The Loop  ·  Issue N°040

The Loop

A field journal of the AI frontier — for engineers who ship.

§ News

By AI Blog Editor
Oct 7, 2026 · 15 min read

Mistral Large 4 ships at a trillion parameters — Europe's answer to the frontier labs is pitched at the work Claude Opus 5.5 and GPT-6 refuse to do

On Oct 6 Mistral shipped a 1-trillion-parameter MoE model nicknamed Le Chonk and pitched it as the one that will do vulnerability work closed US labs refuse. Open weights land end of October. Trained on 3,800 Grace Blackwell GPUs in Europe.

Arthur Mensch, co-founder and CEO of Mistral AI, photographed at the Slush startup conference on March 16, 2024. Mensch and his co-founders raised Mistral's record €3 billion Series D on September 8, 2026 at a €21 billion post-money valuation and launched Mistral Large 4 — a one-trillion-parameter mixture-of-experts model with 49 billion active parameters, trained on 3,800 Nvidia Grace Blackwell GPUs in Mistral's own European datacenters — three weeks later on October 6, 2026, positioning it as Europe's sovereign-AI answer to Claude Opus 5.5 and GPT-6 Astra.
Arthur Mensch at Slush, 16 March 2024. Photograph by Slush, CC BY 4.0 via Wikimedia Commons.

On Tuesday October 6, 2026, Mistral AI released Mistral Large 4 — nicknamed Le Chonk internally and announced as a 1 trillion parameter mixture-of-experts model with 49 billion active parameters, trained on 3,800 Nvidia Grace Blackwell GPUs in Mistral's own European datacenters. Preview access landed the same morning via Mistral Studio, at $1.36 per million input tokens and $4.18 per million output tokens on the standard tier (preview-tier discounts bring that to $0.68 / $2.09). The open weights are promised for "the end of this month" — three to four weeks after the announcement.

The parameter count is not what makes this a Loop story. The pitch is. Mistral's own launch post calls ML4 "one of the world's strongest AI models for cybersecurity" and includes this line: "defending software often starts with proving that a flaw is real, exactly the kind of work safety filters in closed models can block." The Decoder's writeup names the exact models Mistral has in mind: "Claude Opus 5.5 (refuses cybersecurity tasks)" and "GPT-6 Astra (refuses cybersecurity tasks)." The top of Mistral's launch deck is a product-differentiation attack against the US frontier labs' safety posture — one Mistral has decided is a business opportunity rather than a shared norm.

The specs, including the one that is still a promise

Mistral Large 4 is sparse-MoE: 1 trillion total parameters, 49 billion active per token, with a 1.6 billion parameter vision encoder and a 1 million token context window (The Decoder spec sheet). The training run used around 3,800 Grace Blackwell GPUs for pretraining and roughly 3,000 more for reinforcement learning — numbers Mistral VP of Science Pierre Stock contextualised to TechCrunch's Anna Heim as "two to three times less than our Chinese competitors, and significantly less than the closed source competitors." Mistral Large 3 (December 2025) scored 9 on the Artificial Analysis Intelligence Index; Large 4 scores 38 (Simon Willison noted) — a four-fold jump in ten months.

The benchmark line that supports the cybersecurity pitch is 93% on Cybench, 82% on vulnerability reproduction and patching, and a top-five global ranking on the Artificial Analysis Cyber Index, where Mistral says ML4 leads all open-weight models built outside China. On safety-side evals it posts 93.3% on Lakera's B3 attack-resistance benchmark and 1.691/2.0 on KORABench. On general capability it hits 61.7% on DeepSWE v1.1, 59.4% on SWE-Atlas-QnA, and claims state-of-the-art among open-weight models on SciCode-Verified.

But the model is not open-weight today. The announcement is a preview — the kind of launch where you can read the benchmarks and call the API, but you cannot download the file. Mistral promises the weights at "the end of this month," with full technical documentation and license to follow. In the three-and-a-half weeks between now and that date, Mistral says it will "work with trusted partners and governments to make sure that the open source weights can be used to defend, but not to [perform] malicious attacks." That is Pierre Stock's language, and it is the single most interesting sentence in the launch — Mistral is telling you upfront that the open weights it is about to release will be moderated by what trusted governments think open weights should do.

The announcement that is also a promise of an announcement

Mistral has shipped a trillion-parameter model by announcing a release date for the file. This is a pattern the Loop sees often enough that it has a shape — a launch where the artefact is a schedule. Google launched Gemini 4 Argon under its Fairwind Program to 650 vetted cyber-defender accounts five days ago; Anthropic's October 1 Barclays expansion is a direct-enterprise contract that reads as the plan more than the deliverable. Mistral is doing a quieter version of the same move: the model is real, the preview is callable, but the thing the pitch keeps emphasising — the open weights — lands later.

The three-week gap is not accidental. Mistral says it is for safety testing. It is also three weeks in which the loudest claim — "the strongest open-weight cybersecurity model built outside China" — can be re-measured by the labs it names and by independent benchmarkers once the file is out. Until then the comparison is Mistral's own harness against Mistral's own benchmark selections. Pierre Stock's "we'll work with trusted partners and governments" line is doing a lot of work there: the open weights that arrive will be the open weights after the trusted-partners filter, not before it.

Indian Prime Minister Narendra Modi meeting Arthur Mensch, co-founder and CEO of Mistral AI, in Paris on June 18, 2026. Mistral's enterprise customer list now runs to 125+ organisations across 20 countries, including Airbus, ASML and HSBC, and the €3 billion Series D closed on September 8, 2026 was led by Samsung Electronics with the Grand Duchy of Luxembourg among its new investors — a sovereign-wealth-backed round that puts Mistral in direct meetings with heads of state alongside its usual commercial customers.

The Series D is the business model

The pitch cannot be read without the funding round that preceded it. On September 8, 2026 Mistral closed a €3 billion Series D at a €21 billion post-money valuation — the largest equity round ever raised by a European technology company, led by Samsung Electronics and joined by BlackRock, Advent, and the Grand Duchy of Luxembourg, with Scaleup Europe Fund (managed by EQT) and existing investor PSG Equity in the round. Orrick's deal announcement carries the same figures. An €830 million loan is now funding a Paris-area datacenter, en route to 200 megawatts of European compute capacity by end of 2027. Mistral claims 125+ enterprise customers across 20 countries — Airbus, ASML and HSBC among them.

Read against that balance sheet, the sovereignty pitch is not vibes. It is a product. Mistral is selling "ML4 is one of the world's strongest AI models for cybersecurity" to the European customers that need a model which will do vulnerability-reproduction work on their own infrastructure, deployed in European datacenters under European law, specifically because Claude Opus 5.5 and GPT-6 Astra will not. The Mistral blog line — "Forged in Europe. Built for AI sovereignty" — is doing the work of a sales-deck slide, not a brand statement.

Where ML4 actually sits

The gap between the pitch and the state of the frontier is worth being honest about. Simon Willison, who tested the preview, called it "not a Fable-class model" but observed Mistral has delivered "a model that's back to being maybe about 6 months behind the frontier" — up from the roughly 18-month gap after Large 3. The AA Intelligence Index score of 38 puts ML4 just behind DeepSeek 4.1 Flash (a 552B model), which is a defensible spot for an open-weight competitor — but Fable 5 and GPT-6 Astra sit meaningfully above it.

The "best open-weight model outside China" framing is the real claim, and it is the right one. The three Chinese open-weight labs — DeepSeek, Qwen, GLM — have been clearly ahead of Mistral through most of 2026. ML4 does not claim to beat them on general capability; it claims to beat them on cybersecurity and on being European. Both are genuine differentiators for the enterprise customer that cannot ship data to Shanghai and cannot ship vulnerability-reproduction prompts to Anthropic.

What to watch

  1. Do the weights actually ship end-of-October? The announcement promises them in roughly three weeks. If the date slips, the pattern becomes "trillion-parameter preview with weights indefinitely delayed" — the shape of the Argon Fairwind launch five days ago, and the shape most frontier launches now take.
  2. Does the "trusted partners and governments" filter show up in the eventual license? If the Oct-end weights ship under anything more restrictive than Apache 2.0 — a research-use clause, a government-notification requirement, a cybersecurity-usage carve-out — the open-weight claim collapses into a tiered-access claim. The license text is the real deliverable.
  3. Does an independent third-party reproduce the 82% vulnerability-reproduction number? Mistral's cybersecurity pitch rides on this and on the Cybench 93%. Both are first-party numbers on Mistral's own harness. A reproduction from a European security firm within a month of weights-release will decide whether the pitch is real.
  4. Does Anthropic or OpenAI respond publicly to being named? Mistral's launch deck pointing at Opus 5.5 and GPT-6 Astra by name as the models that "refuse cybersecurity tasks" is a direct product-page attack. Anthropic has been clear about its Preparedness Framework and OpenAI about its own refusal policies — but neither has been cited as a competitor's selling point before. A response, or the absence of one, decides whether cybersecurity-doing-ness becomes a published eval axis across labs.

The frame that ships with ML4 is Mistral choosing cybersecurity capability as the ground on which it will differentiate against the US frontier. Three weeks from now the industry finds out whether the weights are real, whether the license matches the pitch, and whether a European lab can hold the ground it has just claimed.

* * *

Thanks for reading. If a line here was useful — or plainly wrong — the comments are below and the newsletter has your back.

Elsewhere in this issue

3 more
  1. 01

    The Patch

    The Patch — October 7, 2026

    Oct 7, 2026

  2. 02

    News

    $100,000 to $10,000 — Microsoft and Meta both cut internal Claude use in the same week Anthropic went direct to Barclays

    Oct 6, 2026

  3. 03

    The Patch

    The Patch — October 6, 2026

    Oct 6, 2026

Letters

Arguments, corrections, questions. Anonymous comments allowed; be kind, be specific.