Google's Gemini 4 Argon goes to cyber defenders first. No date for the rest
Google's new frontier model ships first to vetted security teams and US government pre-release programs. For teams building AI workflows, a model you cannot call is a model you cannot plan around.
77.9% on DeepSWE, by Google's own count. Unless you are a vetted Fairwind partner, you cannot call it yet.
On September 30, 2026, Google announced Gemini 4 Argon in a post by Koray Kavukcuoglu, SVP of Google DeepMind and Google's Chief AI Architect. The model is "rolling out to a set of trusted cyber defenders through our Fairwind Program." Paid API customers and Google AI Ultra subscribers come next. Google gives no date for that step.
What Google says Argon is for
Google says Argon "delivers frontier performance in complex workflows across real-world software engineering, enterprise knowledge work like legal and finance, and cybersecurity defense." The post says it was "built to sustain deep reasoning across complex, long-horizon workflows," meaning tasks that run for many steps in a row.
The biggest spec change is output length. Google is raising the output token limit "to an industry-leading 1M tokens, up from the previous 64K tokens." Some coverage calls this a 1M context window. The post does not say that. It does not state an input context size at all.
Introductory pricing is $2 per million input tokens and $10 per million output tokens, with cached input at 95% off. VentureBeat reports that this rises to $4 and $20 after the introductory period. None of these prices matter yet to a team outside the first access tier.
The benchmark claims, as Google reports them
Every number below is Google's own claim. We have not seen independent runs, and most teams cannot run Argon on their own inputs today.
VentureBeat counted the comparison table and found Argon leading or tying on 13 of 18 disclosed benchmarks. Some gaps are small. On DeepSWE, VentureBeat lists Argon at 77.9%, Claude Opus 5.5 at 74.2%, and GPT-6 Astra at 74.1%. Others are wide: Harvey's Legal Agent Benchmark shows Argon at 19.6% against 5.4% and 3.8%. VentureBeat also reports a 0.7% attack success rate on Gray Swan's indirect prompt-injection benchmark.
Who gets it first
Google's Fairwind Program page lists who can apply: governments and national cyber authorities, critical infrastructure operators (healthcare, telecommunications, energy, financial networks), core technology platforms, and academic labs that work on defensive benchmarking. Partners get Argon plus CodeMender, a code security agent for automated fixes.
The terms are strict. Partners must use phishing-resistant MFA, keep access inside internal security, incident response, or penetration testing teams, and may not "share, redistribute, or sell access." That matters because Google says it will release Argon to these defenders "without cyber guardrails." The trust tier is the guardrail.
Everyone else gets "as soon as possible"
Google's reason for the order is one line: "Safely releasing frontier capabilities at this level requires a phased approach." It says it is taking part in the U.S. government's voluntary process for pre-release model access while it expands access gradually. The wider release is promised "as soon as possible," starting with paid API customers and Google AI Ultra subscribers.
There is no date in the post. The Fairwind page has no timeline either: Google says it will respond to eligible applicants "as soon as we can." So today, a product team with a normal API key can read Argon's scores and cannot test a single prompt against them.
Why a build studio cares
Our AI workflows build takes about a week, and one of its first steps is model selection, scored against eval cases we write from the client's real inputs. The same eval stage tests prompt injection and tool failures before anything touches production. A model we cannot call cannot enter that step. We cannot measure its accuracy, latency, or cost per run on the client's data, so it cannot be in the quote. We pin each workflow to a generally available model, and the exact model version goes into the operator runbook we hand over.
We also keep the model behind one interface in the workflow code, with the eval cases attached to it. When Argon reaches paid API, trying it is a config change plus a full eval rerun. If it loses on the client's cases, the rollback path is the model already pinned. What we do not do is set a delivery date that depends on an unannounced general availability. If a client asks for Argon, we quote on what ships today and list Argon as a later swap with its own eval run.
model: <generally available model, exact version> # what the quote and evals use
candidate: gemini-4-argon # blocked until paid API access exists
swap rule: candidate replaces model only if it passes every eval case
rollback: previous pinned model, one config lineNext step: read Google's Argon announcement for the full benchmark table and the Fairwind Program page for the access terms. If your team has a workflow or agent plan waiting on Argon, write to us at hello@gattyworks.com and we will tell you what to build on a generally available model now and how to keep the swap open.