Mistral AI launched a public preview of Mistral Large 4 on Tuesday 6 October (Europe time) — a natively multimodal, 1-trillion-parameter mixture-of-experts model that runs on just 49 billion active parameters per token. The company’s unofficial nickname for it is Le Chonk. The preview API is live now in Mistral’s Studio console, and the weights themselves land on 27 October, according to The Next Web.
The numbers Mistral published
Mistral’s announcement claims the model was trained from scratch on 3,800 Nvidia Grace Blackwell GPUs in Mistral’s own European datacentres — roughly two months of training at about 10 megawatts, per The Next Web — and that it outperforms “any open-weight model developed in the US or Europe.” The benchmarks are vendor-reported and Mistral flags them as preliminary, with the reinforcement-learning phase still running.
The headline claim is in security. On the Artificial Analysis Cyber Index test that reproduces a real vulnerability in open-source software and then patches it, Mistral says Large 4 scores 82%, the highest of any model tested — and that several leading closed models, including Claude Opus 5.5 and GPT-6 Astra, score near zero on the same test because their safety filters refuse the task. It reports 93% on Cybench, a set of 40 capture-the-flag style challenges drawn from security competitions. Independently compiled figures on CellCog match the announcement’s other numbers: 61.7% on agentic coding benchmark DeepSWE v1.1, 59.9% on AutomationBench across 657 business workflows, and a blind human evaluation with Surge AI where professional annotators ranked it second of five models — behind Claude Opus 5 but ahead of Kimi K3 and two GLM variants.
Pricing for the preview is $0.68 per million input tokens and $2.09 per million output, with a 512K-token context window, according to OpenRouter’s model listing.
The three-week gap before the weights drop
The more unusual part of the release is the gap between the API launch and the weight release. Between now and 27 October, Mistral is red-teaming the model in live conditions — cybersecurity firms, vetted partners, and state authorities get a version with reduced moderation and expanded cyber capabilities, per the announcement, so the open weights surface on day one with the obvious abuse paths already mapped.
That sequence has a logic to it, and a risk. Releasing the API first means paying customers effectively fund the final safety pass on a model whose weights will shortly be downloadable by anyone. Mistral’s argument — laid out in its announcement — is that provider-level refusals are themselves a security liability: if defenders can’t use a frontier model to prove a flaw is real or reverse-engineer malware during an incident, threat actors who jailbreak closed models gain an asymmetric edge. Whether that holds up depends on how the October 27 weights behave outside the red-team sandbox, and Mistral has committed to publishing the architecture details and post-training methodology before then.
Why this one matters outside Europe
Two things distinguish this launch from the usual moar-parameters cycle.
First, the infrastructure claim. Mistral trained and serves this model entirely on hardware it owns in Europe — no hyperscaler tenancy — and will offer an EU deployment it operates “end-to-end, independently of other digital service providers and under European law.” That is the distributed sovereign-AI playbook in miniature: not one national mega-cluster, but a vendor small enough to fit inside a jurisdiction with room to spare. We’ve tracked this pattern across Korea’s $1T megaproject bets and the Nvidia-Korea blueprint that argues small countries don’t need a Super Fund cheque to get sovereign compute — just the right off-the-shelf stack.
Second, the economics. Mistral raised €3B at a €21B valuation only weeks ago (our coverage), and is now spending it on owned datacentres rather than a hyperscaler bill — while pricing the preview at a level that undercuts the closed labs’ equivalent tiers. The bet is that open weights plus owned inference is a defensible business even at commodity training costs, a thesis that lines up with where margin pressure across frontier labs has been heading all year.
The refusal-gap pitch deserves the most attention. If Mistral is right that closed models’ safety filters leave a capability vacuum around defensive security work — and its 82%-versus-near-zero contrast is at least partly a scoring artefact of refusals rather than raw ability — then “fewer refusals” becomes a selling point in itself. That is either a genuinely useful reframe of what model safety means in practice, or a land-grab for the customers the big labs decline to serve. Both readings can be true at once, and it will take the October 27 release — and independent benchmark runs, not vendor charts — to tell which customers are actually buying.
For organisations here, the practical takeaway is simpler: a 49B-active open-weight model is the kind of thing that can eventually run on national-scale but modest hardware, which is exactly the shape of deployment New Zealand’s public sector keeps pretending it can’t afford. Watching how the weights behave in three weeks is time better spent than reading the benchmarks today.