Mistral AI updated its Additional Product Terms on May 29, 2026, shifting from 'Customer' to 'you' language throughout the Third-Party Service integration section. More substantively, the terms now authorize Mistral AI to execute a broader set of actions on data sent to third-party services, expanding from simple access and retrieval to include execute, transmit, modify, delete, invoke, and otherwise act upon necessary data. The updated language also places explicit responsibility on users for actions they request through the product, including compliance with third-party terms.
Consumers and businesses: If you request Mistral AI to perform an action through a third-party integration, you are responsible for that action's consequences and for complying with the third-party service's rules.
Data controllers and organizations: Mistral AI can now perform a broader range of operations on data sent to third-party services beyond simply reading and passing it through.
The updated terms authorize Mistral AI to perform a broader range of actions on data sent to third-party services, moving beyond simple access and retrieval to include execute, transmit, modify, delete, invoke, and otherwise act upon necessary data. Users now explicitly bear responsibility for the actions they request through Mistral AI Products and for compliance with third-party terms. If you use third-party service integrations, you should review what specific actions you are requesting and confirm you understand what data handling Mistral AI is authorized to perform on your behalf.
→ Review which third-party services you have connected to Mistral AI Products and understand what data flows through those integrations.
→ If you are an organization processing customer data, evaluate whether the expanded data handling authorization aligns with commitments you have made in privacy notices or customer agreements.
Across all monitored documents, Mistral AI has made 2 significant changes.
2 of Mistral AI's significant changes have been classified as negative for consumers.
Expanded from 'access, send, retrieve, process, store' to include 'execute, transmit, modify, delete, invoke, or otherwise act upon' data.
Added explicit requirement that users bear responsibility for actions they request through Input and compliance with third-party terms.
This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology
The revised language materially expands the authorization Mistral AI claims over data movement and manipulation when third-party services are connected. The shift from 'Customer grants permission to access...and send data' to authorization for 'execute, transmit, …
Regulatory exposure, obligation change, escalation trigger, board-ready language, and recommended action for legal and compliance teams.
Unlock the full institutional analysis — InsightConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-002442.
Mistral AI's Privacy Policy was updated in an update detected on September 5, 2026, with an effective date of September …
An update was detected in Mistral AI's Data Processing Addendum on September 4, 2026. The change involved removal of the …
On September 4, 2026, Mistral AI removed the 'to Markdown' hyperlink text from the 'Copy to Markdown' navigation option in …
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Get alerted when this policy changes again, including what changed and why it matters.