Skip to content
AI

Google Will Ship Gemini 4 Argon Without Cyber Guardrails

Google announced its new frontier model on 30 September 2026 and said a vetted group of cyber defenders, along with its own internal teams, will get a version with the cyber safety restrictions removed. Everyone else waits.

By
· Updated 3 min read
inLinkedIn𝕏Post
Google data centre, Council Bluffs, Iowa
Google data centre, Council Bluffs, Iowa · chaddavis.photography from United States · CC BY 2.0 · via Wikimedia Commons

Google said on 30 September 2026 that it will release Gemini 4 Argon, its new frontier model, without cyber guardrails to a set of trusted cyber defenders and to its own internal teams. Everyone else waits for a guarded version with no announced date.

For trusted defenders and our own internal teams at Google, we'll be releasing Argon without cyber guardrails so they can leverage its full frontier-level cybersecurity defense capabilities.

— Koray Kavukcuoglu, SVP, Google DeepMind and Chief AI Architect, Google

The route in is the Fairwind Program, launched on 2 September 2026, which Google says has more than 650 participating partners worldwide. Admission is staged across governments and national cyber authorities, critical infrastructure operators and what Google calls core technology platforms. Participants agree to limit access to their own cybersecurity, incident response or penetration testing staff and to deploy multi-factor authentication. Google says it is engaged in the United States government's voluntary process for pre-release model access, with paid API customers and Google AI Ultra subscribers next.

What Google reports the model doing

Google says Argon can autonomously find, validate and patch critical software vulnerabilities, and that it ties for first place on CWE-bench v1 with a score of 68 per cent. CWE-bench is a third-party benchmark. The rest of the cyber evidence is not. Argon beat its predecessor on Google's own internal vulnerability benchmark across 20 programming languages and on Wiz's internal black-box penetration benchmark, neither with published methodology. Google also says Wiz, a Fairwind partner, used Argon through its Scan for Good initiative to find a critical vulnerability exposing personal information in healthcare software used by hospitals worldwide, which earlier frontier models had missed.

Away from security, the headline change is capacity: the output token limit rises to 1 million from 64,000. Google reports a state of the art 77.9 per cent on DeepSWE v1.1 for long-horizon software engineering, first on Zapier's AutomationBench at 51.3 per cent and 91.7 per cent on LVBench for long video understanding. Pricing starts at $2 per million input tokens and $10 per million output, with cached input discounted 95 per cent, and a footnote says the rate doubles once the introductory period expires.

The gap in the record

The honest reading is that Google has inverted the usual order of a staged release. Restricted launches normally keep a capability from everyone until safeguards are ready. Here the restriction governs who goes first, and the cohort at the front is the one receiving the model with its cyber limits deliberately switched off. The defensive logic is real: Google argues early access gives defenders time to harden systems before attackers reach the same capability, and the Fairwind terms are stricter than most launches impose.

What is missing is anyone outside the arrangement who can check the numbers. Google's announcement does not say how many of the 650-plus Fairwind partners are in the initial Argon cohort, does not publish the vetting criteria, and does not describe what separates the unguarded build from the one developers will get. The access restriction that makes the release notable also makes independent replication impossible for now.

The safeguards Google calls unfinished

Google lists four areas it is still strengthening before broad availability: refusing cyber and CBRN misuse under its Frontier Safety Framework, including monitoring the model's internal activations; resistance to indirect prompt injection, measured on Gray Swan's benchmark; misalignment monitoring that watches Argon's chain of thought and halts execution when needed; and sandboxes sealed before high-risk training. Google says it took care not to feed monitoring findings back into training, to avoid shaping the model's reasoning to evade the monitors.

The internal deployment is substantial. Google says thousands of its staff use Argon, and that Argon agents found memory optimisations across its data centres that will free more than 300 TiB once deployed. For libgav1, Google's open source video decoder, agents replaced 32,000 lines of hand-written SIMD code with safe Rust that runs 2.7 times faster than the previous Rust port.

Google is removing the cyber guardrails from a model in the same line as the one it confirmed on 18 September had accessed protected systems at three real companies during a May evaluation, as Parallax Nexus reported. The vetting of the 650 now matters more than the benchmarks.

What happens next?

  • Google has not given a date for the guarded release to paid API customers and Google AI Ultra subscribers.
  • Independent evaluators cannot benchmark the cyber claims until access widens, so the first outside numbers will come from Fairwind participants if they publish.
  • The US government's voluntary pre-release review of Argon is under way, with no stated completion date.
  • Watch whether any Fairwind partner discloses a vulnerability found with Argon, which would be the first external evidence of the capability.

Sources & references

  1. 01Gemini 4 Argon: our next era of frontier intelligence — Googlecompany30 September 2026, by Koray Kavukcuoglu; source of the guardrails statement, benchmark scores, pricing and internal deployment figures.
  2. 02Proactive cyber defense for governments and enterprises — Googlecompany2 September 2026, by Four Flynn; source of the Fairwind partner count, eligibility tiers and access conditions.
  3. 03Google rolls out new Gemini AI model but restricts access over safety concerns — The Guardian (Agence France-Presse)news1 October 2026; wire account of the restricted rollout.
  4. 04Google Returns to the Frontier With Gemini 4 Argon — Futurum Groupreport1 October 2026; analyst context on Argon as the first frontier model since Gemini 3.1 Pro.
  5. 05Google's latest launch puts its AI ambitions to the test — Los Angeles Timesnews1 October 2026; on the abandoned Gemini 3.5 Pro release and market reaction.
Published 2 October 2026 · Updated 2 October 2026 · Report a correction · How we use AI
inLinkedIn𝕏Post

More from Artificial Intelligence

View all
AI

AMD Buys a Model Lab to Learn What Its Chips Must Run

AMD said on 28 September 2026 that it has agreed to acquire World Labs, the spatial-intelligence lab founded by Fei-Fei Li in 2024, in an all-stock transaction valued at about $8.2 billion and expected to close by the end of the year. Li becomes an executive vice president and chief scientist reporting to chief executive Lisa Su.

4 min read
AI

8,000 Mathematicians Object to How AI Labs Announce Proofs

The declaration argues that AI companies announcing solutions in a rush strips out attribution, method and the human transmission of ideas. OpenAI says an internal model has resolved more than 100 open problems since late August, and has published none of them.

3 min read
AI

Alibaba Targets a 10-Trillion-Parameter Model and 20 Gigawatts

Alibaba plans to train a model of 5 trillion to 10 trillion parameters, unveiled the Zhenwu V900 accelerator from its T-Head unit, and set a target for Alibaba Cloud data centre capacity above 20 GW by 2032, chief executive Eddie Wu said on 22 September 2026.

3 min read
AI

OpenAI Asks Washington to Write the Rules for Self-Improving AI

OpenAI said on 21 September 2026 that the United States should lead an international effort to set technical standards for frontier AI, including for recursive self-improvement. The proposal would run through national AI safety institutes and would not license models or require pre-release review. Sam Altman briefs the UN Security Council on 23 September.

4 min read