France Names Mistral Sovereign AI Provider for Government Cybersecurity, Excludes OpenAI

France's decision to name Mistral—and explicitly exclude OpenAI—as a sovereign AI provider for government cybersecurity testing is a pointed statement about digital sovereignty in Europe. Budget Minister David Amiel said the government will use sovereign AI tools to probe public services for vulnerabilities following a DGFiP breach that exposed roughly 700,000 taxpayers' data.
The explicit exclusion of OpenAI signals that European governments increasingly view AI provider choice as a matter of strategic autonomy, not just capability or price. For Mistral, it's a validation of its sovereignty-first positioning, which it reinforced with generally available regional EU/US inference endpoints and a 99.5%-uptime Priority Tier.
Mechanically, Mistral also shipped Agentic Search—a retrieval layer that reduces token use and latency for agents—plus Shieldstral 1.0 (a safety/security model) and a Mistral Medium 3.1 update. The Agentic Search launch lands amid a wave of European open-model activity including Denmark's Mimir and Germany's Soofi S.
Competitively, Mistral is leaning into a European moat that hyperscalers and US labs can't easily match: data residency, sovereignty, and government trust. The caveat is capability—Mistral's models trail frontier US and Chinese systems on raw benchmarks, so sovereignty must compensate. Watch whether other EU governments follow France's exclusion pattern, and how much government revenue Mistral can convert this into.