Google's Gemini 4 Argon goes to cyber defenders first

Google released its new frontier model, Gemini 4 Argon, on 30 September 2026 to a group of vetted cybersecurity defenders before anyone else. Google says Argon can find, check and fix critical software vulnerabilities on its own, and that it has already found a serious flaw in healthcare software used by hospitals worldwide. Developers and businesses get access later.

What happened

Google announced Argon on its blog and is rolling it out first through the Fairwind Program, which it describes as proactive cyber defence for governments and enterprises. SecurityWeek reports that Fairwind started in early September with more than 650 partners.

The key points from Google’s announcement and the coverage:

  • Defenders first. Trusted defenders and Google’s own teams get a version of Argon without cyber guardrails, so they can use its full capability for defensive work.
  • A real find. Google says Argon uncovered a critical vulnerability exposing sensitive personal information in healthcare software used by hospitals worldwide. It has not named the software.
  • Strong scores. Google reports 77.9% on the DeepSWE v1.1 coding test and 68% on CWE-bench v1 for fixing vulnerabilities. SecurityWeek notes that 68% ties with OpenAI’s GPT-6 Astra and xAI’s Grok 4.7.
  • Wider access later. Paid API customers and Google AI Ultra subscribers come next. Google lists introductory API pricing of US$2 per million input tokens and US$10 per million output tokens.

Google also says it is monitoring Argon’s reasoning and actions and will stop execution when needed, as part of its safeguards against misuse.

Why it matters

The same skill that lets an AI model find and fix a flaw for a defender can help an attacker find it first. That is why Google is giving defenders a head start. But it also means the time between a weakness existing and someone finding it is getting shorter for every business, not just hospitals and governments.

For most companies the risk is not in famous software. It is in the custom website, booking system, customer portal or CRM that was built once, works fine and has not been reviewed since.

What it means for UAE businesses

If your business runs any custom software, three steps are worth taking now:

  • Get it reviewed before someone else does. Ask your developer, or an outside team, to audit the code and the setup: logins, admin access, file uploads and anything that touches customer data.
  • Check rate limits and caching. Login pages and forms without rate limits invite brute-force attempts, and poor caching can expose data or slow everything down. These are quick fixes once found.
  • Keep dependencies updated. Old libraries carry flaws that are already publicly known, so set a regular schedule for updates.

Our custom development team builds and reviews web apps, portals and back-office tools with these checks built in.

Frequently asked questions

Can businesses use Gemini 4 Argon now? Not yet unless you are in Google’s Fairwind Program. Google says paid API customers and Google AI Ultra subscribers will be next.

What did Gemini 4 Argon find? Google says it found a critical vulnerability exposing sensitive personal information in healthcare software used by hospitals worldwide. Google has not named the software.

Should a small business worry about AI-powered attacks? Yes, but the answer is ordinary good practice: review custom code, limit login attempts, update dependencies and back up data.

Sources

Note: Model access, pricing and benchmark results are as published by Google and reported at the time of writing, and may change as the rollout widens.

If you want your website or app reviewed, book a free strategy call.

Related service Custom Development

Related reading

Put this to work in your business

Book a free 30-minute strategy call and we will turn these ideas into a concrete plan for your team.