2 OCT 2026 — Google announced Gemini 4 Argon, its new frontier model, on 30 September and gave it first to cybersecurity organisations it has vetted. For them and for its own teams, Google says it is "releasing Argon without cyber guardrails" so they can use the model's full ability to find and fix software flaws. Developers, businesses and consumers get it later, starting with paid API customers and Google AI Ultra subscribers, on no stated date.
The route in is the Fairwind programme, which Google opened on 2 September for an earlier cyber model, Gemini 3.8 Flash Cyber. What decides access is Google's judgement of the organisation applying, not a technical limit on what the model will do.
What Google says Argon can do
In its announcement, Google describes Argon as built for long, multi-step work in software engineering, legal and financial research, and cyber defence. The model can now produce up to 1 million tokens of output, up from 64,000. Its main coding result is 77.9% on DeepSWE v1.1, a test of long software-engineering tasks, and Google says it ranks first on Zapier's AutomationBench with 51.3%.
Google also reports internal results. Teams of Argon agents found memory savings across its data centres that freed more than 300 TiB once rolled out, the company says, and the model is helping move C and C++ code to Rust, including more than 800,000 lines of the Fuchsia Zircon kernel. Those rewrites are still being audited and tested before they reach production.
The cyber claims, and what is missing
Google says Argon "can autonomously find, validate, and patch critical software vulnerabilities". The one public figure behind that is on CWE-bench v1, which tests whether a model can fix security flaws: Argon scored 68%, a tie for first place.
The flaw-finding claims come without numbers. On Google's internal vulnerability benchmark, Argon "uncovered a wide range of exposures" across code in 20 programming languages. On a black-box penetration-testing benchmark run by the security firm Wiz, it outperformed 3.8 Flash Cyber. Neither comparison has a score, a baseline or a count.
Wiz has also been using Argon in Scan for Good, its free programme for critical public infrastructure. Google says the model found a critical flaw exposing personal information in healthcare software used by hospitals worldwide, one that earlier frontier models had missed. The announcement does not name the software or say whether the flaw has been fixed.
Who gets in, and on what terms
The Fairwind page says Google works with more than 650 partners and gives priority to governments and national cyber authorities, critical infrastructure operators in fields such as healthcare, telecoms, energy and finance, and core technology platforms. A subset of those partners gets Argon, and Google says it runs background checks on organisations that apply.
Admitted organisations may give access only to internal cybersecurity, incident-response or penetration-testing teams. They must track who uses the model, require phishing-resistant multi-factor authentication, and may not share or resell access. Permitted dual-use work includes authorised threat simulation, reverse engineering and malware analysis, for defensive and academic research.
The safeguards for everyone else
Google lists four areas it is still strengthening before wider release. The model is designed to refuse harmful cyber requests and requests for chemical, biological, radiological or nuclear attacks, and Google says it is improving how it monitors the model's internal activations to spot misuse.
It is also training Argon to resist prompt injection, in which instructions hidden in content hijack the model. A separate monitor watches the model's reasoning and actions and halts execution when it oversteps what the user intended, and test environments are sealed before high-risk training or evaluation. Google adds that it is taking part in the US government's voluntary process for pre-release access to models.
The general price is already set at an introductory $2 per million input tokens and $10 per million output tokens.
Why the release order matters
Argon is the second Google model to reach Fairwind before anyone else, after 3.8 Flash Cyber. Several labs adopted the same pattern in early September: an application, a check on the organisation, and a decision by the vendor.
A model released without cyber guardrails is only as contained as the organisations allowed to use it. Containment was already tested in September, when a security evaluation of a Gemini model reached three real companies. When Argon reaches paid customers with its guardrails on, the four safeguards above are what will stand between the model and misuse.