Mistral Large 4: Europe's new flagship model, in preview for now
On October 6, 2026, Mistral AI unveiled its new flagship model: Mistral Large 4. At 1.05 trillion parameters, it is more than one and a half times the size of its predecessor, Large 3. Mistral markets it with a promise European IT leaders have wanted to hear for years: sovereignty.
My take after reviewing Mistral's documentation, contract terms and the first press reports: Large 4 is built for sovereignty, but you cannot use it that way yet. For now, it runs only via Mistral's API, as a public preview: a publicly usable early-access version. The weights and the license are still pending. For legally protected data such as patient data or classified information, that is the decisive difference.
A quick note on terms: model weights are a model's trained parameters, stored as files. If they are freely downloadable, the model is an open-weight model. You can then run it on your own hardware without your data leaving the building.
In this article, I explain what lies behind the sovereignty promise and where it ends today. Then I go industry by industry: healthcare, public administration, banks and insurers, law firms, manufacturing, and critical infrastructure. All information as of October 8, 2026.
Key facts at a glance
| Attribute | Mistral Large 4 |
|---|---|
| Status | Public preview since October 6, 2026, API only |
| Architecture | Mixture of experts (MoE): 1.05 trillion parameters in many specialized subnetworks; 52 billion active per token (a word fragment) |
| Context window (the amount of text per request) | 1 million tokens according to Mistral; independent tests measure around 512,000 |
| Input formats | Text and images; over 160 languages, including all official EU languages |
| Training | 3,800 NVIDIA Grace Blackwell GPUs in Mistral's European data centers |
| Downloadable model weights | Announced for the end of October 2026 |
| License | Not yet published |
| API list price | $1.36 per million input tokens, $4.18 per million output tokens |
Three notes on the table: the model platform Hugging Face counts 49 billion active parameters instead of 52 billion, because it excludes the input and output layers. At launch, Mistral is halving its API prices for a limited time without saying when the discount ends, so budget with the list price. The EU endpoint, which processes requests only in EU and EFTA data centers, adds a 10 percent surcharge.
Performance: strong in IT security, behind the leading US models
In the independent index from Artificial Analysis, which combines several benchmarks into one score, Large 4 reaches 38. That makes it the strongest model outside the US and China. The gap to the leaders is still wide: Claude Opus 5.5 scores 58, GPT-6 Astra and Gemini 4 Argon 53 each. Chinese open-weight models also rank ahead: GLM-5.3 (45) and Kimi K3 (44).
Large 4 is strong in IT security: in the B3 test, it fends off 93.3 percent of prompt injection attacks (attempts to slip the model hidden instructions through manipulated text). These are Mistral's own figures, and Mistral says its reinforcement learning run is unfinished. Artificial Analysis also criticizes its very long answers and token count: per task, it costs over four times as much as comparably capable open-weight models.
Large 4 also does well on legal work: in the Vals AI benchmark suite, it places 6th of 76 in the Harvey Legal Agent benchmark, which measures AI agents on legal tasks. My interim verdict: Large 4 is not the best model in the world, but it is the strongest from Europe. Your tasks decide whether that is enough, not the leaderboard.
What Mistral means by "sovereign"
First, the term itself: on its Sovereign AI page, Mistral describes four levels of control. They cover your data, the models and how they are customized, the infrastructure (where and with whom your AI runs), and operational continuity. You are sovereign if you make the decisions yourself on all four levels.
One sentence on the same page is remarkably honest: "Sovereign AI does not mean everything needs to run on-premises." So sovereignty does not necessarily mean your own server room. Some organizations only need an environment reserved for them: a private cloud or a virtual private cloud (VPC), an isolated zone inside a public cloud. Others need fully air-gapped operation.
A second sentence on the same page is awkward for Large 4: "Your licensing and operating rights should also survive the end of the commercial relationship." Yet the Large 4 license is exactly what Mistral has not published. Until it does, you cannot check whether your usage rights would survive the end of the contract.
Why control matters more than the leaderboard
June 2026 showed how real the risk of a shutdown is. A US government export control order barred all foreign nationals from accessing Anthropic's Fable 5 and Mythos 5 models. According to Anthropic, the models then had to be switched off abruptly for all customers.
This case goes to the heart of the debate. Sovereignty answers who can pull the plug. It does not answer how good a model is.
No one can use an order to switch off an open-weight model you self-host. A model you only use through a provider's API can be switched off that way, however good it is.
Large 4 via Mistral's API is more European than a US service. By Mistral's own definition, it only becomes sovereign when you run it yourself or have a hosting provider of your choice run it. The conclusion: a model is only as sovereign as the place it runs.
The fine print: where sovereignty ends today
How I went about it: I analyzed Mistral's contract terms, its list of subprocessors, and its Trust Center. You should know four points before you feed Large 4 real company data.
Preview means Mistral may train on your data
Section 4.3 of the Commercial Terms of Service, in effect since September 25, 2026, governs preview models: Mistral may train on your inputs and the model's responses. Your training opt-out does not apply to these models, and neither does Zero Data Retention (ZDR), Mistral's commitment not to store prompts and responses after processing. Mistral itself writes: "If you do not want your data or outputs used for training, do not use Labs or Preview Models."
Large 4 is explicitly labeled a public preview and, by the wording, falls under Section 4.3. Mistral's ZDR documentation, however, names only the experimental "Labs" models as an exception. Until Mistral resolves this inconsistency in writing, put nothing into the preview that you would not be prepared to publish.
Then there is the lifecycle: under Mistral's model lifecycle policy, preview models may be updated without notice. Mistral does not guarantee that the preview will ever become a regular, stable release (general availability, GA). It only has to announce a shutdown one month in advance.
The supply chain behind Mistral's API
Mistral promises to run the preview in Europe and entirely under its own control. Even so, its general list of subprocessors names US corporations: Microsoft, Google, CoreWeave, and Cloudflare. Have Mistral confirm in the contract which of them are actually involved in running Large 4.
Mistral also has a US subsidiary, Mistral AI Inc. That matters because of the US CLOUD Act, which obliges providers under US jurisdiction to hand over data to US authorities when ordered to, even if it is stored abroad. The US Department of Justice (DOJ) holds that the law can sometimes reach foreign companies with sufficient US ties too. Whether US authorities could reach your data this way is legally unresolved.
We explain why such residual risks matter in Is our data still safe in the United States?
Certifications: what is in place and what is missing
Mistral's Trust Center lists certifications to ISO/IEC 27001:2022 and ISO/IEC 27701 plus a SOC 2 Type II report. It lacks a C5 attestation: an audit report against the C5 cloud criteria catalog of Germany's Federal Office for Information Security (BSI). That is exactly what matters in German healthcare (more below). Mistral itself also lacks France's HDS certification for health data hosting and SecNumCloud, the cloud qualification of France's cybersecurity agency ANSSI.
License: the most important open question
Mistral plans to release the weights at the end of October; Hugging Face gives October 31, 2026. Mistral has not yet said which license will apply. The predecessor, Large 3, uses Apache 2.0. Other current Mistral models such as Medium 3.5, by contrast, use a modified MIT license that excludes companies with more than $20 million in consolidated monthly revenue.
For most mid-sized companies, such a cap would not be a problem: it equals $240 million in annual revenue. Large corporations, major banks, and large insurers would exceed it. So check the license before any architecture decision. A model without secured usage rights is not a sovereign model.
Four deployment models and what they mean for your data
An overview first: once the weights are released, you can use Large 4 in four ways. Only the first is confirmed today. They differ in who sees your data and who can switch the model off.
| Deployment model | Available | Who sees the data? | Suitable for |
|---|---|---|---|
| Mistral API, global endpoint | yes, as a preview | Mistral and its subprocessors, no fixed processing location | public and non-sensitive data |
| Mistral API, EU endpoint | unconfirmed for Large 4 | Mistral in the EU and EFTA; administrative data such as account, API keys and billing (the control plane) possibly elsewhere | internal data after contract review |
| European hosting provider | after the weights are released | the hosting provider as your processor | personal data, depending on the attestation |
| Self-hosted (run by you, on your own or rented hardware) | after the weights are released | only you | data under professional secrecy, patient data, classified information |
Self-hosting means the model runs on hardware you control, in your own data center or on a rented server. For Large 4, that means data-center-grade hardware, and Mistral has not yet published official requirements.
My back-of-the-envelope calculation: at 8-bit precision, the weights take up around 1.05 TB of GPU memory (VRAM); quantized to 4 bits, around 525 GB. In both cases, add the KV cache (memory for requests in progress). On paper, that means eight H200 GPUs at 8 bits or eight H100 GPUs at 4 bits.
Our article on self-hosting LLMs covers what such a setup costs and at what volume it becomes cheaper than the API. For many tasks, a smaller model is enough anyway if each request includes relevant excerpts from your internal documents. Our article RAG instead of fine-tuning shows how that works.
One more legal note: if you build your own application on Large 4, via the API or self-hosted, you generally become the provider of that AI system under the EU AI Act. Since August 2, 2026, that has meant duties such as the transparency obligations in Article 50. Our article on the EU AI Act explains what this means in practice.
Healthcare: the C5 attestation matters, not the provider's origin
A European provider alone is not enough in healthcare. The framework is § 393 SGB V (Section 393 of the German Social Code, Book V): doctors, hospitals, other healthcare providers and statutory health insurers may process health data in cloud services only under strict conditions. In my assessment, a language model you use via the API is such a cloud service once patient data passes through it. Three conditions are decisive:
- Location: Processing only in Germany, the EU, the EEA, Switzerland or a third country with an EU adequacy decision. In addition, the processing entity needs an establishment in Germany.
- Attestation: You need a current C5 attestation, which as of July 2025 must generally be Type 2. Type 1 checks whether the controls are suitably designed at a given date; Type 2 also checks whether they worked over an audit period. As of January 2026, newly launched systems may start with Type 1 for 18 months.
- Customer obligations: You implement the customer-side criteria listed in the audit report yourself.
Mistral falls short on the second condition: it has no C5 attestation. The C5 Equivalence Ordinance (C5-Gleichwertigkeitsverordnung) does allow ISO 27001 as a substitute, but then requires a binding plan to close the gaps to C5. You also need to establish whether Mistral's German GmbH is the processing entity.
Medical confidentiality also applies: under § 203 StGB, the German Criminal Code's provision on professional secrecy, doctors may involve service providers only where necessary. Everyone involved must be bound to secrecy. According to the law's explanatory memorandum, that requires an unbroken chain of contracts down to the last subcontractor. With a supply chain including Microsoft, Google and CoreWeave, that takes considerable effort.
Documentation assistant or medical device?
A second check concerns the purpose. Under the EU guidance document MDCG 2019-11, an assistant that transcribes dictation or formats text is not a medical device. Software that supports diagnostic or therapeutic decisions is one: under Rule 11 of the EU Medical Device Regulation (MDR), at least Class IIa. The AI Act's high-risk obligations apply to it from August 2, 2028.
Our recommendation for healthcare: put nothing more than synthetic test data into the preview. For production use, wait for the weights and run the model in your own data center or with a hosting provider that holds a C5 attestation. Whether you need to train your own model at all is covered in our article on training your own AI model.
Public administration: open-weight models in your own data center
The guardrails for the German federal administration are clearly defined. The German federal government's guidelines for the use of AI in the federal administration, published in March 2025, allow only public data as a rule. When in doubt, sensitive data stays out of external infrastructure. Where possible, the guidelines favor models with "freely available parameters".
Classified information has a hard limit: it may only be processed on VS-IT, meaning IT specifically approved for that purpose. The AI platform KIPITZ from ITZBund, the federal government's central IT service provider, shows this works with language models too. It runs in ITZBund's own data center, relies mainly on open-source models and is approved for VS-NfD classified information ("Nur für den Dienstgebrauch", roughly "restricted, for official use only").
Large 4 will fit this pattern once the weights are released. The political groundwork is laid: in November 2025, Germany and France announced a sovereign AI for public administration with Mistral and SAP. A binding framework agreement was planned for mid-2026; I could not verify whether it has been signed.
Under the AI Act, the use case matters. A system that checks eligibility for public assistance benefits counts as a high-risk AI system under Annex III, with obligations from December 2, 2027. Germany's national AI Act implementation act rules out fines against public authorities, but the obligations themselves still apply.
Our recommendation for public authorities: test the preview only with public data, for example information for citizens or translations. Plan production use from the start in your own data center or a government cloud, and build model-agnostic. Then you can swap Large 4 for another open-weight model if the license or performance does not fit.
Banks and insurers: DORA requires an exit plan
In finance, the question is not whether you may use a language model, but how you document it. DORA, the EU Digital Operational Resilience Act, has applied since January 17, 2025. Every ICT (information and communication technology) services contract goes into the register of information, language model APIs included. If the service supports critical or important functions, you need tested exit plans for switching providers and unrestricted rights of access, inspection and audit.
BaFin, Germany's Federal Financial Supervisory Authority, gets more specific in its December 2025 guidance on ICT risks in the use of AI, which treats the model itself as an ICT asset. Financial institutions should detect unannounced model changes by third-party providers and, before signing, establish in which formats models and data can be exported.
This is exactly where the preview collides with BaFin's requirements: Mistral may update preview models without notice, which rules the preview out for critical functions. Once the weights are released and you self-host Large 4, things change: you control the version and any changes, and the exit plan shrinks to switching models in your own environment. The global bank HSBC already runs Mistral models on its own systems.
Two more items belong on your checklist. Under the AI Act, AI systems for creditworthiness assessments and for risk assessment and pricing in life and health insurance are high-risk AI systems, with obligations from December 2, 2027. And BAIT, BaFin's IT requirements for banks, will lapse entirely at the end of 2026: from then on, DORA and the new MaRisk (Minimum Requirements for Risk Management), issued in June 2026, are what count.
Our recommendation: critical functions never belong in the preview, only on self-hosted systems.
Law firms, manufacturing, critical infrastructure: three sectors, one rule
Three more sectors in brief, each with the point that tips the balance for Large 4. The basic rule is the same as for the industries above: weights and license first, then sensitive data.
Law firms and tax advisers: contracts and confidentiality
For lawyers, § 43e BRAO (German Federal Lawyers' Act) governs the use of service providers: a contract in text form (email suffices) and a confidentiality undertaking with a briefing on the criminal consequences of a breach. Tax advisers and auditors face comparable rules in § 62a StBerG and § 50a WPO (German Tax Advisers Act, Public Accountants Act). According to the explanatory memorandum, notaries may not use services provided abroad.
The German Federal Bar (BRAK) advises fully anonymizing documents before entering them: in its view, removing names and addresses is usually not enough. With a self-hosted Large 4, this problem disappears because the data never leaves your network. Our article on self-hosting LLMs breaks down what running such a model costs.
Manufacturing: trade secrets and export control
In manufacturing, two points matter. First, trade secrets: under the German Trade Secrets Act (GeschGehG), they are only protected if you take reasonable secrecy measures. Engineering and design data are a poor fit for a preview in which Mistral may train on your inputs.
Second, export control: according to a guidance leaflet from BAFA, Germany's Federal Office for Economic Affairs and Export Control, uploading listed (export-controlled) technology to a server outside the EU is an export requiring a license, and you are the exporter.
In late September, Mistral announced a new hub in Munich and named BMW and Siemens Energy as partners. For engineering and production, the basic rule stays the same.
Critical infrastructure: supply chain and reporting channels
Germany's NIS2 implementation act, which transposes the EU NIS2 cybersecurity directive, has been in force since December 6, 2025. It requires in-scope entities to secure their supply chain and report significant incidents within 24 hours. In my assessment, a language model provider belongs in your supply chain risk analysis. To meet the 24-hour deadline, you also need a reporting chain from the provider to you.
As of July 2026, Germany's KRITIS umbrella act for critical infrastructure (KRITIS-Dachgesetz) goes even further: an AI that monitors or controls physical processes in a critical facility counts as part of the facility itself. The French energy group EDF takes an instructive approach: it uses Mistral for engineering work on nuclear power plants and explicitly excludes the control systems. In short: the AI may help plan, but not help control.
What the German tech press says
The first assessments are mixed. The quotes are my translations from German. Below I summarize the key voices and link to the originals:
- heise online: Christopher Kunz credits Large 4 with strengths in IT security, but considers its coding rather mediocre. He criticizes Mistral for leaving the leading US models out of its comparisons: "the results of the leading models from OpenAI and Anthropic (not shown in the charts) are significantly higher".
- Golem: Michael Linden reaches a similar verdict: convincing in IT security tests, question marks over coding. Only independent testing, he writes, will show how reliable Mistral's own figures are.
- xpert.digital: Konrad Wolfenstein warns against a misunderstanding: "In this context, sovereignty must not be confused with complete self-sufficiency." Mistral, too, depends on NVIDIA chips and global supply chains. His advice: Large 4 should "neither be favored out of European patriotism nor be hastily ruled out because it lags behind in individual leaderboards".
- Caschys Blog: Felix Frank sees Large 4 as "the most potent AI model from Europe to date, one that also takes on various frontier models".
My verdict: both camps are right. The critics measure Large 4 against the global frontier and find a gap that independent tests now confirm. The supporters look at the deployment model and find the strongest European model, one you will soon be able to run yourself. For regulated sectors, the second argument carries more weight, but only from the day Mistral releases the weights.
In his article, Wolfenstein draws a conclusion I share: "For high or constant usage volumes, it is worth evaluating running it in-house or a European managed offering after the weights are released." My addition: check the license first.
Our recommendation: which data may go into the model, and when
To close, our overview. It is organized by type of data, not by industry: what you process determines the deployment model. Pick the most sensitive type of data in your use case. Its row applies to the entire system.
| Type of data | Today: preview API | After the weights are released |
|---|---|---|
| Public data, marketing drafts | yes, for testing | any deployment model |
| Internal code without trade secrets | only with Mistral's written commitment not to train on it | EU endpoint or self-hosted |
| Personal customer data | no | European hosting provider with a data processing agreement (DPA) or self-hosted |
| Patient data | no | self-hosted or hosting provider with a C5 attestation |
| Confidential client data and professional secrets | no | self-hosted or contract under § 43e BRAO |
| Critical functions in the financial sector | no | self-hosted with a tested DORA exit plan |
| Classified information (VS-NfD) | no | only self-hosted with VS-IT approval |
Three principles apply across all rows:
- Build model-agnostic: Wrap the model behind your own interface. Then switching models does not trigger a rebuild.
- Start small: A smaller model with your company knowledge solves many tasks more cheaply than a trillion-parameter model.
- Test now, decide later: Use the preview for quality comparisons with non-sensitive data. Decide how to run the model only once Mistral has published the license and released the weights.
Sovereignty is not in the vendor's logo. You create it yourself: with the weights, the place the model runs, and an exit plan. Our roadmap for adopting AI in your company shows how to proceed step by step.
Next steps
Want to know whether Large 4 fits your use cases and which deployment model suits your data? Then let's work through three things together: your data, your industry's obligations, and the cost of self-hosting.
Once the weights are released, we will test Large 4 on your real tasks and compare it with smaller models, so you decide based on measurements rather than leaderboards. Book a no-obligation initial consultation here. How we approach AI and automation projects is described on our page on process automation.
