AI just caught a security flaw that all previous models missed
Google's Gemini 4 Argon found a critical vulnerability in hospital software that earlier AI models had overlooked — a signal that AI-powered security review is moving from helpful to essential.
- 68%
- on CWE-bench — tied for first in fixing real security flaws
- 77.9%
- on DeepSWE v1.1 software engineering benchmark
- 1M tokens
- context window — reads entire large codebases at once
- Sept 30
- launch date; cyber defenders get access first
Security firm Wiz, using Google's new Gemini 4 Argon, found a critical flaw in healthcare software used by hospitals worldwide. Earlier frontier AI models had scanned the same code and missed it. This AI found what other AI could not. That shift — from helpful to essential — changes how every security team should think about the tools in its process.
Google launched Argon on September 30, giving access first through its Fairwind Program — a restricted group including governments and critical-infrastructure operators. The model was built for long, complex work: vulnerability discovery, large codebase review, finance and legal analysis. Its context window holds one million output tokens, up from 64,000 — meaning it reads an entire large codebase in a single pass. On the CWE-bench security test, it tied for first place at 68% — the best any AI has scored on this measure of real vulnerability fixing.
The Fairwind rollout is deliberate. Google gives defenders access without the usual safety guardrails that limit what a consumer AI will analyze. The logic is the same as giving a penetration tester root access: you need full visibility to find what hides. This is the first time a major AI lab has made a security-focused early-access tier a formal part of its launch strategy.
For any team that ships software, the message is practical. An AI that reads millions of lines in minutes and flags patterns that previous tools missed is not a replacement for a security engineer — it is a force multiplier. Code review without AI now means missing things. Running a full security scan on your codebase costs a few dollars a day — the bar to get started has never been lower.