Google built its most powerful AI yet, and won't let you use it
Gemini 4 Argon, Google's new flagship model, can find and patch security flaws on its own. A little too well, apparently: Google is restricting it to 650 cybersecurity organisations for now, with no public release date. A plain-language look at what Google fears, and what its performance claims are worth.

On September 30, Google unveiled Gemini 4 Argon, the first model of its new Gemini 4 generation and, in its own words, the most powerful it has ever built. But the real news lies elsewhere: you can't use it. Neither can developers, nor businesses. For now, only a few hundred hand-picked cybersecurity organisations have access, and Google gives no date for the rest of the world. It's the first time an AI giant has launched its flagship model while keeping it under lock and key.
1. What Google announced
Argon replaces Gemini 3.5 Pro at the top of the lineup (TechCrunch). It is built for long, multi-step tasks: writing code, conducting research, analysing videos and charts. It can produce up to 1 million tokens in a single response (gHacks). To picture that number: a token is roughly three quarters of a word, so Argon can write the equivalent of several novels, or an entire codebase, in one go. But its specialty, the one that explains everything else, is defensive cybersecurity: Google says it can "autonomously find, validate, and patch critical software vulnerabilities."
2. Why you're not allowed in
Google is rolling Argon out in three phases (TechWire Asia). Phase 1, underway now: partners of the Fairwind program, launched on September 2, which brings together more than 650 organisations (national cybersecurity authorities, critical infrastructure operators, technology companies and security vendors). Even within those partners, access is limited to employees working in cybersecurity, incident response or penetration testing, with mandatory two-factor authentication. Phase 2: paying API customers and Google AI Ultra subscribers. Phase 3: the general public, with no date announced. Google describes a "phased" release made necessary by the model's level of capability.
3. What worries Google, in plain language
An AI that can find and fix security flaws on its own is wonderful for the people defending systems. The problem is that the skill works exactly the same way in reverse: knowing how to find a flaw to fix it means knowing how to find it to exploit it. It's a bit like a locksmith who can open any door in seconds: invaluable when you're locked out, dangerous in the wrong hands. Google names four specific risks: cyberattacks, chemical, biological, radiological and nuclear threats, unauthorised access to systems, and indirect prompt injection. That last term deserves an explanation: it refers to malicious instructions hidden inside a document, a web page or an email that the AI reads while working, designed to hijack its behaviour without the user noticing. The more autonomously a model acts, the more dangerous that trap becomes. To guard against it, Google says it ran manual and automated attack testing, trained the model to resist such injections, and built monitoring that halts execution as soon as the model deviates from the user's intent.
4. Really the most powerful on the market?
Google claims Argon scores significantly higher than OpenAI's GPT-6 Astra and Anthropic's Fable and Opus models, and points to the index run by benchmarking startup Vals, where Argon takes first place (TechCrunch). Two caveats apply. First, these are the numbers Google chose to highlight, and every lab picks the tests that flatter it. Second, almost nobody can verify them independently, because almost nobody has access to the model. On pricing, Google has at least shown its hand for phase 2: $2 per million input tokens and $10 per million output tokens at launch, rising to $4 and $20 once the introductory period ends (gHacks). Premium-model pricing, in line with its direct competitors.
The takeaway: Gemini 4 Argon may be the most powerful model of the moment, but for now it is mostly the least accessible. By reserving it for defenders first, Google is changing how frontier AI gets launched: no longer handed to everyone on day one, but distributed through circles of trust. One question nobody is really asking yet: if a model is considered too risky for developers, at what point does it become safe enough for the general public? Google doesn't have an answer yet. Neither do we.
Sources
- TechCrunch : Google releases Gemini 4 Argon, called its most powerful model yet
- TechWire Asia : Google launches Gemini 4 Argon, but limits access over cybersecurity risks
- gHacks : Gemini 4 Argon: 1 million token output limit, starting with cyber defenders
- 9to5Google : Google announces Gemini 4 Argon as its new frontier model
- CNBC : Google Gemini 4 arrives as Wall Street shifts to personal agents


