I want to start this article with a quick history lesson: a brief history of self-healing software. It’s not the most prolific technical term out there, but I’d wager that in your dealings with technology over the decades, you’ve certainly benefited from it.
At its simplest, this is software that detects a failure and automatically takes action to correct it. As early as the 1990s, engineers were already developing infrastructure with built-in automated recovery, or runtime recovery. By the mid-2000s, things had progressed to automated program repair, where computers were automatically identifying bugs and generating code changes to fix them.
Fast-forward to 2025, and Google launched CodeMender, which uses Gemini-powered agents to scour code for vulnerabilities, generate patches, validate them, and then self-correct when necessary.
Now, Google has announced its Fairwind Program, a new deployment program for specific trusted organizations that combines CodeMender with Google’s latest cybersecurity AI tools.
What is Google’s Fairwind Program and Who is it For?
First up, Fairwind isn’t available to everyone. It’s a limited-access program specifically designed for a select group — albeit a large one totaling 650+ — of Google Cloud customers, government agencies, and cybersecurity partners. The objective is to help these clients tackle cybersecurity risks at scale using an agentic, proactive defense system that taps into Google’s latest AI cybersecurity capabilities.
Essentially, it’s about access to Gemini 3.8 Flash Cyber, Google’s most advanced cyber model, and combining that access with the CodeMender system. What you get is a scenario where AI agents are supercharged with this powerful cyber model to find vulnerabilities, verify them, write and validate fixes, rather than simply flagging them.
According to John “Four” Flynn, VP of Security and Privacy at Google DeepMind, “Instead of taking weeks to manually fix vulnerabilities, defenders can now generate verified, deployment-ready patches in minutes — within an organization’s secure cloud environment.”
This speed is essential to the long-term goals of AI-powered cyber defense, which ultimately come down to staying ahead of attackers before they can exploit AI technology to do the same. It’s also one reason Google has given early access to a select group of organizations, including government bodies, critical infrastructure operators, and core technology platforms.
This early access is deliberately restricted. Gemini 3.8 Flash Cyber isn’t just analyzing cyber threats — it can help discover and fix them. In the wrong hands, the model could potentially be used to exploit those same weaknesses.
“To ensure these powerful AI capabilities are used responsibly, participating organizations agree to strict operational standards, including limiting access to employees within their internal cybersecurity, incident response, or penetration testing teams and deploying protections like multi-factor authentication,” explains Flynn.
Final Thoughts
While CodeMender has been around for almost a year now, this evolution, which combines its capabilities with the properties of a cyber-first model, is exciting. For me, it’s really beckoning in the era of autonomous remediation.
Because as we continue to deploy agentic AI at scale, that is the threat we will be facing. And the only thing that can combat an agent intent on wreaking cybersecurity chaos is another one intent on preventing it from achieving its goals.




