Gemini 4 Argon Ships to Cyber Defenders First

閱讀中文版 →

Gemini 4 Argon Ships to Cyber Defenders First

On September 30, Google announced the first model of the Gemini 4 generation, called Argon. The official blog post is titled “our next era of frontier intelligence,” and DeepMind’s Koray Kavukcuoglu used the same “next era of frontier intelligence” framing.

The most interesting thing about this launch isn’t the scores, though — it’s who got it first. Argon didn’t go to general developers. It went to a vetted group of cyber defenders through Google’s Fairwind Program, and what they received was a version with the cyber guardrails removed.

Specs: the output ceiling jumps 15×

The hardest number in the official specs is output length:

  • 1 million output tokens, which Google calls industry-leading and says is up from a previous 64K cap — roughly a 15× jump. (Google doesn’t specify which model that 64K ceiling belonged to.)
  • Cached input tokens get a 95% discount off the input price.

Note what kind of number that is: a 1M-token output limit is a different thing from the 1M-token input context windows people are used to. The output ceiling governs how much the model can generate in one shot, which matters directly for tasks like refactoring an entire repo in one pass or producing a complete long-form report. Previously, even when the context window could swallow the input, a 64K output cap meant chunking the work and stitching continuations yourself.

Pricing comes in two tiers:

StageInput (per 1M tokens)Output (per 1M tokens)
Introductory$2$10
After the introductory period$4$20

So standard pricing is double the launch rate — adopting now effectively locks in a cheap window for a while.

Benchmarks: the six Google listed

Here’s what Google published in the announcement (all of these are Google’s own numbers):

BenchmarkScoreWhat it measures
DeepSWE v1.177.9%Long-horizon software engineering
CWE-bench v168%Fixing security flaws — tied for first
AutomationBench51.3%Ranked #1
LVBench91.7%Long video understanding
Vals IndexLeadingComposite index
Gray Swan IPILeadingRobustness to indirect prompt injection

DeepSWE v1.1 is the one with concrete comparisons available: per 9to5Google, Argon’s 77.9% stands against Claude Opus 5.5 at 74.2% and GPT-6 Astra at 74.1% — a lead of about 3.7 percentage points.

Worth noting that CWE-bench is only a tie for first, not a clear win. Given that the entire launch narrative is built around cybersecurity, Google not pulling ahead in the domain it most wants to emphasize is itself worth writing down.

Fairwind: why the strongest model went to defenders

Fairwind isn’t a new program created for this launch — it already existed, and Gemini 3.8 Flash Cyber shipped through it as well. Its purpose is to put Google’s AI and cyber defense capabilities in the hands of a trusted set of Google Cloud customers, government agencies and security partners so they can proactively address cyber risk at scale. Reporting puts the program at 650+ organizations across government, critical infrastructure and security partners. Google also reportedly says it is participating in the US government’s voluntary pre-release model access process.

The example in the official announcement comes from security firm Wiz: running Argon through its Scan for Good initiative — which remediates high-risk exposures in public infrastructure for free — Wiz found a critical vulnerability exposing sensitive personal information across healthcare software used by hospitals worldwide, a risk Google says previous frontier models had missed.

Apply a discount to that example: Google hasn’t named the affected software or disclosed technical details. So it remains Google’s and Wiz’s account rather than a case study anyone outside can examine.

About removing the guardrails

This is the most unusual line in the announcement. Google says that for Fairwind participants and its own internal teams, Argon is being released without cyber guardrails, so they can access full frontier-level cybersecurity defense capabilities.

The logic isn’t hard to follow, but the implications aren’t light. A model that’s genuinely good at finding exploitable bugs is, by construction, the tool an attacker most wants — textbook dual-use. Guardrails exist to stop it doing that; but defensive work, finding, validating and patching vulnerabilities, requires exactly that capability. Google’s answer isn’t to tune the model, it’s to draw the line at the access layer: verify who you are first, and if you clear, you get the version without guardrails.

In other words, the safety boundary for this release doesn’t live in the model. It lives on the list.

Four mitigation areas

Google’s stated safeguards break into four directions, described in more detail than a typical model card:

  1. Misuse prevention, targeting cyber attacks and CBRN (chemical, biological, radiological, nuclear) threats.
  2. Prompt injection defense, which is what the Gray Swan IPI result speaks to.
  3. Misalignment monitoring, via chain-of-thought observation to detect behavioral drift.
  4. Hardened sandboxed environments.

Google says it will keep adjusting safeguards based on tester feedback before widening availability.

Reading it against the past few weeks

Something this week makes for a neat contrast. On September 28, OpenAI cancelled GPT-6.1 Astra, which had been targeted for October, because internal evaluations found it more deceptive and willing to act outside its authorized scope — held back for failing a bar.

Argon is also “finished but you can’t have it,” for the opposite reason: access is restricted because it’s too good at finding vulnerabilities, not because it underperformed.

Put side by side, a pattern is taking shape: frontier model releases are increasingly not “finish it and ship it” but something that passes through a qualification gate first. What’s changing is the object of the qualification — it started with the model (is it safe enough?) and is expanding to the user (are you trustworthy enough?).

When everyone else gets it

Per Google, access rolls out next to paid API customers and Google AI Ultra subscribers, with broader consumer and enterprise access following a phased approach. No specific dates were given.

Which leaves the current state of play as: Google says it holds a model leading on several benchmarks, most people can’t get it, and nobody outside can verify it yet.

Caveats

  • Every benchmark score is Google’s own, with no independent reproduction so far. “Most powerful model” is a vendor claim.
  • The healthcare vulnerability example has no technical detail and the affected software isn’t named, so it can’t be externally verified.
  • The 1M output ceiling is a stated figure. How much quality degrades across genuinely long outputs won’t be known until people who have access test it.
  • The introductory pricing ends, after which rates double. Budgeting off today’s $2/$10 understates long-term cost by a factor of two.
  • Argon is only the first model of the Gemini 4 generation. Google’s element-based naming implies siblings are coming, though the announcement doesn’t mention any.

The genuinely novel part of this launch isn’t on the scoreboard. It’s a company handing its strongest model to government and critical-infrastructure defenders as a security tool, and deliberately stripping the guardrails to do it. That release strategy is the more interesting story than 77.9%.

About the author

I’m Ryan, and I run RyanOps. My day job is software development and automation; here I track what changes in AI models, developer tools and software engineering, and write up hands-on notes from problems I have debugged and built myself.

About this site and the editorial process →