Blog · 6 October 2026 · 6 min read

Is Mistral Large 4 Safe? Data, Training and GDPR Basics

Mistral Large 4 launched on 6 October 2026 as a public preview. What Mistral documents on data and training, and what it leaves open.

New model. Same rules. Check the plan.

Whether Mistral Large 4 is safe for your data depends less on the model than on how you reach it. Mistral announced the model on 6 October 2026 as a public preview on its own API and Studio, and its help centre says training use varies by plan. This post covers what Mistral has published so far, what that does and does not tell you, and a short checklist before you paste anything sensitive.

It was written on the day of the launch, so it covers a preview, not a finished product. Where the documents are silent, it says so instead of guessing. It is not legal advice.

What was announced

According to the launch post, Mistral Large 4 is an open-weight, multimodal mixture-of-experts model with about 1 trillion parameters in total and 49 billion active at a time. The model documentation lists a 1 million token context window and marks the model as a public preview, reachable through Mistral’s Studio and API.

Two other details in the announcement matter for safety. Mistral says the full weights follow by the end of October 2026, so they are not downloadable yet. And it says the model is still in red-team testing with cybersecurity leaders and state authorities, which is a polite way of saying the safety work is not finished.

The launch post also says the model was trained in Mistral’s European datacentres and that its European deployment runs under European law. Read that as a statement about training and about Mistral’s own infrastructure. It is not a promise about where your particular requests are processed, and the announcement does not say that.

Does Mistral train on what you send?

It depends on the plan, and that is the point most people miss. Mistral’s help centre article on whether it uses your data to train its models says three things worth knowing:

  • On the free API tier, Mistral says it may use your inputs and outputs to train its models.
  • On pay-as-you-go, customers keep control and can opt out.
  • Using the thumbs up or down buttons authorises Mistral to use that feedback, along with the input and output, to improve its models, whatever your plan.

The same article says the Vibe product trains on standard-tier data by default unless you opt out, and that enterprise accounts are opted out by default. None of those documents says anything different for Large 4. They also do not say that the preview follows different rules, so the sensible reading is that the plan-level rules apply. Treat that as an inference, not a confirmed statement.

Where retention and hosting are actually decided

How long data is kept, and where it is processed, are not in a launch post. They sit in Mistral’s privacy policy, its data processing addendum and its trust centre. This post does not restate figures from them, because they can change and a launch-day summary would age badly. If you are a business customer, the addendum is the document your data protection officer will want.

Mistral is a French company, so the GDPR applies to it directly. That helps with the legal framework, but it does not tell you what a given feature does with a given prompt. The regulation sets duties for whoever processes personal data. Your own responsibility as the person sending it does not go away.

What open weights change, and what they do not

When the weights are released, a team could in principle run the model on its own hardware, and then prompts never reach Mistral at all. That is a consequence of how open weights work, not something Mistral has promised about Large 4, and it only applies once the weights exist. A model of this size also needs serious hardware, so for most people the realistic route stays the hosted API.

Open weights also cut the other way. Anyone can run the model without Mistral’s hosted safeguards, which is why the red-team testing in the announcement matters. Whether a model is open says nothing about whether your data is safe on a given host.

A short checklist before you paste anything

  1. Find out which plan you are on. Free and paid tiers have different training terms.
  2. If you can opt out of training, do it before you send anything you would not want in a training set.
  3. Skip the feedback buttons on any prompt that contains private material.
  4. Keep customer names, health details and contract text out of a preview model until you have read the addendum.
  5. Treat the answers like any other AI output. A confident reply from a 1 trillion parameter model can still be wrong, and checking an AI answer when you are not the expert is a habit that does not depend on the vendor.

How this compares with other launches

The pattern is familiar from other recent launches: the model is new, and the data rules belong to the account. We saw the same split in is GPT-6 Astra safe, where the system card said a lot about behaviour and little about your data, and in is Meta Muse safe, where the controls were about access to connected accounts. Mistral’s version of the question is mostly about plans and opt-outs.

If you plan to build something on top of a model like this, AI agent vs LLM explains why a model with tools carries more risk than a chat window, and agentic workflows covers what to check before you let one act on its own.

The short version

Mistral Large 4 is a preview, the safety testing is still running, and the documents published today leave retention and per-request hosting to the legal pages. Use it for low-stakes work first and read the plan terms before you trust it with anything private. Coursium teaches people to use AI at work, including how to decide what belongs in a prompt in the first place. You can see how Coursium works if that is useful.

Coursium

Stay ahead of AI — learn the tools on your phone.

Get the app