Loading the catalogue…
Loading the catalogue…
Mistral AI is France's leading frontier AI lab, incorporated in Paris with an EU-hosted first-party inference endpoint, giving it the strongest data-sovereignty profile of any frontier lab in Stav's catalogue. It holds SOC 2 Type II and ISO 27001/27701 certifications, signed the EU GPAI Code of Practice, and publishes GDPR documentation naming a DPO — but a CNIL complaint over free-tier training opt-outs remains unresolved, and its licensing model is genuinely mixed (Apache 2.0 for several releases, proprietary for flagship models like Mistral Medium and Magistral).
Independent compute-tracking data (Epoch AI, April 2026) places Mistral among a small group of frontier labs with at least one model plausibly exceeding the EU AI Act's 10^25 FLOP systemic-risk presumption threshold, though no specific model or formal EU AI Office notification has been publicly confirmed.
An unresolved CNIL complaint (filed Feb 2025) alleges Mistral's free-tier training opt-out process is more cumbersome than for paid subscribers, a potential Article 12 GDPR friction point; no decision has been issued as of the latest available reporting.
Deepening French government dependency — including a state decision to use Mistral (and exclude OpenAI) for security testing of government systems following a major tax-agency breach — raises questions about the neutrality/independence of Mistral's commercial roadmap versus state interests.
No public bug bounty or coordinated vulnerability disclosure policy could be located; security assurance is limited to Trust Center compliance-document requests.
Stav’s assessment
Editorial assessment, not legal advice. Stav's risk ratings, scores, and verdicts are our own analysis of publicly available information and may be incomplete or out of date. Verify independently before making compliance or procurement decisions.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Stav review in progress.
Mistral is a confirmed signatory of the EU's voluntary GPAI Code of Practice, an early-adopter signal aligned with Article 53/55 transparency obligations that carries a legal presumption of conformity.
Holds SOC 2 Type II and ISO 27001/27701 certifications, published via its own Help Center and Trust Center.
Operates a fully EU-hosted first-party inference endpoint (jurisdiction: EU, sovereignty: eu_hosted, data residency: EU) confirmed active on Stav, plus a new EU data centre near Paris to further consolidate EU compute control.
Maintains a verified HuggingFace organisation with 75 published models, 19,180 followers, and 7 research papers, including genuinely open Apache-2.0 releases (Mistral Small, Mistral Nemo, Shieldstral).
Continues to expand its enterprise footprint (HSBC, ASML, CMA CGM, European Patent Office, Tesco) and product suite (Vibe, Agentic Search, OCR 4) while pursuing acquisitions (Emmi AI, May 2026) that broaden its industrial-AI offering.
Published safeguards & certifications