Blog · 1 October 2026 · 7 min read

Is Gemini 4 Argon safe? Why Google is holding it back

Gemini 4 Argon was announced on 30 September 2026 but most people cannot use it yet. What Google says about its safety, and what decides your data.

Announced. Not released. On purpose.

Short answer: you probably cannot use Gemini 4 Argon yet, and that is the safety story. Google announced it on 30 September 2026 and gave it first to a vetted group of cybersecurity teams, not to developers or the public. Google’s own reason is that a model this capable needs a phased release while it finishes hardening the safeguards. When it does reach ordinary accounts, what happens to your data will depend on the product you use it through, not on the model — and those rules are already written down.

This post separates the two questions. First, what Google has said about Argon’s behaviour and why access is limited. Second, what happens to the text you type into Gemini, which no model announcement changes.

What Gemini 4 Argon is

Argon is Google’s new frontier model, announced on the Google blog on 30 September 2026. Google pitches it at software engineering, knowledge work such as legal and finance, and cyber defence. Its output limit rises to 1 million tokens, up from 64,000 on earlier Gemini models. The introductory API price is $2 per million input tokens and $10 per million output tokens, in US dollars, rising later to $4 and $20.

On independent testing it lands near the top. Artificial Analysis scores it level with GPT-6 Astra on its Intelligence Index. The Decoder’s write-up reads the same numbers more coolly: Google closes the gap with OpenAI and Anthropic without taking a clear lead.

Who can use it today

Almost nobody outside security teams. Google says Argon is rolling out first to trusted cyber defenders through its Fairwind Program, plus Google’s internal teams and early testers. SiliconANGLE reports that Fairwind opened on 3 September with a smaller cyber model and has signed up more than 650 organisations, CrowdStrike and Palo Alto Networks among them.

Those members get a version of Argon with the cyber guardrails removed, so it can find and fix vulnerabilities on its own. In return they agree to keep access inside their security, incident-response or penetration-testing teams and to protect it with measures such as multi-factor authentication.

Next in line, according to Google, are paid API customers and Google AI Ultra subscribers. There is no public date for either, and none for the free Gemini app. 9to5Google’s report carries the same picture. If you see a site offering Gemini 4 Argon today, be sceptical of what you are actually getting.

What Google says about its safety

Google measures its models against its Frontier Safety Framework, a set of capability levels in areas such as cyberattacks and chemical, biological, radiological and nuclear weapons. For the general release, Google says Argon is designed to refuse harmful requests in those areas while still helping with legitimate dual-use research.

The announcement lists four safeguards. Stronger refusals for cyber and weapons misuse, backed by monitoring the model’s internal activations to spot abuse. What Google calls its most resilient model yet against indirect prompt injection, the attack where hidden instructions in a web page or document hijack an agent. Monitors that watch Argon’s chain of thought and actions and stop it when it goes beyond what the user asked. And sealed, isolated environments for high-risk training.

Google also says it is taking part in the US government’s voluntary process for pre-release model access, and that it is still hardening safeguards against misuse for cyberattacks and weapons. That is a vendor telling you, in its own launch post, that the work is not finished. It is more candour than usual, and it is worth taking at face value in both directions. The broader politics of who checks these models — and why the checks are voluntary — are in our post on the super intelligence executive order.

The safety number that matters at work

For most people the everyday risk is not a cyberattack. It is a confident wrong answer. Here Argon has an early result in its favour: Artificial Analysis measured a 15% hallucination rate on its AA-Omniscience test, against 51% for GPT-6 Astra. In plain terms, Argon is more willing to say it does not know than to guess.

One benchmark is one benchmark. A lower rate still means some wrong answers, delivered just as fluently as the right ones. How to check an AI answer when you are not the expert is the habit that covers you whatever the number says, and what AI is actually bad at lists the places to look first.

What happens to your data

None of this is new with Argon, which is why it gets missed. Data handling follows the product and the plan, not the model name. If the difference between a model and the app you open is fuzzy, AI agent vs LLM sorts it out.

In the Gemini app, the Gemini Apps privacy hub sets the rules. With Keep Activity on, chats are saved and auto-deleted after 18 months by default. With it off, Google keeps conversations for 72 hours to run the service. Either way, a subset of chats is read by trained human reviewers, and reviewed chats are kept for up to three years, disconnected from your account. Google’s own advice is not to enter confidential information you would not want a reviewer to see.

Through the API, the Gemini API terms split on payment. On the unpaid tier, Google may use prompts and responses to improve its products, and humans may review them. On paid services it does not use them for that, and logs them only for a limited time to detect abuse. One exception matters for European readers: in the European Economic Area, Switzerland and the UK, the paid-service rules apply to everything, including Google AI Studio and the free quota.

Since Argon is expected to reach paid API customers and AI Ultra subscribers first, the first people to use it will mostly be on the stricter side of those rules. That is a consequence of the rollout order, not a privacy promise about the model.

What to do before it reaches you

  1. Do not go looking for early access through third-party sites. Google has named who gets it, and an unofficial wrapper decides its own data rules.
  2. Check Keep Activity in the Gemini app once, deliberately, so the setting is a choice rather than a default.
  3. If you use the API at work, confirm whether your project is billed. Paid and unpaid tiers are governed differently, unless you are in the EEA, Switzerland or the UK.
  4. Keep passwords, keys and client data out of prompts. A better refusal filter does not make that a good idea.
  5. Check the output, not the confidence. A 15% hallucination rate is low for a frontier model and still far from zero.

For how other vendors answered the same questions this month, is GPT-6 Astra safe covers a model whose reasoning became harder to watch, and is Claude Sonnet 5.5 safe covers one that shipped widely on day one. Argon took the third route: announce now, release later.

Coursium is a mobile app that teaches people to use AI at work. Model names change every few weeks. Knowing where your data goes and checking what comes back carry over from one model to the next. If that is what you want to practise, have a look at Coursium.

Frequently asked questions

Can I use Gemini 4 Argon now?

Probably not. Google announced it on 30 September 2026 and is rolling it out first to vetted cyber defenders in its Fairwind Program and to internal teams. Paid API customers and Google AI Ultra subscribers are next, with no public date.

Why is Google limiting access to Gemini 4 Argon?

Google says models at this capability level need a phased release, and that it is still hardening safeguards against misuse for cyberattacks and weapons development. It is also taking part in the US government’s voluntary pre-release access process.

Does Google train on what I type into Gemini?

It depends on the product. In the Gemini app, a subset of chats is reviewed by humans and kept for up to three years. On the unpaid Gemini API tier, Google may use prompts to improve its products; on paid services it does not. In the EEA, Switzerland and the UK the paid-service rules apply to all API use.

Coursium

Stay ahead of AI — learn the tools on your phone.

Get the app