Skip to main content
TrustEdge AI
Model developer

Mistral AI

European frontier model developer. This row describes the paid API on the Scale plan, the tier a regulated buyer would contract for; consumer and lower paid tiers carry materially weaker defaults.

6 of 7 criteria carry a sourced value · 1 recorded as a gap ·  Verified August 8, 2026

What this means for a regulated buyer

Our analysis, not Mistral AI’s. Every statement here traces to a sourced claim further down the page.

A European developer whose marketing outruns its contractual documentation, and the only vendor here whose training default depends on which plan you are on.

Where it is strong

  • Data is hosted in the EU by default, which matters for buyers with data-residency obligations.
  • Zero data retention is available on the Scale plan for stateless API calls.
  • Sub-processor notifications cover removals as well as additions, which is unusual and useful.
  • Signatory to the EU General-Purpose AI Code of Practice.

What to check or negotiate

  • The solutions page markets "HIPAA-compliant solutions" while the Data Processing Addendum — a substantial document that addresses GDPR, Standard Contractual Clauses and sub-processors at length — contains no occurrence of "HIPAA" or "Business Associate". Ask for the agreement before assuming one exists.
  • The certification answer says Mistral "complies with" SOC 2 Type II and ISO 27001/27701 frameworks, not that it is certified against them. For an auditor that distinction is load-bearing; obtain the certificate and its scope.
  • Training defaults are plan-dependent. Scale and Vibe Teams/Enterprise are opted out; free, Pro and Education tiers are opted in and must opt out manually.
  • ZDR is not available for stateful products, and requesting it requires "sufficient detail of your legitimate reasons".
  • No default retention period for inference data is published; the published schedule covers account and billing data only.
  • Lowest grade in the FLI Summer 2026 Index — which bears on safety-research posture, not on whether a deployment can be made compliant.

Verdict

Contract on Scale, confirm the plan-level training default in writing, and treat the HIPAA marketing claim as unevidenced until a BAA is produced.

The full record

Every criterion, with Mistral AI’s own wording where it is hedged or carries exclusions, the primary source, and the date we last read it.

FLI safety grade

Safety-research posture, per the Future of Life Institute

F · 0.33 (Summer 2026)

Lowest of the nine companies graded. Worth holding against the assumption that regulatory jurisdiction predicts vendor safety posture: the EU has the world’s most developed AI safety regulation, and the leading European developer placed last in the Index. A failing safety grade is not a bar to compliant deployment, and this row’s other cells are largely independent of it.

Primary source · verified 2026-08-07

BAA available

Will they sign a business associate agreement for PHI

Not publicly documented

Mistral’s Data Processing Addendum, effective July 27 2026, contains no occurrence of "HIPAA" or "Business Associate" while addressing GDPR, Standard Contractual Clauses and sub-processors at length; the help centre has no HIPAA article. Meanwhile Mistral’s solutions page markets "our HIPAA-compliant solutions" to healthcare buyers. A marketing adjective is not a BAA. Ask for the agreement in writing before assuming one exists.

Primary source · verified 2026-08-07

Certifications

Independently audited attestations

SOC 2 Type II (stated as compliance, not certification) · ISO 27001 · ISO 27701

Quoted in full: "Yes, Mistral complies with both SOC 2 Type II and ISO 27001/27701 frameworks." The wording is "complies with … frameworks" rather than "is certified", and the article is answering a question that asked about certification. That distinction is load-bearing for an auditor. Reports are available on request through the Trust Center; obtain the certificate and its scope rather than relying on this sentence.

Primary source · verified 2026-08-07

Trains on your data

Whether your inputs and outputs feed model training

Not by default — Opted out by default on the Scale (API) and Vibe Teams/Enterprise plans only. Free, Pro and Education tiers are opted IN by default and must opt out through the Admin Console.

Mistral: "Customers on a Scale plan are opted out of training by default" and "Users of Vibe Teams or Enterprise plan are opted out of training by default." The default is plan-dependent, which no other vendor tracked here is — everyone else excludes business data by default across their commercial surface. On a Pro or free tier the data is used for training until someone turns it off. Once opted out, "Mistral no longer uses your input or output data for the purpose of training its models." Le Chat has been renamed Vibe.

Primary source · verified 2026-08-07

Retention

How long your data is kept, and where

Zero data retention available on the Scale plan for stateless API calls only, granted on request and subject to justification. No default inference retention period is published.

Mistral: "Zero Data Retention (ZDR) is available only for the Scale plan and only for stateless API calls", and "ZDR is not available for Vibe Work, Chat, libraries, agents, conversations, batch files, or other stateful products that must store data to work." Requesting it requires "sufficient detail of your legitimate reasons". The published retention schedule covers account and billing data — five years for identity data, one rolling year for technical data, ten years for invoices — not inference data, for which no default period is stated.

Primary source · verified 2026-08-07

Subprocessors

Who else processes your data

List maintained in the Mistral Trust Center with opt-in email notification on additions and removals. No advance-notice period published.

Mistral: "The updated list of our subprocessors is available at all times on our Trust Center" and "You can subscribe by email to receive notifications when we add or remove a subprocessor from this list." Notification covers removals as well as additions, which is unusual and useful. No advance-notice period is committed to.

Primary source · verified 2026-08-07

EU AI Act

Obligations, and which transfer to you as deployer

Signatory to the EU General-Purpose AI Code of Practice, the voluntary route to demonstrating compliance with the AI Act.

Listed by the Commission as "Mistral AI". Read from the Commission’s published list rather than from a vendor announcement.

Primary source · verified 2026-08-07

This is a model developer, so the FLI grade above describes its safety-research posture. It says nothing about whether a deployment is compliant — that comes from the contractual terms, either this vendor’s own or those of a platform you run the model through.

This developer’s models are also available through Amazon Bedrock, under those platforms’ terms rather than these. Where the direct API cannot meet a requirement, the platform route often can.

Safety grades come from the FLI AI Safety Index, Summer 2026 — what it measures, and what it explicitly does not.

Deploying Mistral AI in a regulated environment

We help regulated organisations build AI vendor diligence that holds up in an audit.