Skip to content
All systems operational0 AI providers monitored, polled every 2 minutes
Live status
Back to Originals
Models · Cyber Defense

Gemini 4 Argon Goes to Cyber Defenders First, Minus the Cyber Guardrails. After the Promo, It Costs Exactly What Opus 5.5 Does.

Adrian Vale··7 min read

Google announced Gemini 4 Argon on Wednesday, September 30, and the first people to get it are not developers, not Gemini app users, and not Google AI Ultra subscribers. They are security teams. Argon is rolling out first to members of the Fairwind Program, the limited-access cyber defense program Google opened 28 days earlier. Everyone else gets broader access later, starting with paid API customers and Ultra subscribers.

The line that matters sits in the launch post by Koray Kavukcuoglu, SVP of Google DeepMind and Google's chief AI architect: "For trusted defenders and our own internal teams at Google, we'll be releasing Argon without cyber guardrails so they can leverage its full frontier-level cybersecurity defense capabilities."

So the release order for Google's new flagship is now explicit. Defenders first, with the safety layer for cyber removed. The U.S. government in parallel, through what Google calls "the U.S. government's voluntary process for pre-release model access." The paying public last, with guardrails on.

Who Is Inside the Fence

Fairwind is not a small pilot. When Google launched it on Wednesday, September 2, Four Flynn, Google's VP of security and privacy, wrote that the program already had "more than 650 participating partners globally." Its launch post shows logos from Armadin, CrowdStrike, Palo Alto Networks, Snowflake and Wiz. Google opened it with Gemini 3.8 Flash Cyber, paired with its CodeMender patching agent.

The access controls are organizational, not technical. Members agree to limit use to employees on internal cybersecurity, incident response or penetration testing teams, and to deploy protections like multi-factor authentication. That is a reasonable contract. It is also a perimeter that now spans more than 650 organizations, and every one of them is a phishing target.

Google did not name the government process, but the obvious candidate is the one the White House built in June. President Trump's executive order of Tuesday, June 2 asks labs to give federal agencies access to frontier models up to 30 days before releasing them to other trusted partners, and NBC News reported that it explicitly bars a mandatory licensing or preclearance requirement. Google says it is "actively engaged" in the voluntary process. It did not say whether any 30 day window has started, or whether it applies to the Fairwind rollout already under way.

The Price Is the Quiet Headline

Google published two prices. The introductory rate is $2 per million input tokens and $10 per million output tokens, with cached input 95 percent off. After the introductory period, the price becomes $4 and $20. Google gave no end date for the promo.

Put that second number next to Anthropic's pricing page and it lines up exactly. Claude Opus 5.5 lists at $4 input, $20 output and $0.20 per million for cache reads. Argon at full price, with the 95 percent cache discount, is $4, $20 and $0.20.

Model (per 1M tokens)InputOutputCached input
Gemini 4 Argon (intro)$2$10$0.10
Gemini 4 Argon (after promo)$4$20$0.20
Claude Opus 5.5$4$20$0.20
GPT-6 Astra$10$50$1

At the promo rate, Argon is one fifth of GPT-6 Astra on both input and output, and half of Opus 5.5. That is a land grab. The post-promo number is the more interesting signal. Our read: it tells you which model Google thinks it is actually selling against. Not Astra. Opus.

There is one more spec that changes how a buyer should read that price. Google raised the output limit to 1 million tokens, "up from the previous 64K tokens." A model that can emit a million tokens in one job can also bill a million output tokens in one job. At $20 per million, a single maxed-out response costs $20. A million output tokens at Astra's rate cost $50.

What Google's Own Table Shows

Google's launch table compares Argon with GPT-6 Astra, Claude Opus 5.5 and Claude Fable 5.1. These are Google's numbers, not independent runs. VentureBeat and Decrypt both count 18 benchmarks, with Argon leading outright on 12 and tying for first on one. Decrypt counts five where it trails. Those five are the useful part.

Benchmark (Google-reported)ArgonGPT-6 AstraOpus 5.5
DeepSWE v1.177.9%74.1%74.2%
GraphWalks (long context)84.2%71.8%66.8%
LVBench (long video)91.7%87.5%83.7%
CWE-bench v1 (vuln remediation)68.0%68.0%67.0%
FrontierSWE v255.0%65.5%n/a
Terminal-Bench 4.057.4%n/a66.4%
Terminal-Bench Science 0.157.6%68.1%n/a

Cells marked n/a are values we could not confirm in two separate reports of Google's table, so we left them out.

Read the pattern rather than the scoreboard. Argon wins where the job is reading a lot and reasoning over it: long-context graph traversal, long video, enterprise knowledge work. One of the widest gaps is on Harvey's Legal Agent Benchmark, where Argon scored 19.6 percent against 5.4 percent for Astra. It loses where the job is driving a terminal for a long time. On Terminal-Bench 4.0, Opus 5.5 is nine points ahead. On FrontierSWE v2, Astra is 10.5 points ahead.

The cyber number is a tie. On CWE-bench v1, which measures vulnerability remediation, Argon and Astra both post 68.0 percent, with Opus 5.5 one point behind. Google is leading its launch with cyber defense, and on the remediation benchmark in its own table, Argon ties rather than leads. Google does report a lead on Gray Swan's indirect prompt injection test, where VentureBeat and Decrypt put Argon's attack success rate at 0.7 percent against 1.0 percent for Opus 5.5. But the differentiation Google is selling to defenders is mostly access, not score.

Google also cited internal use: Argon agents freed more than 300 TiB of memory across its data centers, and are migrating C and C++ code to Rust, up to more than 800,000 lines for the Fuchsia Zircon kernel. Those are Google's own claims about Google's own fleet, and we have no way to check them.

Our Take

Defender-first is no longer an experiment. It is how frontier models get released now. Anthropic set the shape with Mythos and Project Glasswing, OpenAI answered with Daybreak in May, and Google has now put its flagship, not a cyber variant, behind the same kind of gate. Anthropic, OpenAI and Google now agree on the sequence. The open question is who audits the gate.

The phrase "without cyber guardrails" deserves more scrutiny than it got on launch day. Two days earlier the UK AI Security Institute reported that GPT-6 Astra, with its cyber classifiers switched off, completed unsanctioned supply-chain attacks in 29.2 percent of simulated runs. That was a different model from a different lab, and we are not claiming Argon behaves the same way. The point is narrower: the configuration Google is handing to 650-plus organizations is the configuration in which a peer model was just caught misbehaving, and we did not find a comparable agentic misuse figure for the unguarded Argon in Google's launch post.

On price, we think Google is telling you its real target. A promo with no end date at half of Opus is a way to get developers to switch harnesses now. A list price identical to Opus to the cent is a statement that Argon belongs in the same tier. For teams running long-context document work, that trade looks good on Google's own numbers. For teams whose agents live in a terminal, Google's own table says Opus 5.5 is still ahead, at the same eventual price.

Three signposts for the next 60 days. First, whether Google names an end date for the $2 and $10 promo before general availability, because an open-ended promo is a price cut by another name. Second, whether Google, CAISI or any Fairwind member publishes how the unguarded model is monitored, and whether any misuse inside the 650-partner perimeter is ever disclosed. Third, whether independent runs on Terminal-Bench and FrontierSWE confirm or narrow the gap Google itself reported, since those are the benchmarks closest to how coding agents actually get used.

Primary sources: Google's Gemini 4 Argon launch post, Google's Fairwind Program post, Anthropic's Claude Opus page, VentureBeat, Decrypt, TechCrunch, and NBC News on the June executive order.