
Google has released Gemini 4 Argon, its new frontier AI model, but most users cannot access it yet.
The company is starting with a small group of trusted cybersecurity defenders through its Fairwind Program while it tests stronger safety controls.
Meanwhile, Google says Argon can handle long and complex tasks across software engineering, legal and financial work, and cybersecurity. It can also autonomously find, verify, and patch critical software vulnerabilities.
It is due to this level of capability that Google is limiting access for now.
Why Google Is Holding Back Wider Access
Google says releasing a model with Argon’s capabilities requires a phased rollout. As such, the company is participating in the U.S. government’s voluntary pre-release model access process and collecting feedback from early testers before opening the model to developers, businesses, and consumers.
The concern here is that tools built to find security weaknesses can also be useful to attackers, as Google says Argon is designed to refuse harmful requests involving cyberattacks and chemical, biological, radiological, and nuclear threats.
Google is also testing the model against prompt injection attacks, where hidden or malicious instructions attempt to change how an AI system behaves. It is monitoring Argon for cases where the model could take actions beyond what a user intended and says its systems can stop execution when necessary.
What Makes Argon More Sensitive Than a Normal Chatbot
Argon is built for much longer and more complex work than a typical chatbot request. Google expanded its output limit to as much as one million tokens, up from 64,000 tokens, giving the model more room to work through large and complicated tasks in a single run.
Its cybersecurity abilities are also important, where Argon can independently discover vulnerabilities, validate them, and create fixes. On CWE-bench v1, which measures how well AI models can fix software vulnerabilities, Argon scored 68%, tying for first place with OpenAI’s GPT-6 Astra and xAI’s Grok 4.7. This puts Argon among the strongest models tested on the benchmark and helps explain why Google is treating its cybersecurity capabilities more carefully than those of a regular consumer chatbot.
To emphasize this importance, Cybersecurity company Wiz is already using the model through its Scan for Good initiative, where Argon found a critical vulnerability in healthcare software that exposed sensitive personal information and had been missed by previous frontier models.
In addition, Google is giving approved cyber defenders access to Argon without its normal cyber guardrails so they can use the model’s full cybersecurity capabilities for defensive work.
Who Can Use Gemini 4 Argon Right Now
Access is being controlled through the Fairwind Program, and the search engine giant says participating organisations must pass due diligence checks, restrict the model to approved security teams, use strong authentication, and keep track of employee access.
However, Google is not alone in taking this approach. Anthropic runs a similar Cyber Verification Program (CVP), which gives vetted cybersecurity professionals access to Claude’s Opus and Sonnet models with reduced cyber safeguards for defensive work. Its Project Glasswing initiative has also given selected organisations access to more capable Claude models – Claude Mythos – to find and fix vulnerabilities in important software systems.
For Google, its programme prioritises governments and organisations considered important to the public, including healthcare and telecommunications. As such, partners can carry out authorised threat simulations, reverse engineering, malware analysis, and other defensive research, but they cannot share, redistribute, or sell access to the model.
And while Google says wider availability will come later, beginning with paid API customers and Google AI Ultra subscribers, it has not announced a specific date for that broader rollout.
Ultimately, Gemini 4 Argon offers an early look at how Google plans to release AI models that can perform increasingly sensitive tasks, and the company is giving defenders the first access while it strengthens the safeguards needed before putting the same capabilities in far more hands.
