EU Sovereignty with Mistral: What It Means and What You Should Consider

Mistral positions itself as a European alternative to the major US-based AI providers. The company is building its own computing capacity in Europe and now offers regional endpoints for AI inference. By 2030, its European capacity is expected to reach up to one gigawatt.

This is relevant for companies with stringent data protection and digital sovereignty requirements. However, the provider’s country of origin does not determine where data is processed, who can access it, or which international dependencies remain.

What the European endpoint covers

According to Mistral’s documentation, its European endpoint processes inference inputs and outputs across several data centres in EU and EFTA countries. In addition to the EU Member States, this region includes Iceland, Liechtenstein, Norway, and Switzerland. Unless a region is explicitly selected, the global endpoint is used, for which Mistral does not commit to a specific processing location.

Regionalisation does not cover every component of the service. Information relating to account administration, billing, access management and usage analytics, as well as certain operational metadata, may be processed outside the selected region. The contractual terms also allow limited access by subprocessors outside the region.

Companies should therefore determine which categories of data are processed through each service. A commitment to regional inference should not be mistaken for an assurance that all operational and contractual data will be processed exclusively in Europe.

Processing, storage, and Zero Data Retention

Data location, storage and use for model training are separate issues. Mistral offers a Zero Data Retention option for certain paid, stateless API endpoints. It must be requested and activated by Mistral.

According to the current documentation, this option is not available for Agents, Conversations, Files, Vibe Work, or Chat. A training opt-out does not replace contractual provisions governing data storage. Companies should therefore clarify the following for every service they use: 

  • Which inputs and outputs are stored?
  • How long are logs and metadata retained?
  • Is content used for training or product improvement?
  • Which endpoints are actually covered by Zero Data Retention?
  • What deletion options are available after the contract ends?

How European is the supply chain?

In August 2026, Mistral announced plans to expand its European computing capacity to as much as one gigawatt by 2030. Multi-year commitments from companies are intended to support this expansion through so-called European Compute Units.

However, the infrastructure relies in part on NVIDIA hardware. Further international dependencies may exist in relation to software, network technology, support services and subprocessors. A data centre located in Europe establishes the processing location, but it does not create a fully European supply chain.

The European Commission’s Cloud Sovereignty Framework therefore considers 48 criteria, including jurisdiction, data processing, operational control, supply chains, security and portability.

What should be reviewed before signing a contract?

Sovereignty requirements should first be defined for the specific project. The product description, order form, data processing agreement, subprocessor list and technical documentation should then be reviewed together.

Key points include: 

  • contractually binding processing regions,
  • storage locations for content and metadata,
  • access by support staff and subprocessors,
  • possible third-country transfers,
  • use of data for training and product improvement,
  • retention periods and available evidence of deletion,
  • export formats and rights when switching providers.

Companies must also consider the obligations they have assumed towards their own customers. For example, a company that has committed to processing data within the EU or EEA, specific deletion periods, or the exclusion of training use must contractually extend those requirements to its upstream AI supply chain.

How ePrivacy can support companies

ePrivacy supports companies with the data protection assessment and selection of AI and cloud services. This involves comparing the actual processing operations with the relevant contractual documentation.

The assessment identifies which services are provided within the agreed European framework, where exceptions apply, and which provisions should be renegotiated. It can reveal conflicts with existing customer contracts, evaluate third-country risks, and identify dependencies that may affect a later change of provider.

A European and sovereignty-focused architecture may be possible with Mistral. Its actual scope, however, depends on the selected service, its technical configuration and the binding contractual terms.