Fairwind: Why the public is not getting Gemini 4 Argon first

Google's most capable AI model isn't available to paying customers yet. Vetted cyber defenders got there first, without guardrails,

Contributed Content

gemini 4 argon
Gemini 4 Argon rolls out to vetted cybersecurity defenders via Google's Fairwind Programme before any public release. Image: Created with the TN:AI workflow for illustration purposes.

Google announced its new flagship AI model, Gemini 4 Argon, on 30 September 2026. The first people to get it are not paying API customers, not Google AI Ultra subscribers, not enterprise clients.

They’re vetted cybersecurity defenders, operating inside a programme most people outside the security industry have never heard of. The order of that queue is the story.

Argon is Google’s first true frontier model in more than seven months. It is built for long, complex workflows across software engineering, enterprise knowledge work like legal and finance, and cybersecurity defence.

The output token limit has jumped to one million, up from 64K on the prior generation.

Koray Kavukcuoglu, senior vice president at Google DeepMind and the company’s chief AI architect, called it the start of the company’s “next era of frontier intelligence”. [1]

The Fairwind Programme

Access to Argon runs through Google’s Fairwind Programme, a limited-access scheme that gives what Google describes as “high-priority defenders” including governments, healthcare providers, and telecommunications companies early access to advanced models.

Fairwind launched in early September with more than 650 participating partners. It initially combined an earlier Gemini Cyber model with Google’s CodeMender vulnerability-patching tool.

According to Google, trusted defenders and its own internal teams get Argon without cyber guardrails, so they can use its full vulnerability-hunting capability.

“For trusted defenders and our own internal teams at Google, we’ll be releasing Argon without cyber guardrails so they can leverage its full frontier-level cybersecurity defense capabilities,” Google said in the statement.

Google says it will expand access after gathering feedback from early testers, with paid API customers and Google AI Ultra subscribers next in line. No date has been given for either.

The company is also participating in the US government’s voluntary pre-release model access process, which AI Weekly’s Alexis Dufresne notes suggests the gating order was coordinated rather than improvised.[2]

Before broad release, Google says it is strengthening safeguards in four areas:

  • cyber and CBRN (chemical, biological, radiological, and nuclear) misuse,
  • indirect prompt injection,
  • monitoring of the model’s internal reasoning and actions,
  • chain monitoring that can abort tasks mid-run.

ALSO READ: What OpenAI’s shelved GPT-6.1 Astra means for anyone deploying AI agents

What Argon claims to have found

Google says Argon can autonomously find, validate, and patch critical software vulnerabilities.

Argon allegedly uncovered a critical vulnerability exposing sensitive personal data in healthcare software used by hospitals worldwide, a flaw that earlier frontier models had missed. Google did not name the software or confirm whether a fix has shipped.

Security firm Wiz is already using the model through its Scan for Good initiative, which finds risky exposures in critical public infrastructure at no charge. Fairwind members can also pair Argon with Google’s CodeMender tool for combined vulnerability discovery and remediation work.

Internally, Google says Argon agents have migrated more than 800,000 lines of the Fuchsia OS Zircon kernel from C and C++ to Rust. Those rewrites are still being audited before they reach production.

The benchmarks

On Google’s own published comparison table, Argon leads on most listed benchmarks.

  • On DeepSWE v1.1, a software engineering test, it scores 77.9%, ahead of Claude Opus 5.5 at 74.2% and GPT-6 Astra at 74.1%.
  • On AutomationBench for end-to-end business tasks, it reaches 51.3%, against 42.5% for Opus 5.5.
  • On the Vals Index, which measures economic impact across finance, coding, law, and tax, Argon scores 68.9%, ahead of Opus 5.5 at 67.0%.

On CWE-bench v1, which evaluates a model’s ability to fix security vulnerabilities, Argon ties GPT-6 Astra for first place at 68%, with Opus 5.5 one point behind at 67%. A tie, not a win.

And it’s a vendor-reported result: no independent lab has reproduced a single Argon benchmark score, because the model isn’t publicly accessible yet.

The gaps Google didn’t feature are also worth noting. Argon trails Opus 5.5 by nine points on Terminal-Bench 4.0, which tests command-line task completion, scoring 57.4% against Opus 5.5’s 66.4%.

Opus 5.5 also leads on PostTrainBench, a machine-learning engineering test. GPT-6 Astra beats Argon on FrontierSWE v2, the harder of the two software engineering suites, by roughly 10 points.

On Artificial Analysis’s independent Intelligence Index, Argon scores 53, tied with GPT-6 Astra and behind Opus 5.5 at 58. Futurum’s analysis puts Argon at roughly the level of OpenAI’s best model, and behind Anthropic’s, on early independent tests.

Pricing is set at an introductory rate of $2 per million input tokens and $10 per million output tokens, rising to $4 and $20 after the promotional window. Neither the duration of that window nor a general availability date has been confirmed.

What this means for SA security teams, who are last in line

Fairwind’s early cohort is weighted toward governments and large enterprise partners, most of them US-based or already embedded in Google Cloud.

SA organisations without existing Fairwind relationships, or without the Google Cloud footprint to qualify, will wait for the paid API tier. That tier has no confirmed launch date.

When Argon does reach local security teams, they will get the guardrailed version, not the unrestricted one Fairwind defenders are running now. Whether that version retains enough of the vulnerability-discovery capability to be genuinely useful in underfunded SOC environments, against attack patterns that look different from the US cases in Google’s training data, is a question the benchmarks don’t answer.

Sources:

[1] Kavukcuoglu, Koray. “Gemini 4 Argon: Our Next Era of Frontier Intelligence.” The Keyword (Google blog), September 30, 2026.
[2] Dufresne, Alexis. “Google’s Gemini 4 Argon Rolls Out to Cyber Defenders First.” AI Weekly, September 30, 2026.

Before you @ us:

No, AI did not “write this article.” Calm down. This piece was produced using our TN:AI newsroom workflow. The opinions and typos belong to a human who has algorithmic side quests. (Hi!) We even wrote an AI policy so nobody panics.

🧠 AI-assisted research + summarisation 📝 Human edited + fact-checked

Sharing is caring! 

Featured reads: