Live
Abstract illustration of a faceted violet hexagonal gem inside a ring of gate-like bars with one opening, through which thin rays reach a small cluster of pink and violet nodes.
AI & ML

Gemini 4 Argon, Explained: Why Google’s Top Model Went to Defenders First

Google’s most capable AI model has a benchmark chart, a price list and an output limit no rival matches. Almost nobody can use it. When Google announced Gemini 4 Argon on Sept. 30, the first line of the rollout plan read: “Today, we’re announcing our new frontier model, Gemini 4 Argon, which is rolling out to a set of trusted cyber defenders through our Fairwind Program,” per Google’s announcement post.

Google's key art for Gemini 4 Argon
Google announced Gemini 4 Argon on Sept. 30. Image: Google

Fairwind is not a beta list for enthusiasts. It launched on Sept. 2 with more than 650 partners worldwide, including government agencies, critical infrastructure operators, technology companies and security vendors, TechWire Asia reports. Developers, businesses and people paying for the Gemini app come later, on a schedule Google has not published.

This guide covers what Argon is, who has it, what it costs and why Google decided its best model should go to security teams before anyone else.

What is Gemini 4 Argon?

Argon is Google’s new flagship, and it breaks the company’s familiar Pro and Flash naming, a shift we tracked in our field guide to AI model names. Its headline technical change is length. “We are significantly expanding the model’s output token limit to an industry-leading 1M tokens, up from the previous 64K tokens,” Google wrote. A token is a fragment of a word, so in plain terms Argon can produce answers roughly 15 times longer than its predecessor could in a single response: entire codebases, long reports, full migrations.

Google’s benchmark claims, all self-reported:

  • DeepSWE v1.1 (software engineering): 77.9%
  • CWE-bench v1 (finding and handling vulnerabilities): 68%
  • AutomationBench (agentic work): 51.3%, which Google ranks first
  • LVBench (long video understanding): 91.7%

Google also says Argon leads the Vals Index, ahead of OpenAI’s GPT-6 Astra and Anthropic’s Fable and Opus models, TechCrunch notes, adding that OpenAI and Anthropic made similar top-of-the-chart claims for their own launches. Treat the list as a company’s description of its own product. Because access is restricted, TechWire Asia points out, independent verification isn’t possible yet.

Why Google gated its best model behind cyber defenders

One sentence in the announcement explains the rollout.

Google's CWE-bench chart comparing Gemini 4 Argon with other models
Google’s own CWE-bench results for Gemini 4 Argon. Image: Google

“Argon can autonomously find, validate, and patch critical software vulnerabilities.” Google, announcing Gemini 4 Argon on Sept. 30

A model that can find a flaw and write the fix can, with different instructions, find the flaw and write the exploit. Google’s bet is to put that capability in defenders’ hands first, so the bugs it uncovers get patched before attackers have a model that finds them too. Its early example comes from the security firm Wiz, which Google says used Argon to uncover “a critical vulnerability exposing sensitive personal information across healthcare software used by hospitals worldwide.” Google did not name the software.

The company lists four layers of safeguards it is testing during the restricted phase: refusals for cyberattack and chemical, biological, radiological and nuclear requests, backed by monitoring of the model’s internal activations; automated red-teaming and adversarial training against indirect prompt injection; chain-of-thought monitoring that can halt execution; and sandboxed, isolated environments for evaluation. “Google said models with capabilities at this level require a phased release, with selected cyber defenders receiving access first,” TechWire Asia reports. Fairwind participants must limit use to cybersecurity, incident response and penetration-testing staff, with controls such as multi-factor authentication.

Washington is involved too, on a voluntary basis. “We are actively engaged in the U.S. government’s voluntary process for pre-release model access while we gradually expand access,” Google wrote.

Anthropic did it first with Mythos and Project Glasswing

Google is following a path Anthropic cut in April. Project Glasswing launched on April 7 with partners including Amazon Web Services, Apple, Cisco, CrowdStrike, Google, Microsoft and Nvidia, plus more than 40 organizations that maintain critical software, all using the restricted Claude Mythos Preview for defensive work. Anthropic committed US$100 million (about CA$139 million) in usage credits and says plainly: “We do not plan to make Claude Mythos Preview generally available.”

What these models produce in practice is now showing up in public disclosures. On Sept. 30, the same day as Argon’s launch, the security firm Horizon3.ai published CVE-2026-61500, a flaw in Rejetto HTTP File Server 3.x, an open-source file-sharing server, that it found with Mythos. The bug: session cookies were signed with keys generated by JavaScript’s Math.random(), which is not cryptographically secure. Mythos spotted that, then found a separate code path leaking outputs from the same random-number stream, and chained the two into forged administrator sessions and remote code execution. Horizon3, a Glasswing participant since July, wrote that the model “did not require follow-on prompting” to find the leak that turned a theoretical weakness into a working attack. Internet-exposed servers on default settings, without custom signing keys set, are affected.

That is the trade in miniature. A defender found and disclosed it. The same reasoning, pointed elsewhere, is what gated releases are meant to slow down. Anthropic’s own testing of how close an open-weight rival came to Mythos at this kind of work is in our report on GLM-5.3.

Gemini 4 Argon price, against Mythos

Argon is cheap for a flagship, at least to start. Google’s prices are per million tokens; Canadian figures are our conversion at about 1.39.

Grouped bar chart of API prices per 1 million tokens: Gemini 4 Argon introductory US$2 input and US$10 output; Argon after the intro period US$4 input and US$20 output; Claude Mythos Preview after the preview US$25 input and US$125 output. Cached Argon input tokens are 95% off.
Even after its introductory price doubles, Argon costs a fraction of Mythos Preview per token. Graphic: prompt/power
Model Input, per 1M tokens Output, per 1M tokens
Gemini 4 Argon, introductory US$2 (about CA$2.78) US$10 (about CA$13.90)
Gemini 4 Argon, after intro period US$4 (about CA$5.56) US$20 (about CA$27.80)
Claude Mythos Preview, after preview US$25 (about CA$34.75) US$125 (about CA$173.75)

Google adds that cached input tokens are 95% off the input price. It has not said how long the introductory period lasts. Mythos Preview pricing is from Anthropic’s Glasswing page and applies to participants after the research preview.

When regular users get Gemini 4 Argon

No date has been announced. Google says access will widen to paid API customers and Google AI Ultra subscribers before broader availability, and TechWire Asia notes no public release date has been given.

Meanwhile the Gemini app is about to get more restrictive at the bottom. Google’s support page says that starting Oct. 9, people using a personal account without an AI subscription will get the Flash-Lite model only. AI Plus keeps Flash-Lite and Flash; AI Pro and AI Ultra keep all three, including Pro. Argon does not appear on that page. “It’s not clear where Gemini 4 Argon will fit in,” 9to5Google wrote on Oct. 3, noting Google hasn’t said whether Argon will count as a Pro model or sit in a new tier above it.

What to do

  • Free or AI Plus users: Argon is not on your horizon. The change that affects you is the Oct. 9 model cutback.
  • Thinking of upgrading to AI Ultra for Argon: wait. Google has named Ultra as an early tier but given no date, and the Gemini app’s model list does not include Argon yet.
  • Developers: paid API access is next in line. When it opens, budget for the intro price to double.
  • Security teams at Canadian hospitals, utilities or software firms: Fairwind is the only route today, and Google has not published its partner list, so we can’t say which Canadian organizations are already in.

Back to that healthcare flaw. Google says Argon found it in software running in hospitals worldwide, but has not said which software, which hospitals or whether a patch has shipped. For now the people able to check that claim are the 650-plus organizations Google chose to show the model to.

// Contributor, AI Explained
Catherine Crowe

Catherine Crowe covers AI explained for prompt/power: the plain-English guides that break down how the technology works, what the jargon means and what it changes for everyday people. Originally from Canada, she writes from New Zealand.

Latest from prompt/power

  1. DeepSeek V4.1 Flash Cut the US AI Lead to 3%. What LiveBench MeasuresOct 6
  2. Ben Affleck Calls AI Job Fears ‘Propaganda.’ He Sold an AI Firm to NetflixOct 6
  3. Cohere’s North 2 Puts AI Agents on a Budget. Toronto Bets on BoringOct 6
  4. How to Stop ChatGPT, Claude, Gemini and Meta AI From Training on Your ChatsOct 6
  5. Musk Is a Trillionaire Again After SpaceX Stock Jumps 7.6%Oct 6

Leave a Reply

Your email address will not be published. Required fields are marked *