Google has unveiled Gemini 4 Argon, its new top-tier artificial intelligence model for difficult coding, professional knowledge work and defensive cybersecurity. The announcement is important, but it is not a normal public product launch: Google is initially limiting Argon to a small group of trusted cyber defenders while it tests safeguards and prepares for broader access.
Google announced the model on September 30, 2026. It has not provided a public release date for ordinary Gemini users, developers or businesses.
Gemini 4 Argon starts with a restricted rollout
Argon is the first flagship model in the Gemini 4 generation. Google says it is rolling out through the company’s Fairwind Program to vetted cybersecurity partners, while the company also participates in the U.S. government’s voluntary process for pre-release model access.
This phased approach means most people cannot try the model yet. Google says it plans to expand access to developers, enterprises and consumers after gathering feedback and strengthening guardrails. The company expects paid API customers and Google AI Ultra subscribers to be among the first broader groups, but it has not committed to a date.
That distinction matters because “announced” and “available” are not the same thing here. Consumers should not subscribe to a Google plan today expecting immediate Argon access.
Pricing is confirmed, but availability is not
Google says Gemini 4 Argon will launch with introductory API pricing of $2 per million input tokens and $10 per million output tokens. Cached input tokens will cost 95 percent less than the regular input rate.
The model also raises Google’s maximum output allowance from 64,000 tokens to 1 million tokens. That unusually large output limit is intended for long-running tasks that may require extensive reasoning, tool use and multiple steps rather than a short chatbot reply.
Pricing could make Argon attractive for software development and enterprise automation, but the announced figures are introductory. Google has not said how long the introductory rate will last, and final production access may have additional usage restrictions.
Google is aiming at coding and professional work
Google positions Argon as a model for complex, long-horizon workflows. The company highlights software engineering, financial analysis, legal research and cybersecurity as core areas.
On Google’s published evaluations, Argon scored 77.9 percent on DeepSWE v1.1, a benchmark for long-running software-engineering tasks. It also led the company’s comparison on the Vals Index for knowledge work and scored 51.3 percent on Zapier’s AutomationBench.
Those numbers are useful context, but they are vendor-reported benchmark results rather than independent hands-on testing. Performance also varies by task. Google’s own chart shows Argon trailing some competing models on several coding, computer-use and science benchmarks, so the announcement does not establish it as universally better.
Google says thousands of its employees are already using Argon internally. The company attributes several engineering results to the model, including assistance with large codebase migrations and data-center memory optimization. These are manufacturer claims, and Google has not released enough detail for independent reproduction of every example.
Cybersecurity capability is driving the caution
Gemini 4 Argon can find, validate and patch software vulnerabilities, according to Google. On CWE-bench v1, the model posted a claimed score of 68 percent, tying the top result in Google’s comparison.
Trusted defenders will receive access to stronger cybersecurity capabilities so they can evaluate vulnerabilities in real systems. Google says Wiz is already testing Argon through a program intended to help protect critical public infrastructure.
The same capabilities could be misused. That is why Google is withholding broad access while it works on protections against cyber abuse and chemical, biological, radiological and nuclear threats. The company says it is also improving resistance to indirect prompt-injection attacks—malicious instructions hidden in documents, websites or other data an AI system processes.
New safeguards monitor model behavior
Google says Argon includes several layers of protection. These include refusal systems for dangerous requests, adversarial testing, hardened sandbox environments and monitoring designed to stop the model if its actions move beyond a user’s intent.
The company also says it monitors aspects of the model’s reasoning and actions for signs of misalignment. This is a significant claim because long-running AI agents can take many steps before a person reviews the result. However, the public has not yet had broad access to assess how reliably those safeguards work outside Google’s tests.
Who Gemini 4 Argon matters to
In the near term, the model matters most to cybersecurity teams, enterprise AI buyers and developers planning high-volume or long-running agent workflows. The confirmed token pricing gives those groups a starting point for cost comparisons, even though access remains limited.
For ordinary Gemini users, the practical message is to wait. Google has introduced a powerful new model and published detailed claims, but no consumer launch date, general API date or complete availability schedule.
Argon’s combination of a million-token output limit, lower introductory pricing and strong claimed performance could make it a major competitor to OpenAI and Anthropic. Whether it delivers that advantage in everyday use will remain unknown until independent testers and a much wider range of customers can use the model.
Featured image: official Google DeepMind Gemini 4 Argon artwork. Sources: Google DeepMind’s model page, Google’s announcement, Reuters, and The Verge.
