Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The document enumerates the full set of API endpoints supported by Mistral Medium 3.5, including endpoints for chat completions, function calling, agentic workflows, OCR, embeddings, moderations, audio transcription, text-to-speech, and batch processing.
This analysis describes what Mistral AI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The enumerated endpoint set establishes the scope of data modalities and processing types available through the API, which is operationally significant for developers designing integrations and for compliance teams assessing what categories of data (text, images, audio, documents) may be submitted to and processed by the model.
Interpretive note: The model card discloses endpoint availability but does not specify data retention, processing, or subprocessor terms applicable to each endpoint; the compliance implications depend on Mistral's separate platform terms and DPA.
Under this disclosure, API users may submit text, document images, audio recordings, and structured data for processing across the listed endpoints; the breadth of supported modalities determines the range of input data types that may be transmitted to Mistral's infrastructure.
Cross-platform context
See how other platforms handle Supported API Endpoints and Feature Set and similar clauses.
Compare across platforms →Monitoring
Mistral AI has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Chat Completions /v1/chat/completions Function Calling /v1/chat/completions /v1/conversations Agents & Conversations /v1/agents /v1/conversations Built-In Tools /v1/agents /v1/conversations Structured Outputs /v1/chat/completions /v1/conversations Predicted Outputs /v1/chat/completions /v1/conversations Prefix /v1/chat/completions /v1/conversations OCR /v1/ocr Annotations - Structured /v1/ocr BBox Extraction /v1/ocr Document QnA /v1/chat/completions /v1/conversations FIM /v1/fim/completions Embeddings /v1/embeddings Moderations /v1/moderations Chat Moderations /v1/chat/moderations Transcriptions /v1/audio/transcriptions Text to Speech /v1/audio/speech Timestamps /v1/audio/transcriptions Batching /v1/batchExcerpt from Mistral AI's Mistral Medium 3.5 Model Card
(1) REGULATORY LANDSCAPE: The audio transcription (/v1/audio/transcriptions) and OCR endpoints engage GDPR and CCPA obligations where inputs contain personal data in audio or document form; voice data and biometric-adjacent identifiers may trigger heightened obligations under Illinois BIPA or similar state biometric privacy statutes depending on the nature of the audio processed. The moderation endpoints (/v1/moderations, /v1/chat/moderations) may engage content moderation obligations under the EU Digital Services Act for downstream platform operators. (2) GOVERNANCE EXPOSURE: Medium. The combination of audio, image, document, and text processing endpoints means that a wide range of personal data categories could be submitted via the API; governance exposure depends on what data categories downstream deployers submit and what data processing agreements are in place with Mistral AI. (3) JURISDICTION FLAGS: Illinois BIPA creates heightened exposure for any deployment that submits voice recordings of Illinois residents to the audio transcription endpoint. EU/EEA deployments processing personal data via any endpoint require a GDPR-compliant data processing agreement. California CCPA obligations would apply to California residents' personal data submitted through any endpoint. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should confirm that a data processing agreement (DPA) with Mistral AI covers all endpoint categories in use, particularly audio, OCR, and agentic endpoints that may process sensitive or personal data. The model card does not itself constitute a DPA. (5) COMPLIANCE CONSIDERATIONS: Data mapping exercises should enumerate which API endpoints are used in production and what categories of personal data are submitted through each; this informs GDPR Article 30 records of processing activities and CCPA service provider agreement requirements.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
The enumerated endpoint set establishes the scope of data modalities and processing types available through the API, which is operationally significant for developers designing integrations and for compliance teams assessing what categories of data (text, images, audio, documents) may be submitted to and processed by the model.
Under this disclosure, API users may submit text, document images, audio recordings, and structured data for processing across the listed endpoints; the breadth of supported modalities determines the range of input data types that may be transmitted to Mistral's infrastructure.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Mistral AI.