The AI price war ended in a tie
Google's Gemini 4 Argon landed at the same $2 / $10 per million tokens as Claude Sonnet 5.5 and GPT-6.1 Sol. When the fare is identical, the fight moves to what the model is allowed to do on your behalf.

Google announced Gemini 4 Argon on 30 September, and the number that mattered was not a benchmark. It was $2 per million input tokens and $10 per million output tokens. That is exactly what Anthropic lists for Claude Sonnet 5.5. It is exactly what OpenAI lists for GPT-6.1 Sol.
Three labs. Three flagship working models. One price. That is not a coincidence, that is a market finishing an argument.
When every airline charges the same fare, you read the baggage rules
For two years the pitch was raw capability, and the counter-pitch was cost. Both just got neutralised at the top of the market. So the question changes. You stop asking which model is cheaper and start asking what it is permitted to touch, who has to say yes before it acts, and what it writes down afterwards.
Before anyone reorganises their stack around Argon, the fine print deserves a read. The $2 / $10 is an introductory price. After it ends, the list price is $4 / $20, double. Google has not said when the introductory period ends. Cached input is 95% off, which works out to about $0.10 during the intro. The output ceiling jumps to 1M tokens, up from 64K, which is a genuinely big change if you generate long documents rather than short answers.
The vendor-reported scores are strong: 51.3% on AutomationBench and ranked first (that is Zapier's multi-step business-workflow benchmark), 77.9% on DeepSWE v1.1, 68% on CWE-bench v1 tied for first, and top of the Vals Index. And you almost certainly cannot try it. Argon is rolling out first to "trusted cyber defenders" through Google's Fairwind Program, plus the US government's voluntary pre-release access process. Paid API customers and Google AI Ultra subscribers come after that, with no date given. Bloomberg reported that some Google employees are skeptical of the model.
The feature Google led with was a brake pedal
Here is the part I keep rereading. Google says Argon runs a misalignment monitor that watches the model's chain of thought and its actions, and stops execution when necessary if the model goes beyond what the user actually asked for. Google also claims Argon leads Gray Swan's indirect prompt-injection benchmark. Trusted defenders get a special build with the cyber guardrails removed.
A flagship launch where a serious chunk of the pitch is "it stops itself when it starts doing something you did not ask for" is a tell. Scope control is now a product feature, not a safety footnote.
Robinhood shipped that same idea to ordinary people
On 29 September, at its HOOD Summit, Robinhood announced Robinhood Agents: an in-app agent that researches, builds strategies and places trades inside dedicated agentic accounts. It is the clearest consumer version of the permission pattern I have seen.
"With approvals on, your agent cannot place an order until you approve it. You can turn trade approvals off."
Think of it as a valet key for your brokerage account. The agent gets its own compartment, and you decide whether it needs your signature. There is also a feature called Loops, coming soon, that turns a strategy into a standing instruction running "day and night". Switching a Loop off does not reverse trades it already placed. And the liability line is unambiguous: customers "assume all risk for trades executed by AI agents and for any use of your data by third-party LLM providers", and Robinhood "does not control, supervise, monitor, recommend, or audit agents".
The usage numbers are the real story. Since May, Robinhood reports 150,000+ agentic trading accounts, and connected agents calling its tools almost 30 million times a day. People were already pointing their own agents at their money before the broker built one.
Washington handed everyone the vocabulary
At a White House meeting the same Tuesday, Anthropic, OpenAI, Google, Meta, Nvidia and others signed the White House Accord on Super Intelligence. It sets four layers of control per company: internal evaluations, external audits, and review by a committee of each company's board.
It also has no penalties, no requirement to publish audit findings, and no deadline. The text says companies "should implement" the steps. Trump called it "morally binding". Dario Amodei called it "a start". Trump separately signed an executive order telling federal agencies to say "Super Intelligence" instead of AI. (Reports differ on the full signer list, so treat the roster as provisional.)
Voluntary does not mean inert. It gives regulated buyers their wording. "External audit", "board oversight", "preventing unintended system access" are the phrases that will show up in procurement questionnaires. Meanwhile the hard deadlines are elsewhere: the ECB gave major eurozone banks until 31 October to show supervisors how they will defend against AI-driven cyberattacks, and Australia's ASIC said on 30 September it will review how banks use AI with customers.
And the plumbing underneath is wide open
OX Security published a census of 15,465 published MCP servers on 24 September. MCP is the connector standard that lets an agent reach your files, your CRM, your ticketing system. Across 5,095 unique hostnames: 15.6% resolve outside the US (19 in China, 18 in Russia), 0.45% sit on home networks or consumer tunnels, 2.3% no longer resolve at all, and 6 abandoned domains were for sale at $4 to $12 a year.
Six dollars to buy a domain that agents are still pointed at. That is the whole attack.
The test that should bother you most: in Claude Code running Haiku 3.5, a malicious MCP server used prompt injection to turn a single "Always-Allow" permission for a harmless file request into reading a sensitive .env file, with no second confirmation. OX says Opus 4.6 and 4.7 detected and blocked the same attack. All of this is vendor-reported, but the structural point stands: MCP does not define who runs a server, where it runs, or whether the code behind it matches the published source.
The three questions that replaced "which model"
If model choice is now a coin flip on price, the useful work moved one layer out. For any agent you run, or any vendor who runs one for you:
- What can it reach? Every connector, every "always allow" you have ever clicked, and who actually operates the server on the other end.
- What needs a human yes? Especially anything that sends a message or spends money. Robinhood made that a switch. Most tools have not.
- Where is the log, and who reads it? An audit trail nobody reviews is decoration.
One more, from the OX finding: the cheap model fell for the attack and the expensive ones did not. That is a real argument against running your smallest, cheapest model on the tools that can read your secrets. Saving money on tokens is a false economy if the saving is spent on blast radius.
The price war is over and it ended in a draw. The permission war just started.
One signal a day. No noise.
A 3-minute read when something genuinely shifts in AI, automation, or defense tech. Free, most weekdays.
Free, most weekdays. No spam, unsubscribe anytime.Sources
- Google - Gemini 4 Argon - https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-4-argon/
- Google DeepMind - Fairwind Program - https://deepmind.google/fairwind-program/
- CNBC - Google Gemini 4 Argon - https://www.cnbc.com/2026/09/30/google-gemini-4-argon-ai.html
- VentureBeat - Google unveils Gemini 4 Argon, retaking benchmark lead in limited release - https://venturebeat.com/technology/google-unveils-gemini-4-argon-retaking-benchmark-lead-over-openai-and-anthropic-but-in-limited-release
- PYMNTS - AI giants sign White House safety pact with no penalties attached - https://www.pymnts.com/news/artificial-intelligence/2026/ai-giants-sign-white-houses-safety-pact-with-no-penalties-attached/
- CoinDesk - Robinhood is giving customers an AI agent that trades for them - https://www.coindesk.com/markets/2026/09/30/robinhood-is-giving-customers-an-ai-agent-that-trades-for-them-plus-10x-crypto-bets
- PR Newswire - New research: MCP servers connect AI agents to China, Russia, home networks and abandoned domains - https://www.prnewswire.com/news-releases/new-research-mcp-servers-connect-ai-agents-to-china-russia-home-networks-and-abandoned-domains-302888066.html
- Infosecurity Magazine - MCP creating major governance gaps - https://www.infosecurity-magazine.com/news/mcp-creating-major-governance-gaps/
Quick answers
How much does Gemini 4 Argon cost?
Google lists an introductory price of $2 per million input tokens and $10 per million output tokens, with cached input 95% off (about $0.10). After the introductory period it goes to $4 / $20. Google has not stated when that period ends.
Can I use Gemini 4 Argon today?
Probably not. It is rolling out first to trusted cyber defenders through Google's Fairwind Program, alongside the US government's voluntary pre-release access process. Paid API customers and Google AI Ultra subscribers come afterwards, and no date has been given.
Does the White House accord on AI safety have any teeth?
Not yet. It commits signatories to internal evaluations, external audits and board-level review, but it carries no penalties, no requirement to publish audit findings, and no deadline. The text says companies "should implement" the steps, and that they could later become law.
What did the OX Security research find about MCP servers?
Across 15,465 published MCP servers and 5,095 unique hostnames, 15.6% resolved outside the US, 2.3% no longer resolved at all, and 6 abandoned domains were on sale for $4 to $12 a year. In one test, a single "Always-Allow" permission was escalated via prompt injection into reading a sensitive .env file on a small model, while larger models blocked the same attack. The findings are vendor-reported.