Your bank already talks to Mistral. Your doctor, perhaps to a different AI.
A video is going around with a simple, effective line, almost perfectly built to provoke a reaction:
“Mistral is in your bank, in your Doctolib, without telling you.”
The headline lands because it mixes three very current anxieties: invisible AI, personal data and digital sovereignty.
And as often with good viral lines, there is a share of truth, a share of shortcut and a share of confusion.
Yes, Mistral AI, the French artificial intelligence champion, is already present in essential services.
Yes, you can interact with systems powered by Mistral without necessarily knowing it clearly.
Yes, banking, the state, the armed forces and large French corporations already use its models.
But the Doctolib example is more complicated than the video suggests. Microsoft did present a Doctolib consultation assistant built on Azure OpenAI Service and Mistral Large on Azure. But the recent controversy around Doctolib does not name Mistral as the central player. It is mainly aimed at the opacity of the American subcontractors: Microsoft Azure, Anthropic and Google.
And that is exactly where the subject becomes interesting.
The real problem is not only whether Mistral is everywhere.
The real problem is knowing which AI is already hiding behind our essential services, what it processes, where the data goes, and why the end user almost never knows.
Mistral: small to the public, huge behind the scenes
To the general public, Mistral stays relatively discreet.
Its assistant Le Chat exists, its models are respected, but the average user mainly knows ChatGPT, Gemini or Claude.
It would nonetheless be a mistake to think Mistral is a small player.
Founded in 2023 in Paris by Arthur Mensch, Guillaume Lample and Timothee Lacroix, Mistral AI has become, in two years, one of the symbols of European AI.
In September 2025, the company raised 1.7 billion euros. The operation took its valuation to 11.7 billion euros, or roughly 12 billion depending on the rounding used in the French business press.
ASML, the Dutch giant of the lithography machines used in semiconductor manufacturing, invested 1.3 billion euros in that round and holds around 11% of Mistral. It has become its largest shareholder.
That is already a first nuance worth keeping in mind: Mistral is French, but its largest shareholder is Dutch. And its development still depends on a hardware ecosystem largely dominated by Nvidia, and therefore by the United States.
Sovereignty exists, but it is never pure.
”In your bank”: here, it is true
On banking, the video is right.
Hello bank!, BNP Paribas’s online bank, has launched HelloiZ 2.0, a banking assistant powered by Mistral AI’s models.
According to the information published around the launch, HelloiZ 2.0 is deployed to more than a million customers. It can steer users towards 25 types of operation, such as transfers, blocking a card, managing the digital key or certain routine account actions.
The date matters: the public rollout of this new version is announced around 19 January 2026.
By the end of 2026, Hello bank! expects some operations to be executable directly inside the conversation thread. The assistant would then no longer merely answer or guide: it could act.
That is an important shift.
When a banking AI starts to understand a request, steer it towards an operation and soon execute it, it is not only doing customer service. It is entering the banking relationship itself.
And this is not an isolated trial.
BNP Paribas has worked with Mistral since 2023 and extended its partnership in May 2026. The group says it wants to accelerate the deployment of generative AI across several business lines: assistants, compliance, document search, internal functions, investment banking and cybersecurity.
Reuters reports that BNP Paribas uses Mistral in several areas, including virtual assistants for customers in France and Belgium, compliance at BNP Fortis, document extraction and tools for investment banking.
So yes: Mistral is indeed in banking.
Not necessarily in a visible form.
Not necessarily with a displayed logo.
Not necessarily with a clear message saying “this model is Mistral”.
But in the systems, the assistants and the day-to-day uses, it is already there.
Banking is also where AI is already being pointed at the institutions themselves: we covered the moment AI started finding the flaws in banks, and regulators stepped in.
What this changes for the user
The subject is not only technical.
When you talk to your bank, you think you are talking to a banking interface, an adviser or an automated service.
But behind that interface, there can be an AI model.
That model can be French, American, European, hosted locally, used through a cloud, connected to internal tools, restricted to certain tasks, or able to act on operations.
The user almost never sees that whole chain.
They see a button, an answer, a recommendation.
The rest is invisible.
And that is precisely the problem: AI is entering trusted services before the user has really learned to recognise it.
Why banking is adopting Mistral
Banking is almost an ideal terrain for generative AI.
A large banking group constantly handles:
- documents;
- contracts;
- customer emails;
- repetitive requests;
- compliance alerts;
- internal procedures;
- reporting;
- case summaries;
- risk analyses;
- market information;
- cybersecurity incidents.
A well-integrated AI can help read, sort, summarise, search, extract, assist and accelerate.
But banking is also a regulated sector. It cannot plug just any tool into just any data. It needs control, security, traceability, compliance and managed rollouts.
That is exactly Mistral’s niche: selling an AI that is more controllable, more European, more acceptable to sensitive sectors.
Not necessarily better known to the public.
But easier to sell to large institutions.
”In the state”: also true
Mistral is not settling only into banks.
On 17 November 2025, the DINUM (France’s interministerial digital directorate) announced a trial of Mistral AI in the interministerial AI Assistant.
The trial covers 10,000 public servants, across 8 ministries, over 8 months.
The aim is to test an enriched version of a sovereign conversational assistant: drafting emails, summarising documents, translation, help with repetitive tasks.
The important detail is the hosting: the AI Assistant relies on the Mistral Medium 3 model, hosted in France at Outscale, under public supervision. The DINUM emphasises a closed, secured framework, with AI referents inside the participating administrations.
Here, the sovereignty argument is more solid.
We are not only talking about a French model. We are talking about a deployment framework: data in France, controlled infrastructure, public supervision, closed perimeter.
That is exactly what is often missing from the debate: the nationality of the model counts, but the deployment architecture counts just as much.
”At the Caisse des Depots”: also true
On 4 May 2026, the Caisse des Depots announced a collaboration with Mistral AI.
The aim: to pool generative AI solutions across the group, support sovereign digital technology, acquire generative AI licences and set up an “AI Factory”.
The partnership covers many subsidiaries: Bpifrance, CNP Assurances, La Banque Postale, Docaposte, CDC Habitat, Icade, Geopost and several other entities.
Figures of 40,000 licences and 19 subsidiaries have circulated around this partnership. They should be treated as tied to the Caisse des Depots announcement rather than as independently verified. What is certain is that the group publicly owns a strategy of industrialising generative AI internally with Mistral.
Here again, we see the same movement: Mistral is not only trying to win over individual users. It is coming in through institutions, public groups, large networks, the structures that irrigate the French economy.
It is less visible than a consumer app.
But potentially far deeper.
”In the armed forces”: also true
Another important point: Mistral is also documented in defence.
On 8 January 2026, the French defence ministry formalised a framework agreement with Mistral AI.
The agreement, signed on 16 December 2025, covers the use of the startup’s models, software and services inside the ministry’s entities and certain public bodies under its supervision.
LeMagIT specifies that the agreement lets all of the ministry’s armed services, directorates and departments use Mistral’s models, and also bodies such as the CEA, ONERA or SHOM.
Central point: Mistral states that its solutions will be deployed inside French infrastructure, with control over the data and the critical technologies.
Oversight is handled by the ministerial agency for defence artificial intelligence, AMIAD.
In defence, that detail is not cosmetic.
The stake is not only having a high-performing AI. The stake is knowing where it runs, who can access it, who controls the data and under what conditions the models can be customised.
Here too, Mistral is becoming a piece of infrastructure.
”In large companies”: largely true
Mistral is also settling into large corporations.
On its customers page, Mistral highlights references such as ASML, CMA CGM, HSBC, BMW, Stellantis, the European Patent Office and the Austrian Academy of Sciences.
CMA CGM signed a major partnership with Mistral in April 2025 around AI applied to its logistics, maritime, media and customer service activities. The figure of 100 million euros appears in several communications around that partnership.
TotalEnergies also announced a partnership with Mistral in June 2025 to create a joint AI innovation laboratory.
Le Monde and several business sources have also cited contracts or partnerships with groups such as Orange, BNP Paribas, Cisco, Stellantis and Veolia.
So the movement is clear: Mistral does not need to be on every phone to be everywhere.
It is enough for it to be inside the systems of the companies that structure our daily lives.
Transport, banking, energy, industry, administration, defence.
That is less visible than a viral chatbot.
But potentially more important.
The Doctolib example: the shortcut is too simple
This is the most sensitive point.
The video says: “Mistral is in your Doctolib.”
That sentence hits hard. But it needs to be precise.
Microsoft did publish a case study explaining that Doctolib uses Microsoft technologies to build an AI-powered medical assistant, combining Azure OpenAI Service and Mistral Large on Azure.
The study states that consultations can be summarised in 15 seconds. It also explains that the assistant relies in particular on GPT-4o through Azure OpenAI Service, and that Doctolib worked with a chain of models running from Azure OpenAI Service to Mistral Large on Azure.
So yes, Mistral does appear in the public technical history of the Doctolib assistant.
But that is not the whole story.
The recent controversy of June 2026, triggered by Le Canard enchaine and then examined by Next, Clubic and others, is mainly about the American subcontractors listed in Doctolib’s documents: Microsoft Azure, Anthropic and Google Ireland.
Next indicates that Microsoft, Google and Anthropic appear in Doctolib’s contractual documents as downstream subcontractors, in particular for supplying LLMs and for automation tasks.
Doctolib replies that these companies act as technical providers, on instruction, with no right to retain or exploit the data for their own account, nor to train their models on it.
Clubic frames the problem usefully: using an AI to process a request is not the same thing as training it on the data. But the contracts are not public, so the user has to trust Doctolib and its providers.
So the shortcut “Mistral is in your Doctolib” is both partly true and misleading.
Partly true, because Mistral Large on Azure does appear in the Microsoft case study.
Misleading, because the current controversy over health data mainly concerns American AI and cloud giants, along with the readability of Doctolib’s documents.
And above all: if Mistral is used through Azure, that is not exactly the reassuring image of a fully sovereign French AI, isolated from American infrastructure.
Doctolib: the real problem does not need a slogan
Even without reducing the subject to Mistral, the Doctolib file remains major.
An AI consultation assistant can be useful. It can save doctors time, reduce the administrative load, structure the notes, spare them from spending the consultation staring at a keyboard.
Microsoft states that the Doctolib assistant transcribes the consultation in real time and produces a structured summary in 15 seconds. The case study also says the audio and the transcript are destroyed shortly after the doctor has checked the medical summary.
On paper, the benefit is clear: less paperwork, more time for the patient.
But the questions remain heavy:
- does the patient really understand that an AI is involved?
- do they know which model processes the information?
- do they know whether the AI goes through Microsoft, Google, Anthropic, Mistral or another provider?
- do they know where the data travels?
- do they know whether the data is used to improve a model?
- do they know who can technically access it?
- do they know how long the logs exist?
- do they know how to refuse?
- do they know who is responsible if the summary omits or badly rephrases a piece of information?
That is the real subject.
Not only “Mistral or not Mistral”.
The real subject is: who is listening to the consultation?
That last question is not theoretical. When Microsoft measured what models do to ordinary documents, they found that AI can damage a file in silence — and a medical summary is exactly the kind of document nobody re-reads line by line.
What Doctolib answers
Doctolib rejects the idea that its users’ health data would be handed to the AI giants to train their models.
According to Next, Doctolib states that Microsoft, Google and Anthropic act as technical providers, solely on its instructions, within a strict contractual framework, with no right to retain or exploit the data for their own account, and above all no right to use it to train their own models.
Doctolib also states that medical data is hosted exclusively in France and Germany, encrypted at rest and in transit, with keys stored at Eviden, part of the Atos group.
That is an important defence. It has to be quoted.
But the limit has to be restated too: the contracts are not public. The user cannot verify.
And in healthcare, trust should not rest solely on an invisible contractual promise.
Pseudonymised does not mean anonymous
In this kind of debate, one word keeps coming back: anonymisation.
It pays to be precise.
Anonymised data no longer allows a person to be identified. Pseudonymised data masks certain identifiers, but can sometimes be linked back to a person if enough information is cross-referenced.
In healthcare, the risk is higher.
An age, a rare condition, a town, a medical speciality, a consultation date, a treatment or a history can sometimes be enough to re-identify someone under certain conditions.
So when a platform talks about anonymised, pseudonymised, encrypted or provider-processed data, you have to ask exactly what that means.
Who can read it?
When?
For how long?
In which country?
For what purpose?
And under whose oversight?
”Without telling you”: that is the heart of the problem
The viral line mostly holds here: “without telling you”.
Today, the end user rarely knows which AI is working behind a service.
In a bank, you see an assistant, an automated answer, a summary, an internal tool helping an adviser. You do not necessarily see the model.
In a public service, you see an interface, a form, an administrative answer. You do not always know whether Mistral, OpenAI, Google, Anthropic or another model helped produce or process the information.
In healthcare, the subject becomes more sensitive still, because the patient is not only handing over a request. They are handing over symptoms, history, documents, worries, sometimes very intimate data.
The problem is not necessarily that AI is being used.
The problem is that AI is becoming invisible.
And when AI becomes invisible, consent becomes fragile.
Banking, health, public services: AI is settling into essential services, often without the user clearly knowing which model processes their data.
The AI Act will change part of the game
The European AI regulation is progressively imposing transparency obligations.
Article 50 provides in particular that users must be informed when they are interacting with an AI system, with some exceptions. It also sets out marking rules for certain AI-generated or AI-manipulated content.
The date to remember is 2 August 2026: that is when the transparency obligations of Article 50 start becoming a concrete matter for the providers and deployers concerned.
But we have to stay clear-eyed.
Knowing that you are talking to an AI is not the same as knowing:
- which model is being used;
- which country controls the company;
- where the data is processed;
- whether the data is used for training;
- whether a foreign provider is involved;
- whether the answer is checked by a human;
- how long the data stays accessible;
- whether you can refuse without losing the service.
Regulatory transparency is coming.
But it will not necessarily be enough to make what is actually happening understandable.
AI sovereignty: useful, but often oversold
Mistral has become the symbol of European AI sovereignty.
That is understandable.
The company is French. It develops its own models. It offers both open and proprietary models. It can be deployed on controlled infrastructure. It works with sensitive sectors such as banking, administration and defence.
From a sovereignty point of view, that is better than depending entirely on an American model operated from foreign infrastructure.
But the slogan has to be avoided.
Mistral still depends on Nvidia chips.
Mistral has ASML as its largest shareholder, so a powerful European player, but not a French one.
Mistral can be used through cloud environments such as Azure, depending on the case.
And above all: “sovereign” does not mean “automatically transparent”.
A French AI can be used opaquely.
A European AI can process sensitive data without the user understanding what it does.
A French AI used through American infrastructure does not mean the same thing as a French AI hosted in France, under public supervision, with controlled data.
Sovereignty reduces some risks.
It does not remove the need for clear information.
The trap in the debate: French versus American
It would be too quick to sum it up as:
Mistral = good.
OpenAI, Google, Anthropic = danger.
That would be too simple.
The real criterion is not only the model’s nationality.
You have to look at:
- the data being processed;
- the sensitivity level;
- the hosting;
- the providers;
- the encryption;
- the applicable law;
- human access to the data;
- model training;
- the logs;
- the information given to the user;
- the ability to refuse;
- whether or not there is a responsible human.
An American AI in a harmless use can be less problematic than a badly explained French AI in a sensitive one.
And conversely, a French AI deployed on controlled infrastructure can be the better choice in banking, defence or administration.
The real question is less “which country does the AI come from?” than “who controls the use?”
What the video is right to point at
Even if it simplifies the Doctolib example, the video puts its finger on an important truth: AI is entering our services without the end user seeing the switch.
It is not spectacular.
There is not always a big announcement.
Not always a pop-up.
Not always a model name on display.
Not always clear consent.
AI arrives in small touches: a banking assistant, a medical summary, a compliance tool, an internal search engine, an automated reply, a decision aid, a case summary.
And one day, it is everywhere.
Not because you chose “Mistral”.
But because the organisations around you chose it for you.
What the video misses
The video misses an important point: technical presence, real sovereignty and data responsibility must not be confused.
If Mistral is in banking, it can be documented.
If Mistral is in the administration, it can be documented.
If Mistral is in defence, it can be documented.
If Mistral appears in Doctolib’s technical architecture through Azure, that can be said too.
But none of that proves that Doctolib would be a simple example of “sovereign Mistral in healthcare”.
On the contrary, the Doctolib case shows a blurrier chain: Azure OpenAI, Mistral Large on Azure, Google, Anthropic, Microsoft, subcontractors, non-public contracts, European hosting, encryption, Eviden keys, data in transit, consent, possible training of internal models.
The danger is not one single name.
The danger is invisible complexity.
Le Recul’s reading
Mistral is succeeding where too few people are looking: invisible infrastructure.
While the public compares ChatGPT, Claude, Gemini and Le Chat, the real battles are being fought in contracts with banks, ministries, manufacturers, insurers, carriers, energy companies and public services.
That is less spectacular than a viral chatbot.
But it may be more important.
An AI in a banking app can influence the customer relationship.
An AI in a ministry can structure administrative work.
An AI in the armed forces can touch critical data.
An AI in healthcare can listen to or summarise a consultation.
Each time, the question is not only “is it convenient?”
The question is: who controls the AI, who controls the data, and who informs the user?
If you want to see where these models actually stand rather than where their contracts place them, our AI assistant ranking compares them on public, continuously refreshed sources.
What to take away
Mistral is well documented in banking, notably at Hello bank! and BNP Paribas.
Mistral is also documented in the state, with an interministerial trial announced on 17 November 2025 covering 10,000 public servants across 8 ministries.
Mistral is documented in French defence, through a framework agreement signed on 16 December 2025 and formalised in January 2026, with deployment planned on French infrastructure.
Mistral is present in large groups and institutions, notably ASML, CMA CGM, HSBC, Stellantis, TotalEnergies, the Caisse des Depots and others.
On Doctolib, the claim has to be qualified: Microsoft does state that the consultation assistant uses Azure OpenAI Service and Mistral Large on Azure, but the recent controversy is mainly about the American providers Google, Microsoft and Anthropic, and about the clarity of the contractual documents.
The real stake is not “Mistral is spying on us”.
The real stake is wider: AI is becoming invisible inside our essential services.
And when a technology becomes invisible, the user loses the simplest thing of all: knowing who they are talking to, and what they are handing over.
The figure to remember
11.7 billion euros: the valuation Mistral AI reached after its funding round led by ASML.
That figure says something simple: Mistral is no longer only a promising French startup.
It is a strategic piece of European AI.
But the figure does not settle the real question.
The next battle will not only be about the best model.
It will be about transparency: which AI are you already using without knowing it?