← All posts / Models

No Guardrails for Defenders: Google's Gemini 4 Argon Arrives With 1M-Token Output and a Hospital Vulnerability to Prove It

Google's new frontier model Gemini 4 Argon pairs an industry-first 1M-token output limit with state-of-the-art agentic coding and cyber-defense skills — and launches first, without cyber guardrails, to vetted defenders in the Fairwind Program.

No Guardrails for Defenders: Google's Gemini 4 Argon Arrives With 1M-Token Output and a Hospital Vulnerability to Prove It

On September 30, Google DeepMind announced Gemini 4 Argon, its next frontier model — and then did something unusual with it: instead of shipping it to ChatGPT-scale consumers on day one, the company handed it to a vetted cohort of cybersecurity defenders through its Fairwind Program, with cyber guardrails deliberately removed. The message is twofold. First, Argon is Google’s claim to frontier leadership in real-world software engineering, enterprise knowledge work, and cyber defense. Second, in a year when AI-discovered vulnerabilities are being weaponized within a day of discovery, Google has decided that the safest first users of a model that can autonomously find, validate, and patch critical flaws are the people defending networks — not everyone.

What Argon is

Argon is the first of the Gemini 4 generation, announced by Koray Kavukcuoglu, SVP of Google DeepMind and Chief AI Architect. It is built for long-horizon work: deep, multi-step tasks that unfold over thousands of actions — migrating a codebase, running a financial research pipeline, triaging an attack surface. To sustain that kind of reasoning, Google expanded the model’s output token limit to an industry-leading 1 million tokens per response, up from 64K in previous Gemini generations. When a model has headroom to think and generate for hundreds of thousands of tokens in a single trajectory, it can attack hard problems in one pass rather than fragmenting them across sessions.

Pricing at launch is an introductory $2 per million input tokens and $10 per million output tokens, with cached input at 95% off. After the introductory period, list pricing reverts to $4 and $20 respectively. Independent trackers put Argon’s blended cost per Intelligence Index task at $1.99 versus $3.26 for OpenAI’s GPT-6 Astra — a meaningful efficiency gap if the scores hold up in production.

The numbers Google published

Against GPT-6 Astra and Anthropic’s Claude Opus 5.5, Google reports Argon leading 12–13 of the 18–19 benchmarks it disclosed, with several standout results:

  • DeepSWE v1.1: 77.9% — a new state of the art on real-world, long-horizon software engineering, ahead of Opus 5.5’s 74.2%.
  • LVBench: 91.7% — state of the art in long-video understanding, reflecting strong visual reasoning over extended content.
  • AutomationBench: 51.3%, rank #1 — Zapier’s benchmark for end-to-end execution across core business functions.
  • Vals Index — Argon is the leading model on this index of economic impact across finance, coding, legal, and tax work, with each sector weighted by its contribution to U.S. GDP. It also leads Vals Finance Agent v2 for multi-step financial research and Harvey’s Legal Agent Benchmark for legal research and drafting.
  • Cybersecurity — On CWE-bench v1, which evaluates vulnerability remediation, Argon ties for first at 68%. On internal evaluation it leaps over Gemini 3.8 Flash Cyber: 85.8% on vulnerability discovery versus 71.0%, and 70.9% on penetration testing versus 58.2%, per Fairwind access documentation.

The picture is not uniformly dominant. Independent analysis and community breakdowns note that GPT-6 Astra still wins FrontierSWE v2 and Terminal-Bench Science, and the two models tie on CWE-bench. On Artificial Analysis’ aggregate intelligence index, Argon (High) scored 52.6 against Astra’s 52.7 — statistically level, and slightly behind Claude Opus 5.5 on some measures. Bloomberg reported that some Google staff doubt how the benchmark numbers translate to real work. Argon’s edge, on Google’s own telling, is specialization: long-horizon professional work and defense, not universal domination.

Already changing how Google builds

The most concrete section of the announcement is what Argon agents are already doing inside Google — because these are production numbers, not slideware:

  • Quantum computing: Argon is helping researchers optimize the spacetime resources (qubits × gates) of subroutines that bottleneck real applications. In one example it beat the published baseline by 40% in minutes.
  • Data center efficiency: A team of Argon agents analyzed fleet-wide profiling telemetry and autonomously applied memory optimizations across Google’s data centers, freeing over 300 TiB of memory, with estimated total savings of 500 TiB to 1 PiB.
  • Rust migration at scale: Argon agents are porting C/C++ to Rust across Google — from tens of thousands of lines in core libraries like re2 and libgav1 up to 800K+ lines of the Fuchsia Zircon kernel, with rigorous automated and manual auditing before anything ships. For libgav1, Argon took an existing Rust port and replaced 32K lines of SIMD code through profile-guided experimentation, producing safe Rust that the compiler auto-vectorizes — a memory-safe video decoder running 2.7× faster than the previous port, with identical output.

The Fairwind-first launch, explained

The decision to release first to trusted defenders — and to ship Argon to them without cyber guardrails — is the strategic heart of the launch. For vetted defenders and Google’s internal teams, the model’s full frontier-level cyber capabilities are unlocked. Wiz is already using Argon under its Scan for Good initiative, which finds and remediates high-risk exposures in critical public infrastructure for free.

The proof point Google chose to highlight: in early deployment, Argon uncovered a critical vulnerability exposing sensitive personal information in healthcare software used by hospitals worldwide — a severe risk that previous frontier models had missed. It is difficult to read this as anything other than a direct response to the current moment. Days earlier, OpenAI had disclosed disrupting a coordinated distillation campaign against its models, and an AI-discovered flaw in Rejetto HFS was reportedly exploited in the wild within a day of discovery. Frontier-scale offensive capability is now ambient; Google’s answer is to arm the defense side first.

Google is also engaging with the U.S. government’s voluntary pre-release model access process while it phases in availability — a notable data point for anyone tracking how the White House’s post-memorandum framework is working in practice.

Safeguards before broad release

Before Argon reaches the public, Google says it is strengthening four classes of frontier safeguards:

  1. Misuse defense — refusing harmful cyber and CBRN requests while preserving legitimate dual-use research, with improved monitoring of the model’s internal activations to spot misuse, red-teamed internally and externally.
  2. Prompt injection resilience — through automated red teaming and adversarial training, Argon leads on Gray Swan’s Indirect Prompt Injection benchmark, Google’s most resilient model yet against indirect injection.
  3. Misalignment monitoring — systems that watch Argon’s chain-of-thought and actions and halt execution when the model steps beyond user intent. Notably, Google explicitly calls on the rest of the industry to preserve reasoning transparency “in these pivotal moments of increased capabilities” — a quiet but pointed position in the ongoing debate over hidden reasoning traces.
  4. Hardened sandboxes — isolating and sealing evaluation environments before high-risk training or testing, in line with its agent control roadmap, with practices to be shared with partners.

What happens next

Wider availability comes “as soon as possible,” starting with paid API customers and Google AI Ultra subscribers, after early testers help harden the guardrails. Introductory pricing takes effect at that public launch.

For the frontier race, Argon reframes 2026’s competition in two ways. It makes output capacity — that 1M-token trajectory — a headline capability rather than a footnote, betting that long-horizon agency is won on sustained generation, not just benchmark accuracy. And it makes who gets the model first a safety decision: defenders before developers, vetting before volume. Whether the gated launch reads as prudence or as theater depends entirely on how fast the broader rollout arrives — and on whether models like Argon find hospital-software flaws faster than adversaries find ways to use them.


Coverage based on Google’s announcement, security-press reporting, and independent benchmark analysis linked above.