Who could use Argon on September 30
Google announced Gemini 4 Argon on September 30, 2026 as its new frontier model and began rolling it out to a set of trusted cyber defenders through its Fairwind Program, the access program it introduced earlier that month with Gemini 3.8 Flash Cyber. Thousands of Google employees were already using it internally. Nobody else could use it on the day: there was no Gemini app or general API release. [1][4][2]
Google said it was taking part in the US government's voluntary process for pre-release model access while it expanded access gradually. It plans to release Argon to developers, enterprises and consumers after gathering feedback from early testers, starting with paid API customers and Google AI Ultra subscribers. It gave no date for that step, and same-day coverage reported none. [1][2][3]
The Fairwind gate
Fairwind gives high-priority defenders, such as governments, healthcare providers and telecommunications operators, early access to advanced models. Google says it works with more than 650 partners, and that a subset of them get exclusive access to Argon, including inside CodeMender, Google's code security agent. Google says it is releasing Argon to these defenders and its own internal teams without cyber guardrails. [4][1]
The terms are specific. Partners may only use it for defensive and academic dual-use work such as authorized threat simulation, reverse engineering and malware analysis. Access is limited to internal security, incident response and penetration testing teams, with user-level authentication, phishing-resistant multi-factor authentication and tracked employee use. Partners may not share, redistribute or sell access, and Google runs background checks on applicants. [4]
Announced pricing
Google said Argon will launch at an introductory price of $2 per million input tokens and $10 per million output tokens, with cached input at 95 percent off the input price. After the introductory period, the price becomes $4 and $20. Google did not say how long the introductory period lasts. These are announced prices for a release that had not reached paying API customers on September 30. [1][2]
What Google reports about the model
The headline technical change is the output limit: Google raised it to 1 million tokens, up from 64,000, so the model can produce hundreds of thousands of tokens of reasoning and output in one run. Google reports 77.9 percent on DeepSWE v1.1, a long-horizon software engineering test, which it calls a new state of the art. 9to5Google's summary of Google's comparison table puts Claude Opus 5.5 at 74.2 percent and GPT-6 Astra at 74.1 percent on the same test. [1][2]
Google also reports that Argon leads the Vals Index of finance, coding, legal and tax work, ranks first on Zapier's AutomationBench at 51.3 percent, scores 91.7 percent on the LVBench long-video test, and ties for first on CWE-bench v1, a vulnerability remediation test, at 68 percent. All of these numbers come from Google's announcement. None had been independently reproduced on the day, and the general public could not yet run the model to check. [1][2]
Google described internal results as well. It says a team of Argon agents identified and applied memory optimizations across its data centers, found in profiling data, that are expected to free more than 300 TiB once rolled out, and that Argon agents rewrote 32,000 lines of SIMD code in a Rust port of the libgav1 video decoder so it ran 2.7 times faster. It says Wiz, through its free Scan for Good program, used Argon to find a critical vulnerability in hospital software that earlier models had missed. These are Google's own accounts. [1]
Safeguards Google says come first
Google listed the work it is doing before broad availability. It says the model refuses cyber and chemical, biological, radiological and nuclear attack requests under its Frontier Safety Framework, with monitoring of internal activations to spot misuse. It says it monitors Argon's chain of thought and actions to stop it going beyond what the user intended, and that it hardens sandboxed environments before high-risk training and evaluation. It also claims the lead on Gray Swan's indirect prompt injection benchmark. [1]
A staged release, like its rivals'
Atlas interpretation: Argon follows a pattern the other frontier labs set in 2026. Anthropic kept Claude Mythos Preview inside an invitation-only program for infrastructure operators, and OpenAI shipped GPT-6 Astra to a first set of organizations with its offensive cyber capability held back for vetted customers. Google's version puts vetted defenders first and the paying public second, which means the people best placed to test Google's benchmark claims are mostly not yet able to. [1][4][3]
Sources
- Gemini 4 Argon: our next era of frontier intelligence
Google · Sep 30, 2026
- Google announces Gemini 4 Argon as its new frontier model
9to5Google · Sep 30, 2026
- Gemini 4 Argon is Here But Not For You
Droid Life · Sep 30, 2026
- Fairwind Program
Google DeepMind · Sep 30, 2026