Google's low-cost cyber AI challenges Anthropic's Mythos
Google has unveiled a cut-price security model built to hunt and patch software flaws, undercutting Anthropic's Mythos. For India's cost-conscious defenders, the price tag may matter most.
The News
Google has introduced a new security-focused artificial intelligence model built to find and fix software vulnerabilities at speed, and it is pricing the product as the affordable option in a fast-crowding field. In a blog post published on Tuesday, the company unveiled Gemini 3.5 Flash Cyber, describing it as a "cost-efficient and highly capable alternative" to larger and pricier systems, singling out the model offered by rival Anthropic's Mythos.
The new model is built on top of Gemini 3.5 Flash, Google's lightweight and lower-cost tier, and is tuned specifically for the work of scanning code, flagging weaknesses and proposing patches. Rather than opening it to everyone at launch, Google says it will make the model available first to governments and trusted partners.
Distribution runs through CodeMender, Google's security-focused tooling for automated vulnerability discovery and repair. The pitch is straightforward: put a capable defender in the hands of the organisations most exposed to attack, without the heavy compute bill the largest frontier models carry.
Why It Matters
The launch is a clear signal that AI security has moved from novelty to price war. For the past two years the story in security AI was capability, whether a model could reason its way through a tangled codebase at all. Google is now competing on cost, betting that good-enough autonomy at a fraction of the price beats best-in-class autonomy that few can afford to run at scale.
That shift echoes what happened across the wider model market in early 2025, when a wave of cheaper systems forced incumbents to defend their pricing rather than just their benchmarks. Once buyers learn that a lighter model can do most of the job, the premium tier has to justify every extra rupee or dollar. Security is a natural place for that logic to bite, because vulnerability scanning is high-volume work where running costs compound quickly.
Positioning the product explicitly against Anthropic's Mythos is also telling. Google is not claiming to have built the most powerful defender in the world. It is claiming to have built the one most organisations can actually deploy, which is a different, larger market.
Indian Angle
For Indian buyers, the cost framing lands squarely on the pain point. Indian enterprises and public bodies operate under some of the strictest incident-reporting rules anywhere, with CERT-In requiring certain cyber incidents to be reported within six hours of detection. That compliance clock rewards tooling that can triage and patch fast, and a model priced for continuous, high-volume scanning fits Indian security budgets far better than a premium frontier system.
The "governments and trusted partners" rollout is worth watching in New Delhi. India's government and its large network of managed-security providers, including the security arms of TCS, Infosys and Wipro, are exactly the kind of high-volume, cost-sensitive customers a cheaper defensive model is designed for. If Indian IT services firms can fold automated patching into the managed-security contracts they already sell to global clients, the economics of that business change.
There is a home-grown dimension too. India's push for sovereign AI and its growing cybersecurity startup scene mean cost-efficient security models set the benchmark that domestic builders will be measured against. Cheaper defensive AI also matters for the Data Protection framework under the DPDP Act, where the cost of finding and closing a flaw before a breach is now a compliance question, not just an engineering one.
FAQ
What is Gemini 3.5 Flash Cyber?
It is a security-focused AI model from Google, built on the lower-cost Gemini 3.5 Flash tier and tuned to find software vulnerabilities and suggest patches. Google positions it as a cost-efficient alternative to larger, more expensive security systems such as Anthropic's Mythos.
Who can use it first?
Google says the model will be available first to governments and trusted partners, distributed through CodeMender, its security-focused tooling for automated vulnerability discovery and repair. A broader rollout was not detailed at launch.
Why does the "cost-efficient" label matter for India?
Security scanning is high-volume, repetitive work, so running costs add up fast. A cheaper capable model suits Indian enterprise and government budgets, and supports fast compliance with CERT-In's six-hour incident-reporting rule and the DPDP Act.
Where can I read the original announcement?
Google detailed the model in a blog post published on Tuesday. The Verge's report, linked below, summarises the launch and its positioning against Anthropic's Mythos.
This story was reported by The Verge. Read the full original coverage at The Verge.