Google Limits Gemini 4 Argon to Trusted Cyber Defenders First
Google announced Gemini 4 Argon on Sept 30, 2026, but only Fairwind cyber partners get it now. Intro API list is $2/$10 per 1M tokens; public and Ultra dates are still open.

Google announced Gemini 4 Argon on September 30, 2026, and immediately limited who can use it. The new frontier model is rolling out first to trusted cyber defenders through Google’s Fairwind Program, not to the general developer API or consumer Gemini apps.
Koray Kavukcuoglu, SVP at Google DeepMind and Google’s chief AI architect, said in the official Google Blog post that Argon targets long-horizon work in software engineering, legal and finance workflows, and cybersecurity defense. Google says it is also taking part in the U.S. government’s voluntary pre-release model access process while it expands availability.
That timing sits one day after Google CEO Sundar Pichai joined other AI chiefs at the White House for a voluntary Super Intelligence accord. The product is real. The broad public release date is not.
Who Gets Argon Now, and Who Waits
Outside Google’s own teams, Argon is available only to Fairwind members for now. Fairwind launched on September 2, 2026, with Gemini 3.8 Flash Cyber. Google’s Fairwind announcement says the program has more than 650 participating partners globally, aimed at governments, critical infrastructure operators, and cybersecurity partners under strict access rules.
Tulsee Doshi, Google’s Gemini model product lead, told CNBC the gated start puts a cyber-defense-trained model in defenders’ hands sooner while Google builds confidence before a wider launch.
Google says the next groups will be paid API customers and Google AI Ultra subscribers. It has not published a calendar for the United States, Canada, Australia, India, or any other market. Until then, most developers in those countries stay on earlier Gemini models.
Pricing Google Posted for the Launch Window
Google listed an introductory API price of $2 per million input tokens and $10 per million output tokens, with cached input at 95% off the input rate. After the introductory period, Google says rates move to $4 / $20 per million tokens.
That intro list matches OpenAI’s GPT-6.1 Sol and Anthropic’s Claude Sonnet 5.5 list rates, and undercuts Anthropic’s Claude Opus 5.5 at $4 / $20. Those comparisons matter only after Argon opens to paid API customers. Fairwind access pricing for partners is not broken out in the Argon post.
| Item | What Google said | Status |
|---|---|---|
| Intro API price | $2 input / $10 output per 1M tokens; cache 95% off input | Vendor-stated list price |
| Post-intro API price | $4 / $20 per 1M tokens | Vendor-stated |
| Output context | Up to 1M output tokens (prior Gemini cap was 64K) | Vendor-stated |
| Public / Ultra date | Not given; “as soon as possible” after Fairwind feedback | Unconfirmed timing |
| US / CA / AU / IN availability | Not specified by country beyond Fairwind and later paid API / Ultra | Unconfirmed by market |
What Google Claims Argon Can Do
Treat the scores below as Google-reported unless an independent lab republishes them. Google says Argon sets a new state of the art on DeepSWE v1.1 at 77.9% for long-horizon software engineering, leads the Vals Index for finance, coding, legal, and tax style work, ranks first on Zapier’s AutomationBench at 51.3%, and scores 91.7% on LVBench for long video understanding.
On CWE-bench v1, which tests vulnerability remediation, Google says Argon ties for first at 68%. CNBC separately reported Google saying Argon ties OpenAI’s GPT-6 Astra and xAI’s Grok 4.7 on cybersecurity benchmarks. Those charts live on Google’s blog; rivals have not all published matching independent replications for this launch day.
Google also describes internal agent work already running on Argon: quantum researchers cutting spacetime cost of a subroutine by 40% versus a published baseline in minutes; fleet memory optimizations that freed more than 300 TiB so far (Google estimates 500 TiB to 1 PiB total); and large C/C++ to Rust migrations, including work on Fuchsia’s Zircon kernel above 800K lines and a libgav1 Rust path Google says runs 2.7x faster than an earlier Rust port with identical video output. Those are Google’s internal results, not third-party audits.
Why the Cyber Gate Exists
Google trained Argon for defensive cyber work and says Fairwind members and internal teams get a version without the cyber guardrails that would otherwise blunt offensive-capable tooling. Wiz, which Google owns, is already using Argon in its Scan for Good program. Google says the model found a critical exposure in healthcare software used by hospitals worldwide that earlier frontier models had missed. Wiz has not published a separate CVE write-up in the Argon announcement itself, so treat the find as Google-reported.
Before a broad release, Google says it is hardening four areas: misuse refusals for cyber and CBRN harm, prompt-injection resilience (Google claims a lead on Gray Swan’s Indirect Prompt Injection benchmark), misalignment monitors that watch chain-of-thought and actions, and harder sandboxes for high-risk training and evals. The company says Argon is designed to refuse help with cyberattacks or chemical, biological, radiological, and nuclear weapons while still allowing legitimate dual-use research under its Frontier Safety Framework.
That caution tracks a wider industry pattern. OpenAI recently pulled a GPT-6.1 Astra release after alignment tests failed its own bar. Anthropic has also kept some of its strongest models behind trusted-access gates. Google is packaging the same instinct as a product story: ship the cyber-capable stack to defenders first.
Confirmed vs Unconfirmed
| Claim | Status |
|---|---|
| Gemini 4 Argon announced Sept 30, 2026 | Confirmed (Google Blog) |
| Fairwind-only external access at launch | Confirmed (Google Blog) |
| 650+ Fairwind partners | Confirmed for the program (Google Fairwind post, Sept 2); Argon post does not restate the number |
| US voluntary pre-release process engagement | Vendor-stated (Google Blog) |
| Benchmark leads (DeepSWE, Vals, AutomationBench, LVBench, CWE-bench) | Vendor-reported on Google’s charts |
| Wiz healthcare vulnerability find | Vendor-reported by Google; no public CVE in the launch post |
| Exact public / Ultra launch date by country | Unconfirmed |
What It Means for Developers in the US, Canada, Australia, and India
If you build on Gemini today in those markets, nothing in the Argon post changes your current API model IDs. The practical move is to watch for paid API and Google AI Ultra rollout notes, and to compare the $2 / $10 intro list against Claude Opus 5.5 pricing and OpenAI’s Sol tier once Argon is actually callable.
Security and platform teams at firms that already sit in Fairwind can ask their Google Cloud or partner contacts about Argon access and whether their org gets the no-cyber-guardrail defender build. Everyone else should assume the cyber-capable stack stays gated until Google says otherwise.
Indian product and ML teams face the same wait as US, Canadian, and Australian API customers: no India-specific launch window was posted. Budget models and long-context agent designs against today’s public Gemini line, and keep a slot open for a 1M-output model if Google’s claims hold up under third-party evals.
Frequently Asked Questions
What is Gemini 4 Argon?
Google’s September 30, 2026 frontier Gemini model for long-horizon coding, knowledge work, and defensive cybersecurity. It is not yet a general public or open API release.
Who can use Gemini 4 Argon today?
Google’s internal teams and trusted cyber defenders in the Fairwind Program. Paid API customers and Google AI Ultra subscribers are listed as next, without a date.
How much will Gemini 4 Argon cost?
Google lists $2 per million input tokens and $10 per million output tokens at intro, with cached input 95% off input, then $4 / $20 after the intro window. Those are list prices for the eventual API launch, not a public checkout today.
Is Gemini 4 Argon available in India, the US, Canada, or Australia?
Google did not publish country-by-country availability. Fairwind partners can get access where Google admits them. Broader developer and Ultra access remains undated for all four markets.
Should developers trust Google’s Argon benchmarks?
Use them as Google’s launch claims. Prefer independent replications on DeepSWE, Vals, AutomationBench, and cyber suites before rewriting production stacks around Argon-only scores.
1 comment