Mistral AI updated its privacy policy effective July 27, 2026, making several product name and operational clarifications. The company replaced references to 'Le Chat' with 'Vibe' across multiple sections describing data handling practices. The policy expanded its definition of 'Input' data to explicitly include data accessed through third-party integrations and services connected by users, and changed language describing product improvement datasets from 'aggregated and anonymous statistics' to 'aggregated or anonymous datasets or statistics.' The company removed a sentence stating that Input and Output data are not used to train AI models when using Le Chat Enterprise or paid APIs, and that third-party service data connected to Mistral products are not used for model training.
The updated policy now explicitly includes data accessed through third-party services and integrations users connect to Mistral AI Products as 'Input' data subject to collection and use. The policy removed its prior statement that Input and Output data are not used to train AI models when using Le Chat Enterprise or paid versions of Mistral APIs. This creates operational ambiguity: users of paid services and Enterprise customers no longer have a documented commitment that their data will be excluded from model training, though the privacy policy does not affirmatively state that model training now occurs. The policy also changed language describing product improvement from 'aggregated and anonymous statistics' to 'aggregated or anonymous datasets or statistics,' broadening the stated scope of what can be collected for improvement purposes.
The removal of explicit training exclusions for paid services may affect vendor contracts and Data Processing Addenda that organizations relied on to satisfy their own privacy commitments. The expanded definition of Input data to include third-party integration data means Mistral now processes a broader scope of user information for its stated business purposes. Together, these changes may require organizations to renegotiate vendor agreements and revise customer-facing privacy disclosures to reflect the updated scope of data collection and processing.
→ Review existing vendor agreements or Data Processing Addenda with Mistral to determine whether they relied on the removed training exclusion language.
→ Request clarification from Mistral regarding whether the removal reflects a change in actual data handling practice or is a policy clarification only.
→ If using third-party integrations with Mistral products, audit which third-party services are connected and ensure your privacy notices to downstream customers disclose this expanded data collection scope.
→ Organizations using paid Mistral APIs or Enterprise accounts will operate under the updated policy without explicit contractual clarity on whether their data is used for AI model training.
→ Third-party service data connected to Mistral products will be treated as Input data subject to Mistral's stated use purposes, including aggregation and anonymization for product improvement.
→ Vendor agreements that relied on the removed training exclusion may no longer reflect the current privacy policy, creating potential disputes regarding data handling commitments.
Across all monitored documents, Mistral AI has made 3 significant changes.
3 of Mistral AI's significant changes have been classified as negative for consumers.
Removed explicit statement that paid API and Enterprise user Input/Output data would not be used for AI model training.
Expanded to include data accessed through third-party integrations and services users have connected.
This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology
The policy no longer explicitly commits that your data used with paid services or Enterprise accounts will be excluded from AI model training.
The policy now treats data from any third-party service or integration you connect to Mistral as data Mistral collects and can use for its stated purposes.
Mistral AI removed contractual language explicitly excluding paid API and Enterprise user data from AI model training. This removal is significant for organizations purchasing Mistral services: the prior policy stated confidentiality and training exclusion commitments that supported vendor contracts and data processing agreements; their removal may require review of existing vendor relationships, data processing addenda, and privacy compliance obligations. The expanded definition of 'Input' to include third-party integration data may affect how organizations assess data flows through Mistral services. Compliance teams should evaluate whether existing Data Processing Addenda (DPAs) or vendor agreements relied on the removed training exclusion language, and whether amendment or renegotiation is warranted. EU customers and those subject to GDPR or other privacy frameworks should review whether the removal of training exclusions affects lawful basis for processing or contractual vendor commitments.
ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-004012.
Mistral AI updated its Data Processing Addendum effective July 27, 2026, making four targeted revisions. The most significant change clarified …
Mistral AI updated its Usage Policy on June 17, 2026, making three operational changes. The policy now references 'Vibe' instead …
Mistral AI updated its Additional Product Terms on May 29, 2026, shifting from 'Customer' to 'you' language throughout the Third-Party …
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Get alerted when this policy changes again, including what changed and why it matters.