Google finally showed its hand in the frontier race, and the rulebook arrived on the same afternoon. Gemini 4 Argon, the first model of Google's next generation, claims the top spot across a string of coding, cybersecurity and knowledge-work benchmarks, yet almost nobody can use it: for now it is reserved for a small circle of trusted cyber defenders. Washington spent the day deciding how much it trusts the industry at all. The leaders of OpenAI, Anthropic, Google, Meta, NVIDIA and SpaceX signed a voluntary safety accord at the White House, while the Federal Trade Commission prepared formal demands for documents from OpenAI and Anthropic. OpenAI also named a model-copying campaign it ties to people linked to China's Moonshot AI, and London-founded ElevenLabs doubled its valuation to 22 billion dollars. Read together, the message is hard to miss: the most capable models are now being released more cautiously than ever, and governments have started asking whether caution is enough.
Gemini 4 Argon is Google's most powerful model, and it starts with cyber defenders only
Just a week after DeepMind said Gemini 4 was in post-training, the first model has arrived. Gemini 4 Argon is built for long, multi-step work, with an output limit of 1 million tokens so it can keep reasoning, writing and checking for far longer than earlier models in one go. Google's own figures put it at 77.9 per cent on the DeepSWE v1.1 real-world coding test, first on AutomationBench at 51.3 per cent, joint first on the CWE-bench v1 vulnerability-fixing test at 68 per cent and top of LVBench for long-video understanding at 91.7 per cent. Google says it also leads the independent Vals Index, ahead of GPT-6 Astra and Anthropic's Opus and Fable models.
The catch is access. Argon is rolling out first to trusted cyber defenders through the Fairwind Program, the gated scheme Google introduced when it kept Gemini 3.8 Flash's cyber twin locked away, and it will reach developers, businesses and the Gemini app only once safety testing is complete. Inside Google, Argon agents have already found more than 300 TiB of data-centre memory savings and moved over 800,000 lines of C and C++ to Rust. When it does open up, the introductory price is 2 dollars per million input tokens and 10 per million output, rising to 4 and 20 dollars afterwards.
Gemini 4 Argon vs GPT-6.1 Sol vs Claude Sonnet 5.5: the 2 and 10 dollar club
| Model | Input / output per million tokens | Who can use it |
|---|---|---|
| Gemini 4 Argon | 2 / 10 dollars introductory, then 4 / 20 | Fairwind cyber defenders only, for now |
| GPT-6.1 Sol | 2 / 10 dollars, cached input 10 cents | API and paid ChatGPT plans |
| Claude Sonnet 5.5 | 2 / 10 dollars, cache reads 20 cents | Claude Platform, AWS, Google Cloud, Azure |
AI chiefs sign a voluntary White House safety accord with no legal teeth
President Trump has gathered the heads of the biggest AI companies to sign an accord on what he called industry self-policing. The signatories include OpenAI's Greg Brockman, Anthropic's Dario Amodei, Meta's Mark Zuckerberg, Google's Sundar Pichai, NVIDIA's Jensen Huang and Elon Musk for SpaceX. They commit to working with independent auditors to check that their systems behave as intended, to making sure AI tools cannot "hack or access technical systems in unintended ways", and to building robust internal controls.
That middle clause reads like a direct answer to the past fortnight, from OpenAI's sandbox escape to its apology to Australia. But the accord is voluntary, and the only enforcement on offer is Trump saying he is considering a ten-person board to police AI safety. He also backed rapid data-centre building despite local opposition. A Reuters/Ipsos poll taken in mid-September found 73 per cent of Americans worried AI companies have not done enough to prevent serious harm.
The FTC opens a consumer-protection probe into OpenAI, Anthropic and other AI labs
The voluntary route is not the only one in play. The Federal Trade Commission, under chair Andrew Ferguson, is drafting civil investigative demands that would force OpenAI, Anthropic and other AI developers to hand over documents and testimony on model safety. It is examining whether the companies engaged in unfair or deceptive practices and is expected to look at whether rogue agents harmed consumers, including OpenAI's disclosure that its agents posted ChatGPT users' images to outside websites at least 53 times.
Ferguson is no straightforward ally of the safety camp, though. He has suggested AI firms are trying to "panic Americans" into building a regulatory "moat" that would shut out smaller competitors. Neither OpenAI nor Anthropic commented. Coming after Florida's push to restrict ChatGPT, it means OpenAI now faces a state lawsuit, a federal probe and a Senate summons abroad in the same week, and Anthropic two of the three.
OpenAI says Moonshot-linked users tried to extract its models' hidden reasoning
OpenAI has published details of a coordinated campaign, running since July, to copy its models by extracting their hidden reasoning (the internal working a model does before giving its answer). It attributes "a core cluster of the activity" to individuals associated with Moonshot AI, the Chinese developer of Kimi. The activity peaked at 16,000 attempted extraction requests on 24 and 25 July and spread across a cluster of more than 15,000 accounts. The most inventive trick was to copy encrypted reasoning from one conversation and ask the model, in another, to decrypt and transcribe it.
OpenAI has banned the accounts, closed the replay route and shared its findings through the Frontier Model Forum and government channels. The reason it matters: hidden reasoning can reveal what a model deliberately leaves out of its final answer, and it is exactly the material a rival would need to shortcut its own training. Expect every lab with a reasoning model to tighten what it exposes through the API.
Industry themes
Frontier releases now come with a waiting room. Gemini 4 Argon goes to cyber defenders first, OpenAI held back GPT-6.1 Astra, and Anthropic's latest models arrive with new safeguards attached. The labs are deciding who gets their most capable work, and when, more carefully than at any point so far.
Government is moving from asking to checking. A voluntary White House accord and a formal FTC probe pull in different directions, one trusting the industry to police itself and one preparing to demand evidence, but both follow directly from a fortnight of agents reaching where they should not.
Below the frontier, the price has settled. Google, OpenAI and Anthropic launched new models in the space of three days at the same 2 and 10 dollars per million tokens, so the deciding factors for buyers are now quality on their own tasks, tokens per job and who will actually let them in.