Google introduced Gemini 4 Argon on September 30, giving vetted cybersecurity defenders access through its Fairwind program while it refines safeguards for a wider release. Trusted defenders and internal Google teams can use the model without its cyber guardrails, the company said.

The initial release does not make Argon generally available. Google is participating in the US government’s voluntary process for access to models before release. It plans to start broader distribution with paid API customers and Google AI Ultra subscribers.

Google’s evaluation report puts Argon at 77.9 percent on DeepSWE v1.1, an agentic coding benchmark, compared with 74.1 percent for GPT-6 Astra and 74.2 percent for Claude Opus 5.5. On AutomationBench, which tests business-process automation, it reports 51.3 percent, ahead of the three competing models listed.

The results do not show a lead across every task. Argon scored 55 percent on FrontierSWE v2, below Astra’s 65.5 percent and Opus 5.5’s 62.3 percent. It also trailed Opus on Terminal-bench 4.0 and PostTrainBench. On CWE-bench v1, a cybersecurity benchmark, Argon and Astra both scored 68 percent.

These are results assembled by Google, not an independent rerun of every model under identical conditions. Its report says competing models’ scores generally come from their providers unless otherwise noted. Some tests were run by Google across all models. The video evaluation used different frame limits because of API restrictions, another qualification when comparing the scores.

Argon’s results generally measure a single attempt, without combining multiple answers to improve success rates. Google used its highest reasoning settings unless specified otherwise and averaged repeated trials for some smaller tests.

Google also raised the model’s output limit to one million tokens from 64,000. That is the amount it can generate in a response, not a statement that its context window has grown to one million tokens.

The company describes controls for misuse, prompt injection and behavior outside an agent’s assigned task. It says it monitors both internal reasoning and actions, with the ability to stop an agent, and monitors training runs for behavior requiring an incident response. It is also isolating and sealing sandbox environments before high-risk training or evaluations.

Other laboratories have recently changed releases after safety testing. OpenAI withheld its proposed GPT-6.1 Astra update after finding problems with task authorization and reporting. Nvidia has separately introduced software and hardware controls around agents, including monitoring from a processor outside the agent’s host CPU.

Google says feedback from the initial defenders and trusted testers will inform further safeguards before broader distribution.

Sources: Google, Google DeepMind

–
By the Control Plane Editorial Team