France France SREN digital regulation law

France's SREN Law Barely Touches Mistral's Frontier Open Model. The EU AI Act Does the Real Work

Mistral Large 4 tests the AI Act's open-weight rules, not France's SREN law, whose cloud and minors provisions mostly sit elsewhere. Rules should stay proportionate.

Mistral Large 4 by the numbers People of Internet Research · France ~1T Total parameters ML4 is roughly 1 trillion paramete… 49B Active parameters Parameters active per token. 3,800 Training GPUs Nvidia Grace Blackwell GPUs in Mis… 10^25 FLOPs Systemic-risk compute threshold AI Act Article 51(2) presumption o… peopleofinternet.com
Mistral Large 4 by the numbers People of Internet Research · France ~1T Total parameters 49B Active parameters 3,800 Training GPUs 10^25 FLOPs Systemic-risk compute threshold peopleofinternet.com

Key Takeaways

What Mistral released

On 6 October 2026 Mistral put Mistral Large 4 (ML4, nicknamed 'Le Chonk') into public preview. Silicon Republic reports that it is a roughly 1-trillion-parameter, natively multimodal model with 49 billion active parameters. It was trained on 3,800 Nvidia Grace Blackwell GPUs in Mistral's own European data centres. Mistral says the weights will follow by the end of October. It also claims that ML4 leads open-weight models built outside China by a wide margin on the Artificial Analysis Cyber Index. On a test that asks a model to reproduce and patch a real open-source vulnerability, Mistral says ML4 scored 82% while closed rivals score near zero because they refuse the task. These are the company's own claims, and the report does not say they have been independently verified.

The release prompts an obvious question: which French and European rules apply to a frontier-scale open model built in France? The answer is more nuanced than 'the SREN law', and the difference matters for policy.

What SREN actually covers

Loi n° 2024-449 of 21 May 2024, 'visant à sécuriser et à réguler l'espace numérique', is the SREN law. Its consolidated text on Légifrance is organised around other problems:

None of these provisions regulates the training or release of an AI model. SREN touches ML4 only at the edges. A public body that hosts sensitive data on an ML4 deployment would face the cloud rules. Mistral itself would be a cloud provider only if it sold hosted infrastructure services. Releasing weights is neither.

The AI Act is the operative regime

The obligations that bind ML4 come from Regulation (EU) 2024/1689. The European Commission's GPAI guidelines page says the general-purpose AI obligations have applied since 2 August 2025. It adds that the Commission's enforcement powers, including fines, begin on 2 August 2026, so they are already live.

The open-weight question turns on two articles. Article 53(2) exempts open-source model providers from the technical-documentation duties in points (a) and (b). But it states: 'This exception shall not apply to general-purpose AI models with systemic risks.' Article 51(2) presumes systemic risk when cumulative training compute exceeds 10^25 floating-point operations.

Mistral has not published ML4's training compute in the sources I could verify. A 49-billion-active-parameter model trained on thousands of Blackwell-class GPUs is very plausibly above that line, but that is an inference, not a confirmed figure. If it is above the line, ML4 cannot use the open-source exemption. Mistral would owe full documentation and the systemic-risk duties in Article 55 regardless of how permissively it licenses the weights.

The strongest case for strict treatment

The case for tough rules is serious. A model whose headline strength is offensive-adjacent cyber capability, with no safeguards that refuse such tasks, can be copied once its weights are public and then fine-tuned freely. A regulator can reasonably say the party that creates that capability should document it, test it and report incidents. Open weights cannot be recalled, and the Act's systemic-risk duties exist for exactly this reason.

Why proportionality should still govern

The same facts support a more careful reading. The cyber benchmark Mistral cites measures patching, which is defensive work. Closed models score near zero on it because they refuse, and the vendor's own claim is that refusal blocks defenders along with attackers. Blanket restrictions on cyber-capable open weights would therefore fall hardest on security teams, researchers and small firms that cannot afford closed-API terms.

Three principles follow.

What to watch

Three things will decide this. First, whether Mistral discloses ML4's training compute and its Article 55 compliance when the weights ship at the end of October. Second, how the AI Office uses its enforcement powers on a European champion with open weights. Third, whether independent evaluators reproduce the cyber results. Until they do, the 82% figure is a vendor claim and policy should not be built on it.

Sources & Citations

  1. EU Better Internet for Kids: Loi n° 2024-449 (SREN)
  2. European Commission: GPAI guidelines
  3. AI Act Article 53
  4. AI Act Article 51
  5. Silicon Republic: Mistral unveils ML4
  6. EFF: Digital Sovereignty