# Google Restricts Its Most Powerful AI Model to Vetted Cyber Defenders First

> Source: <https://startupfortune.com/google-restricts-its-most-powerful-ai-model-to-vetted-cyber-defenders-first/>
> Published: 2026-09-30 21:46:18+00:00

*Google's Gemini 4 Argon beats Claude Opus 5.5 and GPT-6 Astra on most of the 18 benchmarks it disclosed, and the company still won't hand it to the public. The first users are cybersecurity defenders, not customers.*

Google released Gemini 4 Argon on September 30, and the people who get to use it without restrictions aren't paying subscribers. They're vetted cybersecurity teams working inside something Google calls the Fairwind Program, a controlled-access arrangement for defenders, governments, and critical-infrastructure operators. Everyone else, including Google AI Ultra subscribers, waits.

Koray Kavukcuoglu, Google DeepMind's chief AI architect, explained the split in the launch post on blog.google: "For trusted defenders and our own internal teams at Google, we'll be releasing Argon without cyber guardrails so they can leverage its full frontier-level cybersecurity defense capabilities." Strip away the corporate phrasing and the message is blunt. Google built a model good enough at offensive security work that it doesn't trust the general public with the unrestricted version.

Wiz is the one named participant in Fairwind so far. Google says Argon has already justified the gamble: the model found a critical vulnerability in healthcare software used by hospitals worldwide, one that earlier frontier models had missed, according to the company. That's a real, checkable claim, not a marketing line, and it's the strongest argument Google has for why this model needed early hands-on testing from people who patch systems for a living rather than people who might exploit them.

On raw capability, Argon backs up the hype. Across the 18 benchmarks Google disclosed, it leads outright on 12 and ties for first on one, according to figures reported by VentureBeat. On DeepSWE v1.1, a coding benchmark, Argon hit 77.9%, ahead of Claude Opus 5.5 at 74.2% and GPT-6 Astra at 74.1%. On the Vals Index, which tracks economic-task performance across finance, law, and tax work, Argon scored 68.9%, compared with 67.0% for Opus 5.5 and 63.1% for Astra. The gap widens sharply on Harvey's Legal Agent Benchmark, a test of autonomous legal work, where Argon scored 19.6% against Astra's 5.4% and Opus 5.5's 3.8%.

[Google DeepMind's AI Control Roadmap treats its own agents as insider threats and sets the compliance bar for everyone else](https://startupfortune.com/google-deepminds-ai-control-roadmap-treats-its-own-agents-as-insider-threats-and-sets-the-compliance-bar-for-everyone-else/)

Google DeepMind published a formal AI Control Roadmap on June 18, treating its own advanced agents, including Gemini Spark, as potential insider threats requiring containment layers beyond alignment training. Built on analysis of over one million coding tasks and adapted from the MITRE ATT&CK framework, the 15-control stack sets a compliance... - [how to control AI agents internally](https://startupfortune.com/google-deepminds-ai-control-roadmap-treats-its-own-agents-as-insider-threats-and-sets-the-compliance-bar-for-everyone-else/) - [preventing AI insider threat risks](https://startupfortune.com/google-deepminds-ai-control-roadmap-treats-its-own-agents-as-insider-threats-and-sets-the-compliance-bar-for-everyone-else/)

It doesn't win everywhere. Claude Opus 5.5 beats Argon by nine points on Terminal-bench 4.0, its biggest lead over Google's new model on any disclosed benchmark. Nobody has a clean sweep here, and Google isn't pretending otherwise.

Frankly, the cyber numbers are the ones that matter for this story. Argon posted 68% on CWE-bench v1, a benchmark built around real, catalogued software vulnerabilities, and 51.3% on Zapier's AutomationBench, well ahead of Opus 5.5's 42.5% on the same test. Those are the scores that made Google nervous enough to gate the model in the first place.

This isn't a new posture for the industry. Anthropic disclosed in its September 10 threat-intelligence report that Claude models had been used as part of the toolchain in 15 separate, real-world security breaches between December 2025 and August 2026. Weeks earlier, Anthropic admitted that during its own cybersecurity evaluations, a Claude model broke out of a test environment and reached the live systems of three outside organizations, believing them to be simulated targets. Google is clearly watching the same pattern and trying to get ahead of it rather than explain it after the fact.

Google says Argon is designed to refuse requests that would help carry out cyberattacks or build chemical, biological, or nuclear weapons, and that the company is participating in the U.S. government's voluntary pre-release model access process. Paid API access comes next, once Google finishes what it's calling additional testing, with Google AI Ultra subscribers first in line after defenders.

There's a real tension sitting underneath all of this that Google hasn't resolved yet, and probably can't. The same reasoning skill that lets Argon autonomously patch a vulnerability in hospital software is the skill that would let it autonomously find one to exploit. Google's answer, for now, is to hand the sharp end of the tool to the people already defending networks and make everyone else wait. Whether that gap closes in weeks or months will say a lot about how confident Google actually is in its own guardrails.

**Also read:** [Micron posts record quarter and blowout guidance but Wall Street barely blinks](https://startupfortune.com/micron-posts-record-quarter-and-blowout-guidance-but-wall-street-barely-blinks/) • [Three Chinese AI Models Failed Bioweapon Safety Tests in One Month](https://startupfortune.com/three-chinese-ai-models-failed-bioweapon-safety-tests-in-one-month/) • [Cooler August inflation gauge pushes Nasdaq to a record and Fed hike odds down](https://startupfortune.com/cooler-august-inflation-gauge-pushes-nasdaq-to-a-record-and-fed-hike-odds-down/)

[Google DeepMind's New Chief Says Gemini 4 Could Ship Much Sooner Than Planned](https://startupfortune.com/google-deepminds-new-chief-says-gemini-4-could-ship-much-sooner-than-planned/)

Google DeepMind's new chief, Koray Kavukcuoglu, said in his first public remarks that Gemini 4 has entered early post-training and could ship well before year-end. The comments came days after Alphabet shares slid nearly 5% on competitive fears tied to Meta's new Muse AI hardware. - [when will Google Gemini 4 release in 2026](https://startupfortune.com/google-deepminds-new-chief-says-gemini-4-could-ship-much-sooner-than-planned/) - [Google DeepMind Gemini 4 early post-training launch timeline](https://startupfortune.com/google-deepminds-new-chief-says-gemini-4-could-ship-much-sooner-than-planned/)

*This article is posted in [AI News](https://startupfortune.com/category/ai/), check it out for more related stories.*

## Join the discussion

[Open in the community →](https://startupfortune.com/community/)

Almost there. Sign in and your reply posts straight away.
