
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.

Google’s next frontier model is being tested first with the US government and selected cyber defenders before a wider rollout to developers, enterprises and consumers Google is initially giving selected cyber defenders access to Gemini 4 Argon before a wider rollout to developers, enterprises and consumers Google has given an early look at Gemini 4 Argon, its next frontier AI model, with a one million-token output limit, stronger long-running reasoning and new capabilities aimed at software engineering, enterprise work and cybersecurity.
Summary
The model is not yet on general release. Google is initially providing access to selected cyber defenders through its Fairwind Program and is participating in the US government’s voluntary process for pre-release model access while it continues testing safeguards. Sundar Pichai, CEO of Google, used LinkedIn to frame the announcement as an early preview rather than a full launch: “We’re going to make it available as soon as we can and as safely as we can.” When wider access begins, Google says Gemini 4 Argon will start with paid API customers and Google AI Ultra subscribers.
Introductory API pricing is set at $2 per million input tokens and $10 per million output tokens, with cached input priced at 95% below the standard input rate. One of the biggest technical changes is scale. Argon can produce up to one million output tokens in a single trajectory, compared with a previous limit of 64,000.
Google wants the model to remain engaged with a problem for much longer, carrying out multi-step work rather than answering a prompt and stopping. Google is already putting Argon to work internally Thousands of Google employees are already using Argon across coding, research and other internal workflows, according to the company. Some of the examples go well beyond everyday chatbot use.
Google says its quantum researchers used Argon to optimize the spacetime resources required by computational subroutines, beating a published baseline by 40% in one example. Elsewhere, a group of Argon agents analyzed profiling data across Google’s infrastructure to identify memory optimizations. Google says changes already rolled out have freed more than 300 TiB of memory, with estimated total savings eventually reaching between 500 TiB and 1 PiB.
The model is also being used on large code migrations. Argon agents are working on moving C and C++ codebases to Rust, ranging from tens of thousands of lines in individual libraries to more than 800,000 lines in the Fuchsia Zircon kernel. Google stresses that those rewrites are still subject to automated and manual auditing, testing and review before production deployment.
For its open-source libgav1 video decoder, Google says Argon agents replaced 32,000 lines of SIMD code in an existing Rust port after repeated profiling and compiler analysis. The resulting version ran 2.7 times faster than the previous Rust port while producing identical video output, according to the company. The benchmark results point in the same direction, although they remain model evaluations rather than evidence of performance in every real-world setting.
Argon scores 77.9% on DeepSWE v1.1, a benchmark focused on long-horizon software engineering. Google also reports a 51.3% score on AutomationBench, which assesses end-to-end work across business functions, and 91.7% on LVBench for long-video understanding. Cybersecurity is getting a different rollout Cybersecurity is where Google is being noticeably more selective about access.
Argon has been trained to find, validate and patch software vulnerabilities, and Google is initially making versions without cyber guardrails available to selected defenders and its own internal teams. That access is not intended for general users. One early partner is Wiz, which is using Argon through its Scan for Good initiative to look for vulnerabilities affecting public infrastructure.
Google says Argon identified a critical vulnerability that exposed sensitive personal information across healthcare software used by hospitals worldwide, a flaw that previous frontier models had not found. On CWE-bench v1, which tests vulnerability remediation, Argon scores 68% and ties for the highest result reported by Google. Pichai highlighted cyber defense as one of the model’s core strengths on LinkedIn, describing Argon as showing “frontier performance in complex workflows, cyber defense and software engineering.” He also pointed to its use inside Google, from coding to quantum computing, rather than presenting the model solely as a consumer assistant.
Stronger capability comes with more monitoring Google is pairing the model’s increased autonomy with additional controls before general release. The company says Argon is being tested against cyber misuse and chemical, biological, radiological and nuclear threats, with internal and external red teams attempting to break its safeguards. Prompt injection is another focus.
Google describes Argon as its most resilient model yet against indirect prompt-injection attacks, where malicious instructions hidden in external material attempt to redirect an AI system. The company is also monitoring for cases where Argon attempts to go beyond a user’s intentions in order to complete a task. Its mitigation system can monitor the model’s reasoning and actions and stop execution when necessary.
That approach extends to Google’s own model training. The company says similar monitoring has been used during training runs, with alerts sent to a dedicated incident-response team. Its testing environments are also being hardened through isolation and sandboxing before high-risk training or evaluations begin.
Taken together, the rollout is deliberately split in two: selected government and cybersecurity users get early access while Google continues testing, with broader availability following later. Google has not given a public release date, but says developers, enterprises and consumers will receive access after the current testing phase, starting with paid API customers and Google AI Ultra subscribers.
KazaSec's take
A newly disclosed vulnerability is only a real risk to your organization once it's confirmed present and exploitable in your own environment, not every CVE applies equally to every network. Knowing the difference is exactly what a proper vulnerability assessment is for.
Coverage details
We've archived 238 other articles touching the same topic (skills and workforce, ai) , see the full security news archive.
Related security advisories
Relevant from KazaSec
More coverage on this topic
We help organizations find and fix the gaps before they make headlines.