← All company positions
Mistral AIagenda

European AI: a playbook to own it

Published April 7, 2026 · Printed on the landing page as "Published April 7, 2026", above the byline "By Mistral AI". The 24-page whitepaper itself prints no date: a sweep of all 24 pages found none. So the date is the publisher's, on the page hosting the document, not on the document.

Not law. This is a company's own public position on AI regulation. It is not law, and it carries no legal force.

What it argues for

Mistral argues that Europe's problem is not a shortage of rules but a shortage of capability, and that the two are connected: regulatory complexity is itself one of the things stopping European AI companies from reaching the scale that would let Europe set its own terms. The paper is explicit that this is a competitiveness argument rather than a safety one — the stated goal is "strategic autonomy", and the harm it names is dependence on foreign providers, not unsafe models. Its regulatory ask therefore runs in two directions at once, and the combination is what makes it distinctive. On compliance it asks for less: eliminate the overlaps between the AI Act, GDPR, the Data Act, DSA, DMA, CRA and NIS2; let a company demonstrate compliance once and be exempt from equivalent obligations elsewhere; and make implementing acts, standards and guidelines a precondition for new rules applying at all. On market structure it asks for considerably more: a European preference in public procurement for strategic sectors, gated on three cumulative tests of European control; mandatory third-party-verified life-cycle environmental assessments as a condition of bidding for anyone above €500m in revenue; and a statutory revenue-based levy on every commercial provider placing AI models on the European market. That last measure is the sharpest thing in the document. In exchange for the levy, which would fund European content creation, Mistral proposes that AI providers "are shielded from liability for training on materials accessible on the web" — replacing the current opt-out regime with compensation. It is a company arguing for a new tax on itself, in return for legal certainty it does not currently have.

Stated positions (16)

  • The EU digital rulebook should be revised to "clarify inconsistencies, eliminate overlap, and reduce compliance efforts without sacrificing underlying regulatory goals" — named instruments are the AI Act, GDPR, the Data Act, DSA, DMA, CRA and NIS2 (Measure 6).
  • A company that demonstrates compliance with an equivalent obligation under one regulation should be exempted from the redundant requirement under another (Measure 6).
  • The availability of implementing acts, standards and guidelines should be "a prerequisite for the application of new rules" — that is, new obligations should not bite until the guidance to comply with them exists (Measure 6).
  • Documentation and impact-assessment obligations across the AI Act, GDPR and the Data Act should be streamlined into "common templates, aligned timelines, and unified control authorities" (Measure 6).
  • Incident notification should run through one centralized EU platform with standardized forms and a single deadline — the paper proposes 72 hours for all "significant/severe incidents" under NIS2, GDPR and the CRA (Measure 6).
  • Regulatory sandboxes should be expanded to general-purpose AI developers, giving them access to EU-level sandboxes and real-world testing "beyond high-risk AI systems" (Measure 6).
  • Systemic-risk thresholds for general-purpose AI under the AI Act should be defined, and harmonized standards accelerated, because the current documentation requirements are unclear (Measure 6).
  • A centralized multilingual "EU AI compliance portal" should let developers generate standardized reports and automate compliance checks across the AI Act and GDPR in one place, modelled on the European Single Access Point (Measure 7).
  • Public procurement in strategic sectors should carry a European preference, restricted to bidders meeting three cumulative tests: an EU corporate seat, European control with no third-country decisive influence, and substantial EU operations (Measure 17).
  • That preference is scoped by reference to Article 4(1) of Regulation (EU) 2019/452 and covers AI, robotics, semiconductors, cybersecurity, quantum, energy storage, nuclear, nano- and biotechnologies, with exceptions only where no suitable EU alternative exists, urgent public interest demands it, or interoperability requires it (Measure 17).
  • Every AI provider operating in the EU above €500 million in annual revenue should have to submit "standardized, third-party-verified life-cycle assessments covering the full life cycle of their AI systems as a prerequisite for eligibility for public procurement contracts" (Measure 18).
  • Public compute-infrastructure procurement should require open-source or dual-licensed models, EU data residency under EU jurisdiction, energy efficiency at PUE below 1.3, and infrastructure "physically and legally anchored in the EU, including in terms of majority voting rights" (Measure 19).
  • A revenue-based levy should apply to all commercial providers placing AI models on the European market, including those based abroad, with proceeds flowing to a central European fund for new content creation (Measure 20).
  • In return for that levy, "AI providers are shielded from liability for training on materials accessible on the web" — though the paper is explicit this "would not replace licensing agreements or the freedom to contract" (Measure 20).
  • Europe's "restrictive copyright framework compared to other world regions significantly harms Europe's global competitiveness", and the resulting legal uncertainty risks "long-term dependence on foreign developed AI models" (Measure 20).
  • An "AI Blue Card" should grant AI researchers and engineers a four-year EU-wide work and residency permit processed in 15 working days through a unified digital portal (Measure 1).

About this document

A 24-page whitepaper published on its own dedicated subdomain, europe.mistral.ai, with a scrolling web edition and an 11 MB PDF download. It is bylined to Mistral AI corporately rather than to a policy team, and opens with a signed foreword from co-founder and CEO Arthur Mensch. The page advertises a 52-minute read. The structure is four chapters — attract and retain talent; scale through the single market; adopt European AI across the real economy; power Europe with local infrastructure and data — carrying 22 numbered measures between them. Each measure is written as a drafting instruction rather than a principle: it names the instrument to amend, the threshold to set, or the body to create. Measure 17 specifies three cumulative eligibility criteria and cites Article 4(1) of Regulation (EU) 2019/452; Measure 19 specifies a PUE figure; Measure 1 specifies 15 working days. Fourteen of the 22 measures concern market structure, funding, talent or infrastructure rather than AI regulation as such, so this is an industrial-policy document that contains a regulatory position, not a regulatory position paper. It is unusually candid about being self-interested. The paper says it is "born from the lived experience of a European AI startup", and cites the company's own encounters with "misaligned equity frameworks, bureaucratic barriers that require the CEO to travel for basic administrative tasks, and legal uncertainty". Statistics are sourced to the European Court of Auditors, the European Parliament and DG GROW. A contact address, [email protected], is printed at the foot.

How this sits against AI law

Each stance compared with what EU and US instruments actually require. Where no instrument addresses a theme, that gap is shown rather than hidden.

Reducing overlap and compliance burden across the digital rulebook

The AI Act, GDPR, Data Act, DSA, DMA, CRA and NIS2 should be revised to eliminate overlapping obligations, with a company that complies with an equivalent obligation under one instrument exempted from the redundant one under another, and common templates and unified control authorities across the AI Act, GDPR and Data Act.

European UnionAsks for less

The Act as enacted stacks on top of the GDPR and the other digital instruments rather than consolidating with them, and contains no general exemption for a provider that has met an equivalent obligation elsewhere. The ask is for materially less compliance work than the current text requires.

United StatesAligned

The executive order's stated purpose is removing regulatory barriers to AI leadership, so the deregulatory half of Mistral's ask points the same way as current US federal policy — though the order addresses US rules and has no bearing on the EU instruments Mistral names.

New obligations should not apply before the guidance to comply exists

Availability of implementing acts, standards and guidelines should be "a prerequisite for the application of new rules", and systemic-risk thresholds for general-purpose AI should be defined and harmonized standards accelerated.

European UnionContradicts

The Act sets its application dates in the legislation itself and they run regardless of whether harmonised standards have been published; obligations do not wait on guidance. Making availability a precondition would change when the Act bites, not merely how it is complied with.

United StatesNo equivalent law

No US federal instrument conditions the entry into application of AI obligations on prior publication of standards.

A single portal for AI compliance reporting

A centralized multilingual EU portal should let developers generate standardized reports, get real-time guidance and automate compliance checks across the AI Act and GDPR together, with pre-filled data and proportionate templates for SMEs.

European UnionAsks for more

The Act creates an EU database for registering high-risk systems, but nothing that spans the AI Act and the GDPR as one reporting surface, and nothing offering automated compliance checking. This asks for machinery the Act does not provide.

United StatesNo equivalent law

No US instrument creates a federal AI compliance reporting portal.

Regulatory sandboxes opened to general-purpose AI developers

EU-level regulatory sandboxes should be opened to general-purpose AI developers, allowing real-world testing "beyond high-risk AI systems".

European UnionAsks for more

The Act obliges Member States to establish national sandboxes and frames real-world testing around high-risk systems. Mistral asks for the sandbox to exist at EU level and to reach GPAI developers, which is broader than what the Act sets up.

United StatesNo equivalent law

There is no federal AI regulatory sandbox; a handful of state proposals are not comparable in scope.

European preference in public procurement for strategic sectors

Public buyers in strategic sectors should prefer European-controlled bidders, defined by three cumulative tests — EU corporate seat, European control with no third-country decisive influence, and substantial EU operations — with exceptions only where no suitable EU alternative exists, urgent public interest demands it, or interoperability requires it.

European UnionNo equivalent law

The AI Act regulates what may be placed on the market and on what conditions; it does not govern who may win a public contract. This is an ask aimed at EU procurement law, not at AI law, and no AI instrument addresses it.

United StatesAligned

America's AI Action Plan likewise treats public purchasing and export promotion as levers for a domestic AI stack. The instrument shape is the same and the intended beneficiary is the mirror image — which is why a European preference mechanism and the Action Plan point at each other rather than at a shared rule.

Verified environmental life-cycle disclosure as a condition of public contracts

Every AI provider operating in the EU above €500 million in annual revenue should submit standardized, third-party-verified full life-cycle assessments as a prerequisite for public procurement eligibility, and public compute contracts should require PUE below 1.3.

European UnionAsks for more

The Act approaches energy and resource consumption for general-purpose models through documentation and voluntary codes of practice, with no third-party verification and no consequence for market access. Making a verified life-cycle assessment a gate on public contracts is a materially harder obligation, and it lands on large providers specifically.

United StatesNo equivalent law

No US federal instrument conditions AI procurement on environmental disclosure; the Action Plan treats energy as a supply constraint to be relieved rather than an impact to be reported.

A levy on model providers in exchange for a training-data liability shield

A revenue-based levy should apply to all commercial providers placing AI models on the European market, including foreign ones, funding European content creation — and in return "AI providers are shielded from liability for training on materials accessible on the web", without displacing voluntary licensing.

European UnionContradicts

The Act requires general-purpose model providers to put in place a policy respecting EU copyright law, including the reservation of rights under the text-and-data-mining exception, and to publish a summary of training content. A blanket liability shield for training on web-accessible material would displace that rights reservation with a compensation scheme — a different legal settlement, not a stricter or looser version of the same one.

United StatesNo equivalent law

No US federal instrument establishes a training-data levy or a statutory liability shield; the question is being settled in litigation rather than legislation.

Mistral is the only company in this set arguing from the position of a challenger inside the jurisdiction it is addressing, and that shows in what it asks for. The American labs argue about where the regulatory perimeter should sit — which capability threshold, which risk domains, who counts as a frontier developer. Mistral barely engages with that question. It does not propose a compute threshold, name a catastrophic-risk taxonomy, or commit to a deployment gate; safety is largely absent from the document. What it asks for instead is industrial policy with a regulatory instrument attached. Its deregulatory asks are about the cost of compliance for a company of its size, not about the principle of regulating, and it is careful to say the goals should survive — "without sacrificing underlying regulatory goals". Meanwhile its procurement, environmental and copyright measures would each impose obligations the EU AI Act does not currently impose, several of them squarely on the larger US providers: a €500m revenue threshold for verified environmental audits, and a levy that would apply to foreign providers "equally", are asks that cost Mistral's competitors more than they cost Mistral. That is the mirror image of the American frontier-lab pattern, where the proposed perimeter tends to sit just above the proposer.

Source

https://europe.mistral.ai/
Date on the page:
April 7, 2026 — printed on the landing page as "Published April 7, 2026". Verified as described: a regex sweep of all 24 pages of the whitepaper PDF found NO date printed anywhere in the document itself, so there is no conflicting date, but equally the date belongs to the hosting page rather than to the document.
Source checked:
opened and confirmed on 2026-09-18