Google Launches Gemini 4 Argon With Guardrail-Free Access for Vetted Defenders
Google's Gemini 4 Argon AI model found a critical vulnerability in hospital software.
Summary
Google has launched Gemini 4 Argon, a new frontier AI model initially available to vetted cyber defenders. The model is designed for complex tasks, including finding and patching software vulnerabilities. In an early test, Argon discovered a critical flaw in healthcare software used by hospitals worldwide, a vulnerability missed by previous AI models. Google is gradually expanding access and strengthening safeguards before a wider release.
Full text
Google on Wednesday announced Gemini 4 Argon, its new frontier AI model, which it is initially rolling out to a select group of trusted cyber defenders through its Fairwind Program. Google’s internal teams are also using the model. The company says it will expand access gradually as it gathers feedback from early testers. The tech giant says Argon is designed for complex workflows in software engineering, enterprise knowledge work such as legal and finance, and cybersecurity defense. On the security side, the company says it trained the model to be highly capable at cyber defense, and that it can autonomously find, validate, and patch critical software vulnerabilities. “For trusted defenders and our own internal teams at Google, we’ll be releasing Argon without cyber guardrails so they can leverage its full frontier-level cybersecurity defense capabilities,” the company said. Google launched Fairwind in early September as a limited access program for governments, Google Cloud customers, and cybersecurity partners. It initially combined the Gemini 3.8 Flash Cyber model with Google’s CodeMender harness, which finds, verifies, and fixes vulnerabilities. At launch, the program had more than 650 participating partners. Google says Argon found a flaw in hospital software Wiz, which Google acquired earlier this year, is using Argon in its Scan for Good initiative, which finds and remediates high-risk exposures in critical public infrastructure for free.Advertisement. Scroll to continue reading. “In an early demonstration of its impact, the model uncovered a critical vulnerability exposing sensitive personal information across healthcare software used by hospitals worldwide, identifying a severe risk that previous frontier models had missed,” Google said. The announcement does not name the affected software or say whether the issue has been addressed. On CWE-bench v1, a vulnerability remediation benchmark developed by Collinear AI, Argon tied for first place with a score of 68%, alongside OpenAI’s GPT-6 Astra and xAI’s Grok 4.7. The company also claims improvements in vulnerability discovery compared to Gemini 3.8 Flash Cyber. On Google’s internal vulnerability benchmark, Argon found a wide range of exposures across complex codebases written in 20 programming languages. On Wiz’s internal black-box penetration testing benchmark, which targets live web systems without access to source code, Argon outperformed Gemini 3.8 Flash Cyber. Google says it was better at discovering the attack surface, identifying vulnerabilities, and producing proof-of-concept evidence. Google is strengthening safeguards before a wider release “Safely releasing frontier capabilities at this level requires a phased approach,” Google said, noting that it is taking part in the US government’s voluntary process for pre-release model access. For the broader rollout, Google says the model is designed to refuse requests that could enable cyber or chemical, biological, radiological, and nuclear (CBRN) attacks, while still supporting legitimate dual-use scientific research. These safeguards include improved techniques for monitoring the model’s internal activations to spot misuse. Google also describes Argon as its most resilient model yet against indirect prompt injection. “In order to prevent Argon from stepping out of bounds to try to accomplish a task in a way that goes beyond the user’s intentions, we are deploying misalignment mitigations that monitor Argon’s chain-of-thought and actions and stop execution when necessary,” the company explained. The company is also isolating and sealing its sandboxed environments before high-risk training or evaluations begin. Related: Google: AI Is Changing the Pace and Profile of Vulnerability Discovery Related: Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit Related: Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs High-Severity Vulnerabilities Patched in OpenSSL, WolfSSLNew Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data LeaksPentagon Personnel Agency Data Breach Impacts 3 Million PeopleOpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier TrainingApple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’ Nvidia Unveils AI Agent Safety Platform With Hardware-Based WatchdogCitrix Confirms 2 NetScaler Zero-Days After Admins Pulled the PlugMicrosoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks Latest News FTC is Investigating OpenAI and Anthropic Over Possible Risks to ConsumersGoogle: AI Is Changing the Pace and Profile of Vulnerability DiscoveryWatchGuard Patches Critical Fireware OS Code Injection VulnerabilityGovernment, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day AttacksChrome, Firefox Updates Patch Over 100 VulnerabilitiesAnthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking LawsuitRussian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent AttacksShinyHunters Defiant After FBI Calls on Members to Come Forward Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveDavid Cass has joined Grayscale Investments as Chief Risk Officer.Thomas Dager has been appointed Vice President and Chief Information Security Officer at The Goodyear Tire & Rubber Company.Alex Stamos has become Chief Information Security Officer at Cognition.More People On The MoveExpert Insights Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) Flipboard Reddit Whatsapp Whatsapp Email