Mistral AI
French AI lab and platform combining open and proprietary frontier models with agents, coding tools, OCR and voice APIs. Aimed at enterprises and public bodies that want EU-hosted or self-hosted AI they keep under their own control.
What is Mistral AI?
Mistral AI is a French simplified joint-stock company founded in April 2023 and registered in Paris under number 952 418 325, with its head office at 15 rue des Halles and a share capital of 15,000 euros. It was started by Arthur Mensch (CEO), Guillaume Lample (Chief Science Officer) and Timothee Lacroix (CTO), and presents itself as the European leader combining frontier innovation, openness, transparency, cost efficiency and accountability, around a stated mission to make frontier AI open to all. The company builds both its own model family and the software layer that runs it. The catalogue spans Mistral Large 3, Mistral Medium 3.5, Mistral Small 4 and the compact Ministral 3-14B, the coding models Devstral 2, Codestral and Codestral Embed, plus OCR 4 for document parsing, Voxtral TTS for speech, Mistral Moderation and Shieldstral for safety, Leanstral and a 3B Classifier API. Capabilities advertised across the range include text-to-text generation, reasoning, coding, agentic behaviour, multimodality, voice and OCR, in several languages. Part of the catalogue is released open-weight under the Apache 2.0 licence and can be downloaded from Hugging Face. Five products sit on top: Vibe, a long-horizon agent; Vibe for code for software work; Studio to build, test, run and observe agents behind a unified AI registry; Forge for custom training and alignment; and Compute for dedicated GPU clusters. Applied services cover domain adaptation, use-case acceleration, deployment and hands-on support from Mistral's own scientists. Deployment is deliberately portable: self-hosted on a virtual cloud, at the edge or on-premises; on Mistral's own cloud, whose servers are hosted in the EU; or through partner clouds including Google Cloud, AWS, Azure, SAP, IBM, Snowflake, NVIDIA and Outscale. Named customers include HSBC, ASML, CMA CGM, Stellantis, BMW, the European Patent Office, the Austrian Academy of Sciences and TotalEnergies, and the target industries shown are financial services, public sector and government, manufacturing, energy and utilities, with defence mentioned in the company's history. Consumer apps ship on iOS and Android as Le Chat by Mistral AI. One caveat: no security certification is named on the readable pages, so buyers who need one will have to verify it themselves.
What it does
- Ask questions and generate multilingual text with Vibe, on the web or on mobile.
- Run long autonomous tasks with persistent memory and reusable skills.
- Write, review and refactor code from the terminal, from VS Code or JetBrains, or in the background.
- Extract and understand documents at scale with OCR 4 and Document AI.
- Transcribe audio and generate speech with Voxtral and text-to-speech, including voice cloning.
- Build and orchestrate agents in Studio, with evals, judges and guardrails.
- Train, align and distil your own models with Forge, then deploy self-hosted, on Mistral's EU cloud or on a partner cloud.
When to use Mistral AI / When not to
A quick filter to help you decide if Mistral AI is the right fit.
When to use Mistral AI
- Regulated enterprises in financial services, energy, manufacturing and defence that need EU data residency and a documented processing chain.
- Public-sector and government bodies looking for a European supplier they can run on their own infrastructure, on-premises or at the edge.
- Engineering teams that want to fine-tune, align or pre-train models on their own proprietary data through Forge.
- Developers who want coding agents in the terminal, inside VS Code or JetBrains, or running asynchronously in the background.
- Document-heavy operations teams extracting text and structure at scale with OCR 4 and Document AI.
When not to use Mistral AI
- Procurement teams that require a named security certification up front: no SOC 2 or ISO 27001 claim is readable on the public pages.
- Children under 13, and minors who do not have their parent's or guardian's agreement, which the EU consumer terms require.
- Heavy daily users hoping to stay on the Free plan, where messages, web searches and coding sessions are all capped.
- Teams with no way to monitor token spend, or that need a public enterprise price before talking to anyone: API billing is usage-based and Enterprise is quote-only.
- Affiliates, resellers and creators looking for a commission or referral programme, since none is published.
How to use Mistral AI
A typical end-to-end flow, from setup to results.
- Try the assistant first: open Vibe at chat.mistral.ai in a browser, or install the Le Chat by Mistral AI app on iOS or Android.
- Create an account; the Free plan is enough to test messages, web search, image generation and the connector library.
- Plug in your tools from Vibe, with over 100 connectors such as Notion, Slack, Linear and Google Drive, or wire a custom MCP connector in beta.
- For development work, open a Studio account on console.mistral.ai and generate an API key.
- Call the endpoints documented on docs.mistral.ai/api/, selecting a regional inference endpoint where you need one.
- Set your privacy posture before going live: activate the training opt-out in your account, and enable zero data retention on the APIs if required.
- For coding, install the Vibe CLI in your terminal or the VS Code and JetBrains extensions, and hand longer jobs to background agents.
- Track consumption in the Studio dashboard, which breaks down calls, endpoints and cost per service.
- To run models yourself, download the open-weight releases from Hugging Face under the Apache 2.0 licence where it applies.
- For an enterprise rollout, use the Contact sales form or the Enterprise deployment pages to discuss private deployments and custom training.
Pros & Cons
Pros
- The Mistral cloud runs on servers hosted in the EU, and the publisher is a French company directly subject to the GDPR.
- Unusually dense public legal documentation: a full Legal Center, DPA, usage policy, cookie policy, licence notice and AI governance hub, plus a vulnerability disclosure programme run through HackerOne.
- The training opt-out is available directly from the account, and zero data retention can be switched on for the APIs.
- Three deployment modes, including on-premises and edge, which turns the portability claim into something verifiable.
- Part of the catalogue is open-weight under Apache 2.0, so those models can be downloaded and run independently.
- Broad coverage in one place, from text and reasoning to code, OCR, voice, images and agents, with named reference customers such as HSBC, ASML, CMA CGM and Stellantis.
- API prices are published in detail, with explicit batch and cache discounts, a permanent free plan and a 5.99 USD student plan.
Cons
- No security certification is named on the readable pages: the privacy policy refers to "our certifications" without listing them, and the Trust Center that would carry them is JavaScript-rendered.
- The sub-processor list is announced but cannot be read without JavaScript.
- Enterprise pricing is not public, and Enterprise APIs are billed 75% above the list rate.
- Chat and email support is reserved for paid plans; the Free plan only gets the help centre.
- No time-limited trial of the paid plans is advertised, only a capped Free plan.
- Prices are shown through a USD/EUR selector with a tax-included toggle, which makes comparison less direct than it should be.
- The publisher acknowledges technical limits on data rights requests concerning model training, and there is no affiliate or referral programme.
Pricing & Plans
A permanent Free plan is available at no cost. The lowest paid entry point open to all users is Pro at 14.99 USD per month, while Team is priced at 24.99 USD per user per month and a verified-student Education plan is offered at 5.99 USD; Enterprise pricing is available on quotation only. Prices may be displayed in USD or EUR, excluding or including tax. API usage is billed separately per million tokens, with Mistral Medium 3.5 at 1.50 USD for input and 7.50 USD for output, OCR 4 at 4 USD per 1,000 pages, Document AI at 5 USD per 1,000 pages and Voxtral TTS at 0.016 USD per 1,000 characters. Batch processing is discounted by 50% and cached input tokens by 90%, whereas Enterprise APIs carry a 75% premium. Pay-as-you-go credits extend usage beyond plan limits, and all plans are subject to fair use limits.
- a personal AI agent for everyday tasks
- with web and mobile access to Vibe
- state-of-the-art models
- capped messages and web searches
- image generation and 100+ connectors.
- higher usage limits
- more messages and searches
- complex tasks
- all-day coding in the CLI
- IDE and web
- more image generations
- chat and email support
- and the training opt-out.
- a secure collaborative workspace
- 30 GB of storage per user
- domain name verification
- data export and the training opt-out.
- private deployments
- custom models
- agents and workflows
- audit logs
- SAML SSO
- white-labelling and the training opt-out.
- reserved for verified students of accredited institutions
- limited to 12 months and to users who have not previously used Vibe or Le Chat.
Data, GDPR & hosting
A consolidated view of how Mistral AI handles your data.
GDPR overview
GDPR compliance is documented in detail. Mistral AI is a French company, so the Regulation applies directly; the privacy policy in force since 27 July 2026 and a Legal Center effective 28 November 2025 set out the framework. A Data Protection Officer is appointed and reachable through the Privacy Requests form or by post marked "Attn: DPO". The rights listed cover access, portability, rectification, erasure, objection, withdrawal of consent, restriction, automated decision-making, post-mortem instructions and complaint to the CNIL. Account settings allow deletion, export and objection to model training. A public DPA incorporates the 2021/914 standard contractual clauses, and Article 46 safeguards cover transfers outside the EU; sub-processors are listed in the Trust Center, with a ten-day objection window at privacy@mistral.ai. No Article 27 representative is designated, the company being established in the EU. Mistral AI acknowledges technical limits on requests touching model training.
Who owns the data?
Ownership depends on how the service is used. For business use, the privacy policy in force since 27 July 2026 states that the customer is the data controller and that Mistral AI acts as a processor on the customer's behalf; the policy itself does not govern that processing. For consumer use, Mistral AI is the controller. In both cases the Input you submit and the Output you receive remain yours, and account holders can export their data. The EU consumer terms additionally grant portability and switching rights, so conversations and files can be taken elsewhere when an account is closed.
Reuse rights
The privacy policy effective 27 July 2026 lists the purposes: delivering the service, powering Vibe's memory, debugging, account management, support, security, communication, product improvement outside training, model training, moderation, billing, disputes and handling data rights. The legal bases invoked are performance of the contract, legitimate interest, consent and legal obligation. Input and Output may be used to train the models under legitimate interest, subject to an opt-out you activate from your account, while Third Party Content returned by web search and verified news is expressly excluded from training. The models themselves are trained on publicly available internet data, third-party datasets and synthetic data, with collection started in 2023. Mistral AI states that it carries out no profiling and no automated decision-making, and that it neither sells nor shares personal data within the meaning of US state privacy laws, including for users under 18.
Data retention & training
Hosting summary
Hosting depends on the deployment mode. On Mistral's own cloud, the company states that its servers are hosted in the EU, and the API pricing page advertises regional inference endpoints. Self-hosting is available on a virtual cloud, at the edge or on-premises, in which case, in the publisher's words, your data stays within your walls. A third route runs the models through partner clouds: Google Cloud, AWS, Azure, SAP, IBM, Snowflake, NVIDIA and Outscale. For its own processing, Mistral AI says it gives priority to service providers located in the EU and only exceptionally uses providers outside it, under standard contractual clauses and the safeguards of Article 46 GDPR. No specific hosting country is ever named, the commitment being stated at EU region level, which is why no country is listed on this page. One distinction matters: the mistral.ai marketing site is itself hosted by Netlify, Inc. in San Francisco, as declared in the legal notice, and the domain resolves to a Cloudflare anycast node. Neither tells you anything about where customer data is processed.
Things to keep in mind
Risks and trade-offs to weigh before adopting Mistral AI.
- Input and Output feed model training by default: the opt-out has to be switched on in your account, and the pricing table only shows the "Model training: Opt-out" line for paid plans.
- Vibe's persistent memory can retain sensitive details pasted into prompts; memories can be turned off in the settings, but only if you think to do it.
- On the APIs, Input and Output are kept for a rolling 30 days for abuse monitoring unless zero data retention is enabled.
- Data rights requests that touch model training face technical limits acknowledged by the publisher, so erasure may not be complete in practice.
- Civil identity data is kept five years after the account is closed and invoices ten years, which is longer than most users assume.
- No security certification is publicly named and the Trust Center is unreadable without JavaScript, so do not assume a certification exists simply because a trust page does; note too that the domain resolves to a Cloudflare CDN node in the United States, which says nothing about where customer data lives.
- Delegating long autonomous tasks and background coding agents makes it easy to stop reading the output: keep a human review on generated code, figures and legal wording.
Setup & Integrations
Technical difficulty
Difficulty scales with the mode of use. For consumer use there is nothing to install: create an account and open Vibe on the web or on mobile. For developers, the effort is that of any LLM API, with an account on console.mistral.ai, an API key and documented REST calls, the Vibe CLI and the VS Code or JetBrains extensions being installed separately. Self-hosting and on-premises deployment are infrastructure projects that require MLOps skills. Custom training with Forge comes with support from Mistral's own scientists, and Compute means operating dedicated GPU clusters, which belongs to an infrastructure team.
Deployment
Apps stores
Integrations
Supported languages
Behind Mistral AI
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
Is there a free plan?
How much does the first paid plan cost?
How is the API billed?
Is my data used to train the models?
Where is the data hosted?
Is a data processing agreement available?
What is the minimum age?
Are there mobile apps?
Are the models open?
How do I contact support?
Should you pick Mistral AI?
Mistral AI is one of the few European players that keeps research, models, products and infrastructure under one roof, from open-weight releases on Hugging Face to dedicated GPU clusters. That vertical integration is what makes its central argument credible: control. The same models can run on your own hardware, at the edge or on-premises, on Mistral's EU-hosted cloud, or through a partner cloud, and you can move between those routes without changing supplier. The legal side sits well above the sector average. A complete Legal Center, a published DPA carrying standard contractual clauses, an account-level training opt-out and zero data retention on the APIs give a compliance team far more to work with than most competitors offer. Two reservations remain. First, no security certification is named anywhere on the readable pages: the privacy policy alludes to our certifications without listing them, and the Trust Center that would carry them does not render without JavaScript, so a certification-driven procurement process will need its own verification. Second, enterprise economics are opaque, since Enterprise pricing is quote-only and Enterprise APIs carry a 75% premium over the list rate. The natural audience is clear enough: regulated companies, public bodies and technical teams that value sovereignty, portability and a documented processing chain more than the lowest sticker price. Individual users are well served by the Free and Pro plans, but that is not where the platform shows its real advantage.
- Choosing a selection results in a full page refresh.
- Opens in a new window.