The Mistral AI Usage Policy sets the content and conduct rules for Mistral AI’s hosted products. It is supplemented for commercial customers by the Additional Product Terms, which add rules for features such as web search, connectors, third-party models and audio. The Usage Policy is effective 2026-06-11 and applies to “All the Mistral AI products accessible on our platform or applications, including Vibe and Mistral AI Studio”.[1] The Additional Product Terms are effective 2026-09-25. Their first section requires the customer to comply with the Usage Policy whenever it uses Mistral AI products on Mistral AI’s infrastructure.[2]
For a software asset or AI governance team, these documents decide which internal uses of Vibe or the API need extra controls. They also set what the organization must do about connected tools and third-party models.
Scope
The Usage Policy covers products on Mistral’s platform, all their users, the content generated through them and the activity on them. It “does not apply to Mistral AI Products deployed on a customer’s infrastructure, on the infrastructure of our partners, or to our open-source AI models and products” (rule Usage Policy does not apply to customer-infrastructure deployments or open-source models).[1] Self-deployed open-weight models are governed by their own licences instead, as described in Mistral AI licensing.
The Additional Product Terms have separate parts for each deployment type. When products run on Customer IT Infrastructure under an Order Form, only some sections of the Mistral-infrastructure terms carry over: Media Customers, Conversation Links, Third-Party Connectors, Third-Party Technologies, Third-Party Content (where a feature returns it) and Audio products. “For the avoidance of doubt, provisions not expressly incorporated do not apply” to use on Customer Infrastructure.[2]
| Rule set | Mistral AI Infrastructure | Customer Infrastructure | Open-source models |
|---|---|---|---|
| Usage Policy | Applies[1] | Does not apply[1] | Does not apply[1] |
| Connectors, third-party technologies, audio | Applies[2] | Applies by incorporation[2] | Model licence only |
| Moderation, prohibited content, usage data | Applies[2] | Not incorporated[2] | Model licence only |
Prohibited content and activities
The Usage Policy lists prohibited categories: illegal activities, child sexual abuse material, non-consensual intimate imagery, hate and discrimination, violence and threats, self-harm, fraud and scams, misinformation, privacy violations, professional advice and security violations.[1] Most are content rules. Three matter most in a business setting.
- Professional advice. “You shall not use our Mistral AI Products to provide professional advice without proper qualification.” The examples are investment advice and financial planning, legal counsel and interpretations of the law, and medical diagnoses or treatment suggestions (rule Usage Policy: no professional advice without proper qualification).[1] An internal assistant that answers employees’ legal or financial questions should be reviewed against this rule.
- Security. Users may not compromise the security of Mistral AI, its products or third parties, including “creating malware and exploiting vulnerabilities”. The policy adds: “You shall not try to circumvent security protections and AI safety filters.” (rule Usage Policy: no circumvention of security protections or AI safety filters)[1] The Commercial Terms of Service separately restrict reverse engineering and the resale of API keys or accounts (rule Commercial Terms: no reverse engineering, key resale or Vibe embedding).[3]
- Intellectual property and high-risk uses. Under illegal activities, the policy bars content that “infringes, misappropriates, or otherwise violates any third party’s rights, including intellectual property rights”. It also bars content related to “activities with high-risk of physical harm”, such as weapons development or the operation of critical infrastructure.[1]
Violations “may result in temporary suspension or permanent termination of your account” and, where appropriate, reporting to the authorities. Mistral reserves the right to update the policy from time to time on its website.[1] Material updates to the Commercial Terms, Additional Terms and Usage Policy take effect 30 days after notice (rule Material updates to the Commercial Terms take effect 30 days after notice).[3]
Moderation and prohibited content
On Mistral’s infrastructure, “Mistral AI may monitor use of the Mistral AI Products through automated means in accordance with the Usage Policy.” Customer Data and Outputs may not violate applicable law or the Usage Policy. Mistral may review, remove, restrict access to or disable content, using automated tools that support human review “where required by law”.[2] This monitoring takes the place of an audit clause for hosted use. The Commercial Terms of Service contain no software audit section for Mistral AI Infrastructure.[3]
Connectors and third-party models
Third-Party Connectors. Customers may connect services that Mistral does not provide, including Model Context Protocol (MCP) servers. Enabling a connector lets Mistral access it, send input to it and act on the customer’s request. “Customer may only connect a Third-Party Connector to a Mistral AI Product if Customer has all necessary rights, licenses, and permissions to connect such Third-Party Connector to Mistral AI Products in accordance with these Terms.” The customer must keep access for the subscription and “is solely responsible for complying” with the connector’s terms (rule Third-Party Connectors and MCP servers: customer must hold the rights and follow their terms).[2] A connector to another vendor’s SaaS can therefore raise licence questions under that vendor’s terms, for example on automated access or API use.
Third-Party Technologies. Third-party models served through Mistral AI products “do not constitute Mistral AI Products and are neither owned, developed, nor expressly warranted by Mistral AI”. They are provided “as is” under their own licences, and Mistral “will have no obligation to indemnify Customer against any third-party claim” about them, including intellectual property claims. Mistral assigns to the customer whatever rights it has in Output generated with them (rule Third-Party Technologies such as third-party models carry no Mistral indemnity).[2] An inventory of model use should therefore record whether a workload calls a Mistral model or a third-party model, since the indemnity position differs.
Web search and shared links
Web search can return hyperlinks, images, thumbnails or snippets alongside the Output. This Third-Party Content “does not constitute Customer Data or Outputs”, and Mistral grants no rights in it “other than viewing it”. Customers may not copy, store, archive, cache or build a database from it, redistribute or resell it, use it in machine learning, or use it to build products for third parties (rule Web-search Third-Party Content: view only; no storing, reselling or training).[2] Media Customers may not use the verified news feature, such as AFP news, for editorial use without contacting Mistral.[2]
Conversation Links let users share a conversation with third parties. Anyone with the link can view the conversation, and “Mistral AI does not monitor or control who accesses conversations via Conversation Links”.[2] Organizations that restrict data sharing should cover this feature in their own user policies.
Audio products
For audio products, including voice cloning, the customer may not “impersonate others, clone voices without explicit consent”, or use them for fraud, deception or misinformation. “Customer must disclose AI-generated or partially AI-generated content generated through the audio Mistral AI Product where required by applicable law.” (rule Audio products: no voice cloning without explicit consent; disclose AI-generated audio where required)[2] This section also applies to audio products deployed on Customer Infrastructure.[2] The Usage Policy separately bars using another person’s likeness or voice “without their prior consent”.[1]
Usage data
Mistral creates aggregated or anonymized datasets from usage and operational data, such as “product usage events, performance metrics, billing metrics, and Feedback”. “Usage Data is the sole property of Mistral AI and does not constitute Customer Data or Outputs.” (rule Usage Data is Mistral AI property and not Customer Data)[2] The rules for Customer Data, Output ownership and training opt-outs are in Mistral AI commercial terms, accounts and data.
Out of scope
- Model licences for self-deployed weights (Apache 2.0, modified MIT, MRL, MNPL), covered in Mistral AI licensing.
- Partner-served deployment terms, covered in Mistral AI deployment options and partner-served terms.
- Consumer terms of service and the Data Processing Addendum.
- Legal obligations that arise outside the Mistral documents, such as AI regulation, which the Usage Policy refers to only as “applicable laws”.[1]