Google is putting **Gemini 4 Argon** in front of vetted cyber defenders before the rest of the market — and stripping **cyber guardrails** for that Fairwind cohort and Google’s own security teams — while it says it is still hardening misuse, prompt-injection, and misalignment controls ahead of any broad launch.
In a September 30, 2026 Google DeepMind blog post, SVP Koray Kavukcuoglu introduced Argon as Google’s new frontier model for long-horizon software engineering, enterprise knowledge work, and cybersecurity defense. The company is not opening a public API or Google AI Ultra switch today. Access starts through the **Fairwind Program**: trusted cyber partners plus Google internal users get the model **without cyber guardrails** so they can run full frontier-level defensive vulnerability work. Everyone else waits on a phased plan Google ties to early tester feedback, guardrail iteration, and the U.S. government’s **voluntary pre-release model access** process. Broader availability to developers, enterprises, and consumers is promised only “**as soon as possible**,” starting with **paid API** customers and **Google AI Ultra** subscribers — **with no calendar date** in the announcement.
## Fairwind first, not self-serve
Fairwind launched September 2, 2026 as a limited program for governments, Google Cloud customers, and cybersecurity partners, originally around **Gemini 3.8 Flash Cyber** and Google’s **CodeMender** harness. DeepMind now says a set of Fairwind partners get exclusive Argon access — alone or with CodeMender — and that the program works with **more than 650** partners globally. Priority seats go to national cyber authorities, critical-infrastructure operators (healthcare, telecom, energy, finance), and core technology platforms; academic labs doing defensive benchmarking may apply. Access is vetted, limited to internal cybersecurity / incident-response / penetration-testing teams, and barred from sharing or reselling.
That structure is the story: Google is treating Argon’s cyber offense-adjacent power as something to stage behind identity, partner diligence, and (for the general public) refusal training — while giving approved defenders the ungated defensive stack first.
## What Google claims Argon can do
Google says Argon can **autonomously find, validate, and patch** critical software vulnerabilities, and that it sustains deep multi-step agent work with an industry-leading **1 million** output-token limit (up from 64K). It cites frontier coding and knowledge-work scores, and — on defensive remediation — a **68%** top score on **CWE-bench v1**, which Google describes as tying for first. Collinear AI’s public CWE-bench v1 leaderboard confirms that figure as a **three-way tie** with OpenAI’s GPT-6 Astra and xAI’s Grok 4.7. Treat Collinear as a third-party bench, not a Google/Wiz shop floor.
Separately, Google points to **Google-internal** vulnerability discovery across 20 languages and a **Wiz-internal** black-box web pentest where Argon beat 3.8 Flash Cyber. It also says Wiz is using Argon in **Scan for Good** and that the model found a critical personal-data exposure in healthcare software used by hospitals worldwide — without naming the product or a CVE. Those Google/Wiz lines are **not independent evals**; Wiz is Google-owned. Flag anything beyond Collinear’s published 68% tie as company- or affiliate-attributed unless a named third party publishes its own run.
Introductory API pricing, when Argon does launch commercially, is listed at **$2 / $10** per million input/output tokens (cached input 95% off), rising to **$4 / $20** after an unspecified introductory period.
## Safety language before the open door
Google’s own framing is capability-plus-control: refuse cyber and **CBRN** misuse while preserving legitimate dual-use research under its Frontier Safety Framework; harden against indirect prompt injection; monitor chain-of-thought and actions for misalignment and halt runs when needed; isolate high-risk sandboxes. Fairwind’s ungated cyber path sits inside that staged map — defenders early, mass market after more safety work — not as an open weights dump.
## Competitive timing (light only)
The announcement lands in the same news cycle as OpenAI’s DevDay / **Dots** push. Timing is competitive context; this tip is Google’s **Fairwind-gated Argon** path. Do not re-litigate Dots product claims here.
**Stakes:** If Fairwind-style cyber-first gating becomes the default for frontier defense models, the real product launch is less the leaderboard row than who gets the ungated agent — and how long everyone else sits on “as soon as possible.”