Why it matters
Google opened a preview of CodeMender, an AI code-security agent delivered through Gemini Enterprise Agent Platform and AI Threat Defense. It is designed to inspect code, identify and validate potentially exploitable defects, and produce targeted fixes, with Google’s specialized Gemini 3.5 Flash Cyber model initially restricted to governments and trusted partners.
My takeaway: Treat autonomous vulnerability discovery and repair as a controlled engineering pipeline: isolate analysis environments, require reproducible evidence, review every generated patch, measure false negatives and regressions, and keep repository credentials and merge authority outside the agent’s default reach.