signaldigital.comEst. 1994Berlin — Copenhagen — London — ParisConcept + Design + Technology

Gemini 4 Argon: The Noble Gas Has a Guest List

From the editors

Berlin

Argon is a noble gas. It doesn’t react with anything. Welders use it as a shield. Google has named its new frontier model after it, and the name fits twice: Argon is built to shield, and for now it doesn’t react with anyone outside a very short guest list. Your business is not on it.

What Google actually launched

On 30 September, Google DeepMind announced Gemini 4 Argon, its new frontier model aimed at three jobs: long-horizon software engineering, enterprise knowledge work such as legal and finance, and cybersecurity defence. The headline technical change is output. Argon can now produce up to 1 million tokens in a single run, up from 64,000. In plain terms: it can think for a very long time and write an enormous amount before it stops.

The numbers Google chose to show are strong. A state-of-the-art 77.9% on DeepSWE v1.1 for real-world coding. First place on Zapier’s AutomationBench at 51.3%, which measures end-to-end business tasks. 91.7% on LVBench for long video understanding. A tie for first on CWE-bench v1 at 68% for fixing security flaws. Inside Google, Argon agents have reportedly freed over 300 TiB of data-centre memory and are migrating hundreds of thousands of lines of C and C++ to Rust.

Impressive. Now look at who gets to use it.

The guest list

Argon is rolling out first to a set of trusted cyber defenders through Google’s Fairwind Program. Google says it is taking part in the U.S. government’s voluntary pre-release access process while it widens access step by step. After that come paid API customers and Google AI Ultra subscribers. Then, eventually, developers, enterprises and consumers.

The announcement contains no date for general availability and no mention of Europe at all. Tested in Washington. Priced in dollars. Benchmarked on American GDP.

That last part is literal. Google’s headline claim for knowledge work is leadership on the Vals Index, which weights finance, coding, legal and tax work by each sector’s contribution to U.S. GDP. Every benchmark needs a weighting, and phasing a powerful model in slowly is the responsible thing to do. Nobody sensible argues otherwise. But the weighting tells you whose economy the model was built to impress, and the queue tells you whose businesses get the head start. A Belgian bookkeeper and a Danish parts distributor are neither.

The price is the headline. The footnote is the story.

Argon launches at an introductory $2 per million input tokens and $10 per million output tokens, with cached input 95% off. Then comes the footnote: once the introductory period ends, the price becomes $4 and $20. Double. The announcement doesn’t say when the introduction ends.

For a small business, that is the number to plan on. Build your business case on $2 and it breaks on the day the discount does. We made the same point about OpenAI’s pricing in GPT-6.1 Sol: The Sun Is Cheaper Than the Stars: the sticker is marketing, the steady-state bill is the product.

A worked example: twelve people in Ghent

Take a 12-person industrial distributor in Ghent. Every month it receives around 400 supplier documents: price lists, datasheets, order confirmations. It wants a model to read each one, check it against its catalogue and flag changes. Say each document averages 20,000 tokens in and 3,000 tokens out.

  • Input: 400 x 20,000 = 8 million tokens. At $2, that’s $16. At $4, $32.
  • Output: 400 x 3,000 = 1.2 million tokens. At $10, that’s $12. At $20, $24.
  • Total: $28 a month at launch, $56 a month afterwards.

Cheap, either way. If the catalogue is sent with every request and cached, the repeated part costs a fraction of that. This is not where the risk is.

The risk is the 1 million output tokens. That headroom is a feature and a meter. One run that uses all of it costs $10 at launch and $20 later. Let an agent take ten deep runs a working day and you are at 220 runs a month: $4,400 at the full price. For twelve people in Ghent, that is not a rounding error. It’s a salary. Headroom you don’t cap is headroom you pay for.

The shield reaches you before the model does

Here is the part that matters even if you never buy a single Argon token. Google says the model can find, validate and patch serious software vulnerabilities on its own, and trusted defenders get it without the usual cyber guardrails. Wiz is already using it in a free programme to protect public infrastructure, and says it found a critical flaw exposing personal data in healthcare software used by hospitals worldwide, one earlier models had missed.

That is good news. The open-source libraries and the SaaS tools your business runs on will get patched faster. But it also tells you where the bar is going. Models that find holes this well won’t stay in defenders’ hands forever, and under NIS2 many EU businesses already answer for the security of their supply chain. The question to ask your vendors this autumn is simple: who is scanning your code, and with what?

One more detail worth your attention. Google says Argon is its most resistant model yet to indirect prompt injection, where hidden instructions in an email or document try to hijack an agent. If you plan to point an AI agent at your inbox or your supplier PDFs, that is the attack you actually face. Better resistance is welcome. Zero risk it isn’t.

The fine print

  • You can’t buy it yet. There is no public date, and paid API customers in general come after the trusted testers.
  • The introductory price has no stated end date. Plan on $4 and $20.
  • Nothing on Europe. The announcement says nothing about EU availability, data residency or regional processing. Check your data processing terms and where requests are handled before any customer data goes near it.
  • The benchmarks are chosen by the seller. Several come from partners. Strong results, but test on your own documents before you trust them.
  • Trusted is defined elsewhere. Who qualifies as a trusted defender, and gets the model without guardrails, is decided by Google, not by EU regulators.

What to do now

  • Price any Argon plan at $4 / $20, not $2 / $10.
  • Set a hard cap on output tokens per task before you let an agent think as long as it likes.
  • Keep your stable context (catalogues, templates, policies) in a cached prefix to cut the input bill.
  • Ask your software vendors whether they use AI-assisted vulnerability scanning, and document the answer for NIS2.
  • Don’t wait for Argon. Build the workflow on a model you can use today, and keep it model-neutral so you can swap when the guest list opens.

Argon is a shield. Right now it shields Google, American institutions and a hand-picked set of defenders. Europe’s small businesses will get it the way noble gases get anywhere: slowly, and only once someone else has opened the valve.

FROM THE EDITORS

Sources

— FROM THE EDITORSSignaldigital

Leave a Reply

Discover more from SIGNALDIGITAL.COM

Subscribe now to keep reading and get access to the full archive.

Continue reading