Google is limiting access to Gemini 4 Argon, its new artificial intelligence model capable of autonomously finding, validating and patching critical software vulnerabilities, to a vetted group of cybersecurity experts. The restricted rollout is intended to give defenders access to the model’s capabilities while Google strengthens safeguards against potential misuse by malicious actors.
Koray Kavukcuoglu, SVP of Google DeepMind and Chief AI Architect at Google, announced the model on September 30, 2026. Google is initially distributing it through its Fairwind Program and plans to expand access after gathering feedback from trusted testers and refining its security measures.
The decision puts the focus on a central cybersecurity challenge: AI that can help security teams identify and fix weaknesses could also provide capabilities that attackers might misuse to discover and exploit vulnerabilities.
Gemini 4 Argon Discovers Critical Software Vulnerabilities
Google says Gemini 4 Argon can identify, validate and patch vulnerabilities across complex software environments. Its reported capabilities include examining codebases, identifying potential exposures and producing evidence to validate security weaknesses.
In an early deployment, cybersecurity company Wiz used Argon through its Scan for Good initiative, which focuses on identifying and remediating high-risk exposures affecting critical public infrastructure.
According to Google, the model discovered a critical vulnerability that exposed sensitive personal information in healthcare software used by hospitals worldwide. The company said previous frontier AI models had missed the issue but did not publicly identify the affected software or provide technical details about the flaw.
On CWE-bench v1, a benchmark designed to evaluate vulnerability remediation, Argon tied for first place with a score of 68%.
Google also reported improvements over its earlier 3.8 Flash Cyber model in internal testing. On Wiz’s internal black-box penetration testing benchmark, Argon performed better at identifying attack surfaces, discovering vulnerabilities and generating proof-of-concept evidence to validate its findings.
These results are based on Google’s and its partners’ reported evaluations. They do not establish how reliably the model will identify vulnerabilities across every real-world environment.
Why Google Is Limiting Access to Gemini 4 Argon
Google is taking a phased approach because the model’s advanced capabilities require additional safeguards before wider deployment.
For defenders, automated vulnerability discovery could help identify weaknesses earlier and reduce the time needed to investigate and remediate them. However, similar capabilities could also be misused to locate weaknesses in systems that attackers want to compromise.
Google said trusted cyber defenders and its own internal teams will receive access to Argon without cyber-specific guardrails so they can use its full defensive capabilities. The company is also participating in the US government’s voluntary process for pre-release AI model access.
Google has not announced a specific date for general availability. It said it will continue evaluating feedback from early testers while strengthening protections against misuse.
Prompt Injection Attacks Among Key Security Concerns
Google has identified several areas where it is strengthening safeguards before expanding access to Gemini 4 Argon.
One is prompt injection attacks, in which malicious instructions hidden in external content attempt to manipulate an AI model’s behavior. Google said Argon demonstrated improved resilience against indirect prompt injection on Gray Swan’s Indirect Prompt Injection benchmark.
The company is also testing protections against requests that could facilitate cyberattacks or the development of chemical, biological, radiological and nuclear threats. Google said internal and external red teams assessed these safeguards using manual and automated attack methods.
Additional measures monitor the model’s reasoning and actions for potential misalignment, with mechanisms designed to stop execution when necessary. Google is also hardening isolated testing environments used for high-risk training and evaluations.
These measures are intended to reduce risks, but the announcement does not establish that every possible misuse scenario or security failure has been eliminated.
Gemini 4 Argon Availability and Pricing
Google plans to expand access to Gemini 4 Argon after gathering feedback and continuing its safeguards work. Paid API customers and Google AI Ultra subscribers are expected to be among the first groups to receive broader access.
The announced introductory API pricing is $2 per million input tokens and $10 per million output tokens. Cached input tokens receive a 95% discount on the standard input price.
For cybersecurity teams, the key issue is whether the model’s reported vulnerability discovery capabilities translate into reliable results across production systems. Its wider rollout will also test whether safeguards can keep pace with AI systems capable of supporting both vulnerability remediation and offensive security techniques.






































