Arthur Mensch, co-founder and CEO of Mistral AI, warns companies that by using closed AI models they are effectively sharing their business processes with the providers of those models. Anyone who runs their workflows and data through a proprietary model gives that model's provider a view into how their organisation operates. That is the core of his message, which he has stated publicly.
Mensch argues that AI labs are storing increasing amounts of customer data. In some cases, the Mistral CEO claims, labs have used that information to enter markets in which their customers are active. In his view, this means those customers are unwittingly supplying competitive intelligence to the very parties on which they depend.
Mistral itself releases both open and closed models and positions itself as a European alternative, with European data sovereignty as a key differentiator. That context colours Mensch's remarks, as Mistral competes directly with the American labs he is criticising.
What Mensch means by a 'first-class view' of business processes
When a company calls a closed AI model via an API for tasks such as customer service, contract analysis or internal search, the associated data flows to the provider's infrastructure. How that data is subsequently stored, analysed or used depends on the terms and policies of the lab in question.
Mensch points out that AI labs can thereby build a detailed picture of their customers' operations: which products they sell, what questions their customers ask, and what internal processes look like. At sufficient scale and over time, this yields information comparable to what a strategic consultant or market research firm would gather.
The step from data collection to competition is a large one, but Mensch claims it has already been taken by some labs. He names no specific companies or documented cases in the available reporting, which makes the claim difficult to verify independently. Nevertheless, the underlying mechanism, that providers of closed models structurally gain insight into customer usage, is a real consequence of how these services are technically structured.
Mistral as a European alternative, with its own interests
Mistral AI was founded in Paris in 2023 by Mensch and two other former researchers from Google DeepMind and Meta. The company releases both open models, which can be freely downloaded and run, and closed models via its own API. Open models can be run by companies on their own infrastructure, without data leaving their own environment.
That distinction is central to Mensch's argument. A company running an open model locally shares no data with an external party. One using a closed model via the cloud does. Mistral positions its open offering and its European origins as a response to concerns about data sovereignty, a topic that carries significant political and legal weight in Europe due to the GDPR and related regulation.
At the same time, it is worth noting that Mistral does not compete on equal footing with frontrunners OpenAI and Anthropic in terms of model performance. Independent benchmarks consistently place Mistral's models in a lower performance tier than the most recent models from those two American labs. The emphasis on sovereignty and transparency is therefore also a strategic choice: it is the area in which Mistral has a distinctive argument of its own.
How companies can weigh the trade-offs
For companies, the trade-off between closed and open models involves more than performance alone. Relevant questions include what data the prompts contain, whether the provider offers contractual guarantees on data usage, and whether there is a data processing agreement that meets GDPR requirements.
The major American labs now offer enterprise contracts under which they commit not to use customer data for model training unless the customer explicitly permits it. How robust those guarantees are in practice, and how they are enforced, is a question that requires legal and technical expertise. Open models on a company's own infrastructure offer a structurally different situation on this point, since data does not leave the organisation's environment, but they require their own computing resources and management.
Mensch's warning aligns with a broader discussion that has been ongoing among CISOs, legal counsel and procurement departments at larger organisations. It is not a new observation, but the source, the CEO of a competing lab, gives it a different weight than when the same concern is raised from a privacy or security perspective.
Implications for the European AI landscape
For European companies and policymakers, the debate around data sovereignty in AI models is not an abstract topic. The GDPR sets requirements on where personal data is processed and on what legal basis. In the coming years, more AI applications will process commercially sensitive and personal data, making the choice of provider increasingly legally significant.
Mistral is not the only European player capitalising on this. Other European labs and cloud providers, including Dutch ones, are positioning themselves with similar arguments towards governments and large enterprises. The question is whether performance gaps with American frontier models will narrow over time, and whether European providers will then be able to claim a stronger position, or whether the sovereignty argument will remain a temporary niche for organisations where compliance outweighs model performance.