Gemini 4 Is Here, and Google’s Flagship Tops All Other AI Models on Cybersecurity
Google on Wednesday unveiled Gemini 4 Argon, its new ‘‘frontier’’ AI model designed for coding, office tasks and cyber defense. In Google's internal comparison table Argon led on 12 of 18 benchmarks, scored 77.9% on DeepSWE v1.1, resists indirect prompt-injection attacks better than several rivals, and can produce up to one million tokens in a single reply.

Why It Matters
Argon’s combination of high scores on engineering benchmarks, an unusually large single-reply context window, and stronger resistance to prompt-injection makes it notable for organizations that use AI for software and security tasks. Google is initially providing the model to vetted cyber defenders without the usual safety refusals, a rollout choice with direct operational and risk-management implications.
Key Facts
- Model name: Gemini 4 Argon
- DeepSWE v1.1 score (Google): 77.9%
- Benchmarks led (Google table): 12 of 18
- Indirect prompt-injection (Gray Swan) attack success rate: 0.7%
- Comparative Gray Swan scores (Claude Opus 5.5, Claude Fable 5.1): 1.0% each — GPT-6 Astra 8.5% — Grok 4.6 and Kimi K3 ~52%
Google introduced Gemini 4 Argon as its latest frontier model, positioning it as the company’s most capable system for coding, office productivity and cyber defense. In a self-published comparison table, Google reported Argon leads on 12 of 18 evaluated benchmarks, ties one and trails on five across a mix of coding, science and control tests. On the DeepSWE v1.1 benchmark — which measures performance on long, real-world software engineering tasks — Argon scored 77.9%, ahead of Claude Opus 5.5 (74.2%), GPT-6 Astra (74.1%) and Claude Fable 5.1 (67.4%).
Argon expands the model’s single-response capacity substantially: Google says it can write up to one million tokens in a single reply (roughly 750,000 words), compared with a previous limit of 64,000 tokens. The company cautioned that the DeepSWE number is its own computed score, while some rival figures come from public leaderboards or company reports.
A highlighted capability for Argon is its robustness against indirect prompt-injection attacks, where malicious instructions are hidden inside content the model reads. On Gray Swan’s Indirect Prompt Injection benchmark — which measures attack success over up to 15 tries — Argon posted a 0.7% attack success rate, lower than Claude Opus 5.5 and Claude Fable 5.1 (both 1.0%) and markedly better than GPT-6 Astra (8.5%). Other models tested, including Grok 4.6 and Kimi K3, were tricked at rates above 50%.
Google is initially making Argon available to vetted cyber-defender organizations through its Fairwind Program, a limited-access initiative launched on September 2 with more than 650 partners including governments and critical infrastructure operators. The company says Argon will be provided to these security teams without the typical cyber guardrails that block wrongdoing, on the rationale that defenders need tools that can emulate attackers to surface and patch vulnerabilities. Google plans a phased wider release to paid API customers and Google AI Ultra subscribers; introductory pricing is $2 per million input tokens and $10 per million output tokens, with standard rates listed as $4 and $20 respectively.
Keep Reading

OpenAI, Google and Meta pledge independent AI safety audits under voluntary White House deal
Google shows it’s not out of the AI race just yet

Asus won’t say how it escaped the US router ban
