Google Cloud has moved its CodeMender AI security agent from research preview into a broader enterprise preview, enabling security teams to scan, verify, and automatically remediate software vulnerabilities at machine speed.
The launch, announced on July 22, 2026, by Michael Gerstenhaber, VP of Product Management for Gemini Enterprise, and Clemens Viernickel, Director of Product Management for Cloud AI, positions CodeMender as a direct counter to adversarial AI-driven attacks on code.
CodeMender was originally introduced by Google DeepMind in October 2025 as an experimental agent for autonomous vulnerability discovery and patching.
It is now generally available through the Gemini Enterprise Agent Platform or as a core component of Google’s AI Threat Defense suite, giving organizations flexibility to deploy it inside existing CI/CD pipelines or local developer environments via a lightweight CLI client.
Google Launches CodeMender AI Agent
The agent follows Google’s multi-model strategy, letting teams pick models optimized for cost, speed, or deep-scanning performance, with support for third-party frontier models planned later this year.
CodeMender works across three phases: scan, verify, and remediate, supporting languages including C/C++, Go, Java, Python, Ruby, Rust, and TypeScript.

It hunts for hard-to-detect flaws such as memory corruption, injection bugs, cryptographic weaknesses, and insecure data handling, then builds and runs proof-of-concept exploits in an isolated, customer-managed sandbox to confirm real exploitability before generating a fix.
- Scan: identifies vulnerabilities using contextual understanding of the codebase, not just static pattern matching
- Verify: constructs and executes exploit code to eliminate false positives and reduce alert fatigue
- Remediate: generates a tested patch delivered as a code diff, using an LLM-as-a-judge check to confirm functionality isn’t broken
Developers retain full control, reviewing and approving every patch before it reaches the repository.
Underpinning the agent’s deeper analysis is Gemini 3.5 Flash Cyber, a specialized variant of Gemini 3.5 Flash fine-tuned specifically to detect, validate, and repair code vulnerabilities.
Google says the model has already surfaced 55 confirmed issues in the V8 JavaScript engine during testing. For now, Gemini 3.5 Flash Cyber access through CodeMender is restricted to a limited pilot of governments and trusted partners, positioning it as a lower-cost rival to models like Anthropic’s Mythos, with broader availability planned over time.
Security leaders at major enterprises have publicly backed the tool. Salesforce CISO Iain Mulholland described CodeMender as accelerating “the path from validated vulnerability to tested fix,” while Robinhood’s Scott Ponte noted it caught critical flaws that other AI tools missed.

CodeMender also integrates with Wiz within AI Threat Defense: Wiz orchestrates prioritization through its Security Graph, calls CodeMender for scanning and patch generation, and triggers Wiz Red Agent for AI-driven penetration testing to confirm exploitability before remediation.
The agent runs inside a secure-by-design Agent Platform with enterprise governance controls, including VPC traffic routing, data isolation and encryption, and zero retention of source code.
Google frames CodeMender as a step toward a “continuous, self-healing agentic software development lifecycle,” where vulnerabilities are found and fixed before ever reaching production.
As AI-generated attacks accelerate, tools like CodeMender signal a shift in enterprise security workflows from passive detection toward autonomous, verified remediation at scale.
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.