Key takeaways
- Google announced Gemini 4 Argon on September 30, 2026. It is available now only to a selected set of trusted cyber defenders through the Fairwind Program, not generally to Gemini API developers or consumers.
- Google says the introductory price will be $2 per million input tokens and $10 per million output tokens, with cached input 95% below the input rate. The announcement does not publish a billing start date, API model ID or complete pricing conditions.
- Argon raises the stated maximum output from 64K to 1 million tokens. Google did not publish a total context-window specification in the reviewed announcement, so the output ceiling should not be described as a 1-million-token context window.
- Google reports 77.9% on DeepSWE v1.1, 51.3% on AutomationBench, 91.7% on LVBench and 68% on CWE-bench v1. These are vendor-presented results, not AccessAllGPT reproductions.
- Paid API customers and Google AI Ultra subscribers are named as the first broader audiences, but Google says only “starting with” those groups and gives no release date. Builders should wait for a public model card, API identifier and account-visible terms before planning production migration.
Google announced Gemini 4 Argon on September 30
Google announced Gemini 4 Argon on September 30, 2026 as a frontier model for long-running software engineering, enterprise knowledge work and cybersecurity defense. The company says the first live rollout is to selected trusted cyber defenders in its Fairwind Program. It plans to widen access after gathering feedback and strengthening guardrails, beginning with paid API customers and Google AI Ultra subscribers.
That sequence matters more than the launch language. The reviewed public material does not provide a general-release date, public API identifier, account eligibility page or consumer rollout schedule. Google’s live developer pricing catalog, updated October 1, did not yet contain an Argon entry. Argon is an announced model with narrow early access today—not a generally available endpoint that every builder can call.
The announced price is $2 input and $10 output
Google says Argon will launch at an introductory rate of $2 per million input tokens and $10 per million output tokens. Cached input is described as 95% off the input rate, which corresponds to $0.10 per million cached input tokens. The announcement does not state a free-tier allowance, batch rate, context-based surcharge, cache-storage charge, regional premium or date when billing begins.
Treat those numbers as planned introductory list prices, not a current invoice guarantee. The word “introductory” leaves future duration and replacement pricing unspecified, and the absence of Argon from the public pricing table means there is not yet a complete public billing contract to evaluate. Cost-per-task also depends on reasoning length, unusually large outputs, retries, tool calls and whether cache reuse is attainable.
One million output tokens is not a context-window claim
Google says Argon increases the maximum output-token limit from 64K to 1 million so the model can sustain long reasoning and generation trajectories. That is a major interface claim, but it is specifically an output limit. The reviewed announcement does not state Argon’s maximum input size or total context window.
A larger ceiling does not establish that typical responses should approach it, that long trajectories remain correct, or that an application can safely consume the resulting latency and cost. Teams should separately measure accepted outcomes, completion time, truncation, repetition, tool-state drift and reviewer burden across increasing output bands once a documented endpoint is available.
Google reports leads in coding, enterprise and video evaluations
Google reports Argon at 77.9% on DeepSWE v1.1 for long-horizon software engineering, 51.3% and first place on Zapier’s AutomationBench, 91.7% on LVBench for long-video understanding, and leadership on the Vals Index plus named finance and legal evaluations. These figures come from Google’s launch presentation; AccessAllGPT did not reproduce them or review complete per-task traces and contamination controls.
The announcement also describes internal outcomes: a quantum subroutine example beating a published baseline by 40%, agent-driven memory optimizations that freed more than 300 TiB after rollout, and code-migration work including a 32K-line SIMD replacement for libgav1. These are Google-reported case studies, not general performance guarantees. Buyers still need workload-specific comparisons with fixed tools, stop conditions and accepted-output scoring.
Cyber defenders get a distinct early-access path
Google says Argon can find, validate and patch vulnerabilities and that selected Fairwind defenders receive a configuration without cyber guardrails for authorized defensive use. The Fairwind page says a subset of approved partners can use Argon as a standalone managed model or with CodeMender. It prioritizes governments, critical-infrastructure operators, core technology platforms and academic defensive benchmarking labs.
This is controlled access, not an open cyber model release. Participating organizations agree to user-level authentication, phishing-resistant multifactor authentication, access tracking and restrictions to internal cybersecurity, incident-response or penetration-testing teams. Google prohibits sharing, resale and malicious tasks. The page says zero data retention is supported when Argon is accessed directly as a managed model on Gemini Enterprise; teams must verify that configuration and contract in their own tenant.
The safety evidence is promising but incomplete publicly
Google says Argon ties for first at 68% on CWE-bench v1, improves on 3.8 Flash Cyber in internal vulnerability testing and leads Gray Swan’s indirect prompt-injection benchmark. It describes internal and external red teaming, activation monitoring for misuse, chain-of-thought and action monitoring for misalignment, and hardened isolated environments for high-risk evaluations.
Those are vendor claims and control descriptions. The launch page does not provide a public system card with complete evaluation sets, confidence intervals, subgroup failures, monitor thresholds, bypass rates or deployment incident data. Monitoring model reasoning may help detect failures, but it should not replace deterministic authorization, least privilege, isolated execution, independent logs and tested rollback around consequential actions.
What builders and buyers should do next
Most teams should wait for three concrete artifacts: an account-visible API model identifier and availability notice, a full model or system card, and complete pricing and service terms. At that point, freeze representative coding or knowledge-work cases and compare Argon with the current production model under identical tool permissions, time budgets, stop conditions and review rules. Measure accepted outcomes, severe failures, latency, total tokens, cache behavior, retries and cost per accepted task.
Eligible Fairwind defenders can consider a bounded pilot now, but should record the exact managed route, zero-retention setting, permitted users and tasks, authentication, external tool authority, monitoring, escalation and revocation evidence. Do not schedule a production migration from the headline alone. The useful decision today is wait, or run a tightly governed early-access evaluation if Google has explicitly approved the organization.
Copy-ready Gemini 4 Argon readiness record
Complete this when Argon becomes visible in your account or your organization receives Fairwind approval. Mark anything not documented for that access path as unresolved.
Entries stay in this browser tab and are not submitted to AccessAllGPT. Blank responses are copied as [Unresolved].
Program, account, region, plan, approval, availability date, API or managed-model identifier and responsible owner.
Input, cached-input and output rates; batch, storage, tool and regional charges; introductory-price duration; quotas and spend limits.
Input and total context, 1M output eligibility, modalities, tool support, streaming, structured output, caching and endpoint constraints.
Named task, current model, frozen cases, tools, permissions, stop conditions, acceptance checks and reviewers.
Accepted results, severe failures, latency, output length, repetition, tool-state errors, retries, reviewer effort and cost per accepted task.
Retention mode, training use, region, subprocessors, logs, cache lifecycle, deletion, contract evidence and tenant screenshots.
Permitted users and tasks, identity and MFA, read/write scopes, isolation, approvals, monitor response, kill switch and rollback.
Missing system card, benchmark details, API documentation, safety thresholds, incident evidence or final service terms.
Wait, pilot, constrain, deploy or reject; traffic ceiling, expiry, owner, unresolved blockers and revalidation triggers.
Primary sources
Browse the publication-wide evidence index →
- Gemini 4 Argon: our next era of frontier intelligenceGoogle · Reviewed: September 30 announcement; initial Fairwind rollout; planned audience; introductory pricing; output limit; internal use cases; coding, enterprise and cyber evaluations; safeguards; rollout sequence · Retrieved · Supports: Google announced Gemini 4 Argon on September 30, 2026, said access is initially limited to selected Fairwind cyber defenders, stated a planned introductory price of $2 per million input tokens and $10 per million output tokens, and reported a 1-million-token output limit plus vendor and partner evaluation results.
- Fairwind ProgramGoogle DeepMind · Reviewed: Program purpose; partner scope; Gemini 4 Argon access; CodeMender integration; governance; authentication and access controls; eligibility; permitted dual-use tasks; managed access; zero data retention FAQ · Retrieved · Supports: Google DeepMind says selected approved Fairwind partners have exclusive early access to the cyber-defense configuration of Gemini 4 Argon, with controlled use by eligible defensive teams and zero-data-retention support when the model is accessed directly through Gemini Enterprise.
- Gemini Developer API pricingGoogle AI for Developers · Reviewed: Current model navigation; free, paid and enterprise tiers; model-by-model pricing table; page update timestamp of October 1, 2026; search for an Argon listing · Retrieved · Supports: Google’s live Gemini Developer API pricing page was updated October 1, 2026 but did not yet list Gemini 4 Argon or an Argon API model identifier when AccessAllGPT reviewed it. This supports treating the announced price as future introductory pricing rather than proof of general API availability.
Limitations
AccessAllGPT reviewed public first-party Google pages only. We did not have Gemini 4 Argon or Fairwind access; call an Argon endpoint; confirm a private API identifier, quota, region, modality, context window, latency or final bill; reproduce DeepSWE, Vals, AutomationBench, LVBench, CWE-bench, Gray Swan or internal Google and Wiz evaluations; inspect evaluation prompts, complete traces, contamination checks or uncertainty; validate the reported internal deployments; test cyber capabilities, prompt-injection resistance, misuse refusal, reasoning monitors, sandboxing, CodeMender integration or zero data retention; or review a customer contract. The introductory price lacks complete public billing conditions, and all broad-release timing remains unspecified. Product pages, prices, access and safeguards can change.
Disclosures
AccessAllGPT did not receive Google access, credits, a subscription, briefing, demo, review or compensation for this article. Google did not sponsor, review or endorse it. AccessAllGPT Research is operated by NeuralArc, is independent, and is not affiliated with Google, Google DeepMind or organizations cited. Publication-wide relationships are listed on the disclosures page.
Further AccessAllGPT guidance
- OpenAI Launches GPT-6.1 Sol at $2 Input and $10 Output per Million Tokens
- Google Launches Gemini 3.8 Flash With Explicit Reasoning Controls
- Gemini 3.8 Live Avatar Reaches General Availability
- GPT-6 Astra: Test the Agent Controls Before You Trust the Benchmark Lead
- Anthropic Says GLM-5.3 Completed 50 of 410 Exploit Attempts
- Choose a Model Without Chasing the Leaderboard
- Move an LLM API Without Breaking Production
- AccessAllGPT Research methodology
- Publication disclosures
Continue the research
Get evidence-led updates for teams making production AI decisions.