Stories

Mistral's European guarantee leaves out agents, file storage and batch jobs

Open-source AI agents broke into 85 Taiwan government accounts in four days, and Mercury now issues corporate cards to AI agents.

By , Senior AI ConsultantEdition of

4stories
3minute read
In This Edition

Agents, file storage and batch jobs are outside Mistral's new European guarantee. Those three are what a company reaches for when it wants AI to do work rather than answer one question, and each of them keeps data after the request ends, which is why they are excluded. Mistral calls such features "stateful".

Mistral charges 10% extra to keep requests inside Europe, and 75% extra for priority processing when the service is busy. The 10% covers the compute step: the model reads the request in Europe and answers there.

For a bank or an insurer, the difference between European hosting and a covered service is a contract term. The EU's operational resilience rules for financial firms, known as DORA, require the contract with a technology supplier to name the regions or countries where the service is provided and where data is processed, including where it is stored, and to require advance notice before the supplier changes any of those locations. Article 30 applies the same words to subcontracted work.

Reading Mistral's documentation, the site The Decoder found that account settings, API keys, billing records and usage statistics can still be processed outside the chosen region, and that Mistral's announcement mentions limited, secured transfers to subcontractors outside it.


Over the first four days of July, AI agents mapped 21 Taiwanese government systems, broke into 85 user accounts and extracted more than 2,500 personnel records. The Israeli security firm Dream published the account on 12 August, after finding the operation documented in a 160 MB archive of 1,395 files left online. From the government network the agents reached Taiwan's nuclear safety agency and at least seven energy companies.

The software was two open-source agent frameworks, Hermes and OpenClaw, that anyone can download. Up to eight sub-agents ran in a single wave, one collecting credentials while another pulled records. The system ranked the possible routes in and reordered them as it learned more, and when one failed, another agent searched the internet and produced a different method. Some of what it opened needed no password at all, interfaces that answered any request reaching them. Dream's chief strategy officer, Amir Becker, said he had never seen such an "end-to-end autonomous attack" against a government target.

Among the material taken were seven single-sign-on client secrets and a full export of every user in one department's system, which is the raw material for a later intrusion.

Anthropic disclosed in November 2025 that a Chinese state-sponsored group had manipulated its Claude Code tool into performing 80% to 90% of the work in intrusions against about 30 organizations that September, among them banks and chemical manufacturers.


Mercury now issues a company card to a piece of software. Its new Spend product lets a business hand an AI agent a virtual card with its own budget, a limit enforced at the point of sale and a list of merchants or merchant categories it may use. Immad Akhund, Mercury's co-founder and chief executive, told Fast Company that customers had already been issuing virtual cards to agents by hand.

The card networks have been building the same thing for more than a year. Mastercard announced Agent Pay on 29 April 2025, with a token bound to one agent, one merchant scope and one consent policy. Visa's Intelligent Commerce followed in May 2025, and Ramp issues limited virtual cards that outside agents can use inside a company's policy, through Visa.

All of it is permission written in advance, because afterwards there is nothing to dispute. A purchase an agent makes inside its limits is not fraud, so no bank reverses it; the company approved that money when it set the limit. At Mercury a person still has to issue each agent card, and the ledger shows which agent spent what.


The model inside Writer's new Palmyra X6 is a Chinese open source model. Writer, whose customers include Accenture and Uber, sells what it built around that base: the retrieval, the tool calls, the routing of each step to a model no larger than the step needs.

The same finished task can cost very different amounts of tokens depending on those choices. Writer's previous model, Palmyra X5, costs $0.60 per million input tokens and $6 per million output tokens, on Amazon's own announcement page for it. GPT-5.4 costs $2.50 and $15, and Claude Sonnet 4.6 $3.00 and $15, in a price comparison published by the cost management firm CloudZero.


THE DAILY BRIEF

Get the next edition in your inbox.

A five-minute read, every weekday morning.

Free forever · Unsubscribe anytime

Share This Brief