· artificial intelligence · 4 min read
AI and cloud briefing: cheaper, faster AI models, and an AI that fixes code
A short, factual briefing for 22 July 2026: Google's new Gemini Flash models are cheaper and faster, a new AI model built to find and patch security bugs, and why agentic AI is starting to reshape the software you already pay for.

Here is our latest round-up of what matters in AI and cloud for UK businesses. It is short and factual, with links to credible sources so you can read further.
Google’s new AI models are cheaper and faster
On 21 July, Google released three new models in its Gemini Flash family: Gemini 3.6 Flash, Gemini 3.5 Flash-Lite, and Gemini 3.5 Flash Cyber. The headline is not raw intelligence. It is cost and speed.
Gemini 3.6 Flash keeps the large 1-million-token context window but does more work for less money. According to Artificial Analysis, the new model roughly halves the time it takes to finish a task and uses about 17% fewer output tokens than the model it replaces. The output price drops from $9.00 to $7.50 per million tokens, with input at $1.50 per million. Its knowledge now runs to March 2026, and it scores better on coding tests such as SWE-Bench Pro. TechCrunch notes there was no new “Pro” model this time, only a tease of what comes next.

Why this matters: the price of “good enough” AI keeps falling. If you fixed your model choice six months ago, you are probably paying too much and running slower than you need to.
What to do this week:
- Match the model to the task. A smaller, cheaper model often does the job that a large, expensive one is doing today.
- Review your model choices on a schedule, not once. Prices and quality move every few weeks.
- Track token spend as a named cost. Faster, cheaper models only save money if you actually switch to them.
An AI model built to fix security bugs
One of the three new models is aimed squarely at security. Gemini 3.5 Flash Cyber is tuned to find, confirm, and help patch software vulnerabilities, and to do it cheaply enough to scan large codebases again and again.
Google reports that in testing on the complex V8 JavaScript engine, the model found 55 unique confirmed issues, compared with 47 for the standard Flash model and 36 for a leading rival model. It works alongside Google’s CodeMender agent, which runs the model many times over to widen coverage and then pulls the findings into a single report. For now it is a limited pilot, offered to governments and trusted partners first.

Why this matters: AI is no longer only a tool for attackers. It is now being used to defend code as well. That is welcome, but it does not replace the basics.
What to do this week:
- Keep patching on a clear timetable. AI that finds bugs faster only helps if you fix them faster too.
- Ask your software suppliers whether, and how, they use AI to test their own code for security flaws.
- Treat AI security tools as an extra layer, not a reason to relax your existing controls.
Agentic AI is starting to reshape the software you already pay for
The bigger shift is in everyday business software. Gartner estimates that up to $234 billion of enterprise application software spending is “at risk” between now and 2030, as AI agents take over tasks that used to need a person clicking through an app. That is about a fifth of software-as-a-service spending by 2030.
This is not a far-off idea. Gartner also expects 40% of enterprise applications to include task-specific AI agents by the end of 2026, up from under 5% in 2025, and industry surveys already report that most enterprises run at least one live application with an AI agent inside it.
Why this matters: agents are arriving inside tools you already use, often without a big announcement. Each one is a new piece of software with its own access to your data. Left unchecked, that is both a cost and a security question.
What to do this week:
- Make a simple list of where AI agents are turning up in your existing tools, and what data each one can reach.
- Give every agent the least access it needs, and turn off any you are not using.
- Put a small, named budget behind governance. Knowing what your agents are doing is now part of the running cost.
The takeaway
Two clear themes this week. First, AI is getting cheaper and faster, so revisit your model choices and make sure you are not overpaying. Second, AI agents are spreading into everyday software and into security itself, which means they need the same access controls, patching discipline, and cost tracking as everything else you run. If you would like help reviewing your AI spend or securing your agents, get in touch.