Mistral Large 4 is here: a 1 trillion parameter model trained in Europe, with open weights due this month
Mistral AI released a public preview of Mistral Large 4, a 1 trillion parameter multimodal model with 49 billion active parameters, trained on 3,800 Nvidia GPUs in Europe. It leads on several security tests, trails Claude Opus 5 on code quality, and the open weights are promised for the end of October.

Mistral AI has released its biggest model so far. On Tuesday, 6 October 2026, the Paris based lab introduced Mistral Large 4, which the team unofficially calls ML4 and, with a wink, "Le Chonk". It is a natively multimodal model with 1 trillion parameters, of which 49 billion are active for any given token. You can try it today as a public preview through Mistral's own API, and the company says the open weights will follow by the end of October, after a round of safety testing with security partners and government agencies.
That combination is what makes this launch stand out. Very large open models have mostly come from China in the last two years, while the strongest models from the United States stay closed behind an API. Mistral wants ML4 to sit in the space between those two camps: a frontier sized model that is trained and hosted in Europe, that customers will be able to download and run themselves, and that is tuned for the industries where Mistral sells most, such as cybersecurity, finance, law and engineering.

What Mistral actually released
The launch post on mistral.ai is unusually detailed for a preview. Here are the points that are on the record.
- Size and design. ML4 is a mixture of experts model with 1 trillion parameters in total and 49 billion active parameters per token. It takes text and images as input and combines instruction following, reasoning and agent work in a single model instead of shipping separate "thinking" and "chat" versions.
- Availability. A public preview API is live now. Mistral says it will release the weights by the end of this month, together with more details on the architecture, more benchmarks and a description of its post training.
- Training hardware. The model was trained from scratch on 3,800 Nvidia Grace Blackwell GPUs in Mistral's own data centers in Europe. TechCrunch, quoting Mistral's VP of Science Pierre Stock, rounds this to about 4,000 GPUs, which Stock says is two to three times less than Mistral's Chinese competitors use.
- Languages. A large share of the training data was multilingual. Mistral says it covers more than 160 languages, including every official language of the European Union.
- Hosting. The preview runs on the same European infrastructure. Mistral says it will offer the model in several regions worldwide, including a European deployment it runs end to end under European law and independently of other digital service providers.
- Status. Mistral stresses that this is an early version. The reinforcement learning run behind the preview is still going, and the company expects "large and rapid improvements" in the coming weeks.
Why Mistral leads with cybersecurity
The most eye catching part of the announcement is about security work. Mistral says ML4 ranks among the top five models in the world on the Artificial Analysis Cyber Index, an independent evaluation of how well models find and fix flaws in real software, and that it leads every open model built outside China there by a wide margin.
On one test inside that index, the model has to reproduce a real vulnerability in open source software and then write the patch. ML4 scores 82 percent, which Mistral calls the highest score of any model. It also solves 93 percent of the 40 challenges in Cybench, a benchmark built from capture the flag security competitions.

The interesting detail is why some famous models do badly on that same patch test. According to Mistral, Claude Opus 5.5 and GPT-6 Astra score close to zero, not because they cannot do the work, but because they refuse it. Proving that a flaw is real usually means writing something that looks like an exploit, and safety filters in closed models often block exactly that. Mistral's argument is that defenders need a tool that does not stop halfway through an incident, especially while attackers keep finding ways to jailbreak the same closed models.
This is also why the weights are not out yet. Until the end of October, Mistral says it is red teaming ML4 with cybersecurity companies, vetted partners and state authorities, who get access to a version with reduced moderation and expanded cyber capabilities. Pierre Stock told TechCrunch the goal is to make sure the open weights "can be used to defend, but not to" carry out malicious attacks.
Mistral also claims the model is careful where it should be. On Lakera's public prompt injection benchmark, ML4 resisted 93.3 percent of attacks, and Mistral says its refusal rate on malicious cyber prompts is higher than that of any other open model it tested. Both claims are Mistral's own measurements, so they deserve independent checks once the weights are public.
Coding and agents: strong, but not the very top
For software work, Mistral reports 61.7 percent on DeepSWE v1.1, 59.4 percent on SWE-Atlas-QnA and 28.3 percent on Terminal-Bench 4. Its combined Coding Agent Index score of 49.8 percent puts it ahead of DeepSeek V4 Pro 0813 and Qwen3.8 Max, according to the company.

For general agents that gather information, use tools and produce finished work, Mistral points to AutomationBench, a set of 657 business workflows across apps such as Gmail, Google Sheets, Slack and Salesforce. ML4 scores 59.9 percent there, ahead of Kimi K3, MiMo V2.6 Pro and DeepSeek V4 Pro. On AA-Briefcase, which tests long knowledge work tasks such as spreadsheets, slides and PDFs, it reaches 1,393 Elo.
Mistral was refreshingly honest in one place. It ran a blind human evaluation with Surge AI, in which professional annotators rated code from five models on a scale of 1 to 5 without knowing which model wrote what. ML4 came second with 3.74, ahead of GLM-5.3 at 3.60, Kimi K3 at 3.59 and GLM-5.2 at 3.40, but clearly behind Claude Opus 5 at 4.22.

So the honest summary is this: ML4 looks like one of the best open models for coding and agents, competitive with the top Chinese releases, but the strongest closed coding models are still ahead. For many companies that will be fine, because the point of an open model is control, cost and privacy, not winning every leaderboard.
Vision, science and office work
Mistral calls ML4 a step change in image understanding for its models. The launch post shows demos of the model inspecting gigapixel satellite images, checking mechanical parts in engineering drawings and pulling evidence out of PDFs. On the Dense 200 visual grounding test, Mistral reports 42 percent for ML4 against 41 percent for GPT-6 Astra, a narrow lead but a rare case of an open model beating a frontier closed one.
On science, Mistral says ML4 is the best open model on SciCode-Verified, a test of turning scientific workflows into working code, and shows it writing a full Hartree Fock chemistry simulation in one go. Internal comparisons by expert annotators preferred ML4 over GLM-5.3 for CAD and STEM tasks, while the two were on par or close in finance and coding.
For office work, Mistral says third party evaluators found ML4 ahead of GPT-6 Astra on representative legal and financial tasks, and that it beats all open source models on Harvey's Legal Agent benchmark. Those are the kinds of claims enterprise buyers will want to test on their own documents before they believe them.
Built in Europe, on purpose
The launch post carries the line "Forged in Europe. Built for AI sovereignty." That is more than marketing. European governments and companies have been asking for AI they can run under European law, without depending on an American cloud or a Chinese model whose training data and safety rules they cannot inspect. ML4 is Mistral's answer: trained on its own hardware in Europe, hosted in Europe if you want, and soon downloadable so you can run it on premise.
The money behind it is European too. Mistral describes ML4 as the first milestone funded by its 3 billion euro Series D, which it calls the largest equity round ever raised by a European technology company. TechCrunch notes that the round in September valued Mistral at 21 billion euros and that chip equipment maker ASML is one of its main backers, which helps explain why chip design is on Mistral's list of target use cases. Mistral says it is now scaling up compute in its own European data centers, with much more capacity coming online in the next months.
There is also a business angle. Mistral recently started hosting Chinese models on its platform, which led some observers to wonder whether it would become a pure inference provider. TechCrunch reports that Mistral rejects that reading, and Le Chonk is its way of showing it still trains frontier models itself.
What is still open
As impressive as the numbers look, a few things are not settled yet.
- The weights. The download is promised for the end of October, not today. Until then, ML4 is effectively an API product.
- The license. Mistral has not yet said which license the weights will use. Its past large models have come with different terms, so this matters a lot for companies.
- Independent benchmarks. Almost all of the figures above come from Mistral or from evaluators it worked with. TechCrunch notes that broader benchmark results were still pending at launch.
- Running costs. A 1 trillion parameter model with 49 billion active parameters still needs a serious GPU cluster to run. "Open" does not mean it will run on a laptop.
- The final version. The model in the preview is not the final one. The reinforcement learning run is still in progress, so scores may change before the weights ship.
Why it matters
For the last two years, the conversation about open AI models has been dominated by DeepSeek, Qwen, Kimi and GLM. ML4 is the first time in a while that a European lab claims a seat at that table with a model of the same size class. If the benchmarks hold up once the weights are out, companies and governments in Europe will have a serious option that they can host themselves, inspect, and adapt to their own languages and rules.
The cybersecurity angle is a smart bet as well. Security teams are exactly the users who get frustrated when a closed model refuses to help with a real incident, and they are also the users most worried about sending sensitive data to a foreign cloud. A capable open model that runs in their own data center solves both problems at once, as long as Mistral manages the risk that attackers will use the same weights.
We will look at Mistral Large 4 again when the weights are released at the end of October and the first independent tests come in.

Sources
- Mistral AI: Introducing Mistral Large 4 (6 October 2026)
- TechCrunch: Mistral's new 1T model aims to leapfrog closed and open rivals (6 October 2026)
Source: mistral.ai