Skip to content
The AI-First Web

Google plans to lift cyber limits on Gemini 4 Argon first for trusted defenders

Access to the guardrail-free version is becoming a tier. Ask where your defenders and vendors sit.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Google plans to lift cyber limits on Gemini 4 Argon first for trusted defenders

AI-generated image for WebPulse. About our images

In brief
  • Google is rolling out Gemini 4 Argon first to trusted cyber defenders and plans a version without cyber guardrails for them and its own teams.
  • Google reports a 68% score on CWE-bench v1 and a healthcare-software flaw it says earlier models missed. The software was not named.
  • Ask whether your vendors can reach such programs, who triages AI-found flaws, and who reviews AI-written patches before they ship.

The safety setting is becoming a privilege

Most AI news is about what a model can do. The more useful question for an executive is who gets to use it, and with which limits switched on or off.

Google's announcement of Gemini 4 Argon puts that question in plain view. The first users are a set of trusted cyber defenders in Google's Fairwind Program. Google plans to give those defenders, and its own internal teams, a build of Argon with the cyber guardrails removed. Its stated reason is that they can then use the model's "full frontier-level cybersecurity defense capabilities."

This shows that a guardrail is no longer only a safety feature. It is also becoming a tier of service. Google has not said whether anyone outside the trusted group will ever get the guardrail-free build. It has not said when anyone else gets Argon in any form.

What Google says Argon can do

Google says it trained Argon to work through the full defensive cycle on its own: finding software flaws, confirming they are real, and fixing them. Wiz is already using the model in Scan for Good, a free program that looks for high-risk exposures in critical public infrastructure.

Google points to one early result. Argon turned up a serious flaw that exposes sensitive personal data in healthcare software used by hospitals around the world. Google says earlier frontier models had missed it. The Hacker News reports that Google did not name the affected software. So the claim cannot yet be checked from outside.

68%
CWE-bench v1 score (vulnerability remediation)
Source: Google, Gemini 4 Argon announcement (covered by The Hacker News, October 1, 2026)
20
Programming languages in Google's internal vulnerability benchmark
Source: Google, Gemini 4 Argon announcement (covered by The Hacker News, October 1, 2026)

Every figure here comes from Google's own announcement. CWE-bench v1 tests whether a model can fix known classes of software weakness. Google says Argon ties for first place. Wiz runs a separate test that asks a model to probe live web systems without seeing the source code. Google says Argon beats its predecessor, Gemini 3.8 Flash Cyber, at mapping the attack surface and producing proof-of-concept evidence.

How the guardrails work, and what removing them means

Google describes several layers of protection. It says it built Argon to decline requests that would help with cyber attacks or chemical, biological, radiological and nuclear attacks. The model should still help with legitimate dual-use science. Google is also improving how it watches the model's internal activations for signs of misuse. A separate monitor reads the model's chain-of-thought and actions and halts it when needed.

The guardrails matter because the same skill serves both sides. A model that can write a proof-of-concept to confirm a flaw could, in principle, be asked to do so for the wrong reasons. Lifting the cyber limits for vetted users takes that friction away for people Google has chosen to trust.

Google also says Argon resists indirect prompt injection. That is an attack where malicious text hidden in a document or web page tries to hijack the model. It matters most when an AI agent reads content it did not write. Google says Argon leads on Gray Swan's benchmark for this.

Finding flaws is only half the job

Someone also has to ship a safe fix. In our view, that is the harder half, because a bad patch can create new problems. Google's announcement does not rank the two tasks.

One example from Google is worth reading carefully. Argon agents are migrating C and C++ code to Rust, a language built to prevent memory errors. The largest job is more than 800,000 lines for the Fuchsia Zircon kernel. This is a code rewrite, not a vulnerability patch. It is not evidence about AI-written security fixes.

800K+ lines
Largest code migration Google cites (Fuchsia Zircon kernel)
Source: Google, Gemini 4 Argon announcement (covered by The Hacker News, October 1, 2026)

It still offers a useful comparison. Google says these rewrites face "rigorous automated and manual auditing, emulation testing, and review before rolling out to production." If Google audits AI rewrites of critical code this heavily, buyers should expect similar review of AI-written security patches.

What leaders should ask

Google gives no date for wider availability. It says it will keep gathering tester feedback and refining guardrails first, then open Argon "as soon as possible." Paid API customers and Google AI Ultra subscribers come first. Introductory pricing is $2 per million input tokens and $10 per million output tokens. After that period, Google lists $4 and $20.

Four questions for your security team and key vendors:

First, do we or our software suppliers have access to programs like Fairwind or Scan for Good? Second, if an AI-found flaw is reported to us, who triages it and how fast? Third, who reviews an AI-written patch before it ships? Fourth, where do our own AI agents read untrusted content, and what limits their actions?

One caveat applies throughout. This is one vendor's launch, backed by its own benchmarks. The facts support attention and good questions. They do not support a verdict. The shift is plain, though: the first release of the strongest defensive build goes to a vetted group, and everyone else will be asking about access.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Google.

Share this insight