Gemini Skills, Argon access, and OpenAI’s model defenses
Issue date:
This issue covers reusable instructions in Gemini, the limited launch of Gemini 4 Argon, and OpenAI’s account of attempts to extract hidden model reasoning. These are at different stages: Skills are rolling out in chat, Argon has a narrow initial audience, and OpenAI is reporting on an earlier security incident.
This issue may include important events published earlier.
Google rolls out Gemini Skills and prepares to replace Gems
Google has begun rolling out Skills globally in Gemini chat. Users can save an instruction and invoke it by typing “/” followed by the Skill name. Skills can already include reference materials such as plain-text files, PDFs, and images, and users can combine several of them. Google also says Gemini can create a Skill from a chat and apply it to a matching request. Workspace Business, Enterprise, Nonprofit, and Education customers are due to receive access in the coming weeks; this does not mean every such customer has it today.
Key facts
Google says Skills are available across Google AI subscription tiers for users aged 18 and over; access for younger users is planned for later.
Google plans to end Gems support starting in November 2026 for personal accounts, March 2027 for Workspace Business, Enterprise, and Nonprofit, and June 2027 for Workspace Education.
Google plans to migrate Gems into Skills automatically when Gems go away. Sharing Skills, adding Google Drive files, and adding Gemini Notebook materials are planned for the coming weeks.
Why it matters
A saved instruction may spare staff from rewriting the same request. Meeting preparation and drafting are plausible uses, but neither time savings nor output quality is guaranteed. The Gems transition is a separate task: teams can review existing settings before support ends, then check what migrated and who can access it. Shared Skills should not become a dependency in a team process until that capability arrives.
Business processes
Presentation and meeting preparation — One instruction could set a consistent outline for slides, talking points, and questions at recurring meetings; staff would still check the content.
Drafting to brand guidelines — A writing-style Skill could be combined with brand instructions to produce a draft, leaving approval with a person.
Managing AI work instructions — An inventory of Gems can identify instructions still in use and the materials or permissions that will need checking during the move.
Automation opportunities
Recurring drafts in Gemini: Save a reviewed instruction as a Skill and call it by name instead of re-entering it. Start with a task whose output has clear review criteria. Conditions: Skills are rolling out in Gemini chat; access for a particular user should be checked.; Subscription terms and current age restrictions apply.; Staff must continue to review model-generated material.
Moving a team from Gems to Skills: Inventory Gems and associated materials before support ends; after automatic migration, verify instructions and access in Skills. Conditions: The support end date depends on account type.; Google plans automatic migration when Gems go away, not in advance.; Sharing and adding Google Drive files to Skills are planned for the coming weeks.
Impact on manual work
Reusing instructions may reduce repeated prompt-writing. Google provides no measured time savings, while checking outputs and migrated settings remains staff work.
Limitations and risks
The chat rollout does not amount to immediate access for every Workspace customer.
The Gems schedule varies; Google does not promise to migrate Gems by Google Labs into Skills.
Reference files can be added to Skills now, but sharing and adding files from Google Drive are planned for later.
Google’s efficiency claims are not accompanied by measured results for teams.
Google announces Gemini 4 Argon with limited initial access
Google has announced Gemini 4 Argon and begun providing access to a group of trusted cyber defenders through its Fairwind Program. It plans a wider release after early-user feedback and further work on safeguards, but gives no date. Google states that the model can produce up to 1 million output tokens, compared with a previous 64,000-token limit. Its announced introductory prices are $2 per million input tokens and $10 per million output tokens; cached input tokens are priced 95% below regular input tokens. Google Blog lists post-introductory prices of $4 and $20 respectively.
Key facts
Initial Gemini 4 Argon access is for trusted cyber defenders through Fairwind; access for developers, enterprises, and consumers is planned for a later phase.
Google lists introductory prices of $2 and $10 per million input and output tokens. The post-introductory prices of $4 and $20 are listed in Google Blog.
Google reports Argon scores of 77.9% on DeepSWE v1.1 for software engineering tasks and 51.3% on AutomationBench for business-task execution. These are vendor-reported evaluations, not a test in any particular organization.
Why it matters
Argon may become a candidate for extended, multi-step work in code analysis, code changes, research, and vulnerability defense. Most teams cannot yet test it themselves. Even a published automation score does not show how it will perform with an organization’s data, access rules, and process-specific errors. Adoption would call for a safe pilot, an assessment of the cost of long outputs, and specialist review of results.
Business processes
Software development and maintenance — Once access is granted, teams could compare it with existing tools on debugging, code analysis, and narrowly scoped migrations.
Financial and legal research — Google claims suitability for multi-step document work; conclusions would need accuracy checks, review of source material, and appropriate data controls.
Defensive cybersecurity — Early users could test vulnerability discovery and remediation in a controlled setting without authorizing the model to deploy changes on its own.
Automation opportunities
Multi-step code analysis: Once access opens, run a limited pilot comparing accuracy, cost, and reliability with the current process on tasks whose results can be checked. Conditions: Access beyond the initial group is not yet open.; Critical changes require automated tests and engineer review.; Spending limits and controls on data sent to the model are needed.
Vulnerability defense: In an environment available to trusted users, test the model’s proposals to find, validate, and fix vulnerabilities before changing any system. Conditions: Initial access is for trusted cyber defenders.; Google says it may release the model to these defenders and its internal teams without cyber guardrails.; Isolation, action logs, and specialist approval before applying a fix are needed.
Impact on manual work
Google describes internal Argon use in engineering, research, and writing but provides no independent measurement of reduced manual work. The effect for external teams remains unestablished.
Limitations and risks
Broad model access is not yet open; published prices do not mean the API is generally available.
Benchmarks and internal-use examples come from Google, not from testing in a reader’s working environment.
Google says it is still improving defenses against misuse, malicious instructions in supplied material, and actions that depart from user intent.
The stated 1-million-token output limit is a capacity claim, not evidence of accuracy; long-running tasks need cost controls and review of consequential actions.
OpenAI describes attempts to extract hidden model reasoning and its defenses
OpenAI says it disrupted coordinated attempts to obtain hidden model reasoning for distillation: using one model’s output to help train another. Its disclosure concerns past activity, not a new product. The company says it closed paths for repeatedly obtaining reasoning, strengthened account and infrastructure controls, and inspected streamed output. OpenAI also shared findings with partners but says defenses in partner deployments and for data from connected tools still need work.
Key facts
According to OpenAI, the activity began on July 1, 2026, and a core account cluster had been disrupted by July 28.
OpenAI reports 16,000 extraction attempts from more than 4,000 users on July 24–25; related prompt activity involved more than 15,000 users. These counts do not show how many attempts succeeded.
OpenAI links a core cluster to individuals associated with Moonshot AI but does not say one actor operated the entire campaign. This is OpenAI’s assessment, not independent attribution.
OpenAI says it found no encryption break, database compromise, or direct access to stored user conversations.
Why it matters
For an AI service operator, security involves not just protecting an API key but also understanding request patterns, account settings, and what responses may reveal. Agent systems face another concern: connected tools can supply instructions the model should not obey. OpenAI’s report does not demonstrate theft of user conversations or measure the effectiveness of every defense described. It does give teams a reason to examine their limits and their process for investigating anomalies.
Business processes
Operating AI APIs — Teams could compare unusual request volume and repetition with normal use, then send suspicious cases for investigation.
Protecting model outputs and intellectual property — Operators can assess whether responses can be collected at scale, including through streaming, and what controls constrain collection.
Integrating external tools — Tool-supplied data should be kept separate from trusted instructions, with agent actions checked before execution.
Automation opportunities
Monitoring AI API abuse: Set alerts for repeated request patterns, unusual rates, and linked accounts, then examine the context before deciding to block access. Conditions: Alert thresholds should account for legitimate users.; False positives need human review and a way to contest a block.; OpenAI’s report does not establish that these settings alone will prevent extraction.
Safeguarding agents with external tools: Validate tool-supplied data, restrict agent permissions, and retain action logs for incident investigation. Conditions: Controls must fit the particular integrations and threat model.; OpenAI says work remains on partner deployments and tool-supplied data.; Sensitive actions still require human review.
Impact on manual work
Automated alerts may reduce initial manual review of requests, but the report does not measure labor savings. Investigations, assessment of false positives, and restriction decisions remain specialist tasks.
Limitations and risks
The link to people associated with Moonshot AI is OpenAI’s assessment; it has not established that all operators belonged to one actor.
The 16,000 figure counts attempts on the stated days, not confirmed extractions or compromised accounts.
OpenAI reports no compromise of stored chats; attempts to obtain reasoning should not be described as theft of user conversations.
OpenAI acknowledges that defenses for partner deployments and tool-supplied data still need work.