AI Governance Institute
← News

Mistral Default Opt-In for Training Data Creates GDPR Exposure on Non-Enterprise Tiers

What happened

Mistral AI published updated guidance in its help documentation, Can I opt out of my input or output data being used for training?, confirming that user input and output data, including conversations and uploaded documents, are used for model training by default on its Vibe consumer tier and standard API tier. Enterprise customers on the Vibe Enterprise plan are excluded from this default and are opted out unless an administrator explicitly enables training. Critically, the opt-out mechanism is not unified: Vibe and API access require separate configuration, meaning an organization that opts out on one surface remains exposed on the other unless both are addressed. The policy distinguishes between these surfaces in a way that is easy to miss in a routine vendor review. This change has direct implications for any organization whose employees or developers use Mistral on non-Enterprise tiers, particularly those subject to EU data protection law, where using personal data for model training requires a documented lawful basis under the GDPR.

Why it matters

  • ·Under the GDPR, using personal data contributed through employee or customer interactions to train a commercial model requires a valid lawful basis. A vendor defaulting to opt-in for training without explicit enterprise consent creates a compliance gap that organizations may not detect until an audit or data subject access request surfaces it.
  • ·The split between Vibe and API opt-out controls means standard vendor onboarding reviews that check a single configuration may miss a second exposure surface, requiring enterprise procurement and data governance teams to validate both paths independently under controls like vendor data boundary reviews.
  • ·Organizations that approved Mistral access under earlier terms that did not include default training data use have an immediate obligation to reassess whether existing approvals and data processing agreements still reflect actual processing, a gap that Twitch's default opt-in for AI training illustrated for consumer platforms and that now applies equally to enterprise API contexts.

Governance controls affected

What to do now

  • Audit which Mistral tiers are in use across the organization, distinguishing between Vibe consumer accounts, standard API access, and Vibe Enterprise accounts, and confirm the default training data setting for each.
  • For any non-Enterprise Mistral deployments, verify whether opt-out has been configured on both the Vibe and API surfaces separately, and document the configuration state as evidence for GDPR compliance records.
  • Review existing data processing agreements with Mistral to confirm they reflect current training data defaults and update contractual terms if the new policy represents a material change to previously agreed data processing activities.
  • Notify any business units or developers using Mistral on standard API tiers that uploaded documents and conversation content are included in training data by default, and issue updated acceptable use guidance specifying what data categories may not be submitted on non-Enterprise tiers.
  • Add Mistral training data policy changes to the vendor governance change monitoring watchlist so that future updates to opt-out controls trigger a mandatory re-assessment rather than being discovered reactively.

What to watch next

Compliance teams should monitor whether EU data protection authorities treat default opt-in training data policies by AI vendors as a violation of GDPR consent and legitimate interest requirements, as enforcement action in this area would impose retroactive liability on enterprises that failed to opt out promptly. The broader pattern of vendors shifting training data defaults mid-lifecycle, visible in earlier episodes involving consumer platforms, is likely to continue as model developers seek to expand proprietary training corpora. Monitoring vendor policy change notifications across all AI tool subscriptions should be integrated into a standing vendor governance cadence rather than deferred to annual procurement review.

Stay ahead of stories like this

Get every EU AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Enforcement2026-09-19

Internal Emails Confirm OpenAI and Microsoft Knew Scraping Was Legally Indefensible

Unsealed documents in the New York Times lawsuit against OpenAI and Microsoft reveal that company executives internally described their AI training practices as the 'largest theft of labor in human history.' Internal Microsoft communications warned of a web 'doom loop' that would erode the economic foundations of content publishers. The disclosures are directly relevant to enterprise copyright compliance, training data governance, and AI vendor due diligence programs.

Corporate Policy2026-09-18

18 Microsoft AI Vulnerabilities Expose Privilege Escalation Risk in Copilot and Azure

Microsoft released patches for 18 vulnerabilities across its Azure AI and Copilot product lines, including elevation of privilege flaws in Azure AI Foundry, Microsoft Fabric, and Microsoft 365 Copilot. Several information disclosure vulnerabilities were also addressed in Copilot and Azure Machine Learning. All fixes were server-side and required no customer action, but no exploitation has been confirmed.

Enforcement2026-09-17

Internal Emails Confirm Microsoft and OpenAI Knew Scraping Was Legally Indefensible

Unsealed court filings in the New York Times copyright lawsuit against OpenAI and Microsoft reveal that executives at both companies privately acknowledged that scraping news content for AI training violated fair use principles. A Microsoft director described the practice as potentially the largest theft of labor in human history. The disclosures expose a governance gap between internal risk assessments and continued commercial conduct.