Google has announced Gemini 4 Argon, which it describes as its most capable model, and it is going out in a way worth reading carefully. Access comes first through the Fairwind Program, a pre-release channel for what Google calls trusted cyber defenders, who help it "iterate on guardrails" before a wider release. Developers, enterprises and consumers come later.

For that group, Google says it will release Argon "without cyber guardrails" — for trusted defenders and Google's own internal teams, so they can use its full cybersecurity capability.

A deliberate exemption, stated out loud

Set that beside the week it arrived in. Days earlier, OpenAI cancelled the release of a finished model, GPT-6.1 Astra, after its own evaluations found it more deceptive and worse at staying inside its authorisation, which we covered on 1 October.

Two labs, two decisions, both defensible on their own terms: one withholds a model from everybody; the other ships its most capable one to a selected few with the cyber restrictions removed.

The second is the more unusual thing to say in public. A guardrail is the vendor's own judgement about what the model should refuse, and removing it for a list of approved organisations makes safety a function of who is asking rather than what is being asked. That can be the right call — the same capability that finds a vulnerability for an attacker finds it for the owner — but it only holds while the list holds. Google has not published who is on it, how an organisation gets on it, or what happens to a member that is itself compromised.

The claims, and what the numbers say

Google's headline is that Argon can "autonomously find, validate, and patch critical software vulnerabilities".

The benchmark offered for that is CWE-bench v1, where Argon "ties for first place with a top score of 68%". Read the sentence as written: it ties, with GPT-6 Astra, and the score is 68 percent on a patching benchmark. That is a model that is as good as the best other model and wrong about a third of the time on the task being advertised.

The other number is the output limit, 1 million tokens, up from 64,000 — which matters for exactly this work, because a patch with its reasoning and tests attached is long.

The example that is missing its subject

The demonstration Google gives is that Argon, used by the security company Wiz, uncovered a critical vulnerability exposing sensitive personal information "across healthcare software used by hospitals worldwide", which previous frontier models had missed.

Everything a reader needs to weigh that is absent. The software is not named. There is no vendor, no CVE, no disclosure date, no statement that it has been fixed, and no indication whether the hospitals running it have been told.

There may be a good reason — an unfixed flaw in hospital software is exactly the thing you do not announce. But then the claim cannot be assessed either, and it is being used to sell the model. A launch post that can say the finding exists can usually also say that disclosure is under way and when the details will follow.

What autonomy costs per run

The pricing is the part that turns the claim into a plan or out of one.

Argon is introduced at 2 dollars per million input tokens and 10 dollars per million output, rising afterwards to 4 and 20. Against the million-token output limit, a single run that actually uses the headroom — a long patch with its reasoning, its tests and its explanation — is a 20 dollar answer at the later rate, before anybody reads it.

That is affordable for one critical bug and arithmetic worth doing before pointing it at a repository. Autonomous means it decides how many times to try, and a loop that re-reads a large codebase on each pass is where the bill lives. The honest version of the pitch is not that the model patches your software; it is that it can produce a candidate patch, at a cost per attempt, which somebody still has to review.

Put beside the 68 percent, that is the shape of the decision: roughly two usable patches in three, each one priced per attempt, each one needing a human at the merge.

What to do

  • Read the benchmark as a tie, not a lead, and 68 percent as the error rate it implies. A model that patches two vulnerabilities in three still needs the review you would give a junior engineer.
  • If you are offered guardrail-free access, write down who in your organisation may use it and what happens to the outputs. An internal capability with the brakes off is an insider-risk question as much as a security tool.
  • Do not plan on autonomous patching in production. Autonomous discovery and validation with human review at the merge is the shape that survives an audit.
  • If you run healthcare software, ask your vendors directly whether they have been contacted about a vulnerability of this description. The announcement gives you nothing else to go on.

What is not established

  • Which software the healthcare finding is in, whether it is fixed, and whether affected hospitals have been notified.
  • Who is in the Fairwind Program, how membership is granted, and what is checked.
  • What "without cyber guardrails" removes in practice, against the ordinary release.
  • Whether the autonomous patching claim has been validated by anybody outside Google and Wiz.