Google introduced a new flagship artificial-intelligence model on Tuesday, but most people cannot use it yet. Gemini 4 Argon, the company’s first new frontier model since Gemini 3 last November, is being handed first to a small group of cybersecurity experts through a program Google calls Fairwind. The staggered release is deliberate, a signal that Google is more worried about what a capable model could do in the wrong hands than about being first to a general launch.
Argon is built for deep reasoning across long, complex tasks, the kind of work that takes a model many steps to finish. Google said the model delivers frontier performance on software engineering, enterprise knowledge work such as legal and finance, and cybersecurity. A company spokesperson said Argon is larger than Google’s previous top-tier Pro models and compares with frontier models such as OpenAI’s Astra and Anthropic’s Opus on key coding and cyber benchmarks.
The choice to open with cyber defenders is new for Google and reflects how the model was trained. Argon is geared toward defensive security work, and Google says it can autonomously find, validate and patch software vulnerabilities. The company is also participating in the U.S. government’s voluntary process for pre-release model access, and it said access will widen in phases as it collects feedback from early testers and hardens the model’s guardrails.
Google did not say when the model will reach the public. After the cybersecurity testers come paid API customers and Google AI Ultra subscribers, the company said, and developers, enterprises and consumers after that. In the meantime, the company has raised Argon’s output limit to 1 million tokens, up from 64,000 in earlier Gemini models, so it can complete longer tasks in a single pass.
The pricing was the one concrete number Google shared. Argon launches at an introductory price of $2 per million input tokens and $10 per million output tokens, with cached input tokens priced at 95 percent off the input rate. After the introductory period, the price rises to $4 per million input tokens and $20 per million output tokens.
The early results Google is willing to show come from its security partners. Wiz, a cloud security company, said it used Argon to uncover a critical vulnerability that could expose personal information in a hospital system used around the world, a flaw Google said other frontier models missed. Thousands of Google employees are already using Argon internally, and teams of Argon agents freed more than 300 terabytes of memory across Google’s data centers, the company said.
The model arrives after a stretch in which Google’s flagship releases slipped behind its own schedule. The company had promised a Gemini 3.5 Pro model back in June, but it spent the summer shipping smaller Flash models instead, and rivals such as OpenAI and Anthropic advanced on some frontier benchmarks in the meantime. Argon is the company’s bid to return to the front of the race, and it is doing so carefully, trading a headline-grabbing general launch for a slower, safer one.
The phased approach is also a concession to how the ground has shifted under the industry. Frontier-model developers now release capable systems in stages, first to researchers and vetted partners, then to developers and consumers, with government reviewers looking over their shoulder. Google is following that playbook to the letter, and it is leaning on cyber defenders, the one group whose job is to find what a powerful model can break, as its first test audience.
Google’s Gemini line has followed a familiar rhythm since its debut in late 2023: a frontier release, then smaller, cheaper models that carry the same name to a wider audience. Argon inverts that order. The company is starting with the most restricted group it can find, cyber defenders, and only then will it open the model to the developers and consumers who normally get a new Gemini first.
The Fairwind Program, the vehicle for that first access, is Google’s security initiative for putting advanced models in the hands of people whose job is defending networks. By making cyber defense the model’s public debut, Google is betting that the first stories written about Argon will be about vulnerabilities found and patched, rather than about what an unfettered model might do.
Whether the caution costs Google momentum is the open question. A model most developers cannot buy yet is a model most developers cannot test against the competition. Google is betting that cyber defenders, and the government reviewers watching over its shoulder, will vouch for Argon before the doors open to everyone else. If that bet pays off, the wait looks prudent. If rivals ship comparable models to everyone first, the phase-in will look like caution at the wrong moment.


