Google has announced a new Gemini model with an unusually large appetite for difficult work. The catch is that most of us cannot use it yet.
Google announced Gemini 4 Argon on 30 September 2026 with a pitch built around extended software projects, specialist research and cyber defence. Google’s announcement describes a staged release, starting with selected trusted defenders. Paid API customers and Google AI Ultra subscribers are planned starting groups for wider access, with no calendar date given.
That makes this an announcement to understand before it becomes a product to choose. There is an interesting idea underneath it: give a model enough room to stay with a difficult problem, rather than expecting every useful job to fit into a quick exchange.
Availability and announced billing details were checked against Google’s public pages on 3 October 2026.
The bigger output limit and Google’s reported results point in that direction. The restricted rollout is equally important. A model’s promise and your ability to put it to work are two separate pieces of news.
Key points
- Argon is announced, with restricted early access. Selected trusted cyber defenders get the first release through Fairwind.
- Wider access is planned. Google names paid API customers and AI Ultra subscribers, but has not given a public launch date.
- Introductory API prices are US$2 input and US$10 output per million tokens. The announced later rates are US$4 and US$20.
- The million-token headline is an output limit. It gives the model more room for long runs; it is not an announcement of a new million-token input window.
- The results show strengths, not an across-the-board winner. Google’s table includes tasks where GPT-6 Astra and Claude Opus 5.5 score higher.
Who can actually use Argon?
The starting point is Fairwind, Google’s programme for trusted cyber defenders. It is a restricted route with approved organisations and defined uses, rather than a general invitation to everyone with a Gemini account.
| Access route | Current position | What it means for you |
|---|---|---|
| Selected Fairwind partners | Restricted early access | Approved defenders can use Argon, including with CodeMender |
| Paid Gemini API customers | Wider rollout planned | The announcement does not establish ordinary public API access today |
| Google AI Ultra subscribers | Planned starting group for wider release | An Ultra subscription is not, by itself, confirmation of current Argon access |
| Other Gemini users | No general access established by the announcement | Wait for a specific product and account rollout notice |
The Fairwind programme details limit access to approved trusted partners and internal defensive teams, with account controls and tracking. Partners cannot sell or redistribute access. The future API and Ultra plans come from the launch announcement.
This matters if you are wondering whether to change a subscription. Buying into a named future access group is still buying before the feature is available to you. I would want an actual rollout notice and a clear account entitlement before treating Argon as a reason to upgrade.
For developers, the same distinction applies. A model announced on a stage is not automatically a model you can put into the app you are shipping this week.
Google has announced the price, including the price after the offer
The introductory rates are competitive-looking. The later rates deserve just as much attention.
| Announced API rate, US dollars per million tokens | Introductory period | After the introductory period |
|---|---|---|
| Input | US$2 | US$4 |
| Output | US$10 | US$20 |
| Cached input | 95% below the input rate, implying US$0.10 initially | The announced discount needs to be read with the final billing terms |
Google has not stated when the introductory period ends. Full public billing details will matter when wider access arrives, including charges for tools, caching and any other options. These announced model rates are separate from an AI Ultra subscription fee and are quoted in US dollars.
I would budget around the later price if I were planning a lasting product. An introductory offer can make a trial appealing; the ongoing rate decides whether you can keep running it.
There is another wrinkle with a model designed for long work. A low price per token can still add up when the task uses a lot of tokens. The useful question is what it costs to finish the job, and whether the result is worth the time and money spent getting there.
What the million-token output limit means
The most striking capacity claim is Google’s announced jump in the output limit from 64K to one million tokens. Google describes that extra room as support for longer reasoning runs, rather than a requirement to produce enormous answers.
There is still a detail to settle: Vals AI’s evaluation record lists a smaller 262,144-token setting. That does not establish how the announced limit will work for ordinary accounts. The public API specification still needs to confirm which limits apply in practice.
Context and output are different. Context is the information a model can consider. Output is what it generates during a run, under the applicable model and billing rules. This announcement is about the second number.
In plain terms, Google wants Argon to have room to stay with a difficult job for longer.
Imagine a software change that initially seems straightforward. The first attempt reveals a compatibility problem. Fixing that uncovers a performance issue. Solving the performance issue requires a different approach. A useful agent needs to carry what it has learnt through those stages, rather than repeatedly starting from the first version of the brief.
That is a plausible use for more headroom. Asking for a shorter email is not.
The capacity interests me because some valuable work is inherently untidy. You do not always know the right route before you start, and the first approach can be the one that teaches you why another is needed. The model still needs to recognise when it is getting somewhere and when it is merely continuing.
The benchmark picture is more interesting than “best model”
Google reports strong results on extended software work and automation. Its published comparison also shows other models ahead on some tasks. That is a useful reminder that “coding” contains several different kinds of work.
| Selected result in Google’s performance table | Argon | Comparison shown by Google |
|---|---|---|
| Extended software changes, DeepSWE v1.1 | 77.9% | GPT-6 Astra: 74.1% |
| Multi-step business tasks, AutomationBench | 51.3% | GPT-6 Astra: 41.4% |
| Command-line coding, Terminal-Bench 4.0 | 57.4% | Claude Opus 5.5: 66.4% |
| Scientific workflows, Terminal-Bench Science 0.1 | 57.6% | GPT-6 Astra: 68.1% |
These are Google’s published results, rather than tests conducted for this article. The evaluation methodology also matters: competitor results mostly come from provider reports or public leaderboards, and tools and settings differ. It is not one uniform independent experiment across every model. For the science result, Google used a six-times verifier timeout for Argon and took competitor scores from the public leaderboard.
I would resist squeezing this into a single winner. Investigating a large project, handling a terminal task and working through a scientific problem ask for different strengths. An advantage in one can coexist with a weakness in another.
The more useful reading is that Argon looks like a serious candidate for sustained work. Where it becomes the best choice will depend on what the person or product is asking it to do.
Why cyber defenders get the first turn
Google’s cyber capability overview describes work on finding vulnerabilities, investigating live systems and proposing patches. Those are tasks where a model has to connect evidence, follow a problem through several stages and check whether a change actually addresses it.
They are also capabilities that need controlled access. Fairwind’s restricted release gives approved defenders a route to the model while Google works towards broader availability.
There is a distinction worth keeping in mind here: finding a worrying flaw and repairing it successfully are different achievements. A security team needs a clear explanation of what is wrong and a fix that preserves the software’s intended behaviour.
A flood of possible problems with weak evidence can create more work. A smaller set of well-understood findings, with reviewable fixes, can be useful. That is the standard I’d want a security model judged against, rather than the dramatic language that tends to accompany cyber announcements.
Ordinary readers do not need the details of the programme’s account controls. They do need to know that this first release is for a defined group, and that its capabilities are not being handed to every Gemini user at once.
Longer work still has to come back as something useful
One of the more revealing parts of Google’s announcement is its description of internal code migrations. The company says large rewrites are going through automated and manual auditing, testing and review before production rollout.
That is a useful picture of what sustained AI work could look like. The model does the investigation and prepares changes; the surrounding process establishes whether those changes belong in a working system.
For the rest of us, the appeal would be similar even on a smaller job. Give the assistant something substantial, let it work through the complications and return to a result you can understand and use. More reasoning is valuable when it gets you further through the problem.
The less attractive version is an agent disappearing for a long time and returning a mountain of explanation. A generous output limit makes room for progress, but also for an impressive amount of waffle. The product experience will have to make the distinction clear.
Argon is worth following, with the next announcement still to come
There is a compelling ambition here: AI that can keep thinking and working through problems larger than a quick conversation.
Google has supplied enough detail to explain that ambition. The public pages checked for this article on 3 October 2026 do not establish general access, a public rollout date or complete billing terms.
The next useful news will be the release people can actually reach: which accounts get it, how much work their plans include and what it feels like to give Argon an ordinary difficult task.
Until then, I’d keep it on the watch list. A model can be significant before it is available to you. It becomes personally useful when those two things finally meet.



