Security3 publishers2 min readPublished
Google gives vetted defenders a Gemini 4 Argon build without cyber guardrails
Google will give vetted defenders and its own teams a Gemini 4 Argon build with no cyber guardrails, saying the model finds and patches critical flaws unaided. Wiz is the first named outside user, and the bug-finding evidence published so far comes from Google's own internal tests.
The Watch · Security desk

What happened
- Developers, enterprises and consumers get Argon later, starting with paid API customers and Google AI Ultra subscribers.
- Google says Argon found a critical flaw exposing personal data in healthcare software used by hospitals worldwide, but did not name the product or say whether it is patched.
- In Wiz's black-box test against live web systems, Argon beat 3.8 Flash Cyber at mapping attack surface, finding flaws and producing proof-of-concept evidence.
- On CWE-bench v1, a test of fixing security vulnerabilities, Argon scored 68% and tied for first place.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Hospitals running the unnamed healthcare software cannot check their exposure or patch status, so the one field finding Google cites does nothing yet for the people it affects.
- precedent The first Argon-found bugs most operators see will likely arrive through Fairwind vendors such as Wiz, whose Scan for Good program fixes public-infrastructure exposures for free, before customers can run the model.
- constraint Automated patches will still go through human review. Google is holding its own 800,000-line Zircon kernel rewrite in audits and emulation testing before production.
- cost At launch prices even a maximal run is cheap, so the guardrails Google is still tuning will be the main barrier to offensive use of the public model.
Google ties the unguarded build to a staged rollout that starts with trusted defenders in its Fairwind Program [1]. It says a phased approach is required to release capabilities at this level safely [7]. Before the broad release, Google says, it is strengthening safeguards against cyber and chemical, biological, radiological and nuclear misuse, and internal and external red teams have tested them [5]. Monitors watch Argon's reasoning and actions and stop execution when needed, according to Google [6]. The company is also taking part in the U.S. government's voluntary process for pre-release model access [8].
For organisations outside the vetted group, the launch does not change what an attacker can do today [3]. Help Net Security's account describes no attacker use of Argon and no copy of the unguarded build outside the Fairwind defenders and Google's internal teams [3]. On that record, the route to Argon for anyone else is the later public release, behind guardrails Google says it is still adjusting with feedback from early testers [7].
The long unattended runs come from a larger output budget. Google raised the output limit from 64,000 tokens to 1 million [11], about 15.6 times the old ceiling [1]. Google says the model can now think and write for hundreds of thousands of tokens in a single run [12]. A run that fills the full million-token window costs $10 in output at launch rates and $20 once they double [2]. Cached input costs $0.10 per million tokens during the introductory period [3].
Google's discovery numbers come from an internal test spanning complex codebases in 20 programming languages [16]. On fixing, the public evidence is one benchmark score and Google's own code migrations. Argon's CWE-bench v1 score is 32 points short of a perfect mark [4]. Argon agents replaced 32,000 lines of SIMD code in the libgav1 video decoder with Rust [13]. The new decoder runs 2.7 times faster than the earlier Rust port, with identical video output [13]. Agents also applied memory optimizations across Google's data centers that freed more than 300 TiB once rolled out [20].
What to watch
- Google or the software maker naming the hospital software Argon flagged, with a CVE and patch status.
- A date for the paid API and AI Ultra release, and a description of which cyber guardrails ship with it.
- Fairwind participants beyond Wiz being named, or Argon-found bugs appearing in public vendor advisories.