Mistral now trains on user input by default, except on enterprise tier
Mistral, a European AI firm previously lauded for its privacy-centric approach, has reportedly changed its default policy to train on user input for non-enterprise tiers, sparking a heated debate on data governance and trust. This shift, which also allegedly removes central organizational opt-out controls, is seen by many as another instance of "enshittification" in the AI space. Hacker News is abuzz with users expressing disappointment and questioning the viability of privacy-preserving AI models.
The Lowdown
Mistral, an AI company, has altered its default data handling policies, now opting to include user input and output data in its model training programs for certain service tiers. This change primarily affects non-enterprise users of services like Vibe and Mistral Studio/API, where data training is now on by default, requiring users to actively opt out. Previously, some organizational plans had training disabled by default.
Key aspects of the policy shift include:
- User input and output data (conversations, documents, etc.) may be used for model training.
- The opt-out process varies by service and platform.
- For Mistral Studio and API, users can opt out via an Admin panel.
- Critically, for Vibe Team plans, the ability to centrally disable training for an entire organization appears to have been removed, forcing individual users to opt out.
- The Enterprise tier still defaults to not training on user data and offers admin-managed opt-out.
- This policy adjustment has ignited controversy, particularly as Mistral had been perceived as a privacy-conscious European alternative to US-based AI providers.
The move has raised significant concerns among users, especially organizations, who view the lack of a central opt-out mechanism for Team plans as a major privacy and compliance hurdle. It also feeds into a broader narrative about AI services gradually eroding user privacy protections.
The Gossip
Privacy Pledge Peril: Mistral's European Credibility Crisis
Many commenters express a strong sense of betrayal, arguing that Mistral, previously seen as a privacy-focused European alternative, has gone back on its implicit or explicit promises. They view this policy shift as a classic case of "enshittification," where services degrade their value to users over time to extract more data or revenue. The discussion highlights the disappointment of those who specifically chose Mistral for its perceived privacy stance, contrasting it with US counterparts.
The "Opt-Out" Ontology: Defaults and Organizational Dilemmas
A significant portion of the debate centers on the semantics of "opt-in" versus "opt-out" and how default settings profoundly impact user privacy and organizational control. While Mistral allows individual users to opt out, the alleged removal of a *centralized* organizational opt-out for Team plans is a critical point of contention. This forces administrators to rely on each user remembering to change settings, which is deemed impractical and risky for sensitive data. There was also some initial confusion in the comments about the precise meaning of the terms, particularly from non-native English speakers.
Competitive Compulsions: Data Collection and Model Superiority
Some users speculate that Mistral's policy change is a strategic move driven by competitive pressures. The argument is that collecting more user data is essential for improving model performance and catching up with or surpassing rivals. Conversely, others question Mistral's overall model quality and argue that superior open-source or locally runnable models already exist, making Mistral's offering less attractive, especially with compromised privacy.
Trust, Terms, and Transparency: The AI Industry's Credibility Gap
A pervasive theme is the general skepticism surrounding AI companies' promises about data privacy, regardless of legal terms or public statements. Many commenters believe that companies have a strong inherent incentive to use all available data for training, and that opt-out mechanisms are often superficial or easily changed. This leads to a sense of distrust in the industry as a whole, with some advocating for local LLM execution as the only truly private option.