News

Google Limits Gemini 4 Argon

Google’s newest AI model can help find the software flaws an attacker would need to break in. The company is giving selected cybersecurity defenders first access while it strengthens protections for a wider release.

Gemini 4 Argon, announced September 30, is intended for extended software engineering and enterprise work, including legal and financial research. But its initial rollout makes access itself part of the security strategy: deciding who can use the model while Google tests the safeguards that will govern broader availability.

Google says Argon can autonomously discover, validate, and patch critical vulnerabilities. Trusted defenders and internal Google teams will receive it “without cyber guardrails,” the company said.

That access comes through Google DeepMind’s Fairwind Program, which prioritizes organizations responsible for essential services, including government agencies and healthcare providers. Google argues that giving those organizations an early start can help them repair weaknesses before attackers exploit similar AI capabilities.

Fairwind’s published rules draw a distinction between removing model restrictions and removing oversight. Participating organizations must use authentication and phishing-resistant multifactor authentication, restrict access to designated security teams, and track employee use. They cannot share, redistribute, or sell access.

Google also conducts background checks on applicants. Authorized threat simulation and malware analysis for defensive research are permitted; creating malware for malicious purposes is prohibited.

For security leaders, those conditions make an Argon deployment an access-management decision as well as a technical evaluation. An organization would need to establish who can use it and how that use will be recorded. Membership in Fairwind also does not mean every participant receives Argon: Google says a selected group gets the model.

One application is Wiz’s Scan for Good initiative, which works with public services and critical infrastructure operators to identify and help remediate exposures. Wiz says it combines AI assessment with deterministic checks, validates high-impact findings, and privately discloses them to affected organizations.

Its published examples include exposed hospital staff information and a booking application that could have put patient records at risk. Those examples describe the broader program’s work, rather than establishing how much of it Argon performed.

The need for controls extends beyond deliberate misuse. In its AI Control Roadmap, published in June, DeepMind describes treating untrusted agents as potential insider threats and using supervisory systems to monitor their actions.

The roadmap says permissions should depend on verified behavior. It also distinguishes between reversible actions that can be reviewed afterward and high-risk actions that require intervention before execution. DeepMind reported that most events flagged by its monitoring research reflected misinterpretation or overenthusiasm in pursuing a task, rather than adversarial intent.

That distinction matters for enterprise buyers: a model can cause damage while trying to complete an authorized assignment. Assessing its ability to find a vulnerability is only part of evaluating whether it can safely operate inside an organization’s systems.

Google says paid API customers and Google AI Ultra subscribers will be first in line when access expands. Its announcement did not set a date for that release.

About the Author

John K. Waters is the editor in chief of a number of Converge360.com sites, with a focus on high-end development, AI and future tech. He's been writing about cutting-edge technologies and culture of Silicon Valley for more than two decades, and he's written more than a dozen books. He also co-scripted the documentary film Silicon Valley: A 100 Year Renaissance, which aired on PBS.  He can be reached at [email protected].

Featured