We value your privacy

We use necessary cookies to run the site and, with your consent, analytics and marketing cookies to improve it. You can change your choice anytime. Privacy Policy

  • Security
  • Pricing
Book a scoping call
All AI tools
Mistral Le Chat

Mistral Le Chat

Mistral AI

Low riskLLM / ChatHow we rate

Short answer

Short answer: Le Chat is a lower-risk, EU-jurisdiction option — French company, GDPR/CNIL oversight, a DPA and SOC 2 / ISO 27001. Business plans don't train by default; on free Le Chat, turn training off. Good where EU sovereignty is a requirement.

At a glance

Vendor / legal entity
Mistral AI
Headquarters
🇫🇷 Paris, FR
Category
LLM / Chat
Ownership / jurisdiction
French company incorporated in Paris; GDPR/CNIL oversight; DPA governed by French law and courts.
Trains on your data?
On by default — opt-out available
Data hosting & residency
Mistral prioritises providers within the EU that adhere to the GDPR; an explicit EU-residency guarantee specifically for Le Chat is not stated.
Sub-processors
Sub-processors are published in the Mistral Trust Center (trust.mistral.ai/subprocessors).
Enterprise tier
Teams, Enterprise and Scale plans are opted out of training by default, with a DPA for commercial customers. Free Le Chat trains unless you disable the training toggle.
Certifications
SOC 2 Type II · ISO 27001 · ISO 27701

Why this rating

Low risk

Mistral is a French company under GDPR/CNIL oversight, with a DPA governed by French law, sub-processors published in its Trust Center, and SOC 2 Type II + ISO 27001/27701 certifications. Teams and Enterprise are opted out of training by default; free Le Chat trains unless you toggle it off. EU providers are prioritised, though an explicit EU-residency guarantee for Le Chat is not stated. Low: an EU-jurisdiction, GDPR-native option with a governed enterprise path.

How we rate

What it is

Le Chat is Mistral AI's conversational assistant. Its distinguishing feature for European teams is jurisdiction: Mistral is a French company under GDPR and CNIL oversight, with a DPA under French law, published sub-processors and SOC 2 / ISO 27001 certifications. Business plans (Teams, Enterprise, Scale) are opted out of training by default; the free Le Chat trains unless you disable it. It's a natural default where EU data sovereignty matters.

Legal & compliance examples

How the same tool can be a safe helper or a high-risk deployment — the difference is what it decides about a person. Examples authored with Qadar AI's governance findings.

High riskEU AI Act — Annex III(4) high-risk · Art. 5(1)(f) prohibited

Don't: Screen candidate CVs and auto-reject applicants, or infer a candidate's emotions in a video interview.

Fine: Draft a job description, summarise public market research, or brainstorm interview topics — with no automated decision about a person.

These examples are general information, not legal advice, and are pending a legal review. Your obligations depend on your exact use, tools, and set-up.

Check your EU AI Act risk class →

Frequently asked questions

Is Mistral Le Chat GDPR-friendly?

Mistral is a French company under GDPR and CNIL oversight, offers a DPA under French law and holds SOC 2 / ISO 27001 — a strong EU-jurisdiction basis. As always, compliance depends on your deployment and data.

Does Le Chat train on your data?

Free Le Chat uses your interactions for training unless you disable the toggle. Teams, Enterprise and Scale plans are opted out of training by default.

How do I govern Le Chat at work?

Qadar AI Shield discovers who uses Le Chat, redacts personal data before it reaches the tool, and lets you allow-list it per group.

Sources

Every fact and the risk rating on this page trace to a primary source — the vendor's own trust center, privacy policy, DPA, or a regulator. Verify current terms before relying on them.

  • •Consumer training toggle; enterprise opted out
  • •French company, GDPR; EU providers prioritised
  • •SOC 2 Type II / ISO 27001 / ISO 27701
  • •Sub-processors (Trust Center)

Govern this tool

Qadar AI Shield turns these risk facts into enforcement — discover who uses the tool, redact personal data before it reaches it, and allow-list or block it per team.

Book a demoSee how Shield Web governs AI

Risk levels are Qadar AI's curated assessment from cited primary sources — a curated assessment, not a certification, and not legal advice. Verify a tool's current terms before relying on them.

Subscribe to our newsletter

Product and governance updates — see our privacy policy.

AI security and control for every model your team uses.

Built in Dubai. Designed for teams operating across regions, models, and regulatory environments.

  • Product

    • Shield Web
    • Shield Control
    • Shield Desktop
    • Shield Mobile
    • Pricing
    • Download
  • Solutions

    • For CISOs
    • For Operations
    • For AI Teams
  • Use Cases

    • AI Governance
    • AI Agent Security
    • LLM Access Control
    • Secure AI Deployment
    • Enterprise Operations
    • Financial Services
    • HR & Recruiting
  • Resources

    • Help Center
    • Blog
    • Guides
    • Glossary
    • Changelog
    • Compare
    • FAQ
  • Company

    • About
    • Careers
    • Security & Trust
    • Contact
  • Tools

    • Disclose
    • AI Risk Calculator
    • EU AI Act Checker

© 2026 Qadar AI. All rights reserved.

  • ·Legal
  • ·Privacy
  • ·Terms
  • ·Partner Terms
  • ·GDPR / DPA
  • ·