Back to Blog
AI Security

Mistral Large 4 preview: what open weights mean for AI security teams

Mistral has released a preview of Mistral Large 4, a 1 trillion parameter model, and says open weights will follow by the end of October. For security and governance teams, the open-weights release matters more than the benchmark scores.

PyramidLedger Research3 min read
Share

Key Takeaways

  • Mistral Large 4 is a 1 trillion parameter model with 49 billion active parameters, trained on 3,800 NVIDIA Grace Blackwell GPUs. It is available as an API preview now, and open weights are promised for the end of October.
  • The preview API exposes only two reasoning levels, 'none' and 'high'. Reasoning mode is a deployment setting that changes model behaviour, so it belongs in your test matrix.
  • Open weights move model hosting, patching and guardrails onto the adopting organisation. Treat them as a new supply-chain and governance input, not as a free upgrade.

What was announced

On 6 October 2026 Mistral released a preview of Mistral Large 4 through its API. Per Simon Willison's write-up, it is a 1 trillion parameter model with 49 billion active parameters, trained on Mistral's own cluster of 3,800 NVIDIA Grace Blackwell GPUs. Mistral says the open-weights model will follow at the end of the month.

On capability, Willison reports a score of 38 on Artificial Analysis. That is just behind DeepSeek 4.1 Flash, a 552B model, and far above Mistral Large 3 (December 2025), which scored 9. He describes it as not frontier-class, but roughly six months behind the frontier. This is one commentator's reading of one index, not an independent security evaluation.

Why a security team should care

Nothing in the announcement is a vulnerability. The relevance is operational. A capable model with downloadable weights changes who is responsible for running it safely.

Open weights shift responsibility to you

With a hosted API, the provider operates the serving stack and any moderation or filtering layers. Once you self-host weights, you own the inference infrastructure, access control and logging. You also own the system prompts, tool permissions and output filtering around the model. Those are the layers where prompt injection and excessive-agency problems, as catalogued in the OWASP LLM Top 10, tend to show up in practice.

Reasoning mode is part of the attack surface

The preview API offers only 'none' and 'high' reasoning levels. In Willison's informal test, the 'high' setting produced a better result while using fewer output tokens (2,717 versus 3,275). That is a single data point and says nothing about safety. It does show that a reasoning toggle can change output behaviour and cost. Jailbreak and injection testing done on one setting should not be assumed to transfer to the other.

Preview weights and final weights are different artefacts

The open-weights release is promised, not yet shipped. Anything evaluated through the preview API is a proxy for the eventual download. Quantisation, chat templates, serving configuration and any changes between preview and release can all alter behaviour. Re-run your evaluations against the artefact you actually deploy.

A practical checklist before adopting

  • Verify provenance: download weights only from the publisher's official channel and check published hashes where available. Treat look-alike repositories as a supply-chain risk.
  • Test per configuration: run prompt-injection, data-exfiltration and tool-abuse tests for each reasoning level, quantisation and system-prompt variant you plan to ship.
  • Constrain agents: apply least privilege to any tool or credential the model can reach, whichever model sits behind it.
  • Record it in your AI inventory: a new model is a change to your AI management system. Frameworks such as ISO/IEC 42001 expect documented risk assessment when models change.

Bottom line

The headline numbers are about scale and catching up with the frontier. The security-relevant fact is the promised open-weights release. When it lands, the people who deploy the model, not Mistral, decide how safe it is in production. Plan the evaluation work now, so it is ready when the weights are.

Frequently Asked Questions

What is Mistral Large 4?

It is a model from Mistral with 1 trillion total parameters and 49 billion active parameters, trained on 3,800 NVIDIA Grace Blackwell GPUs. A preview is available through Mistral's API, and open weights are promised for the end of October 2026.

Does an open-weights model make LLM security harder?

It changes who is responsible rather than making the model inherently less safe. Self-hosting means your team owns the serving infrastructure, guardrails, access control and monitoring, so these need explicit testing and governance.

Should we red-team the preview API or wait for the weights?

Do both. Use the preview to build your test harness and baseline results. Re-run the evaluations on the released weights in your own serving configuration before production use, because behaviour can differ between the two.

Sources

  1. 1Introducing Mistral Large 4: Le chonk — Simon Willison
  2. 2OWASP Top 10 for LLM Applications — OWASP GenAI Security Project
  3. 3ISO/IEC 42001:2023 — AI management systems — ISO
Share

Read next