Full Report
Gemini 3.8 Flash Cyber and Wiz's Red Agent team up to protect hospitals, public transit, and tech
Analysis Summary
# Industry News: Google and Wiz Launch "Scan for Good" AI Security Initiative
## Summary
Google and its cloud security subsidiary, Wiz, have launched "Scan for Good," a global initiative utilizing specialized AI agents to autonomously hunt for vulnerabilities in critical infrastructure. The program pairs Google’s **Gemini 3.8 Flash Cyber** model with Wiz’s **Red Agent** to identify and remediate security flaws in hospitals, public transit, and government entities before attackers can exploit them.
## Key Details
- **Date:** September 24, 2026
- **Companies Involved:** Google (DeepMind), Wiz, CISA (Advisory capacity)
- **Category:** Product Partnership / Social Corporate Responsibility / AI Defensive Tooling
## The Story
The "Scan for Good" initiative represents a shift toward proactive, AI-driven offensive security for the public interest. The program utilizes Gemini 3.8 Flash Cyber—a model specifically fine-tuned for software bug hunting—working in tandem with Wiz’s Red Agent. These autonomous systems scan publicly facing APIs, websites, and applications for exposures.
Crucially, the program includes a "human-in-the-loop" requirement: all AI-generated findings are verified by human researchers before disclosure. The initiative has already yielded results, including the discovery of a critical GitHub Actions vulnerability in a Snowflake repository and the securing of a Middle Eastern national archive containing 8.8 million files. Other interventions prevented potential takeovers of hospital servers and municipal transit systems.
## Business Impact
### For the Companies Involved
- **Google/Wiz:** Positions their AI stack as "safe" and "beneficial" amid growing public and regulatory anxiety regarding autonomous AI agents.
- **Brand Equity:** Enhances their reputation as essential defenders of national security and critical infrastructure.
### For Competitors
- **OpenAI:** Directly counters OpenAI’s "Daybreak for Frontline Defenders" initiative, signaling a "goodwill arms race" among AI labs to prove their technology’s defensive utility.
- **Traditional Pentesting Firms:** Puts pressure on manual security service providers by demonstrating the scale and speed of autonomous AI vulnerability discovery.
### For Customers
- **Critical Infrastructure (Hospitals/Transit):** Gains access to high-end offensive security capabilities that these typically underfunded sectors could not otherwise afford.
- **Vulnerability Management:** Shifts the burden of discovery from the victim to a proactive partner, though it requires organizations to trust autonomous bots scanning their perimeters.
### For the Market
- **Standardization:** Sets a precedent for "AI for Good" programs that include government (CISA) oversight and human verification, potentially becoming a blueprint for future AI safety regulations.
## Technical Implications
- **Gemini 3.8 Flash Cyber:** Demonstrates the efficacy of domain-specific LLMs (Large Language Models) optimized for code analysis over general-purpose models.
- **Autonomous Remediation:** The shift from simple "scanning" to "autonomous identification and guided remediation" marks an evolution in automated security workflows.
## Strategic Analysis
- **Market Positioning:** Google is positioning itself as the "Security AI" leader, leveraging Wiz’s cloud security dominance to provide real-world applications for DeepMind’s research.
- **Competitive Advantage:** The integration of offensive AI (Red Agent) with a high-speed inference model (Gemini Flash) allows for massive scale that human-only teams cannot match.
- **Challenges:** The risk of "false positives" or the accidental disruption of sensitive medical/transit systems by autonomous agents remains a primary concern, despite human verification steps.
## Industry Reactions
- **CISA:** Acting Director Nick Andersen praised the initiative, noting that defensive vulnerability discovery is vital for national digital infrastructure.
- **Market Response:** Generally positive, viewed as a necessary step to stay ahead of threat actors who are also adopting AI for automated exploit generation.
## Future Outlook
- **Global Scaling:** Wiz intends to scale this globally with no set end date, suggesting this will become a permanent fixture of Google’s security ecosystem.
- **Regulatory Integration:** Expect similar programs to become part of formal public-private partnership frameworks mandated by governments.
## For Security Professionals
- **Skill Shift:** Practitioners should focus on *verification* and *remediation orchestration* rather than just manual discovery.
- **Tooling:** Monitor the release of Gemini 3.8 Flash Cyber for potential integration into internal enterprise defensive stacks.
- **Collaboration:** Organizations in critical sectors should consider applying for the program or ensuring their VDP (Vulnerability Disclosure Policy) is AI-ready.