Google Built Gemini 4 Argon, Then Decided the Public Could Not Have It Yet
Introduction
On the afternoon of Wednesday, September 30, Alphabet's Google announced a new flagship artificial intelligence model, Gemini 4 Argon, and in the same breath told almost nobody they could use it. The model is not shipping to developers, enterprises, or consumers this week. It is going to a small group of vetted cyber defenders through Google's Fairwind Program, and Google says it will gather their feedback before anyone else gets access.
The framing is deliberate. In Google's own announcement, chief AI architect Koray Kavukcuoglu wrote that "safely releasing frontier capabilities at this level requires a phased approach." Reuters, reporting the same day, described the model as larger than Google's previous top-tier Pro line and said a Google spokesperson viewed it as comparable to rival frontier systems from OpenAI and Anthropic on key coding and cyber benchmarks. Google gave no timeline for public release.
This is the largest story in artificial intelligence this week, and not simply because a new model exists. It is the clearest illustration yet of an industry-wide reversal: the leading labs stopped arguing about how quickly to ship their most capable systems and started arguing about how to ship them slowly.
Main Content
The benchmark picture is genuinely mixed
Argon's headline numbers look strong. Google says it sets a new state of the art on DeepSWE v1.1 at 77.9 percent, a benchmark measuring real-world long-horizon software engineering tasks. It ranks first on Zapier's AutomationBench at 51.3 percent, and leads the Vals Index, which weights finance, coding, legal, and tax work by their contribution to US GDP.
But independent analysis is more measured. The New Stack went through Google's published comparisons and found Argon takes top billing outright or tied in 13 of 18 tests against Anthropic's Opus 5.5 and Fable 5.1 and OpenAI's GPT-6 Astra. It also placed last among the competing models on both FrontierSWE v2 and Terminal-Bench 4.0, trailing by 10.5 and 9 points respectively.
The legal numbers deserve particular attention. Argon scores 19.6 percent on Harvey's Legal Agent Benchmark, nearly triple what Fable 5.1 manages. That is a large relative margin, but it also means the model fully completes roughly one in five legal tasks. On GraphWalks, for inputs between 256K and one million tokens, Argon scores 84.2 percent, more than 12 points ahead of GPT-6 Astra. On the Vibe Code Bench it wins with 91.9 percent, though all four models score above 89 percent.
One caveat that matters for anyone reading leaderboards: on CWE-bench v1, where Argon ties GPT-6 Astra and xAI's Grok 4.7 at 68 percent with Opus 5.5 one point behind, the OpenAI and Anthropic models run inside their own agent harnesses, Codex and Claude Code. Those scores measure a model together with its tooling, not the model in isolation.
A million output tokens, and why Google thinks that matters
Perhaps the most technically interesting change is not a benchmark at all. Google raised Argon's output token limit to one million, up from the 64,000 ceiling on previous Gemini models. One million input tokens is already standard among frontier models; matching that figure on the output side is not.
Google's argument is about reasoning depth rather than raw throughput. When a model has room to think through hundreds of thousands of tokens in a single trajectory, it can attempt problems in one pass that otherwise require many rounds. The practical effect is on long, unattended work.
That claim gets support from an unexpected corner of Google's own infrastructure. According to Google, Argon agents analyzed fleet-wide profiling telemetry across the company's data centers and autonomously identified and applied memory optimizations, freeing more than 300 tebibytes of memory once rolled out, with total savings estimated between 500 tebibytes and one pebibyte, achieved without new hardware.
The model is also being used on quantum computing research. Google said Argon helped researchers optimize the spacetime resources of subroutines that bottleneck important quantum applications, beating a published baseline by 40 percent in a matter of minutes. And Argon agents are migrating C and C++ code to Rust across Google, scaling from tens of thousands of lines in core libraries like re2 and libgav1 up to more than 800,000 lines for the Fuchsia OS Zircon kernel. For libgav1, Google's open-source video decoder, agents replaced 32,000 lines of hand-written SIMD code and produced a memory-safe decoder running 2.7 times faster than the previous Rust port with identical video output.
Google notes that such large-scale rewrites undergo rigorous automated and manual auditing, emulation testing, and review before reaching production.
The cybersecurity story is the actual headline
Argon was trained specifically to find, validate, and patch critical software vulnerabilities, and for trusted defenders plus Google's own internal teams it will be released without cyber guardrails. The rationale is asymmetry: a model good enough to find real flaws is also good enough to find new ones for attackers.
The headline result comes via Wiz, the security company Google acquired for $32 billion in March, which is already using Argon through its Scan for Good initiative, a program that hunts high-risk exposures in critical public infrastructure for free. Google says Argon uncovered a critical vulnerability exposing sensitive personal information across healthcare software used by hospitals worldwide, a flaw previous frontier models had missed.
There is a sharper context for that claim. In August 2026, attackers drained Lightning nodes running BTCPay Server after a flaw surfaced in an AI-assisted review of the code, and victims included hardware-wallet maker Foundation and bitcoin publication Citadel21. A flood of AI-generated bug reports later turned up real flaws in Core Lightning. In July, 1,367 BTC worth nearly $89 million was swept from Coldcard hardware wallets through a five-year-old firmware flaw; Coinkite said it believed someone had used frontier AI to review its public code, though that has not been proven.
Safety is now the product roadmap
What makes this announcement unusual is how much of it is about what Google has not yet built. Four safeguard areas are detailed in the release, and each implies ongoing work rather than a solved problem.
Argon refuses requests that could support cyber or chemical, biological, radiological, and nuclear attacks, per Google's Frontier Safety Framework, while preserving legitimate dual-use research. On prompt injection, Google claims Argon is its most resilient model yet and leads on Gray Swan's Indirect Prompt Injection benchmark. For misalignment, Google is deploying systems that monitor the model's chain of thought and actions and halt execution when necessary. It also hardened its sandboxed environments by isolating and sealing them before high-risk training or evaluations begin, and says it will share those agent security practices with partners.
The chain-of-thought monitoring piece carries a notable caution. Google says it deliberately avoided feeding its own monitoring findings back into training, to avoid shaping Argon's reasoning in ways that would let it evade surveillance. It also asks the rest of the industry to preserve reasoning transparency during capability jumps.
The context: a voluntary pact with no teeth
Argon landed one day after an unusual event at the White House, where OpenAI, Google, Meta, Anthropic, Nvidia, and xAI signed a one-page voluntary accord pledging to submit their AI safety controls to outside auditors. CoinDesk noted the document carries no enforcement mechanism, no disclosure requirement, and no implementation deadline; companies pick their own auditors. President Trump called it "morally binding" and said the firms would have to self-police.
Argon also arrives in a field where two rivals are holding their best work back. Anthropic has kept Claude Mythos Preview restricted to a small number of trusted organisations, and per Reuters Washington briefly forced Anthropic to suspend access to publicly released models in June before establishing the current voluntary pre-release process. Meanwhile OpenAI shelved the planned October release of GPT-6.1 Astra, saying the model improved at finishing tasks but fell short on staying within user authorisation and on reporting accurately what it had done.
Conclusion
Google is pricing Argon at $2 per million input tokens and $10 per million output tokens during an introductory period, rising to $4 and $20 afterward, with cached inputs discounted by 95 percent. Google says release will begin with paid API customers and Google AI Ultra subscribers.
The competitive question is not whether Argon is good. It is whether a model this capable is worth having in the hands of people who did not build it, and Google has answered by not handing it over. That answer is now the industry default rather than the exception, which means the real constraint on frontier AI in 2026 is shaping up to be distribution discipline, not compute, and not research.
For cybersecurity teams watching Argon's progress, the early results are already the point of interest: if a model can find a healthcare-data flaw that prior frontier systems missed, the same capability aimed outward is the scenario every safeguard in that release is trying to address.
Images
![]()
![]()
![]()
References
- Gemini 4 Argon: our next era of frontier intelligence — Google
- Google announces Gemini 4 flagship AI model after months of delays — Reuters
- Gemini 4 Argon is here: It's great, and you can't have it yet — The New Stack
- Google launches Gemini 4 Argon to reclaim the AI frontier — Business Insider
- OpenAI, Google and Meta pledge independent AI safety audits under voluntary White House deal — CoinDesk
- Google restricts access to new AI model over safety concerns — The Straits Times