# Gemini 4 Argon Opens as a Fairwind-Gated Cyber Frontier — Guardrails Come Later

Times of AI Desk · 2026-09-30 · Models

[https://timesof.ai/2026/09/google-gemini-4-argon](https://timesof.ai/2026/09/google-gemini-4-argon)

> Google DeepMind’s Koray Kavukcuoglu named Gemini 4 Argon for long-horizon software engineering, legal/finance knowledge work, and cyber defense. Trusted Fairwind defenders and U.S. voluntary pre-release get it without cyber guardrails first; paid API and AI Ultra wait on safeguard iteration. Lab-claimed benches lead DeepSWE and AutomationBench; CWE-bench v1 ties peers at 68%. No independent Arena Elo yet.

Google just named the frontier SKU that the September 28 post-training tease only hinted at — and the access order is the story: **unguarded for vetted defenders first**, guarded public API later.

**Google DeepMind** SVP and Google chief AI architect **Koray Kavukcuoglu** announced **Gemini 4 Argon** on September 30 as the lab’s next frontier model for long-horizon software engineering, enterprise knowledge work (legal and finance), and cybersecurity defense. Initial access runs through the **Fairwind** program for trusted cyber defenders and the **U.S. government’s voluntary pre-release** process; Google says internal teams already use it. Broader availability for **paid API** customers and **Google AI Ultra** subscribers is planned only after further guardrail iteration. This is the named Argon launch — not a restatement of the earlier “Gemini 4 in post-training” interview tease.

## Access and pricing

| Cohort | Cyber guardrails | Status |
|--------|------------------|--------|
| Fairwind trusted defenders + Google internal | **Off** (full defensive cyber capability) | Rolling out now |
| U.S. voluntary pre-release testers | Phased / feedback loop | Active |
| Paid API + AI Ultra (developers, enterprises, consumers) | On (misuse/CBRN refusals + monitors) | After iteration |

Introductory API pricing: **$2 / $10** per million input/output tokens, with cached input at **95% off** input. After the intro period: **$4 / $20**. Output context expands to **1M tokens** (from 64K) so the model can sustain hundreds of thousands of tokens in a single trajectory.

## What Google claims it can do

Company-reported highlights (not independent Arena Elo):

| Bench | Claimed result | Caveat |
|-------|----------------|--------|
| DeepSWE v1.1 | **77.9%** (SOTA) | Lab figure; long-horizon SWE |
| AutomationBench (Zapier) | **51.3%**, #1 | Lab figure |
| LVBench (long video) | **91.7%** SOTA | Lab figure |
| Vals Index / Vals Finance / Harvey Legal | “Leading” | Lab framing; sector weights claimed |
| CWE-bench v1 | **68%**, tie for first | Google: tie at 68%; **SecurityWeek** names peers **GPT-6 Astra** and **Grok 4.7** |

Google also cites internal wins: quantum subroutine spacetime cut **40%** vs a published baseline in minutes; Argon agents claimed **>300 TiB** memory freed so far (est. **500 TiB–1 PiB**); Rust migrations including **libgav1** SIMD rewrite claimed **2.7×** faster than a prior Rust port with identical video output — all **company anecdotes**, not third-party audits.

## Defender path and the hospital-software claim

Building on September’s [3.8 Flash Cyber / Fairwind split](https://timesof.ai/2026/09/google-gemini-3-8-flash-cyber-fairwind), Google trained Argon for autonomous find/validate/patch of critical vulnerabilities and will release it **without cyber guardrails** to trusted defenders and internal teams. **Wiz** (via **Scan for Good**) used Argon to uncover a **critical vulnerability exposing sensitive personal information** in healthcare software used by hospitals worldwide — a risk Google says prior frontier models missed. Neither Google nor SecurityWeek **names the software** or states remediation status.

On discovery vs 3.8 Flash Cyber, Google claims gains on an internal multi-language vuln bench (20 languages) and on Wiz’s internal black-box pen-test bench (attack surface, vulns, PoC evidence). Those remain **vendor/partner internal** scores.

## Safeguards before broad GA

Before public API / Ultra, Google lists four safeguard tracks: misuse and **CBRN** refusals with activation monitoring (Frontier Safety Framework); leading claim on **Gray Swan IPI** for indirect prompt injection; chain-of-thought / action **misalignment monitors** that can stop execution; and hardened, sealed sandboxes for high-risk evals. Dual-use framing is explicit: unguarded for vetted defenders, refused for offensive cyber/CBRN on the public path.

## Claims vs checks

All headline benches above are **Google-reported**. **SecurityWeek** (October 1) restates Fairwind access, the unnamed hospital vuln, and the CWE-bench peer names. Independent **LMArena / Chatbot Arena Elo** and Artificial Analysis listings for Argon were **not verified** for this piece — no independent ranks are asserted here. Open questions include a named CVE/vendor for the hospital claim, whether cyber guardrails differ by SKU at GA, and third-party CWE-bench / Vals / Arena replication.

## Limits

- Benchmarks and internal productivity anecdotes are **lab-claimed** only; no independent Arena Elo in sources used.
- Hospital-software product is **unnamed**; remediation unknown.
- CWE peer names (Astra / Grok 4.7) come from **SecurityWeek**, not the Google blog’s own wording.
- Dual-use: unguarded defender access is intentional policy, not a leak — treat carefully; this is not an exploit how-to.
- Distinct from any September 28 post-training tease coverage; this slug is the Argon launch only.

## Sources

- [Google: Gemini 4 Argon (September 30, 2026)](https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-4-argon/)
- [SecurityWeek: Google Launches Gemini 4 Argon With Guardrail-Free Access for Vetted Defenders (October 1, 2026)](https://www.securityweek.com/google-launches-gemini-4-argon-with-guardrail-free-access-for-vetted-defenders/)
- [Times of AI: Gemini 3.8 Flash Cyber via Fairwind (September 2, 2026)](https://timesof.ai/2026/09/google-gemini-3-8-flash-cyber-fairwind)
