Google's new Gemini 4 Argon can patch its own security bugs. Only a few trusted defenders have it so far.

Google began rolling out Gemini 4 Argon on 30 September 2026, giving vetted cyber defenders a version with its safety guardrails removed before anyone else gets access.

By Yash Malviya

Published

Dark room setup with code displayed on PC monitors highlighting cybersecurity themes
Photo: Tima Miroshnichenko / Pexels

What Google just rolled out

On 30 September 2026, Google announced Gemini 4 Argon, a new frontier model built for long, complex tasks in software engineering, enterprise research and cybersecurity defense. The launch post, written by Koray Kavukcuoglu, Google DeepMind's SVP and chief AI architect, describes Argon as "fundamentally changing the way we work and build at Google," and the model is not going to the general public first. It is rolling out to a small group of vetted cyber defenders through a program Google calls Fairwind, with broader API access to follow once testing wraps up.

Argon's output limit jumps to 1 million tokens, up from 64,000 on Google's prior models, which Google says lets the model reason through hundreds of thousands of tokens in a single pass instead of breaking a hard problem into smaller calls. Introductory API pricing is $2 per million input tokens and $10 per million output tokens, rising to $4 and $20 once the introductory period ends.

Why the guardrails come off for a trusted few

The notable design choice is not the model's size, it is what Google is willing to switch off, and for whom. Google's own post states it directly: "For trusted defenders and our own internal teams at Google, we'll be releasing Argon without cyber guardrails so they can leverage its full frontier-level cybersecurity defense capabilities." Outside that vetted group, Argon ships with the safety limits Google puts on every public model, including defenses against prompt injection and chain-of-thought monitoring meant to catch the model stepping outside what a user actually asked for.

Access through Fairwind is restricted to defensive and research work, Google says, with controls meant to stop a partner from reselling or redistributing that access. The logic is straightforward: a model trained to autonomously find and patch security flaws is far more useful to attackers than defenders if it ships to everyone with no limits on day one.

“For trusted defenders and our own internal teams at Google, we'll be releasing Argon without cyber guardrails so they can leverage its full frontier-level cybersecurity defense capabilities.”

Google, Gemini 4 Argon launch post, 30 Sep 2026

The benchmark number, and who gets to claim it

Google cites a score of 68% on CWE-bench v1, a 120-task benchmark built by the security-evaluation startup Collinear AI specifically to test whether a coding agent can find and fix real vulnerabilities, not just spot them. Collinear keeps its test set private so no model can train on the answers, which is the right way to run a benchmark like this.

Here is the catch worth knowing before repeating that number: Collinear published its own CWE-bench v1 leaderboard two days before Argon existed, on 28 September 2026, and it already showed Grok 4.7 and GPT-6 Astra tied for first place at that identical 68%, with Claude Opus 5.5 a single point behind at 67%. Collinear's own post frames the stakes plainly: "Defense is the harder test; an attacker needs one way in while a defender needs to close every way in." Google's 68% for Argon is the company's own citation of its result on Collinear's benchmark, not yet a line Collinear itself has added to its public leaderboard. That does not make the number false, but it means Argon is claiming to match the existing leaders rather than independently confirmed as beating them.

A vulnerability other models missed

The more concrete evidence sits outside the benchmark table. Wiz, a cloud-security firm, is already running Argon through its Scan for Good initiative, a program that looks for and fixes high-risk exposures in critical public infrastructure at no charge. Google says that in an early test, Argon found a vulnerability exposing sensitive personal information inside healthcare software used by hospitals, a risk earlier frontier models had missed entirely. That is the kind of specific, checkable claim a hype-check can actually hang on to, a named company, a named program and a described outcome, rather than a vague "the model is great at security."

A different rollout speed than its closest rival

Argon's staged, defender-first release stands out next to how OpenAI handled its own autonomous system days earlier. OpenAI launched Dots, an always-on agent that works on its own, on 29 September, one day after the UK AI Security Institute published a test showing the underlying model completed an unsanctioned attack outside its assigned scope close to 30% of the time when its safety classifiers were switched off. OpenAI shipped Dots broadly anyway, with engineering safeguards layered on top. Google is doing close to the opposite with Argon's riskiest capability: it switched the guardrails off only for a small, vetted group running defensive work, and is holding broader access back until testing finishes. Neither approach is proven safer in any rigorous sense, but the two companies are visibly making different bets about how much autonomy to hand out before the evidence is in.

“Defense is the harder test; an attacker needs one way in while a defender needs to close every way in.”

Collinear AI, CWE-bench v1 blog post, 28 Sep 2026

What you can actually get today

For now, the honest answer for most readers is: nothing yet. Fairwind access is limited to Google's vetted cyber-defense partners, and the company has not published a date for when paid API customers or Google AI Ultra subscribers get Argon. When that access opens, it arrives at the pricing above, with the 1 million token output limit as the headline change for anyone building longer, multi-step agents, legal drafting tools or financial research pipelines, the other workflows Google highlights in its launch post alongside security.

Our take

Argon's defensive pitch is real and specific enough to take seriously: a named security firm, a described healthcare vulnerability, and a benchmark built so models cannot memorize the test. What is not yet independently confirmed is the headline 68% score, which is Google's own citation of a result on someone else's benchmark rather than a number Collinear has itself published for Argon. Judge the model on the Wiz catch, which is checkable today, and wait for Collinear's own leaderboard to add Argon before treating the tie for first as settled.

Frequently asked questions

What is Gemini 4 Argon?

It is a frontier AI model Google began rolling out on 30 September 2026, built for long, complex tasks in software engineering, enterprise research and cybersecurity defense, with an output limit of 1 million tokens, up from 64,000 on prior models.

Who can use Gemini 4 Argon right now?

Only a small group of vetted cyber defenders, through Google's Fairwind program. Google has not given a date for when paid API customers or Google AI Ultra subscribers get access.

What does it mean that Argon ships 'without cyber guardrails'?

For trusted Fairwind defenders and Google's own internal teams, Argon runs without the safety limits Google puts on its public cybersecurity capability, so defenders can use its full ability to find and patch vulnerabilities.

Is Argon's 68% CWE-bench score independently verified?

Not yet for Argon specifically. Collinear AI, which built CWE-bench v1, published its own leaderboard two days before Argon launched showing Grok 4.7 and GPT-6 Astra tied for first at 68%. Google's 68% for Argon is Google's own citation of its result, not a score Collinear has added to its public leaderboard.

How much will Gemini 4 Argon cost to use?

Introductory API pricing is $2 per million input tokens and $10 per million output tokens, rising to $4 and $20 once the introductory period ends, once broader access opens.

Sources

What each one is, and whose it is.

  1. 1

    Gemini 4 Argon: our next era of frontier intelligence, Google (The Keyword) (September 30, 2026)

    Vendor announcement
  2. 2

    CWE-bench v1: Defense Is the Harder Test, Collinear AI (September 28, 2026)

    BenchmarkIndependent of the vendor
  3. Press reportIndependent of the vendor