Mistral AI's help documentation now confirms that the French AI company may include users' input and output data, such as conversations, documents and other user-provided content, in its model training programs by default. The updated support article, titled "Can I opt out of my input or output data being used for training?", states that users "retain full control over this processing and have the right to opt out of these programs at any time," but the default position is that their data can be used.

The change drew swift attention on Hacker News, where a submission titled "Mistral now trains on user input by default, except on enterprise tier" gathered 80 points within hours on September 2, 2026. For a company whose European identity has long been part of its sales pitch, the quiet default is prompting renewed debate about data governance in consumer AI tools.

What the Documentation Says

According to the updated help center article, the specifics differ sharply by product tier:

Vibe: Opt-In for Everyone Except Enterprises

For Vibe, Mistral's agentic coding product, individual users "are not opted out by default and can opt out at any time in their settings." In plain terms, ordinary Vibe users are opted in to having their interactions used for training unless they act. Enterprise Vibe customers sit in the opposite position: they "are opted out of training by default," with the toggle managed at the admin level.

The documentation is explicit that documents attached or uploaded within Vibe are considered input data, meaning files a user shares with the assistant could feed model training unless the opt-out is enabled. That detail matters for developers pasting proprietary code or companies sharing internal documents with the tool.

API and Mistral Studio: A Separate Toggle

Customers using Mistral Studio and the company's API services are covered by a separate mechanism. The help article instructs admins to open the Privacy menu in the Admin panel and disable the toggle under the "Anonymous improvement data" section to prevent API calls and related data from being used to improve Mistral's services. Notably, Mistral states that the Vibe and API opt-out toggles are independent: opting out of one does not opt a user out of the other.

Mobile Apps

On iOS and Android, the opt-out runs through the Settings page, then Data & Account Controls, where users must deselect the "Enable data sharing" checkbox to leave the training program.

Why the Default Matters

The opt-out-versus-opt-in distinction is one of the most consequential design choices in AI data policy. With an opt-out default, a company's training datasets automatically absorb the conversations of every user who never finds the settings page, which in practice is the overwhelming majority. Privacy-conscious users and organizations must actively hunt for toggles that many products bury.

The tiered structure also means protection scales with what a customer pays. Enterprises get default privacy; individuals and small teams get a settings page. Regulators in Europe, where the GDPR's data-minimization and purpose-limitation principles apply, have historically scrutinized exactly this kind of default-on processing, and the help page itself points users to Mistral's GDPR rights documentation and a Zero Data Retention option for those who need stronger guarantees.

The Reputation math for Mistral

Mistral has spent years positioning itself as Europe's answer to American AI labs, and European data protection has been central to that pitch, including partnerships that emphasized keeping European data on European infrastructure. A default that trains on individual users' conversations and code, while sparing only enterprise customers, hands critics an easy comparison to the very practices European users associate with US platforms.

To be fair to the company, the documentation is unusually transparent: Mistral spells out where the toggles live, confirms that opting out stops future use of input and output data for training, and separates the mechanisms per product. Transparency, however, is not the same as a privacy-protective default, and the Hacker News reaction suggests much of the developer community sees the shift as a meaningful step backward.

What Users Should Do Now

Users of Mistral's consumer and pro products who do not want their conversations or uploaded documents used for training should:

1. Opt out in Vibe settings, or via the Admin panel for teams.
2. Disable data sharing in the mobile app under Data & Account Controls.
3. Separately disable the "Anonymous improvement data" toggle for API and Mistral Studio usage.
4. Evaluate Zero Data Retention if their use case involves sensitive material.

Enterprise administrators should verify that their organizations are in fact opted out by default, and confirm that both the Vibe and API toggles are configured as expected.

Stay Ahead of AI

Data policy changes like this one rarely arrive with press releases. Get the latest AI developments from AI Buzz Wire and stay informed about the privacy decisions shaping the tools you use.

Read more AI news, updated around the clock.