Google Unveils Gemini 4 Argon AI Model
Google’s autonomous Argon agents analyzed fleet-wide profiling telemetry—the continuous performance data streaming from machines across the company’s data centers—and applied memory optimizations on their own. Once the changes rolled out they freed more than 300 TiB of memory. Estimated total savings range from 500 TiB to 1 PiB, without new hardware.
The model doing that work is Gemini 4 Argon. On September 30, 2026, as its model page went live, Koray Kavukcuoglu, SVP of Google DeepMind and chief AI architect at Google, wrote: “Today, we’re announcing our new frontier model, Gemini 4 Argon, which is rolling out to a set of trusted cyber defenders through our Fairwind Program.”
The sentence landed after days of noise on X. Earlier in the week the AI community there had been turning over leaked benchmark numbers that looked as if they belonged to a coming Google frontier release. The page supplied the name. It also supplied the first audience, and it was not the public.
Argon belongs to the Gemini line, Google’s family of large language models—the systems behind the company’s generative AI chatbot and tools, trained to handle text, code, images, audio, and video together. The model page does not open that tier to developers or consumers. It opens only through Fairwind, and only to cyber defenders Google is willing to call trusted. The rest of the door stays shut.
A day earlier, Google CEO Sundar Pichai had met at the White House with President Donald Trump and other technology executives and signed a voluntary AI safety agreement. That process now governs how the model leaves the building. “We are actively engaged in the U.S. government's voluntary process for pre-release model access while we gradually expand access,” Kavukcuoglu writes. Google has set its own cut on top of the government track. The company’s access criterion is the word “trusted,” and only the cyber defenders who meet it receive Argon while the pre-release review continues.
Product Lead Tulsee Doshi has cast the order as protective. Giving defenders the tool first, she noted, gives Google time to harden safeguards against prompt injections and misalignment. Prompt injection is an attack that tries to override a model’s instructions through hostile input. Misalignment is the risk that the system’s behavior drifts from what its builders intended. Both are still open work. The company is gathering feedback from the early testers and iterating on guardrails before it widens the circle to developers, enterprises, and consumers. No public launch date is stated. Until that work is finished, Argon stays with the trusted set.
“Gemini 4 Argon delivers frontier performance in complex workflows across real-world software engineering, enterprise knowledge work like legal and finance, and cybersecurity defense,” Kavukcuoglu writes.
The claim rests on room to think. Google expanded the model’s output token limit from 64,000 to 1 million. A token is the basic unit a large language model reads and writes—roughly a word or a piece of one. A million of them in a single trajectory lets Argon keep reasoning and producing across a long, multi-step job without breaking the chain.
The published scores track that reach. On DeepSWE v1.1, which measures real-world long-horizon software engineering, Argon scored 77.9 percent, a new state of the art. It leads the Vals Index, an evaluation of finance, coding, legal, and tax work weighted by each sector’s contribution to U.S. GDP. It ranked first on Zapier’s AutomationBench at 51.3 percent, a test of end-to-end execution across core business functions. On LVBench, which measures long-video understanding, it scored 91.7 percent.
Thousands of Googlers are already running it on specialized coding and deeper research. Quantum computing researchers put the model on subroutines that bottleneck important applications, optimizing the spacetime resources those routines consume. Spacetime resources are the product of the qubits and gates a calculation needs. In one case Argon beat a published baseline by 40 percent within minutes.
The same agents are migrating C and C++ codebases to Rust, a language designed so memory errors are caught before code runs. The work spans core libraries including re2 and libgav1 and more than 800,000 lines of the Fuchsia OS Zircon kernel. Because those systems are critical, the rewrites go through automated and manual auditing, emulation testing, and review before production. For libgav1, Google’s open-source video decoder, the agents took an existing Rust port and replaced 32,000 lines of SIMD code—instructions written to perform the same operation on many data points at once—by running rounds of profile-guided experiments, studying the compiler’s output, and producing safe Rust the compiler would vectorize automatically. Video output stayed identical. The Rust port of libgav1 runs 2.7 times faster.
Google trained Gemini 4 Argon to be highly capable at cybersecurity defense. For the trusted defenders in the Fairwind Program and for the company’s own internal teams, it is releasing the model without cyber guardrails, so they can use the full frontier-level defensive skill set. Argon can autonomously find, validate, and patch critical software vulnerabilities. On CWE-bench v1, which evaluates a model’s ability to remediate security flaws, Argon ties for first place with a score of 68 percent.
Wiz is already running the model through its Scan for Good initiative, a program dedicated to protecting critical public infrastructure for free by “finding and remediating high-rise exposures.” Using Argon, Wiz uncovered a critical vulnerability that exposed sensitive personal information across healthcare software used by hospitals worldwide. Earlier frontier models had missed the flaw.
Introductory API pricing is already posted for the phase that follows. Google lists $2 for every million input tokens and $10 for every million output tokens. Cached input tokens, the ones the system has already processed and can reuse, are priced at 95 percent off the ordinary input rate. After further safety work, the company plans to open Argon to paid API users and to Google AI Ultra subscribers. No public launch date is attached to either opening.
Broader availability is planned for developers, enterprises, and consumers once early testing finishes and the guardrails are judged ready. Google continues to gather feedback from the early testers and to iterate on protections against misuse and prompt injection while it remains inside the U.S. government’s voluntary process for pre-release model access. That process has no stated end date. Until the review and the safeguards advance, Gemini 4 Argon remains limited to the set of trusted cyber defenders rolling out through the Fairwind Program.







