Photo: Dietmar Rabich, CC BY-SA 4.0, via Wikimedia Commons — A Google sign on Charleston Road in Mountain View, California, in 2022.

Google’s New Gemini 4 Argon Model Goes to Trusted Cyber Defenders First

Google announced its new Gemini 4 Argon model on Wednesday, Sept. 30, and is rolling it out first to a limited group of cyber defenders it calls trusted. Developers, enterprises and consumers have to wait. Google’s announcement gives no date for a wider release.

Who can use it now

Google says Argon “is rolling out to a set of trusted cyber defenders through our Fairwind Program.” Google’s own internal teams also use it. Google says it will open the model to developers, enterprises and consumers “as soon as possible,” starting with paid API customers and Google AI Ultra subscribers, after it gathers feedback from early testers.

What the Fairwind Program is

Google launched Fairwind on Sept. 2 with an earlier model, Gemini 3.8 Flash Cyber. When it launched the program, Google said it had more than 650 participating partners worldwide; the Argon post says only that Argon is going to “a set of trusted cyber defenders” in the program. Priority goes to governments and national cyber authorities, critical infrastructure operators in healthcare, telecommunications, energy and finance, and core technology platforms.

Partners agree to conditions, according to Google’s program page. They may give access only to internal cybersecurity, incident response or penetration-testing teams. They must use phishing-resistant multi-factor authentication and track employee access and use. They may not share, redistribute or sell access. Google also says it runs background checks on applicant organizations. The page lists authorized threat simulation, reverse engineering and malware analysis as permitted work, and says “Malicious tasks such as creating malware are not permitted.”

What “without cyber guardrails” means

Google wrote: “For trusted defenders and our own internal teams at Google, we’ll be releasing Argon without cyber guardrails so they can leverage its full frontier-level cybersecurity defense capabilities.” In Google’s words, then, the version for those two groups will come without the cyber guardrails. Google says Argon “can autonomously find, validate, and patch critical software vulnerabilities,” a capability claim that comes from Google. The post does not describe how the guardrail-free version differs in practice.

Safeguards Google says it is strengthening

Before a broad rollout, Google says it is strengthening safeguards in four areas. The first is misuse, including cyber and chemical, biological, radiological and nuclear attacks; Google says those safeguards were tested by internal and external red teams. The second is prompt injection, where malicious instructions hijack a model’s behavior. The third is monitoring the model’s chain-of-thought and actions and stopping execution when necessary. The fourth is hardening the sandboxed environments used for training and evaluation.

Prices

Google says Argon will launch at an introductory $2 per million input tokens and $10 per million output tokens. A token is a small chunk of text, roughly part of a word, that the model reads or writes. After the introductory period, the price becomes $4 and $20. The post does not say how long the introductory period lasts.

Google’s claims and one outside check

Google says Argon sets a new state of the art on DeepSWE v1.1 (77.9%), ranks first on Zapier’s AutomationBench at 51.3%, scores 91.7% on the long-video test LVBench and ties for first on CWE-bench v1 at 68%. Those figures come from Google’s own post.

One independent leaderboard does back part of the story. Vals AI’s Vals Index, which measures models on finance, coding, legal and tax tasks weighted by each sector’s share of U.S. GDP, was updated Sept. 30 and lists Argon first at 68.90%, ahead of Claude Sonnet 5.5 at 67.04% and Claude Opus 5.5 at 66.97%. Google’s post had cited the same index. Vals lists Argon at the post-introductory price of $4 and $20 per million input and output tokens. That is a lead of under two points on a single measure, and it says nothing about cybersecurity defense.

The government link

Google says it is “actively engaged in the U.S. government’s voluntary process for pre-release model access.” The post names no agency. Separately, on Sept. 29, Google CEO Sundar Pichai was among the executives with President Donald Trump at the White House when a voluntary AI accord was released, CBS News reported; see our report on the accord. Google’s post does not connect the two.

Sources and further reading

Share this article