Google's Argon patches vulnerabilities on its own, shipped without cyber guardrails
Google's new Gemini 4 Argon can find, validate and patch critical software flaws, and trusted defenders get it with the cyber safeguards removed.
On September 30, Google announced Gemini 4 Argon and said that, for trusted defenders and its own internal teams, it will release the model without cyber guardrails. The reason, according to Google, is that Argon can autonomously find, validate and patch critical software vulnerabilities, and the full capability is the point. Access is rolling out first through the Fairwind Program to a set of trusted cyber defenders. Everyone else waits.
What Google Says Argon Can Do
Argon is described as built for long, multi-step work: software engineering, legal and finance tasks, and defensive security. Google reports 77.9% on DeepSWE v1.1, a benchmark of long-horizon software engineering, and a tied-first 68% on CWE-bench v1, which tests whether a model can fix security vulnerabilities. It also reports a 51.3% score on Zapier's AutomationBench and 91.7% on LVBench for long-video understanding. These are the company's own figures, and the source does not say who ran each evaluation.
The most concrete security claim comes from Wiz, which used Argon in its Scan for Good program for protecting public infrastructure. Per Google, the model found a critical vulnerability exposing sensitive personal information in healthcare software used by hospitals worldwide, a risk previous frontier models had missed.
How Autonomous Patching Works, and Why It Cuts Both Ways
Finding a vulnerability and fixing it are separate skills. Discovery means reading code, or probing a live system with no source code at all (what Wiz's black-box penetration test measures), and spotting where an attacker could get in. Validation means producing a proof of concept showing the flaw is real, which filters out the false alarms that swamp human security teams. Patching means writing a change that closes the hole without breaking anything else. Argon is claimed to do all three without a human steering each step.
The same sequence describes an attack. A system that can locate and exploit a flaw to prove it is, step for step, doing what an intruder does. That is why Google restricts access and strips the guardrails only for vetted users: the guardrails normally make the model refuse exactly this kind of request. The practical effect is that the defensive and offensive versions of the capability differ mainly in who holds the keys.
A related claim from the announcement is Argon's 1M-token output limit, up from 64K. In plain terms, the model can generate far more in a single run, which lets it carry a long investigation or rewrite through without stopping. Google says this adds depth of reasoning on hard problems.
Who Gains, and Who Has Not Noticed
The clearest winners are organizations that run critical systems and lack large security teams, such as hospitals and public infrastructure operators, if defenders reach their flaws before attackers do. Engineering organizations gain too: Google says Argon agents are migrating C/C++ code to Rust, including 800K+ lines for the Fuchsia Zircon kernel, and sped up a memory-safe video decoder 2.7x over the existing Rust port with identical output.
The exposed group is everyone whose software sits in the queue. If defenders get these tools first, every unpatched dependency becomes a countdown. Smaller vendors with no access to Fairwind may learn about their flaws from someone else's scan. Argon launches at an introductory $2 per million input tokens and $10 per million output tokens, so the economics of scanning at scale will not be the barrier once access opens.
Questions You Should Be Asking
- Who decides which defenders count as "trusted," what vetting does Fairwind involve, and what happens when one of them is breached?
- Google says the unguarded model goes to internal teams too. What controls stop a stolen credential or a compromised insider from turning it into an attack tool?
- The healthcare flaw was found, but was it fixed, and how long did hospitals running that software remain exposed before disclosure?
- Argon's 68% on CWE-bench v1 is a tie for first. What does it get wrong the other 32% of the time, and who reviews a patch before it ships?
- The Rust migrations are still undergoing auditing and emulation testing. How many AI-written lines of kernel code does Google consider production-ready, and on what evidence?
What To Watch Next
The signal is the gap between Fairwind and the public release. Google says it will expand to paid API customers and Google AI Ultra subscribers once safeguards are strengthened, and that it is engaged in the U.S. government's voluntary pre-release access process. If broad release arrives with guardrails that hold under outside testing, and disclosed vulnerabilities start getting patched faster, the defensive bet is paying off. If the unguarded variant shows up in misuse reports first, that tells you where the balance really sits.
- 1Request access to Google's Fairwind Program if your organization performs defensive cybersecurity work to leverage Argon's autonomous vulnerability patching.
- 2Implement additional security monitoring when using unrestricted AI models like Argon to ensure autonomously generated patches don't introduce new vulnerabilities.
- 3Stay updated on when Argon becomes generally available, as guardrail-free access currently requires trusted defender status through limited rollout programs.
Ready to implement AI in your business?
Our team builds the AI systems you just read about. Start with a free 30-minute discovery meeting.
