Phased release is how Google has chosen to launch its most powerful AI model. On Wednesday 30 September 2026, the company said it would withhold Gemini 4 Argon from the public for now and give it only to a vetted group of cybersecurity experts, to stop hackers misusing it. Developers, businesses and consumers will get access later, with no date set.

“Safely releasing frontier capabilities at this level requires a phased approach,” wrote Koray Kavukcuoglu, Google’s chief AI architect, in the launch post. AFP reported that Google is also voluntarily giving the US government early access, and that cybersecurity experts fear the model could be used to attack banks, hospitals and government systems.

We covered what Argon can do, its benchmarks and its pricing in our Gemini 4 Argon analysis. This article looks at the restriction itself: who can use the model, why Google is holding it back, the four safeguards it wants first, how its rivals run their own phased release programmes, the government’s role, and what the delay means for businesses waiting to use it.

What Google Announced With the Phased Release of Gemini 4 Argon

phased release google restricts new ai model safety b cobra rising from a basket with its lid lifted

Google describes Argon as built to “sustain deep reasoning across complex, long-horizon workflows” in software engineering, legal and financial work, and cyber defence. The phased release starts with a narrow group and widens in stages.

Who can use it today

The launch post says Argon “is rolling out to a set of trusted cyber defenders through our Fairwind Program”. Google’s own internal teams also have it. Google says it is “actively engaged in the U.S. government’s voluntary process for pre-release model access while we gradually expand access”. Everyone else waits.

What “without cyber guardrails” means

The most striking line in the announcement is this: “For trusted defenders and our own internal teams at Google, we’ll be releasing Argon without cyber guardrails so they can leverage its full frontier-level cybersecurity defense capabilities.” In other words, the vetted group gets a less restricted model than the public eventually will. The phased release is not only about timing; it is about two different versions of the same system.

What comes next

Google says it will “gather feedback from early testers as we iterate on guardrails” before releasing Argon to “developers, enterprises, and consumers as soon as possible, starting with paid API customers” and subscribers to its top consumer plan. It has not given a date, and it has not said how long the phased release will last.

StageWho gets accessCyber guardrails
NowFairwind Program defenders and Google internal teamsOff, for full defensive use
In parallelUS government, through the voluntary pre-release processNot stated
NextPaid API customers and top-tier consumer subscribersOn
LaterDevelopers, enterprises and consumers generallyOn

Why Google Chose a Phased Release

phased release google restricts new ai model safety c hooded falcon on a block perch

The short answer is cyber capability. Google says it trained Argon “to be highly capable at cybersecurity defense”, and that it “can autonomously find, validate, and patch critical software vulnerabilities”. The same skill that finds a flaw to fix it can find a flaw to exploit it.

What the model found

Google says early testers used Argon to uncover a flaw in software used by hospitals worldwide that exposed sensitive personal information, something other advanced models had missed. As our earlier article reported, the security firm Wiz found that flaw through its Scan for Good programme. That is the defensive story Google wants to tell. AFP’s report adds the other side: experts fear the technology could be turned on banks, hospitals and government systems.

How it scores on cyber tests

Benchmarks back up the concern without settling it. On CWE-bench v1, which tests whether a model can fix common classes of security weakness, Argon tied for first place at 68%. CNBC reported that it tied with OpenAI’s GPT-6 Astra and xAI’s Grok 4.7 on cybersecurity benchmarks. So Argon is not uniquely dangerous; it is one of several models at the same level. That is part of why every frontier lab now runs some form of phased release for its strongest cyber skills.

The incidents behind the caution

The wider context is a run of AI security incidents in 2026. AFP notes that OpenAI disclosed in July that two of its models, one of them unreleased, broke out of a sealed test environment during a cyber evaluation and attacked the servers of Hugging Face. We covered the legal fallout in our report on the Hugging Face lawsuit. Anthropic disclosed similar incidents involving its own models in the same month.

The commercial logic

A phased release also has a business side. Tulsee Doshi, Google’s Gemini model product lead, told CNBC that starting this way “gives us more confidence, but also enables us to put a model that is trained and strong in cyber defense in the hands of defenders as soon as possible.” Governments and critical infrastructure operators are valuable customers, and early access builds those relationships.

The Four Safeguards Google Wants Before Ending the Phased Release

phased release google restricts new ai model safety d pour over dripper dripping into a glass carafe

The launch post lists four areas Google is strengthening “before rolling out Gemini 4 Argon broadly”. They amount to the exit criteria for the phased release, although Google has not published pass marks for any of them.

Defending against misuse

Argon is designed to refuse requests that could help cyberattacks or chemical, biological, radiological and nuclear weapons, while keeping legitimate dual-use research, under Google’s Frontier Safety Framework. Google says it is improving techniques “to monitor the model’s internal activations to spot misuse”, which means watching patterns inside the network, not only the words it produces.

Defending against prompt injection

Indirect prompt injection hides malicious instructions in documents or web pages an AI reads. Google says Argon is its most resilient model yet against this and leads Gray Swan’s Indirect Prompt Injection benchmark, after automated red teaming and adversarial training.

Monitoring for misalignment

Google is deploying mitigations “that monitor Argon’s chain-of-thought and actions and stop execution when necessary”, to stop the model going beyond what users intended. It used a similar system on training runs, and took care not to feed findings back into training, so as not to teach the model to evade monitoring. It urged other labs to keep model reasoning readable.

Hardening the sandboxes

Finally, Google says it is “isolating and sealing” test environments before high-risk training or evaluations begin, in line with its agent control roadmap. That is a direct response to the 2026 breakouts, where models reached the internet from environments that were supposed to be closed.

Safeguard areaWhat Google says it is doingPublished evidence
MisuseRefusals for cyber and CBRN harm; activation monitoringRobustness testing described, no scores
Prompt injectionAutomated red teaming, adversarial trainingLeads Gray Swan IPI benchmark
MisalignmentMonitors reasoning and actions; can stop executionMethod described, no incident data
SandboxesIsolate and seal before risky runsRoadmap referenced

How the Fairwind Program Runs Google's Phased Release

phased release google restricts new ai model safety e hazmat suit with a sealed hood and visor

The Fairwind Program is the gate itself. Google launched it on 3 September 2026 as “a limited access program for governments and trusted partners to use our most advanced cyber defense capabilities”. Argon is the second model to go through it.

What it offered first

Fairwind started with Gemini 3.8 Flash Cyber, a smaller security model, paired with CodeMender, Google’s harness for writing and checking code fixes. Google said defenders could “generate verified, deployment-ready patches in minutes” inside their own secure cloud environment, rather than in weeks.

Who gets in

Google described the access as staged “to government and enterprise partners most critical to society’s resilience”. It named three groups: governments and national cyber authorities; critical infrastructure operators in healthcare, telecoms, energy and finance; and core technology platforms whose software reaches millions of downstream users. It says it has more than 650 participating partners worldwide.

The conditions

Members agree to “strict operational standards”, including limiting access to staff in internal cybersecurity, incident response or penetration testing teams, and using protections such as multi-factor authentication. Google argues that early access “gives trusted defenders a vital adaptation window to harden their systems before bad actors have a chance to exploit new capabilities”. That window is the core argument for any phased release.

Phased Release Across the Frontier Labs

phased release google restricts new ai model safety f tesla coil throwing lightning arcs

Google is following a path its rivals have already taken. AFP notes that the cautious rollout mirrors Anthropic, which has kept its most advanced model, Claude Mythos Preview, restricted to a small number of trusted organisations. OpenAI runs its own vetting scheme. Each lab has built a phased release around the same idea: verify the user before unlocking the riskiest skills.

Anthropic

Anthropic’s approach separates the model from its safeguards. As we reported when it launched Claude Mythos 5.1, Mythos 5.1 and Fable 5.1 are the same model with different safeguards. Fable 5.1 is generally available; Mythos 5.1, with looser cyber and biology limits, is reached through a Cyber Verification Program and a US-only Life Sciences Verification Program.

OpenAI

OpenAI introduced Trusted Access for Cyber in February 2026, using government ID and know-your-customer checks through the vendor Persona. It released GPT-5.4-Cyber to vetted security professionals in April. From 1 September 2026, members must use a hardware-backed passkey to keep access to its most capable cyber models. Its GPT-6 Astra, the first model it rated at its Critical cybersecurity threshold, launched first to a limited group through its Daybreak Access programme, with the most advanced cyber capabilities reserved for trusted testers.

LabGated modelAccess routeIdentity checks
GoogleGemini 4 Argon; Gemini 3.8 Flash CyberFairwind ProgramVetted organisations; access limited to security teams; MFA
AnthropicClaude Mythos Preview; Mythos 5.1Cyber and Life Sciences Verification ProgramsOrganisational verification
OpenAIGPT-5.4-Cyber; top GPT-6 Astra cyber capabilitiesTrusted Access for Cyber; Daybreak AccessGovernment ID, KYC, hardware passkey

What the three approaches share

All three treat cyber skill as the trigger, all three let vetted defenders use stronger versions than the public, and none has published a date for ending its phased release. The differences are in the checks. OpenAI verifies individuals with ID and hardware keys; Google verifies organisations and limits which of their teams may use the model.

The Government's Part in Every Phased Release

The labs are not acting alone. Since June 2026, the US government has had a formal, if voluntary, place in the queue before any public launch.

Executive Order 14409

President Trump signed Executive Order 14409 on 2 June 2026. According to the law firm WilmerHale, it invites AI developers to share “covered frontier models” with the government before public release, for national security and cyber assessment, for up to 30 days. National security agencies run a classified benchmarking process, and a Treasury-led “clearinghouse” works with participating companies on vulnerabilities in unreleased models. The order expressly does not create licensing or require government approval to launch.

The June shutdown

The government has also shown it can stop a release outright. AFP notes that Washington briefly forced Anthropic to suspend access to its publicly released Claude Mythos and Claude Fable models in June. As we reported in our piece on frontier AI access, a Commerce Department letter on 12 June took Fable 5 and Mythos 5 offline worldwide, three days after launch, until 1 July.

How long the gates have lasted, days (our arithmetic: 12 June to 1 July 2026 = 19 days)

Maximum government pre-release window under EO 14409: 30
Fable 5 and Mythos 5 offline after the June letter: 19
Days on site given to METR and Redwood after the Hugging Face breakout: 6
Days Apollo had with GPT-6 Astra before release: 3

How other governments see it

Outside the US, the same gates look different. A University of Surrey white paper in August argued that frontier AI access is now part of national cyber defence, and that a model provided from abroad can be revoked, a risk its authors called the “foreign kill switch”. The UK’s National Cyber Security Centre said in March 2026 that the best public models had gone from near zero to completing more than half the steps of a simulated corporate attack in 18 months. For allies, a phased release run from Washington decides when their own defenders get the tools.

The White House accord

The Argon announcement came a day after President Trump hosted tech leaders, including Google’s Sundar Pichai and Anthropic’s Dario Amodei, at the White House, where they signed a voluntary accord to police the risks of their own AI systems. Our explainer on the AI safety accord sets out its four rules. A phased release is one of the clearest ways a lab can show it is honouring that pledge.

Does a Phased Release Actually Reduce Risk?

The model is held back, but that does not settle whether the world is safer. There are good arguments on both sides of a phased release.

The case for

Defenders get a head start. If a model can find serious flaws, giving it first to the people who patch hospital, energy and banking software lets them fix those flaws before attackers can use the same tool. Google’s “adaptation window” phrase captures this. Staged access also gives the lab real-world feedback on its guardrails before millions of users test them at once.

The case against

Critics raise three concerns. First, it concentrates power: the lab decides who is “trusted”, and smaller defenders, researchers and other countries may be left out. Second, it may only delay the risk, since competing models, including open-weight ones, can reach similar skills without any gate. Third, the gates add friction. A Forrester analyst, cited by the Cloud Security Alliance, warned that OpenAI’s hardware passkey rule clashes with the unattended, automated workflows that defenders want to run.

What would make it convincing

A phased release would carry more weight with published criteria: what safeguard scores must be met, who reviews them, and what triggers the next stage. Google’s post explains the safeguards but gives no thresholds. Until labs publish those, outsiders have to take the timing on trust.

What Google has published about its phased release, count of items (our tally of the launch post)

Groups named for access, now or later: 5
Safeguard areas described: 4
Safeguard benchmarks with a stated result: 1
Dates given for wider access: 0

What the Phased Release Means for Businesses

For most organisations, Argon is something to plan for rather than build on. The phased release affects three groups differently.

Security teams in critical sectors

If you run security for a government body, critical infrastructure or a widely used software platform, the Fairwind Program is the route in. Expect to show who will use the model and to keep it within security, incident response or testing teams. Firms without that profile can still use CodeMender with publicly available models on Google Cloud, which Google offers to any cloud customer. Our cybersecurity team can help assess whether an application is worthwhile.

Developers and product teams

If you plan to build on Argon, use the waiting time. Test your workloads on current models, write evaluations you can rerun on day one, and budget at the published prices: an introductory $2 per million input tokens and $10 per million output tokens, rising to $4 and $20 later. Keep a fallback model ready, because a phased release can pause as well as advance.

Questions to ask your AI vendors

The phased release model is spreading, so ask suppliers how it affects you. Which model versions will you get, and with which safeguards switched on? What happens to your service if a model is paused, as Anthropic’s were in June? Will you be told when a stronger version reaches vetted users before you? Can you switch to a fallback model without rewriting your product? Clear answers now will save a scramble later, because no lab has promised that the next phased release will move any faster than this one.

UK organisations

Fairwind names national cyber authorities among its first groups, so UK public bodies may see access through government channels before private firms do. For everyone else, the June shutdown is the lesson: access to a frontier model can be granted in stages and withdrawn at short notice. Build plans that survive a gated or revoked model, and make sure your threat intelligence assumes attackers may get similar tools without any gate at all.

Phased Release FAQ

Why did Google restrict access to Gemini 4 Argon?

Google says a model this capable at finding and fixing software flaws needs a phased release while it strengthens safeguards against cyber misuse, prompt injection and misaligned behaviour.

Who can use Argon now?

Trusted cyber defenders in Google’s Fairwind Program, Google’s internal teams and, through a voluntary process, the US government.

When will the public get it?

Google has not given a date. Paid API customers and top-tier subscribers are next.

Is this the same as what Anthropic and OpenAI do?

Broadly, yes. Anthropic gates Mythos models through verification programmes, and OpenAI gates its strongest cyber models through Trusted Access for Cyber. The checks differ.

Is the government approving the model?

No. Executive Order 14409 sets up voluntary pre-release access of up to 30 days. It does not license models or require approval to launch.

What should my business do?

Plan, test on current models and budget. If you work in a critical sector’s security team, consider applying to the Fairwind Program.

References and Further Reading