Google DeepMind has introduced Gemini 4 Argon, its new frontier AI model, and made an unusual call on who gets it first. Instead of a broad launch, the model is rolling out to a set of trusted cyber defenders through Google's Fairwind Program, alongside voluntary pre-release access coordinated with the U.S. government. Developers, enterprises and consumers come later, starting with paid API customers and Google AI Ultra subscribers, on a timeline Google describes only as "rolling out soon."

The reason is the model's security capability. Google says Gemini 4 Argon can autonomously find, validate and patch serious software vulnerabilities, and that it shows large gains over its predecessor in discovering attack surfaces and building proof-of-concept exploits. In testing, it identified a previously unknown critical vulnerability in healthcare software that exposed sensitive personal information. Google has not named the affected product. A model that good at finding holes is just as useful to attackers, which is why defenders get the head start.

On published benchmarks, Google is claiming the lead. Gemini 4 Argon scored 77.9% on the DeepSWE v1.1 software engineering benchmark, ahead of the 74.2% Google cites for Anthropic's Claude Opus 5.5 and 74.1% for OpenAI's GPT-6 Astra. It tied for first on the CWE-bench v1 vulnerability benchmark at 68%, ranked first on AutomationBench at 51.3%, and scored 91.7% on the LVBench long-video understanding test. Google also reports leading results on the Vals Index across finance, legal and tax work. These are vendor-reported numbers and will need independent confirmation.

The other headline is output length. Gemini 4 Argon can produce up to 1 million tokens in a single response, up from a 64,000-token limit, which matters for jobs like generating or refactoring large codebases and drafting long documents in one pass.

Pricing is set at an introductory $2 per million input tokens and $10 per million output tokens, with a 95% discount on cached input. After the introductory period, the price doubles to $4 and $20.

On safety, Google says the model includes monitoring of its chain of thought for signs of misalignment, the ability to halt execution when needed, and stronger defenses against indirect prompt injection, the attack where hidden instructions in a web page or document hijack an AI agent. Reports also indicate Google plans a version with fewer guardrails for vetted defenders and internal teams, a decision that will draw debate.

For security leaders, the takeaway is that the gap between AI that writes code and AI that breaks code is closing fast. Organizations should expect vulnerability discovery to speed up on both sides and plan patch cycles accordingly.