Google says new Gemini model found critical flaw in hospital software

Advertisement

Google says its new frontier AI model, Gemini 4 Argon, uncovered a critical vulnerability in healthcare software used by hospitals worldwide that put sensitive personal information at risk.

Google-owned cybersecurity company Wiz found the flaw through its Scan for Good initiative, which offers free scanning to find and fix high-risk exposures at organizations that run critical public infrastructure. Koray Kavukcuoglu, senior vice president of Google DeepMind and chief AI architect at Google, described the finding in a Sept. 30 blog post. Mr. Kavukcuoglu said earlier frontier models had missed the risk.

Google did not name the software or its vendor. It also did not say what specific data was at risk or whether the vulnerability has been patched.

Wiz said Sept. 24 that Scan for Good, using Google’s Gemini 3.8 Flash Cyber model, had found exposures at two unnamed hospitals, which it said were fixed before disclosure. Google did not say whether the Argon finding is related to either case.

Google said Argon can find, validate and patch critical software vulnerabilities on its own. The company is first giving the model to trusted cyber defenders through its Fairwind Program. Those defenders and Google’s internal teams will get a version without cyber guardrails.

Google said it is taking part in the federal government’s voluntary process for prerelease model access. It plans to strengthen safeguards before offering more Argon broadly, starting with paid API customers and Google AI Ultra subscribers, but did not give a date.

This development follows Anthropic’s April decision to withhold its Mythos Preview and launch Project Glasswing, a defensive cybersecurity initiative. Glasswing later expanded to roughly 150 more organizations, including vendors that serve healthcare, such as Epic. OpenAI also has a similar cyber project, called Daybreak.

Advertisement

Next Up in Digital Health

Advertisement