France Taps Mistral AI for Cybersecurity, Formally Excludes OpenAI

France has called on Mistral AI to detect vulnerabilities across its public-service systems while formally excluding OpenAI, a pointed sovereignty decision that leans on the domestic 'Our AI' ecosystem and SecNumCloud-certified data centers to keep sensitive government workloads under French control. The move follows a security breach that exposed the data of nearly 700,000 taxpayers via a compromised VPN, sharpening the government's focus on trusted, locally-controlled AI.
The decision fits Mistral's broader August sovereignty push, which included the general availability of Mistral Regional Endpoints — letting customers choose inference locations in Europe or the US for data residency and regulatory compliance — and a new Priority Tier in public preview offering committed uptime SLAs for mission-critical workloads. Mistral also acquired Emmi AI to expand into physics AI, broadening beyond language models.
Competitively, France's formal exclusion of OpenAI is a striking geopolitical statement in the week's sovereignty theme, paralleling Apple's China-specific model with Alibaba and reflecting a broader fragmentation of the AI market along national lines. Mistral is positioning itself as Europe's sovereign champion, competing with US and Chinese labs on data residency and regulatory alignment rather than raw benchmark supremacy.
The skeptical view is capability: Mistral's models trail the frontier on most benchmarks, so France is trading peak performance for sovereignty and trust. Whether a domestically-controlled but less capable AI can effectively detect vulnerabilities in critical government systems — the exact task assigned — is the open question. The bet is that trust and data control matter more than a few benchmark points for national-security workloads.