Skip to content

Security3 publishers2 min readPublished

Google gives vetted defenders a Gemini 4 Argon build without cyber guardrails

Google will give vetted defenders and its own teams a Gemini 4 Argon build with no cyber guardrails, saying the model finds and patches critical flaws unaided. Wiz is the first named outside user, and the bug-finding evidence published so far comes from Google's own internal tests.

The Watch · Security desk

Illustration accompanying Google gives vetted defenders a Gemini 4 Argon build without cyber guardrails

What happened

  • Developers, enterprises and consumers get Argon later, starting with paid API customers and Google AI Ultra subscribers.
  • Google says Argon found a critical flaw exposing personal data in healthcare software used by hospitals worldwide, but did not name the product or say whether it is patched.
  • In Wiz's black-box test against live web systems, Argon beat 3.8 Flash Cyber at mapping attack surface, finding flaws and producing proof-of-concept evidence.
  • On CWE-bench v1, a test of fixing security vulnerabilities, Argon scored 68% and tied for first place.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Hospitals running the unnamed healthcare software cannot check their exposure or patch status, so the one field finding Google cites does nothing yet for the people it affects.
  • precedent The first Argon-found bugs most operators see will likely arrive through Fairwind vendors such as Wiz, whose Scan for Good program fixes public-infrastructure exposures for free, before customers can run the model.
  • constraint Automated patches will still go through human review. Google is holding its own 800,000-line Zircon kernel rewrite in audits and emulation testing before production.
  • cost At launch prices even a maximal run is cheap, so the guardrails Google is still tuning will be the main barrier to offensive use of the public model.

Google ties the unguarded build to a staged rollout that starts with trusted defenders in its Fairwind Program [1]. It says a phased approach is required to release capabilities at this level safely [7]. Before the broad release, Google says, it is strengthening safeguards against cyber and chemical, biological, radiological and nuclear misuse, and internal and external red teams have tested them [5]. Monitors watch Argon's reasoning and actions and stop execution when needed, according to Google [6]. The company is also taking part in the U.S. government's voluntary process for pre-release model access [8].

For organisations outside the vetted group, the launch does not change what an attacker can do today [3]. Help Net Security's account describes no attacker use of Argon and no copy of the unguarded build outside the Fairwind defenders and Google's internal teams [3]. On that record, the route to Argon for anyone else is the later public release, behind guardrails Google says it is still adjusting with feedback from early testers [7].

The long unattended runs come from a larger output budget. Google raised the output limit from 64,000 tokens to 1 million [11], about 15.6 times the old ceiling [1]. Google says the model can now think and write for hundreds of thousands of tokens in a single run [12]. A run that fills the full million-token window costs $10 in output at launch rates and $20 once they double [2]. Cached input costs $0.10 per million tokens during the introductory period [3].

Google's discovery numbers come from an internal test spanning complex codebases in 20 programming languages [16]. On fixing, the public evidence is one benchmark score and Google's own code migrations. Argon's CWE-bench v1 score is 32 points short of a perfect mark [4]. Argon agents replaced 32,000 lines of SIMD code in the libgav1 video decoder with Rust [13]. The new decoder runs 2.7 times faster than the earlier Rust port, with identical video output [13]. Agents also applied memory optimizations across Google's data centers that freed more than 300 TiB once rolled out [20].

What to watch

  • Google or the software maker naming the hospital software Argon flagged, with a CVE and patch status.
  • A date for the paid API and AI Ultra release, and a description of which cyber guardrails ship with it.
  • Fairwind participants beyond Wiz being named, or Argon-found bugs appearing in public vendor advisories.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories