- Google launched its new frontier model Gemini 4 Argon on Sep 30, 2026. Through the Fairwind program, trusted defenders and Google’s internal teams get a version without cybersecurity guardrails, letting it operate at full cyberdefense capability.
- Google says cybersecurity firm Wiz used Argon in its Scan for Good program to find a critical flaw exposing sensitive patient data in hospital software used worldwide. The company has not disclosed the affected software’s name or its patch status.
- In the CWE-bench v1 vulnerability patching benchmark, Argon scored 68 percent, tying for first place with OpenAI’s GPT-6 Astra and xAI’s Grok 4.7.
On this page
Google removes Argon’s cybersecurity guardrails for trusted defenders
Google said in its Gemini 4 Argon launch post that the new model Argon is being rolled out to a group of trusted cyber defenders through the Fairwind program. Google’s internal teams are also using the model. The company said it will gradually expand access as it gathers feedback from early testers.
Google said Argon is trained to excel at cyberdefense and can autonomously find, verify and patch critical software vulnerabilities. The company said: ‘For trusted defenders and our own internal teams, we will release a version of Argon without cybersecurity guardrails, letting them unlock its full frontier-level cyberdefense capabilities.’
The Fairwind program launched in early September 2026, initially combining the Gemini 3.8 Flash Cyber model with Google’s CodeMender patching tool. It has already attracted more than 650 partners.
Argon finds critical flaw in hospital software
Wiz, the cybersecurity firm Google acquired in early 2026, is using Argon through its Scan for Good program, which finds and fixes high-risk vulnerabilities in critical public infrastructure for free.
Google said: ‘In one early demonstration of impact, the model found a critical vulnerability exposing sensitive patient personal data in hospital software used worldwide, identifying a severe risk that previous frontier models had failed to detect.’ Google did not disclose the name of the affected software or say whether the issue has been addressed.
Argon leads in multiple benchmark tests
In CWE-bench v1, a vulnerability patching benchmark developed by Collinear AI, Argon scored 68 percent, tying for first place with OpenAI’s GPT-6 Astra and xAI’s Grok 4.7. Google also said Argon shows a major improvement in vulnerability discovery compared with Gemini 3.8 Flash Cyber.
Google said that in its internal comprehensive vulnerability benchmark, Argon found multiple vulnerabilities across complex codebases spanning 20 programming languages. On Wiz’s internal black-box penetration testing benchmark, Argon outperformed Gemini 3.8 Flash Cyber at discovering attack surfaces, identifying vulnerabilities and producing proof-of-concept evidence.
Google strengthens safeguards ahead of wider release
Google said: ‘Safely releasing frontier capabilities at this level requires a staged approach.’ The company said it is participating in the United States government’s voluntary pre-release model access process.
For a wider rollout in future, Google said Argon is designed to refuse requests that could facilitate cyberattacks or chemical, biological, radiological and nuclear (CBRN) attacks, while still supporting legitimate dual-use scientific research. The company said it is improving techniques for monitoring the model’s internal activations to detect misuse. Google also said Argon is its most resistant model yet to indirect prompt injection.
What to do now
- Organisations that have joined the Fairwind program or are considering applying should ensure access is restricted, as required, to internal cybersecurity, incident response or penetration testing teams, and should deploy safeguards such as multi-factor authentication.
- Medical software vendors and hospital IT departments should watch for whether Google and Wiz later disclose the specific name of the affected software and patch information, to assess their own exposure.
- Teams using AI models for automated vulnerability patching should note Google’s stated misalignment mitigation mechanisms and chain-of-thought monitoring practices as a reference for evaluating their own AI agent controls.
FAQ
What is the Fairwind program?
The Fairwind program is a limited-access program Google launched in early September 2026. It provides government agencies, Google Cloud customers and cybersecurity partners with the Gemini 3.8 Flash Cyber model, paired with the CodeMender patching tool, to help autonomously find and fix vulnerabilities.
Is Gemini 4 Argon available to the public?
No. Google says Argon is currently being rolled out only to trusted cyber defenders and Google’s internal teams through the Fairwind program. The company says it will gradually expand access, gathering feedback from early testers before opening it to developers, businesses and consumers.
What is the hospital software vulnerability Argon found?
Google says Wiz used Argon through its Scan for Good program to find a critical vulnerability exposing sensitive patient personal data in hospital software used worldwide. Google has not disclosed the name of the software or said whether it has been patched.
How did Argon perform in vulnerability patching tests?
In the CWE-bench v1 benchmark, Argon scored 68 percent, tying for first place with OpenAI’s GPT-6 Astra and xAI’s Grok 4.7.
What is indirect prompt injection?
Indirect prompt injection is when an attacker hides malicious instructions in external content read by an AI model, such as a webpage or document, to trick the model into performing unauthorised actions that deviate from the user’s intent. Google says Argon is its most resistant model yet to this type of attack.



