Mistral AI
Mistral Large 2
v2 · frontier · Released July 24, 2024
Updated August 8, 2026
Mistral's release of Shieldstral, an open-weight Apache 2.0 safety classification model, reinforces the vendor's transparency posture and expands enterprise safety tooling options. No adverse flags have emerged this review cycle.
Enterprise guidance
Mistral Large 2 is developed by a Paris-based company and is a strong choice for organizations with EU data residency requirements or GDPR compliance concerns. La Plateforme (Mistral's API) processes data in France and does not use API data to train models. Mistral Large 2 is also available via Azure AI Foundry and AWS Bedrock with data residency in your chosen region.
Data handling
Default data retention
La Plateforme: transient processing only; prompts not retained for training
Zero-retention available
YesVia: La Plateforme (default behavior); Azure AI Foundry; AWS Bedrock
API data used for training
NoMistral AI does not use La Plateforme API data to train models.
GDPR Data Processing Agreement
AvailableHIPAA Business Associate Agreement
Not availableNot offered directly by Mistral AI. Available through AWS Bedrock with a Bedrock HIPAA BAA.
Data residency options
France (La Plateforme); EU, US, and other regions via Azure AI Foundry and AWS Bedrock
Vendor compliance certifications
Key use restrictions
- —Mistral AI Terms: no illegal content, CSAM, or material facilitating serious harm
- —Commercial API use permitted under standard La Plateforme subscription terms
- —Open-weight research version available under Mistral Research License (non-commercial only)
- —Commercial use of open weights requires La Plateforme subscription or enterprise agreement
Safety documentation
Mistral Large 2 technical blog and benchmark results published July 2024. Mistral AI safety guidelines and guardrails documentation available on the Mistral platform. Limited third-party independent red-team evaluation has been published to date.
Safety documentation →Related governance resources
Governance controls
AI Vendor Due Diligence
Assess AI vendors against security, governance, and compliance criteria before procurement and at defined intervals during the vendor relationship.
AI Contractual Requirements
Set minimum AI vendor contract terms for data handling, transparency, audit rights, and incident notification.
Cross-Border Data Transfer Controls for AI
Govern international personal-data transfers through AI systems. Include transfers to API providers, training pipelines, and cloud infrastructure in other jurisdictions.
AI Procurement Risk Assessment
Assess technical, legal, privacy, and operational risks before approving an AI system or service purchase. Document the findings.
Vendor Safety Commitment Verification
Check whether vendors honor published safety commitments, voluntary pledges, and contractual duties throughout the relationship.
Playbook guides
How do we ensure third-party AI vendors meet our standards?
Review AI vendors for model transparency, data handling, bias testing, and contractual liability for their outputs.
How do we maintain data privacy compliance when using AI?
Review training data sources, data minimization, cross-border transfers, and applicable explanation duties under GDPR and CCPA.
How does the EU AI Act affect our global operations?
Assess how EU requirements affect organizations outside Europe. Decide whether to use its risk-based approach as a global internal standard.
Status history
August 8, 2026· green to green
The Shieldstral release (hWlo3bBQRk9E2j7vADwG) is a net positive safety development from Mistral AI and does not introduce any new risk. Current GREEN status is confirmed and no change is warranted; however, the development is noted as a positive signal supporting continued Cleared designation.
