elevated Mistral · AI Security

Mistral Large 4 preview ships a reduced-moderation cyber tier, and Artificial Analysis lists its 82% as the top score

Data graphic: Mistral Large 4 Preview scores 81.7% on CyberGym-E2E-AA, first of 18 on Artificial Analysis's leaderboard, but 5th of 18 on the composite Cyber Index 49.5 .
AK

Threat intelligence editor · Published Oct 6, 2026, 10:31 AM EDT

Mistral Large 4 is in preview, with vetted partners and states getting a reduced-moderation cyber tier. Artificial Analysis lists its 82% CyberGym score as the top of 18 models.

What happened

On 6 October 2026 Mistral AI opened a public preview of Mistral Large 4 (ML4, nicknamed "le Chonk") through its Mistral Studio API. Mistral says the open weights follow "by the end of the month." VentureBeat reports a specific date of 27 October and a custom Mistral licence. Mistral's own pages do not state either.

The security-relevant part is access. Mistral says it is red-teaming the model "in real-world settings with cybersecurity leaders, vetted partners, and state authorities, who will access the same model with reduced moderation and expanded cyber capabilities." Mistral does not say how partners are vetted or what is relaxed.

Mistral also claims ML4 scores 82% on one test in the Artificial Analysis Cyber Index, "the highest of any model." Its blog chart is titled "Cybersecurity Benchmarks - CyberGym-E2E (AA)," and the test asks a model "to reproduce a real vulnerability in open-source software and then patch it." The blog says ML4 "ranks among the top five models globally" on the index. Mistral says Claude Opus 5.5 and GPT-6 Astra "score near zero on the same test because they refuse to perform the task."

Why it matters

Mistral is pitching refusals as a defender problem: provider-level refusals "can block legitimate vulnerability research and incident response." It wants buyers to run a strong cyber model under their own policies. That is attractive to security teams. A self-hosted model also has no provider-side policy once the weights are out, and that applies to attackers as well as defenders (we covered open-weight GLM-5.3 and exploit writing).

Artificial Analysis (AA) now backs the headline number. Its leaderboard, fetched 6 October, lists "Mistral Large 4 Preview" with 81.7% on CyberGym-E2E-AA, the highest of the 18 models shown, and a Cyber Index of 49.5, fifth of 18. (The figures come from the data embedded in AA's page, not its visible text. Preview scores may change before the weights ship.) VentureBeat said at press time that ML4 "does not yet appear" in AA's public evaluations; it does now.

The other half of Mistral's claim, that rivals score near zero because they refuse, is also in AA's data. It is the counter-view to our earlier read of Claude Opus 5.5 as Anthropic's strongest cyber model. That article explained that Opus 5.5's cyber safeguards block some security requests, such as binary bug hunting, and that blocked requests fall back to Opus 4.8. Mistral argues that this blocking is itself the problem for defenders.

Bar chart of CyberGym-E2E-AA scores: Mistral Large 4 Preview 81.7, MiMo-V2.6-Pro 78.6, GPT-6 Luna 77.9, GLM 5.3 Flash 74.0, Grok 4.7 74.0, GLM-5.3 29.0, DeepSeek V4.1 Flash 22.9, Claude Opus 5.5 0.8 98.5% safety-blocked , GPT-6 Astra 0.0 100% safety-blocked ; safety blocks are scored zero.

CyberGym-E2E-AA scores from Artificial Analysis's leaderboard, fetched 6 Oct 2026, for the public Mistral Large 4 Preview. Refusals count as safety blocks and score zero.

  • Refusals drive the gap. On CyberGym-E2E-AA, AA lists Claude Opus 5.5 (Max, Default Fallback) at 0.8% with 98.5% of tasks safety-blocked, and GPT-6 Astra (Max) at 0% with 100% blocked. AA's launch article names GPT-6 Astra, GPT-6 Sol, Claude Fable 5.1, Claude Opus 5.5 and two Qwen3.8 models as refusing at least 98% of tasks. AA records such refusals as safety blocks and scores them zero, so a top score on this test measures willingness as much as skill. ML4 shows 0 safety blocks. Among models that do not refuse, the lead is narrow: ML4 at 81.7%, then MiMo-V2.6-Pro at 78.6%, GPT-6 Luna at 77.9%, and Grok 4.7 and GLM 5.3 Flash at 74.0%, a 3.1-point margin over second place.
  • The composite tells a different story. The Cyber Index averages three tests: CWE-Bench-AA, DeepsecBench-AA and CyberGym-E2E-AA (launched 28 September 2026 with partners Collinear AI, IBM, NVIDIA and Vercel). Grok 4.7 leads at 56.4, then MiMo-V2.6-Pro at 56.1, GPT-6 Luna at 52.7, GLM 5.3 Flash at 49.9 and ML4 at 49.5. GPT-6 Astra still scores 33.4 and Opus 5.5 28.7, because they do not refuse the other two tests.
  • ML4's weak spot is vulnerability discovery. On DeepsecBench-AA it scores 16.0%, against 26.9% for Grok 4.7. On CWE-Bench-AA it scores 50.8%. (For an open-weight CyberGym result, see Xiaomi's MiMo-V2.6 score.)
  • Still vendor claims: the 93% on Cybench, the "leads open-weight models outside China" line, and that ML4's refusal rate on cyber prompts from JailbreakBench, StrongREJECT and AgentHarm is "higher than all OSS models." That last claim sits oddly beside a reduced-moderation tier, and the final open weights may differ from the preview.

Technical details

  • Size: Mistral's blog says "1 trillion-parameter" with 49 billion active. The Mistral docs page gives 1.05T total, 49B active and a 1.6B vision encoder. We rely on the docs figure for 1.05T. VentureBeat uses one trillion.
  • Architecture: hybrid instruct-and-reasoning mixture-of-experts. Input is multimodal and output is text only (per VentureBeat, quoting Mistral chief scientist Guillaume Lample).
  • Context window: 1M tokens (docs).
  • Price: the docs page shows $0.68 input, $0.07 cached input and $2.09 output per million tokens as the current price, struck against a list price of $1.36, $0.14 and $4.18. The page gives no end date for the discount. The launch blog card and AA use the list price.
  • Against open-weight rivals (AA's listing): DeepSeek V4.1 Flash (Max) is 552B total and 16B active at $0.30 input and $1.20 output per million, with a Cyber Index of 40.8 and 22.9% on CyberGym-E2E-AA. GLM-5.3 (Max) is 753B at $1.40 and $4.40, with an index of 36.4 and 29.0% on CyberGym-E2E-AA. Mistral's own chart shows the same 23 and 29. ML4 at list price ($1.36 and $4.18) costs about GLM-5.3's rate and more than DeepSeek's. AA marks ML4 preview as not open weights for now.
  • Training: from scratch on 3,800 NVIDIA Grace Blackwell GPUs in Mistral's European datacentres (blog). VentureBeat says 4,000.
  • Other cyber claim: 93% of Cybench's 40 challenges (Mistral).
  • Coding: Mistral reports 61.7% on DeepSWE v1.1. VentureBeat notes the live DeepSWE leaderboard shows GLM-5.3 and Kimi K3 near 69%, so the result is competitive but not a clear lead.

What defenders should do

  • Do not read the 82% as general cyber skill. It is one sub-test, and some rivals refuse it outright. Among models that do not refuse, the lead is small (see above). Compare on the full composite, where ML4 is fifth, and on your own tasks.
  • Treat the preview as a hosted service. Do not send proprietary source or incident data to it before you have checked Mistral's data-handling terms.
  • Plan for the weights. If you run a threat model that includes attackers with a capable unrestricted model, assume that the reproduce-and-patch workflow, and the discovery that precedes it, gets cheaper for them. Prioritise patch speed and exposure reduction.
  • If you want the vetted tier, ask Mistral for the eligibility criteria, logging and acceptable-use terms in writing.
  • Evaluate on your own codebases once the weights land. AA's launch article says 31% of passes patch a real crash other than the target, so human review of generated patches still matters.

What is still unclear

  • Whether the exact weights date and the licence terms match VentureBeat's report.
  • Whether 1T (Mistral blog) or 1.05T (docs) is the right total parameter figure. AA lists 1,000B.
  • When Mistral's current discount ends.
  • How partners are vetted for the reduced-moderation tier, and what moderation is removed.
  • Whether the released weights match the preview model, and whether AA's scores hold.

Sources

Keep reading

All latest →
  1. highAI SecurityAWS Patches Critical SageMaker Distribution Flaw That Lets a Project Contributor Hijack Another User's Studio Space5 min
  2. highAI SecurityAWS fixes Loom flaw that gave any network client admin rights on deployments without an identity provider6 min
  3. highAI SecurityMindSearch code-injection flaw (CVE-2026-105135) has a public PoC and no fix6 min
  4. elevatedAI SecurityMCP Fetch Server SSRF (CVE-2026-104120) Has a Public Exploit and No Fix6 min
  5. elevatedAI Securityn8n Queue Mode: Redis Write Access Can Install Any npm Package on Every Instance (CVE-2026-103251)5 min
  6. elevatedAI SecurityLangGraph SDK Auth Bug: `actions=` Ignored on `@auth.on` Handlers (CVE-2026-104873)6 min