Google Gemini 4 Argon: price, access, safety

Official Google key art for Gemini 4 Argon with the Gemini star logo and a large soft-focus numeral 4 on a blue background

/ Google launches Gemini 4 Argon for coding, enterprise, and cyber defense. Fairwind first; Ultra and API next. Intro pricing from $2/$10 per million tokens.

by Hozefa Khety

· 8 min read

Google announced Gemini 4 Argon on September 30, 2026 — its new frontier model for long, multi-step work in coding, enterprise knowledge tasks, and cybersecurity defense. Access starts narrow: trusted cyber defenders via Google's Fairwind Program, plus internal Google teams. Broader availability for paid API customers and Google AI Ultra subscribers is promised after more safeguard testing. Introductory API pricing is $2 per million input tokens and $10 per million output tokens (checked September 30, 2026 against Google's Keyword post).

Official Google key art for Gemini 4 Argon with the Gemini star logo and a large soft-focus numeral 4 on a blue background
Google's official Gemini 4 Argon key art from the September 30, 2026 announcement. (Image: Google)

What Gemini 4 Argon is built for

Koray Kavukcuoglu, SVP at Google DeepMind and Google's chief AI architect, describes Argon as the start of Google's "next era of frontier intelligence," built for deep reasoning across complex, long-horizon workflows. Google says the model already runs inside the company for specialized coding, research, and writing — including quantum algorithm resource optimization, fleet-wide memory savings, and large C/C++ to Rust migrations.

To support those longer jobs, Google is expanding Argon's output token limit to 1 million tokens, up from 64K on the prior generation it cites. The company argues that headroom lets the model keep reasoning in one trajectory instead of chopping hard problems into short replies.

On Google's published scores, Argon leads DeepSWE v1.1 at 77.9% for long-horizon software engineering, ahead of Claude Opus 5.5 at 74.2% and GPT-6 Astra at 74.1% (figures as reported by 9to5Google from Google's materials). Google also claims number-one ranks on Zapier's AutomationBench (51.3%) and state-of-the-art long-video understanding on LVBench (91.7%), plus strong results on Vals Finance Agent v2 and Harvey's Legal Agent Benchmark.

Cyber defense first, then everyone else

Google is leaning hard into defensive cybersecurity. Argon is trained to find, validate, and patch software vulnerabilities. For trusted defenders and Google's own teams, Google says it will ship Argon without cyber guardrails so they can use its full defensive capability. Cloud security firm Wiz is already using Argon in its Scan for Good program; Google says the model found a critical exposure in healthcare software that earlier frontier models missed.

Bar chart from Google comparing Gemini 4 Argon and other models on CWE-bench v1 vulnerability remediation
Google's CWE-bench v1 chart: Argon ties for first at 68% on vulnerability remediation. (Image: Google)

On CWE-bench v1, Google reports Argon tied for first at 68%. The company also highlights stronger black-box penetration-testing results versus Gemini 3.8 Flash Cyber on Wiz's internal benchmark, and broader vulnerability discovery across an internal suite spanning 20 programming languages.

That phased rollout mirrors the industry's nervous mood after OpenAI shelved GPT-6.1 Astra over safety and alignment concerns. Google says it is engaged in the U.S. government's voluntary pre-release model access process while it expands who can use Argon.

Safeguards before a broad launch

Before Argon reaches developers, enterprises, and consumers, Google lists four safeguard workstreams: blocking cyber and CBRN misuse (including monitoring internal activations), hardening against indirect prompt injection, watching for misalignment in the model's chain-of-thought and actions, and sealing sandboxed environments before high-risk training or evaluations.

Google chart showing Gemini 4 Argon leading Gray Swan Indirect Prompt Injection robustness scores
Google says Argon leads Gray Swan's Indirect Prompt Injection (IPI) benchmark for prompt-injection robustness. (Image: Google)

Google calls Argon its most resilient model yet against indirect prompt injections and says it leads Gray Swan's IPI benchmark. On misalignment, Kavukcuoglu writes that Google monitors chain-of-thought and can stop execution when needed — and that similar monitoring during training alerted a dedicated incident team, without feeding those findings back into training in a way that could teach the model to evade monitors.

Price and when you can use it

Google's Keyword post sets introductory API pricing at $2 per million input tokens and $10 per million output tokens, with cached input tokens at 95% off the input price. After the introductory period, rates become $4 per million input and $20 per million output. Google has not published the intro-period end date in the Argon post itself (unlike recent Flash launches that named December 31, 2026).

Who gets it when: Fairwind Program cyber defenders and trusted testers first; then, "as soon as possible," paid API customers and Google AI Ultra subscribers, followed by wider developer, enterprise, and consumer surfaces. The Verge notes the limited start is deliberate so Google can check for misalignment before a broad ship.

What this means for the AI race

Gemini 4 Argon is Google's clearest answer to the agentic coding and enterprise wave OpenAI pushed at DevDay — with a safety-first distribution twist. Consumers will not chat with Argon on day one. Defenders, Google's own engineers, and eventually Ultra/API customers will stress-test a model Google claims can rewrite huge codebases, cut data-center memory waste, and patch critical bugs — while new monitors watch for misuse and misaligned plans.

For now, treat the benchmark chart and internal productivity stories as Google's opening case, not independent third-party reviews. The practical questions are when Ultra and API access actually light up, how long introductory pricing lasts, and whether Fairwind-style limited drops become the normal path for the next frontier models.

GoogleGeminiGemini 4 ArgonGoogle DeepMindAICybersecurityFairwind ProgramLarge language modelsAPI pricingFrontier models

Frequently asked questions

What is Google Gemini 4 Argon?

Gemini 4 Argon is Google's frontier AI model announced on September 30, 2026. Google positions it for complex software engineering, enterprise knowledge work (legal and finance), and cybersecurity defense, with a 1 million token output limit for long reasoning trajectories.

Who can use Gemini 4 Argon right now?

At launch, Google is rolling Argon out to trusted cyber defenders through its Fairwind Program and to internal Google teams. Broader access for paid API customers and Google AI Ultra subscribers is planned after more safeguard work. Exact consumer app dates were not listed in the announcement.

How much does Gemini 4 Argon cost?

Google's official post lists introductory API pricing of $2 per million input tokens and $10 per million output tokens, with cached input at 95% off. After the intro period, pricing becomes $4 / $20 per million input / output tokens (checked September 30, 2026).

How does Gemini 4 Argon score on benchmarks?

Google reports 77.9% on DeepSWE v1.1 (ahead of Claude Opus 5.5 at 74.2% and GPT-6 Astra at 74.1%), a tie for first at 68% on CWE-bench v1, 51.3% on Zapier's AutomationBench, and 91.7% on LVBench for long video understanding. These are Google-published figures, not independent lab replications.

Why is cyber defense getting access first?

Google trained Argon for defensive cybersecurity — finding, validating, and patching vulnerabilities — and says trusted defenders and internal teams will get a version without cyber guardrails. Google also says it is working with the U.S. government's voluntary pre-release access process while it expands availability.

What safeguards is Google adding before a broad launch?

Google cites four areas: misuse defenses (including cyber and CBRN), prompt-injection robustness (leading Gray Swan's IPI benchmark per Google), misalignment monitoring of chain-of-thought and actions, and harder sandboxed environments for high-risk evaluations.

How is this different from Gemini 3.8 Flash?

3.8 Flash (and 3.8 Flash Cyber) are Google's recent workhorse and cyber-focused Flash models. Gemini 4 Argon is a new frontier-tier model with a new naming scheme, a 1M output token limit, and a Fairwind-first rollout. Google also says Argon shows leaps over 3.8 Flash Cyber on internal vulnerability discovery tests.

Related