7 Flash while often approaching the performance of more expensive frontier models. The company specifically highlights long-horizon software engineering, financial analysis and legal tasks as areas where the model performs strongly.

Perhaps more importantly, Google is positioning the model around autonomous work.

This distinction matters.

The first generation of widely used generative AI systems primarily responded to individual requests. A user asked a question, supplied a document or requested some code, and the model generated a response.

Agentic systems operate differently.

They can break larger objectives into smaller tasks, interact with tools, inspect results, correct mistakes and continue working toward an objective over longer periods.

The economic implications are significant.

If capable models become inexpensive enough to perform hundreds or thousands of iterative actions, AI becomes useful for a much broader category of work. Tasks that were economically impractical when every interaction with a powerful model was expensive may become routine.

This could accelerate automation in software development, research, administration, financial analysis and other knowledge-intensive fields.

But declining costs also create a second-order problem.

When powerful capabilities become inexpensive, they become easier to deploy at scale.

And not every capability scales harmlessly.

Cybersecurity Makes the Tension Visible

Gemini 3.8 Flash Cyber provides an unusually clear example of this tension.

According to Google, the specialized model can autonomously search complex codebases for vulnerabilities and assist with repairing them. Google says that on an internal benchmark covering 20 programming languages, the model achieved a vulnerability-discovery success rate above 70 percent.

The company is already applying the technology internally. Google says its Chrome security team obtained 2.6 times more correct vulnerability patches from Gemini 3.8 Flash Cyber than from larger commercial models. It also reports that its Cloud Vulnerability Research team used the model to identify a critical vulnerability in less than two hours, compared with research that could otherwise take months.

These are potentially valuable defensive capabilities.

Software vulnerabilities remain one of the persistent weaknesses of modern digital infrastructure. Organizations maintain enormous codebases, dependencies accumulate, security teams face limited resources and vulnerabilities can remain undiscovered for years.

An AI system capable of continuously examining software, identifying weaknesses and proposing patches could substantially improve defensive security.

But the underlying capability is inherently dual-use.

A system that can identify vulnerabilities for defenders may also identify vulnerabilities that an attacker could attempt to exploit.

Google has responded by drawing an access boundary.

While Gemini 3.8 Flash includes cybersecurity safeguards, the specialized Cyber model has more permissive cybersecurity mitigations. Google therefore says it is limiting access to trusted defenders who require more comprehensive cyber capabilities.

The decision is understandable from a safety perspective.

It is also a preview of a much larger question facing the AI industry.

What happens when the most useful AI capabilities are also the capabilities that companies are least comfortable releasing broadly?

From Model Access to Capability Access

Until recently, access to artificial intelligence could largely be understood in terms of products and models.

A company released a model. Developers received access through an API. Consumers received access through a chatbot. Enterprises purchased higher limits or additional security and administrative features.

The emerging model may be more complicated.

Instead of simply deciding who can access a particular AI model, providers may increasingly decide who can access particular capabilities.

Cybersecurity is an obvious example, but it may not be the last.

Consider AI systems capable of advanced biological research, sophisticated chemical analysis, autonomous financial operations, large-scale infrastructure management or increasingly independent software engineering.

Each capability can have legitimate applications.

Each can also introduce risks that are very different from asking a chatbot to summarize a report.

As models become more capable, providers may therefore create increasingly sophisticated access structures around them.

A general-purpose model might be available to everyone. More autonomous versions might require additional verification. Specialized capabilities could be available only to enterprises, researchers, governments or approved organizations. Particularly sensitive tools could operate through controlled environments rather than unrestricted APIs.

Access to AI would no longer be binary.

It would become layered.

The Emergence of a Tiered AI Ecosystem

This could produce something that has received less attention than the race toward artificial general intelligence: a tiered AI ecosystem.

At the broadest level, consumers would continue to have access to increasingly capable general-purpose assistants.

Developers and businesses would have access to models with greater autonomy, larger usage limits and deeper integrations.

Specialized organizations could receive access to models designed for particular professional domains.

And a smaller group of vetted institutions might gain access to capabilities considered too consequential for unrestricted distribution.

Google’s Fairwind Program already resembles this final category. The company describes it as a limited-access program for governments and trusted partners to use advanced cyber defense capabilities.

There are reasonable arguments for such restrictions.

An unrestricted vulnerability-discovery system could create obvious security concerns. Similar concerns could emerge around future biological, chemical or infrastructure-related capabilities. AI companies cannot simply ignore foreseeable misuse because broad access is philosophically appealing.

But restricted access introduces its own questions:

  • Who qualifies as a trusted organization?

  • What standards determine eligibility?

  • Can independent security researchers participate, or will access primarily favour governments and large corporations?

  • Can smaller organizations obtain the same defensive capabilities as the institutions they may need to defend themselves against?

  • How transparent should AI providers be about why access is granted or denied?

  • And perhaps most importantly, how much authority should private technology companies have to determine who receives access to increasingly consequential forms of computational capability?

These questions become more important as the technology becomes more powerful.

Safety and Concentration Can Coexist

There is a temptation to frame this debate as a simple conflict between openness and safety.

That would be a mistake.

Some capabilities genuinely require safeguards. Releasing every powerful AI capability without restrictions would not necessarily produce a healthier or more equitable technological ecosystem.

At the same time, restricting capabilities can concentrate power.

Both things can be true.

A company may have legitimate reasons for limiting access to a powerful cybersecurity model while also gaining substantial influence over which institutions benefit from that technology.

The challenge is therefore not simply deciding whether access controls should exist.

It is designing access controls that are proportionate, transparent and accountable.

That could eventually require clearer eligibility criteria, independent oversight mechanisms, researcher access programs, auditability and pathways through which smaller organizations can demonstrate legitimate need.

Otherwise, the AI ecosystem could gradually develop an unusual asymmetry.

The cost of intelligence may continue falling while the institutional barriers surrounding particular capabilities increase.

The technology becomes cheaper.

The permission to use it becomes more valuable.

Cheap Intelligence Changes the Economics of Autonomy

There is another reason Gemini 3.8 Flash deserves attention.

Google is not simply claiming better performance. It is emphasizing the combination of capability, speed and cost.

That combination is particularly important for agents.

A traditional chatbot interaction might involve one model request. An autonomous workflow might involve dozens, hundreds or potentially thousands of model interactions as the system plans, searches, evaluates, writes code, tests results and revises its approach.

The economics of agentic AI therefore depend heavily on inference costs.

A model that is slightly less capable but dramatically cheaper may sometimes be more useful than a frontier model if it can economically perform far more iterations.

As smaller models approach frontier-level performance, the practical bottleneck may increasingly shift away from intelligence itself.

The important questions become reliability, permissions, tool access, oversight and the consequences of allowing the system to act.

That represents a meaningful transition in how we think about AI progress.

For years, much of the conversation has focused on what models know and what they can generate.

The next phase may focus increasingly on what models are permitted to do.

The Governance Layer is Becoming Part of the Product

This also means AI governance is becoming less separable from AI engineering.

Safety policies, access controls, identity verification, monitoring systems and usage restrictions are sometimes treated as constraints placed around the technology.

Increasingly, they may become part of the technology itself.

Gemini 3.8 Flash Cyber is not simply a model with a policy document attached to it. Its distribution model is part of how Google has chosen to deploy the capability.

That distinction matters.

As AI systems gain greater autonomy, governance decisions will increasingly determine the practical capabilities available to different users.

Two organizations might theoretically have access to the same underlying intelligence while receiving very different levels of autonomy, tool access or specialized functionality.

In that environment, understanding an AI system will require looking beyond benchmark scores.

We will also need to understand the permission architecture surrounding it:

  • Who can access it?

  • What tools can it use?

  • What actions can it perform?

  • What safeguards constrain it?

  • Who decides when those safeguards can be relaxed?

Those questions may eventually matter as much as model size or benchmark performance.

A Different Kind of AI Divide

The digital divide has traditionally been discussed in terms of access to computers, broadband, software and technical skills.

Artificial intelligence may introduce another layer.

At first, that divide appeared likely to be about access to models themselves. Organizations able to afford powerful AI would gain an advantage over those that could not.

Falling inference costs may weaken that particular barrier.

But another could replace it.

If powerful general intelligence becomes inexpensive while specialized capabilities remain controlled, the meaningful divide may shift from who can afford AI to who is authorized to use particular forms of AI.

That would have consequences far beyond cybersecurity.

Universities, independent researchers, startups, nonprofits, public institutions and smaller businesses could find themselves operating with a different capability ceiling than governments and major corporations.

In some domains, that may be justified.

In others, it could create new forms of technological concentration.

The difficult task will be distinguishing between the two.

What Comes Next

Gemini 3.8 Flash and Gemini 3.8 Flash Cyber are individual products in an industry that changes remarkably quickly. Another model will inevitably outperform them.

The more lasting significance may be the deployment pattern they represent.

AI is becoming more capable.

It is becoming cheaper.

It is becoming more autonomous.

And, at the same time, some of its most consequential capabilities may become more carefully controlled.

Those trends are not contradictory. They may develop together.

The future of artificial intelligence may therefore be shaped by two races happening simultaneously.

One is the familiar race to build better and cheaper intelligence.

The other is the emerging race to determine how that intelligence should be distributed, constrained and governed.

The first race determines what AI can do.

The second may determine who gets to do it.