Google announced Gemini 4 Argon, its new frontier AI model, on September 30, 2026, in a post on Google’s official blog. It is rolling out to a set of trusted cyber defenders first, through the Fairwind Program, according to Google.
The Brief
- Trusted defenders and internal teams get Argon “without cyber guardrails”, according to Google.
- Argon ties for first place with a top score of 68% on CWE-bench v1, according to Google, whose post cites no independent verification.
- Wiz used Argon to find a critical flaw in healthcare software that hospitals use worldwide, according to Google.
- The wider release starts with paid API customers and Google AI Ultra subscribers, per Google.
Beyond security, Google said Argon raises the output token limit to 1 million tokens, up from the previous 64,000 tokens. It also sets a new state of the art on DeepSWE v1.1 (77.9%), a software engineering test.
Launch pricing is $2 per million input tokens and $10 per million output tokens. Google labels that an introductory price.
Introducing Gemini 4 Argon – our new frontier model.
— Google DeepMind (@GoogleDeepMind) September 30, 2026
It’s built for complex workflows across coding, enterprise knowledge work, and cybersecurity defense – rolling out today to a set of trusted testers through our Fairwind Program. pic.twitter.com/X8acOWJOSF
Trusted defenders get Argon without cyber guardrails
In its announcement, Google said Argon can autonomously find, validate, and patch critical software vulnerabilities. For trusted defenders and its internal teams, Google will release the model without cyber guardrails. The stated aim is to let them use its full frontier-level cybersecurity defense capabilities.
Wiz is already using Argon through its Scan for Good initiative. In an early demonstration, Google said the model uncovered a critical vulnerability exposing sensitive personal information across healthcare software used by hospitals worldwide. Google added that it identified a severe risk that previous frontier models had missed.
The CWE-bench v1 tie means Argon shares the top spot rather than owning it. Every benchmark figure in this story comes from Google. Its post cites no independent verification, so the result remains a vendor claim.
Four safeguard areas come before broad release
Google said it is strengthening safeguards across four main areas before rolling Argon out broadly. It is also actively engaged in the U.S. government’s voluntary process for pre-release model access while access expands in phases.
On misuse, Google said Argon is designed to refuse harmful requests tied to cyber or chemical, biological, radiological, and nuclear (CBRN) attacks. The company is improving how it monitors the model’s internal activations. Google said internal and external red teams tested those safeguards with manual and automated attacks.
On prompt injection, Google said Argon is leading in prompt injection robustness on the Gray Swan’s Indirect Prompt Injection (IPI) benchmark. Such attacks use malicious instructions to hijack a model’s behavior. .
For misalignment, Google is deploying misalignment mitigations that monitor Argon’s chain-of-thought and actions and stop execution when necessary. It is also hardening its sandboxes by isolating and sealing them before high-risk training or evaluations begin.
Google also shared internal results. A team of Argon agents found data center memory optimizations that free up over 300 TiB of memory once rolled out. They also produced a memory-safe libgav1 video decoder that runs 2.7x faster than the Rust port, with identical video output.
The same autonomous find-and-patch skill that helps defenders also explains the gating. Layered monitoring helps reduce risk, but the red-team results are self-reported. The next marker is the broader release. Google said it goes to developers, enterprises and consumers, starting with paid API customers and Google AI Ultra subscribers.