Google Locks Gemini 4 Argon to Vetted Cyber Defenders, Citing Its Hacking Power
The new frontier model tops Anthropic's Claude Opus 5.5 on most benchmarks. Google is giving first access to 650 security organizations and the U.S. government.

Google on Wednesday unveiled Gemini 4 Argon, its newest frontier AI model, and said it will not release it broadly at first because its cyber capabilities could be misused for attacks. Initial access is limited to vetted security organizations through a program called Fairwind, along with Google's own internal teams.
The Fairwind Program launched Sept. 3 and has already enrolled more than 650 organizations, including CrowdStrike and Palo Alto Networks, according to SiliconANGLE. Paying developers and Google AI Ultra subscribers are next in line. "Safely releasing frontier capabilities at this level requires a phased approach," said Koray Kavukcuoglu, Google's chief AI architect. Trusted defenders and Google teams get Argon without cyber-specific guardrails so they can use its full defensive abilities, and the U.S. government is getting early access as part of a voluntary pre-release evaluation process.
Argon is designed for long, multi-step work in software engineering, enterprise tasks and security, and Google says it is trained to find, validate and patch software vulnerabilities on its own. On benchmarks, SiliconANGLE reports, it scored 77.9 percent on DeepSWE v1.1 against 74.2 percent for Anthropic's Claude Opus 5.5, and 51.3 percent against 42.5 percent on AutomationBench. Of 18 benchmarks Google measured, Argon led outright on 12.
Google also described internal use. Its teams have run Argon agents on large engineering jobs, including converting more than 800,000 lines of C and C++ code to Rust and freeing more than 300 tebibytes of wasted memory across data centers. The company says Argon includes defenses against prompt injection and separate monitors that watch the model's chain of thought to stop unintended actions.
Launch pricing is $2 per million input tokens and $10 per million output tokens, according to the report, with rates set to rise later to $4 and $20, matching Anthropic's pricing.
The approach also reflects a competitive reality. Google is describing Argon as ahead of rivals on most of the measures it published, and those figures come from Google's own benchmarking, so independent testing will matter once more people can use the model. Defenders get the model first because the same skills that let it find and patch a flaw can in principle be turned toward exploiting one. Google says the staged rollout is meant to give security teams a head start before wider access begins.
The restricted release comes as the Federal Trade Commission opens an investigation into OpenAI, Anthropic and other AI companies over consumer risks, and shortly after the White House announced a voluntary AI accord with no legal force. Withholding a flagship model from the public because of its offensive potential is rare for a company racing rivals on capability. It suggests the largest labs now treat cyber ability as a release-gating risk, and that the first real test of voluntary government pre-release review is underway.
