• Latest
  • Trending
  • All
Official Mistral AI announcement thumbnail for Shieldstral, with the model name set over the Mistral gradient artwork.

Shieldstral 1.0: the 3B guard model that ties a 20B

5 August 2026
Answer card stating that Ternary Bonsai 2 27B, released by PrismML on 17 September 2026 under Apache 2.0, packs Qwen3.8 27B into 5.95 gigabytes at 1.72 bits per weight, keeps 98.2 percent of the 14-benchmark average, about 75 percent on SWE-bench Verified and Terminal-Bench 2.1, and needs PrismML's llama.cpp fork to run.

Does Bonsai 2 27B really keep 98% of Qwen3.8 in 5.95 GB?

20 September 2026
Answer card stating that Jev 1.13 from TypeSafe AI is a decision model in early access since 15 September 2026 that returns typed probabilities instead of text, priced at 42 dollars per billion input tokens with output tokens free, answering in 70 to 500 milliseconds, with a 64K token request budget, text input only, and a documented list of things it does badly, including counting and dates.

Jev 1.13 bills $42 a billion tokens, and it can’t count

19 September 2026
Answer card stating that Qwen3.8-Omni-Flash launched on 17 September 2026 as an API only model on Alibaba Cloud Model Studio, taking text, images, audio and video in a 1M token context and returning text only, priced at 0.15 dollars per million input tokens for every modality and 0.47 dollars per million output tokens in the international regions, with no open weights published and the Qwen-Live Harness GitHub repository returning 404.

Qwen3.8-Omni-Flash bills audio at $0.15 and ships no weights

18 September 2026
Answer card stating that on 15 September 2026 AWS said it is unable to restore access to resources and data hosted exclusively in the Middle East Bahrain region me-south-1 and in the mec1-az2 zone of the UAE region, because the damage spanned multiple Availability Zones and exceeded what multi-AZ services are designed to withstand.

AWS can’t restore me-south-1, six months after the drone strikes

17 September 2026
Answer card stating that Google released Gemini 3.8 Live and Gemini 3.8 Live Extended Thinking on 15 September 2026 at 3 dollars per million audio input tokens and 12 dollars out, that the thinking model requires asynchronous tools, and that Artificial Analysis scores it 82.6 on its Speech to Speech Quality Index.

Gemini 3.8 Live Extended Thinking rejects any tool that blocks

16 September 2026
Answer card summarising the Atria Dawn Preview release: 744B GLM-5.2 base, MIT licence, 1.5 TB BF16 and 756 GB FP8 checkpoints, 256K context, top on five of sixteen benchmark rows and trailing on SWE-bench Pro.

Atria Dawn Preview is 744B under MIT, and the BF16 weighs 1.5 TB

15 September 2026
Answer card stating that OpenAI released the Agents API in public beta on 10 September 2026 with no separate fee, billed through model tokens, tool calls and hosted sandbox time, with a choice of OpenAI hosted, self hosted or partner sandboxes, US only data residency and no Zero Data Retention support.

OpenAI’s Agents API has no fee, no ZDR and a one hour sandbox clock

14 September 2026
Answer card: Sakana Fugu Max at $2 and $6 per million tokens, Fugu Ultra v2 unchanged at $5 and $30, and Sakana saying Ultra v2 scores without Fable 5 or GPT-6 Astra in its pool.

Fugu Max costs $2 and $6 while Fugu Ultra v2 runs without Fable 5

13 September 2026
Answer card stating that DeepSeek released DeepSeek-V4.1-Flash on 10 September 2026 as a 552 billion parameter mixture of experts model with a new causal encoder decoder architecture that activates 8 billion parameters on input and 16 billion on output, with native vision, a one million token context and MIT licensed weights, that the API model name is now deepseek-flash at 0.15 dollars per million input tokens and 0.60 dollars per million output tokens off peak, and that DeepSeek announced V4 Pro would be routed to V4.1-Flash from 14 September and reversed that on 11 September.

DeepSeek V4.1-Flash arrived, and the V4 Pro retirement lasted a day

12 September 2026
Answer card stating that Cognition released SWE-2 on 10 September 2026, a coding model post-trained from Kimi K3, scoring 50.0 percent on FrontierCode 1.1 Main against 50.9 percent for Claude Fable 5.1 and 27.3 percent on Terminal-Bench 4 against 55.8 percent, available only inside Devin.

SWE-2 trails Fable 5.1 by one point, and by 28 on Terminal-Bench 4

11 September 2026
Answer card for Meta Muse, free to 100 million tokens a week then $20 a month, launched 8 September 2026 for United States adults only, running in a dedicated per user virtual machine.

Does Meta Muse do enough to earn your inbox and a card on file?

9 September 2026
Answer card stating that the public download pages for the VMware Virtual Disk Development Kit on developer.broadcom.com began returning 404 errors on 25 August 2026 with no announcement or deprecation notice, that Broadcom support tells customers the kit is no longer available for use or download, and that release lines 7.0.3.1, 8.x and 9.x are all affected.

Broadcom pulled VDDK 8.0 and 9.0, and the 404 is the only notice

8 September 2026
  • About
  • Contact
  • Privacy
  • Legal
Sunday, September 20, 2026
  • Login
Packet Nebula
  • Home
  • Articles
    • Security
    • Network
    • Dev
    • Sysadmin
    • SEO
    • Email & DNS
  • Tools
    • Network tools: free, fast, no signup
    • Security tools: free, fast, no signup
    • Developer tools: free, fast, no signup
    • Sysadmin tools: free, fast, no signup
    • SEO tools: free, fast, no signup
    • Email & DNS tools: free, fast, no signup
  • Download
  • About
No Result
View All Result
Packet Nebula
No Result
View All Result
Home Dev

Shieldstral 1.0: the 3B guard model that ties a 20B

by stephane
5 August 2026
in Dev
0
Official Mistral AI announcement thumbnail for Shieldstral, with the model name set over the Mistral gradient artwork.
494
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter

Your moderation queue doesn't care which taxonomy a model was trained on. It cares whether that screenshot breaks the rule your legal team wrote last Tuesday. That's the pitch behind Shieldstral 1.0, which Mistral put on Hugging Face on 4 August 2026 under Apache 2.0: a 3B classifier that reads text and images, takes your policy as a plain English question at inference time, and answers with a calibrated probability rather than a fixed category label. It fits in 16 GB of VRAM. Mistral says it matches guard models close to seven times its size, its own paper words that claim more carefully, and we went and read both.

The short answer

Mistral released Shieldstral 1.0 on 4 August, an open-weights classifier that moderates text and images against a policy you write in plain English at inference time. It matches a 20B guard model on text safety and beats a 7B on images, from a checkpoint that fits on one card. What it won’t give you is a reason for any given verdict.

3Bparams, Apache 2.0 weights
16 GBVRAM, one GPU, BF16
84.9 F1text average, same as a 20B
Official Mistral AI announcement thumbnail for Shieldstral, with the model name set over the Mistral gradient artwork. Image: Mistral AI, announcement thumbnail from the Shieldstral release post.

Guard models normally ship with their opinions baked in. Shieldstral ships with a slot where yours goes.

Answer card: Mistral released Shieldstral 1.0 on 4 August 2026, a 3B multimodal safety classifier on Hugging Face under Apache 2.0 that takes a plain English policy and a yes or no question and returns a calibrated probability, running in 16 GB of VRAM.
Open weights, a short licence, and a policy you edit instead of retrain.

The trick is that moderation became a yes or no question

Most guard models learn a taxonomy. Violence, self-harm, whatever the vendor decided mattered, fixed at training time. Shieldstral does something narrower and, honestly, smarter: it treats every moderation job as one binary question-answering problem. The prompt has three labelled blocks. <Instruct> sets the moderator persona, <Query> holds the question you want answered, <Document> holds the content under judgement.

That structural choice is why the training set could be so big. Mistral consolidated roughly 54.1M samples with wildly different taxonomies into one framework, because once every dataset becomes yes-or-no, incompatible label schemes stop mattering. Around 45.2M of those are open-source text, 4.4M are synthetic contrastive pairs built specifically to teach the model to discriminate between policies rather than memorise categories, and 4.5M are multimodal.

The output side is where it gets cheap. The model answers with one token, so you cap generation at one and read the top log probabilities to recover a probability between 0 and 1. No reasoning trace, no JSON to parse.

Terminal figure: serving Shieldstral 1.0 with vLLM on a single 16 GB GPU, then classifying content with max_tokens set to 1 and logprobs enabled, returning yes with a probability of 0.9713.
Serve it with one command, then read the probability behind a single token.

Same job it does for prompt moderation, it does for response moderation, refusal detection and prompt-response pairs. You change the <Query> line. That’s the whole configuration surface.

Read the benchmark line twice

Mistral’s blog says Shieldstral outperforms guard models up to seven times its size. The paper abstract says “matches or outperforms models nearly 7x its size”, and that hedge is doing real work.

On text safety the average is 84.9 F1. GPT-OSS-Safeguard-20B, the strongest text baseline in Mistral’s own table, also scores 84.9. That’s a tie from a model roughly a sixth the size, which is a genuinely good result and is not the same sentence as beating it. The clear win is multimodal, 83.8 against 77.6 for OmniGuard-7B. And on policy adaptability, the metric this entire design exists to serve, Shieldstral takes 91.3 against 94.1 for the 20B. It loses that one.

Bar chart of average F1 scores: Shieldstral 84.9 on text versus GPT-OSS-Safeguard-20B at 84.9, and Shieldstral 83.8 on images versus OmniGuard-7B at 77.6.
A tie on text, a lead on images, a loss on adaptability. All three measured by Mistral.

Per-benchmark numbers on the model card are strong where you’d expect and softer where the data is messy: 99.4 on HarmBench prompts, 88.1 on WildGuardTest, 84.1 on ToxicChat. Multimodal runs 97.7 on VLGuard and 81.8 on UnsafeBench. Nobody outside Mistral has published an independent run yet, so treat all of it as vendor-reported.

When you’d actually reach for it

Here’s the awkward part nobody in the coverage mentioned. Mistral already gives away text moderation: mistral-moderation-2603 is listed on the API pricing page at no cost. If your problem is English text and you don’t mind sending it to Paris, that endpoint was already free before Thursday.

So the case for Shieldstral is narrower and clearer than “better guard model”. Three things push you toward it. Images, because the free endpoint is text-only. Data that can’t leave your building, which is the reason a healthcare platform on Hacker News flagged local deployment as the whole point. And a policy that’s yours rather than a vendor’s, especially the awkward domain-specific rules that never map onto anyone’s stock taxonomy.

For pricing sanity, the Ministral 3B backbone costs 0.10 dollars per million tokens either way on Mistral’s API, which is roughly what you’re replacing with your own electricity. Nothing has been published for shieldstral-1-0 itself, which sits in Public Preview.

What Mistral left fuzzy

Two parameter counts are in circulation right now. The blog and the Hugging Face repo say 3B, the API model card says 3.8B. Our reading, from the config, is that 3.8B counts the Pixtral vision encoder bolted onto the Ministral 3B backbone while 3B counts the language model alone. Mistral hasn’t said that anywhere we could find, so we’re inferring it.

Language coverage moves too. The model card lists 12 languages, the paper evaluates 28 across PolyGuard and RTP-LX, and Mistral admits in its own limitations that prompt classification trails on Arabic and Indonesian. If you moderate in either, benchmark before you commit.

Checklist of what Mistral published about Shieldstral 1.0 and what remains unclear, covering the Apache 2.0 licence, the 16 GB hardware bar, the conflicting 3B and 3.8B parameter counts, and the language coverage.
Two green lines you can build on, two amber ones to verify yourself.

The licence, at least, is boring in the best way. Apache 2.0, no excluded territories, no revenue threshold, no attribution banner in your UI. That is a sharper contrast than it used to be, given MiniMax shipped H3 last week under a licence naming the EU and the US as excluded territories, and given how much work the phrase open weights is doing in current release notes.

One last thing worth planning around if you publish in Europe. Article 50 of the AI Act went live on 2 August, and a moderation classifier is exactly the sort of component that ends up load-bearing in a transparency workflow. A model that emits a number and no reason is a thin foundation for a decision you may have to defend. I’d keep humans on the ambiguous band for now, and I say that as someone who’d otherwise be happy to automate it.

Sources

Announcement and specifications from Mistral AI, the Shieldstral-1.0-3B model card on Hugging Face, and the Mistral API model card. Benchmark tables, training data volumes and the stated limitations come from the technical report, arXiv 2607.25857, submitted 28 July 2026. Pricing for the existing moderation endpoint is from the Mistral API pricing page. Practitioner reaction from the Hacker News discussion, and additional reporting from Unite.AI.

Frequently asked questions

What is Shieldstral 1.0?

It is an open-weights safety classifier Mistral released on 4 August 2026 under Apache 2.0, at mistralai/Shieldstral-1.0-3B on Hugging Face. It takes a moderation policy written as a plain language yes or no question, plus the text or image you want judged, and returns a calibrated probability. Because the policy lives in the prompt rather than in the training data, you change what it enforces by editing a string.

Is Shieldstral free to use commercially?

The weights are Apache 2.0, which is a genuine open source licence with no territory restriction, no revenue ceiling and no obligation to display the model name in your product. That is a real contrast with several recent open-weights releases. On the hosted API the model id is shieldstral-1-0 and it sits in Public Preview, with no price published at the time of writing.

What hardware do I need to run Shieldstral?

One GPU with 16 GB of VRAM runs it in BF16, which puts it inside a single mid-range card rather than a multi-GPU node. Mistral recommends up to 32k of context. The quickest path is vLLM: install it, then run vllm serve mistralai/Shieldstral-1.0-3B with a max model length of 32768. llama.cpp and Transformers are both documented on the model card as well.

Is Shieldstral actually better than a 20B guard model?

On Mistral's own numbers it ties rather than wins. Shieldstral averages 84.9 F1 on text safety, the same figure Mistral reports for GPT-OSS-Safeguard-20B. It leads clearly on multimodal safety at 83.8 against 77.6 for OmniGuard-7B, and it loses on policy adaptability at 91.3 against 94.1. The achievement is the size, not the ceiling.

Can Shieldstral explain why it flagged something?

No, and that is the main practical objection. The model emits a single token, so what you get is a probability, not a reasoning trace you could show a user who appeals a decision. If you need an audit trail, you either pair it with a larger model on the flagged subset or keep humans on the ambiguous band.

Tags: ailocal-aimistralmoderationnewsopen-source
Share198Tweet124
stephane

stephane

  • Trending
  • Comments
  • Latest
Answer card: Proton Lumo 2.0 is private by policy, not by locality. Saved history is locked so even Proton cannot read it, but the prompt is decrypted on a Proton EU server to answer it, then forgotten.

Proton Lumo 2.0 review: how private is it, really?

3 September 2026
The Agentic Coding section of the official Hy4 preview benchmark appendix published by Tencent, a table comparing Hy3 and Hy4 preview against DeepSeek V4 Pro 0813, Qwen 3.8 Max, GLM 5.3, Kimi K3, GPT 5.6 Sol and Claude Opus 5 across SWE-bench Multilingual, SWE-bench Pro, DeepSWE, three SWE Atlas tasks, SWE-Marathon, Terminal-Bench 2.1, NL2Repo-Bench, CyberGym, ProgramBench, PostTrainBench and Harbor-Index.

Tencent’s 770B Hy4 tops one benchmark row in 46

3 September 2026
Answer card: Qwen 3.7 Max is API-only and cannot run locally yet; the open Qwen models (Qwen 3.6 27B, qwen3:8b to 32b) run offline via Ollama.

Qwen 3.7 local: what you can actually run offline

22 June 2026
Answer card: JWTs are not encrypted, anyone can read them; the signature proves who issued the token, not who may read it.

Are JWTs encrypted? No, and the difference will bite you

0
Answer card: a random 8 character password falls in under 2 hours offline, while 16 random characters hold for 1.4 trillion years at the same speed.

How long does it take to crack a password in 2026?

0
Answer card: three DNS records decide if your mail lands or bounces; SPF lists allowed senders, DKIM signs messages, DMARC sets the failure policy.

SPF, DKIM and DMARC explained: the records your email needs

0
Answer card stating that Ternary Bonsai 2 27B, released by PrismML on 17 September 2026 under Apache 2.0, packs Qwen3.8 27B into 5.95 gigabytes at 1.72 bits per weight, keeps 98.2 percent of the 14-benchmark average, about 75 percent on SWE-bench Verified and Terminal-Bench 2.1, and needs PrismML's llama.cpp fork to run.

Does Bonsai 2 27B really keep 98% of Qwen3.8 in 5.95 GB?

20 September 2026
Answer card stating that Jev 1.13 from TypeSafe AI is a decision model in early access since 15 September 2026 that returns typed probabilities instead of text, priced at 42 dollars per billion input tokens with output tokens free, answering in 70 to 500 milliseconds, with a 64K token request budget, text input only, and a documented list of things it does badly, including counting and dates.

Jev 1.13 bills $42 a billion tokens, and it can’t count

19 September 2026
Answer card stating that Qwen3.8-Omni-Flash launched on 17 September 2026 as an API only model on Alibaba Cloud Model Studio, taking text, images, audio and video in a 1M token context and returning text only, priced at 0.15 dollars per million input tokens for every modality and 0.47 dollars per million output tokens in the international regions, with no open weights published and the Qwen-Live Harness GitHub repository returning 404.

Qwen3.8-Omni-Flash bills audio at $0.15 and ships no weights

18 September 2026
  • About
  • Contact
  • Privacy
  • Legal

Copyright © 2026 Stephane Cardon.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Articles
    • Security
    • Network
    • Dev
    • Sysadmin
    • SEO
    • Email & DNS
  • Tools
    • Network tools: free, fast, no signup
    • Security tools: free, fast, no signup
    • Developer tools: free, fast, no signup
    • Sysadmin tools: free, fast, no signup
    • SEO tools: free, fast, no signup
    • Email & DNS tools: free, fast, no signup
  • Download
  • About

Copyright © 2026 Stephane Cardon.