
On 30 September 2026, Google announced the AI model Gemini 4 Argon and said that some users would receive it with its cyber guardrails removed. When one AI is handed out under one name with different settings for different recipients, can a company that uses it find out which settings it has? The only clues are the contract type and the record of when the settings switched over; neither the model name nor the published scores will tell you.
01One AI Model Name Now Covers Different Limits for Different Recipients
Whether a company can learn its own settings depends first on the way Google is distributing the model, and Google is distributing it with different settings for different recipients. The first to receive Argon are organisations in a limited programme called Fairwind. The programme began in early September. Governments, Google Cloud customers and security companies take part, and more than 650 organisations had joined when it started.
The version without limits goes to Fairwind participants and to Google's own internal security staff. After Fairwind, Argon goes to companies using it under paid developer contracts and to Google AI Ultra subscribers. No date has been given for general release.
Google has not said which limits it removed. The announcement also does not say how far the unrestricted version will go in its answers.
The single name "Gemini 4 Argon" refers to at least two configurations. A company using the new model cannot tell, from the name or from the scores, whether its own AI is the restricted version or the unrestricted one.
A company that brings the new model into its work therefore needs to put two questions to Google in writing. The first is which type its contract falls under. The second is when its settings switched over. If the company keeps Google's written answers, it can later explain which settings its AI was running with.
02Google Published Two Scores and Left the Lifted Limits Unlisted
One name covers at least two configurations, so which of the two did Google's published scores measure? Google gave scores on two tests.
On a test of finding weaknesses in software, the new model scored 68%. That test is called CWE-bench v1. On DeepSWE v1.1, a test of solving software development tasks, it scored 77.9%.
According to Tech Wire Asia, both figures were measured by Google itself. No outside body produced them.
The announcement does not state which settings were in place when the scores were measured. Reading the coverage, I cannot tell whether the tests ran on the unrestricted version or on the restricted one. Nor does the current reporting include any result from an outside body running the same tests.
There is one published set of scores. The AI that reaches users, however, splits into two kinds according to contract type. Looking at the scores, a company has no means of confirming whether the AI on its own desk is the one that produced them.
03Drug Companies in Japan Already Record Which Material Went to Which Doctor
However closely a company reads the scores, they do not show who received which configuration of the AI. A rule for recording recipients already exists in another industry. Japanese pharmaceutical companies record, doctor by doctor, the materials they used when explaining their products.
In 2018, the Ministry of Health, Labour and Welfare issued its guideline on sales information provision activities for prescription drugs. Under that guideline, a drug company sends its materials for doctors through review by a department independent of the sales division before anyone uses them. What a sales representative told a doctor, down to oral explanations, is written into a work record and kept.
In a drug company, then, which material was used with which doctor, and when, sits in the company's records. It does not depend on one employee's memory.
| Point of comparison | Supply of Gemini 4 Argon | Materials for prescription drugs |
|---|---|---|
| Who checks before use | Google internally and Fairwind participants | A review department independent of sales |
| Record of recipients | Contract type and switch-over record (not published) | Work records, including the materials used |
| Oral exchanges | No published rule requiring a record | Oral explanations are recorded too |
| Who holds the record | The drug company that used the material |
The drug company case shows that a record of recipients can be built. For the new model, only Google holds the record of which configuration went to whom. A company using the model cannot see Google's record unless it asks for it. Google has not announced that it will show the record to those who ask.
04Google Said a Model This Capable Has to Be Released in Stages
Drug companies keep records of who received their materials. Google, for its part, splits Argon's settings by recipient, and it has given a reason for doing so.
Koray Kavukcuoglu, who leads AI architecture at Google, said that releasing capability at this level safely requires a phased approach. According to an AFP report carried by RTÉ, experts who tried Argon early used it to find weaknesses in hospital software that other frontier models had missed.
The ability to find weaknesses in software helps defenders and attackers alike. Google gave the unrestricted version to defending organisations so that they could use the model's full capability. The Next Web reported that organisations defending against cyberattacks receive the new model first.
The content of the lifted limits has not been published. Because I do not know that content, I cannot judge whether Google's way of distributing the model is sound.
One thing is clear: Google is choosing recipients and changing the settings for them. A company that hands out AI to selected recipients needs a record of who got which version. Without that record, outsiders cannot check afterwards whether the split was carried out as planned.
05A Company Using the New Model Can Check Three Things Itself
Google chooses recipients and changes their settings, and a company on the receiving end can still check three things on its own.
The first thing to check is the contract type. The settings a company receives differ by the contract it uses. There are three kinds of arrangement with Google: membership of the limited programme, a paid developer contract and an Ultra subscription. A company knows which contract it is using. What it cannot see from the announcement is which settings that contract carries, so it confirms that with Google in writing.
The second is the date on which the settings switched over. Because supply widens in stages, the settings can change on a given day even while the contract stays the same. A company that does not know the switch-over date cannot compare last month's answers with this month's under the same conditions.
The third is who measured the scores. The 68% and the 77.9% were Google's own measurements. When a company writes those scores into its internal approval documents, it should add that Google measured them itself.
Get the contract type in writing
Have Google state in writing which type of contract your company holds.
Pin down the switch-over date
Ask Google to record the day the settings changed and what differed before and after it.
Label the source of each score
In every document, note whether a score is the vendor's own measurement or an outside evaluation.
On the content of its settings, the only thing a user company can keep in its own hands is the written answers it gets from Google. An explanation given orally cannot be verified once the settings have switched over.
06The Material for Choosing an AI Moves from the Name to the Contract Text
Once a company starts checking its contract type, its switch-over date and the source of the scores, the material it uses to choose an AI model changes in three ways.
Scores cannot be set beside rivals' scores
Because a score a vendor measured itself carries no guarantee of the same method, it cannot be compared as it stands with another vendor's score, or with the AI under a different contract.
Limits differ by recipient
Within one company, different departments could end up using the restricted and the unrestricted versions.
Contracts and records are the evidence
The material that can be checked lies in the answers Google is able to give in writing.
First, the way companies build comparison tables changes. Tech Wire Asia reported the 68% as Google's own measurement. Placing Google's score next to other vendors' scores gives no guarantee that the tests were run the same way. If a company puts scores into a comparison table, it needs to add a column beside each score showing who measured it.
Second, the assumptions behind internal discussion of AI change. Suppose that in one company, Department A uses the unrestricted version through the limited programme, while Department B uses the restricted version under an ordinary paid contract. The two departments use an AI with the same name, but the settings inside differ. An answer one department gets will not necessarily appear in the other. Google itself has announced that it limits who receives the version without restrictions.
Third, where a company must look for the record changes. In the drug industry, the company that used the material holds the work record. For the new model, only Google knows which configuration went to whom. The only route a company using it has to part of that record is to ask Google in writing. The announcement does not say whether such a request will be answered.
07The Next Dispute May Be Over a Duty to State Per-Contract Settings in Writing
Companies now have to read contract text to learn their settings, and the next issue is whether the law will one day require that disclosure. Two documents offer some guidance.
On 23 September 2026, the attorneys general of 26 US states sent a letter to congressional leadership. They asked for federal oversight of safety testing and standards. They also asked for a system in which, after an incident, investigators can look directly at a company's books and records and then publish the results. And they asked that federal law not override state law.
Article 26 of the EU AI Act requires companies and public bodies that use high-risk AI to keep the logs the AI generates automatically. When police identify a person from recordings after the fact, the Act also requires that each use be written into the police file.
Neither the attorneys general's letter nor the EU AI Act, however, says that settings must be disclosed contract by contract. The letter is a request to Congress, and I have not been able to confirm that it will become law. What the EU AI Act sets is a duty on the side that uses AI to keep records. Article 26 does not address the case in which an AI provider varies its settings by contract.
My own view is this. If AI companies start distributing different settings under one name, an incident investigator will first ask which setting went to whom. If investigators gain the power to look directly at company records, I expect that power to reach the records of how settings were split among recipients.
- Google gives Gemini 4 Argon with its cyber limits removed only to Fairwind participants and its internal security staff. The one name Gemini 4 Argon refers to two kinds of AI, restricted and unrestricted.
- The two scores Google published, 68% on CWE-bench v1 and 77.9% on DeepSWE v1.1, are figures Google measured itself. The scores do not show which limits have been removed.
- In the drug industry, a procedure already runs in which materials are reviewed before use and even oral explanations go into work records. For the new model, only Google holds the record of which settings went to whom.
For a company to know the settings of the AI it is using, it has to look at the contract type and the switch-over record. The model name and the published scores do not reveal the difference in settings.
A company bringing the new model into its work would do well to ask Google three things in writing: its contract type, the switch-over date and the source of the scores. It should keep the written answers. Whether the law will require this disclosure has not yet been decided. Until it is, the written answers a company has kept for itself are the only means it has of explaining the settings of the AI in its hands.
- RTÉ News (AFP). Google restricts new AI model access over safety concerns. 2026-09-30.(General release held back and access limited to selected cyber defence experts; Kavukcuoglu's remark that a phased approach is required; weaknesses found in hospital software)
- Tech Wire Asia. Google launches Gemini 4 Argon, but limits access over cybersecurity risks. 2026-10-01.(Version without limits for Fairwind participants and internal security teams; order of supply; 68% on CWE-bench v1 and 77.9% on DeepSWE v1.1 measured by Google itself)
- The Next Web. Google unveils Gemini 4 Argon, and cyber defenders get it first. 2026-09-30.(Defenders receive the version with limits removed so they can use its full capability; paid API users and Ultra subscribers come next)
- SecurityWeek. Google Launches Gemini 4 Argon With Guardrail-Free Access for Vetted Defenders. 2026-10-01.(Fairwind began in early September with more than 650 participants at launch, covering governments, Google Cloud customers and security companies)
- Ministry of Health, Labour and Welfare (Japan). Guideline on Sales Information Provision Activities for Prescription Drugs. 2018-09-25.(Consulted via the Japan Generic Medicines Association's explanatory page; prior review of materials by an independent supervisory department; creation and retention of work records including oral explanations)
- Attorneys general of 26 states (published by the California Attorney General's office). Letter to congressional leadership on federal regulation of frontier artificial intelligence. 2026-09-23.(Federal oversight of safety testing; incident investigations with direct access to books and records and publication of results; no preemption of state law)
- European Union. Regulation (EU) 2024/1689 (Artificial Intelligence Act), Article 26. 2024-06-13.(Obligations of those using high-risk AI; retention of automatically generated logs; recording each use of post remote biometric identification)
