Google Unveils Gemini 4 Argon With 1M-Token Output and Frontier Cyber Skills
Google's Gemini 4 Argon pairs a 1M-token output limit with leading coding and cyber scores, phased access, and API pricing from $2 per million inputs.
Summary
Google announced Gemini 4 Argon on September 30, 2026, initially releasing it without cyber guardrails to trusted defenders through the Fairwind Program. Developers, enterprises and consumers follow after tester feedback, safeguard work and the U.S. government’s voluntary pre-release access process, starting with paid API customers and Google AI Ultra subscribers. Its output limit rises from 64K to 1 million tokens. Introductory API pricing is $2 per million input tokens and $10 per million output tokens, with cached inputs 95% cheaper, later doubling to $4 and $20.
Thousands of Googlers are using Argon for coding, research and writing. It beat a published quantum optimization baseline by 40% within minutes; memory agents freed over 300 TiB, with estimated savings of 500 TiB to 1 PiB; and agents are migrating C/C++ systems to Rust, from re2 and libgav1 to the 800K-plus-line Fuchsia OS Zircon kernel. For libgav1, Argon replaced 32K SIMD lines, producing identical output while running 2.7 times faster than the existing Rust port. Argon scored 77.9% on DeepSWE v1.1, led the Vals Index, Vals Finance Agent v2 and Harvey’s Legal Agent Benchmark, ranked first on AutomationBench at 51.3%, and reached 91.7% on LVBench.
Argon autonomously finds, validates and patches vulnerabilities, tying first on CWE-bench v1 at 68%. Wiz used it through Scan for Good to uncover a critical healthcare software exposure affecting hospitals worldwide that earlier frontier models missed. It found flaws across 20 programming languages internally and beat 3.8 Flash Cyber in Wiz black-box testing. Before broad release, Google is strengthening protections against cyber and CBRN misuse, indirect prompt injection, misalignment and insecure agent environments through refusal controls, activation and chain-of-thought monitoring, red teaming, adversarial training, execution stops and sealed sandboxes.
Positives
- The 1 million-token output limit expands Argon’s ceiling from 64K for long, multi-step workflows.
- A 40% improvement over a published quantum optimization baseline was achieved within minutes.
- Over 300 TiB of memory was freed, with projected total savings of 500 TiB to 1 PiB.
- Argon’s libgav1 work replaced 32K SIMD lines and ran 2.7 times faster than the existing Rust port.
- A 77.9% DeepSWE v1.1 score and 51.3% AutomationBench result place Argon first on major workflow evaluations.
- Wiz found a critical worldwide healthcare software exposure that previous frontier models had missed.
Risks & concerns
- Trusted cyber defenders receive Argon without cyber guardrails, increasing the importance of strict access controls.
- Cyber and CBRN misuse remain serious enough to require stronger refusal systems and internal-activation monitoring.
- Indirect prompt injection still requires layered defenses despite Argon leading Gray Swan’s IPI benchmark.
- Misalignment controls may stop execution when chain-of-thought and action monitoring detects behavior beyond user intent.
- Large Rust migrations, including the 800K-plus-line Zircon kernel, require extensive auditing, emulation testing and manual review.
- Broad availability remains pending while Google collects feedback and strengthens safeguards.