• Latest
  • Trending
  • All
Official Mistral AI announcement thumbnail for Shieldstral, with the model name set over the Mistral gradient artwork.

Shieldstral 1.0: the 3B guard model that ties a 20B

5 August 2026
Answer card stating that Mullvad announced on 3 September 2026 that it is shutting down its public encrypted domain name system servers on 2 November 2026 and sponsoring the Quad9 Foundation instead, with 194.242.2.2 and its five sibling addresses all going away, and virtual private network customers unaffected.

Mullvad’s DNS servers go dark on 2 November, and Quad9 blocks no ads

5 September 2026
OpenAI announcement image for GPT-6 Astra, a spiral galaxy of white, blue and amber points of light curling around a bright core on a near black star field.

GPT-6 Astra lists at $10 and $50, 2.5x what GPT-5.6 Sol costs

6 September 2026
Google's official announcement image for the release, reading Introducing Gemini 3.8 Flash and 3.8 Flash Cyber in black type over a pale blue background with a blurred white chevron and the four colour Gemini spark below.

Gemini 3.8 Flash keeps the price and the 1 January cliff

3 September 2026
Answer card stating that Anthropic announced Enterprise Frontier Safeguards on 1 September 2026, that activity data used for misuse monitoring moves into cloud storage the customer controls under the customer own encryption keys, that Anthropic charges nothing for the feature while the cloud provider bills storage and egress, and that the phased rollout starts later in autumn 2026 with interim zero data retention on Fable 5 and Fable 5.1 for eligible customers.

Anthropic moves retention into your own cloud, for 30 days

3 September 2026
Official Google diagram of a client connection in three numbered steps: a DNS lookup with a query and an address, a TLS ClientHello and ServerHello, then a content exchange with a website. A callout on the DNS step reads 25% of global web traffic is now protected by encrypted DNS, and a callout beside an Android phone on the ClientHello step reads Android 17 supports ECH GREASE by default.

Android 17 hides the SNI, not your DNS or destination

3 September 2026
Still frame from the Claude Fable 5.1 launch video showing model-designed protein binders in orange docked against twelve grey target proteins, rendered as ESMFold2 structure predictions.

Claude Fable 5.1 breaks forced tool use, cuts cache 75%

1 September 2026
Answer card stating that on 31 August 2026 the European Commission designated ChatGPT a Very Large Online Search Engine under the Digital Services Act, the first conversational AI service classified that way, because it answers user prompts and queries including by searching the web, with OpenAI having declared roughly 159.1 million average monthly users in the European Union for ChatGPT search.

The EU now calls ChatGPT a very large search engine

3 September 2026
Answer card stating that on 31 August 2026 the Department of War added OpenAI ChatGPT Mil and Starshield AI Grok for Government to the GenAI.mil portal alongside Google Gemini, all three accredited at Impact Level 5 for Controlled Unclassified Information, with 1.7 million unique users onboarded out of roughly 3 million eligible personnel, and ChatGPT Mil currently serving GPT-5.4 Terra with GPT-5.6 Terra said to be rolling out.

ChatGPT Mil and Grok reached IL5 on GenAI.mil

3 September 2026
Answer card stating that Anthropic opened a research preview of the Model Hardware Standard on 27 August 2026, standardising the driver layer between an operating system and a laboratory instrument with read and write primitives plus discovery and safety limits, reachable through MCP as well as a command line and code files, with no public specification published.

Anthropic’s Model Hardware Standard is gated, and sits under MCP

3 September 2026
Official Cohere key art for the Parse 5 launch: the Cohere mark and the wordmark Parse with a superscript 5 in white, centred on a soft out of focus gradient of deep blue, violet and amber curves.

Cohere Parse 5 is $1.50 per 1,000 pages, on three of five dimensions

3 September 2026
Title card from the OpenAI announcement video: a man sits on a blue sofa in a loft with tall windows and potted plants, a laptop open on the coffee table in front of him, with the words WebMCP in ChatGPT in large white type across the lower left.

WebMCP in ChatGPT needs GPT-5.6 Sol or Terra

3 September 2026
The Agentic Coding section of the official Hy4 preview benchmark appendix published by Tencent, a table comparing Hy3 and Hy4 preview against DeepSeek V4 Pro 0813, Qwen 3.8 Max, GLM 5.3, Kimi K3, GPT 5.6 Sol and Claude Opus 5 across SWE-bench Multilingual, SWE-bench Pro, DeepSWE, three SWE Atlas tasks, SWE-Marathon, Terminal-Bench 2.1, NL2Repo-Bench, CyberGym, ProgramBench, PostTrainBench and Harbor-Index.

Tencent’s 770B Hy4 tops one benchmark row in 46

3 September 2026
  • About
  • Contact
  • Privacy
  • Legal
Sunday, September 6, 2026
  • Login
Packet Nebula
  • Home
  • Articles
    • Security
    • Network
    • Dev
    • Sysadmin
    • SEO
    • Email & DNS
  • Tools
    • Network tools: free, fast, no signup
    • Security tools: free, fast, no signup
    • Developer tools: free, fast, no signup
    • Sysadmin tools: free, fast, no signup
    • SEO tools: free, fast, no signup
    • Email & DNS tools: free, fast, no signup
  • Download
  • About
No Result
View All Result
Packet Nebula
No Result
View All Result
Home Dev

Shieldstral 1.0: the 3B guard model that ties a 20B

by stephane
5 August 2026
in Dev
0
Official Mistral AI announcement thumbnail for Shieldstral, with the model name set over the Mistral gradient artwork.
491
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter

Your moderation queue doesn't care which taxonomy a model was trained on. It cares whether that screenshot breaks the rule your legal team wrote last Tuesday. That's the pitch behind Shieldstral 1.0, which Mistral put on Hugging Face on 4 August 2026 under Apache 2.0: a 3B classifier that reads text and images, takes your policy as a plain English question at inference time, and answers with a calibrated probability rather than a fixed category label. It fits in 16 GB of VRAM. Mistral says it matches guard models close to seven times its size, its own paper words that claim more carefully, and we went and read both.

The short answer

Mistral released Shieldstral 1.0 on 4 August, an open-weights classifier that moderates text and images against a policy you write in plain English at inference time. It matches a 20B guard model on text safety and beats a 7B on images, from a checkpoint that fits on one card. What it won’t give you is a reason for any given verdict.

3Bparams, Apache 2.0 weights
16 GBVRAM, one GPU, BF16
84.9 F1text average, same as a 20B
Official Mistral AI announcement thumbnail for Shieldstral, with the model name set over the Mistral gradient artwork. Image: Mistral AI, announcement thumbnail from the Shieldstral release post.

Guard models normally ship with their opinions baked in. Shieldstral ships with a slot where yours goes.

Answer card: Mistral released Shieldstral 1.0 on 4 August 2026, a 3B multimodal safety classifier on Hugging Face under Apache 2.0 that takes a plain English policy and a yes or no question and returns a calibrated probability, running in 16 GB of VRAM.
Open weights, a short licence, and a policy you edit instead of retrain.

The trick is that moderation became a yes or no question

Most guard models learn a taxonomy. Violence, self-harm, whatever the vendor decided mattered, fixed at training time. Shieldstral does something narrower and, honestly, smarter: it treats every moderation job as one binary question-answering problem. The prompt has three labelled blocks. <Instruct> sets the moderator persona, <Query> holds the question you want answered, <Document> holds the content under judgement.

That structural choice is why the training set could be so big. Mistral consolidated roughly 54.1M samples with wildly different taxonomies into one framework, because once every dataset becomes yes-or-no, incompatible label schemes stop mattering. Around 45.2M of those are open-source text, 4.4M are synthetic contrastive pairs built specifically to teach the model to discriminate between policies rather than memorise categories, and 4.5M are multimodal.

The output side is where it gets cheap. The model answers with one token, so you cap generation at one and read the top log probabilities to recover a probability between 0 and 1. No reasoning trace, no JSON to parse.

Terminal figure: serving Shieldstral 1.0 with vLLM on a single 16 GB GPU, then classifying content with max_tokens set to 1 and logprobs enabled, returning yes with a probability of 0.9713.
Serve it with one command, then read the probability behind a single token.

Same job it does for prompt moderation, it does for response moderation, refusal detection and prompt-response pairs. You change the <Query> line. That’s the whole configuration surface.

Read the benchmark line twice

Mistral’s blog says Shieldstral outperforms guard models up to seven times its size. The paper abstract says “matches or outperforms models nearly 7x its size”, and that hedge is doing real work.

On text safety the average is 84.9 F1. GPT-OSS-Safeguard-20B, the strongest text baseline in Mistral’s own table, also scores 84.9. That’s a tie from a model roughly a sixth the size, which is a genuinely good result and is not the same sentence as beating it. The clear win is multimodal, 83.8 against 77.6 for OmniGuard-7B. And on policy adaptability, the metric this entire design exists to serve, Shieldstral takes 91.3 against 94.1 for the 20B. It loses that one.

Bar chart of average F1 scores: Shieldstral 84.9 on text versus GPT-OSS-Safeguard-20B at 84.9, and Shieldstral 83.8 on images versus OmniGuard-7B at 77.6.
A tie on text, a lead on images, a loss on adaptability. All three measured by Mistral.

Per-benchmark numbers on the model card are strong where you’d expect and softer where the data is messy: 99.4 on HarmBench prompts, 88.1 on WildGuardTest, 84.1 on ToxicChat. Multimodal runs 97.7 on VLGuard and 81.8 on UnsafeBench. Nobody outside Mistral has published an independent run yet, so treat all of it as vendor-reported.

When you’d actually reach for it

Here’s the awkward part nobody in the coverage mentioned. Mistral already gives away text moderation: mistral-moderation-2603 is listed on the API pricing page at no cost. If your problem is English text and you don’t mind sending it to Paris, that endpoint was already free before Thursday.

So the case for Shieldstral is narrower and clearer than “better guard model”. Three things push you toward it. Images, because the free endpoint is text-only. Data that can’t leave your building, which is the reason a healthcare platform on Hacker News flagged local deployment as the whole point. And a policy that’s yours rather than a vendor’s, especially the awkward domain-specific rules that never map onto anyone’s stock taxonomy.

For pricing sanity, the Ministral 3B backbone costs 0.10 dollars per million tokens either way on Mistral’s API, which is roughly what you’re replacing with your own electricity. Nothing has been published for shieldstral-1-0 itself, which sits in Public Preview.

What Mistral left fuzzy

Two parameter counts are in circulation right now. The blog and the Hugging Face repo say 3B, the API model card says 3.8B. Our reading, from the config, is that 3.8B counts the Pixtral vision encoder bolted onto the Ministral 3B backbone while 3B counts the language model alone. Mistral hasn’t said that anywhere we could find, so we’re inferring it.

Language coverage moves too. The model card lists 12 languages, the paper evaluates 28 across PolyGuard and RTP-LX, and Mistral admits in its own limitations that prompt classification trails on Arabic and Indonesian. If you moderate in either, benchmark before you commit.

Checklist of what Mistral published about Shieldstral 1.0 and what remains unclear, covering the Apache 2.0 licence, the 16 GB hardware bar, the conflicting 3B and 3.8B parameter counts, and the language coverage.
Two green lines you can build on, two amber ones to verify yourself.

The licence, at least, is boring in the best way. Apache 2.0, no excluded territories, no revenue threshold, no attribution banner in your UI. That is a sharper contrast than it used to be, given MiniMax shipped H3 last week under a licence naming the EU and the US as excluded territories, and given how much work the phrase open weights is doing in current release notes.

One last thing worth planning around if you publish in Europe. Article 50 of the AI Act went live on 2 August, and a moderation classifier is exactly the sort of component that ends up load-bearing in a transparency workflow. A model that emits a number and no reason is a thin foundation for a decision you may have to defend. I’d keep humans on the ambiguous band for now, and I say that as someone who’d otherwise be happy to automate it.

Sources

Announcement and specifications from Mistral AI, the Shieldstral-1.0-3B model card on Hugging Face, and the Mistral API model card. Benchmark tables, training data volumes and the stated limitations come from the technical report, arXiv 2607.25857, submitted 28 July 2026. Pricing for the existing moderation endpoint is from the Mistral API pricing page. Practitioner reaction from the Hacker News discussion, and additional reporting from Unite.AI.

Frequently asked questions

What is Shieldstral 1.0?

It is an open-weights safety classifier Mistral released on 4 August 2026 under Apache 2.0, at mistralai/Shieldstral-1.0-3B on Hugging Face. It takes a moderation policy written as a plain language yes or no question, plus the text or image you want judged, and returns a calibrated probability. Because the policy lives in the prompt rather than in the training data, you change what it enforces by editing a string.

Is Shieldstral free to use commercially?

The weights are Apache 2.0, which is a genuine open source licence with no territory restriction, no revenue ceiling and no obligation to display the model name in your product. That is a real contrast with several recent open-weights releases. On the hosted API the model id is shieldstral-1-0 and it sits in Public Preview, with no price published at the time of writing.

What hardware do I need to run Shieldstral?

One GPU with 16 GB of VRAM runs it in BF16, which puts it inside a single mid-range card rather than a multi-GPU node. Mistral recommends up to 32k of context. The quickest path is vLLM: install it, then run vllm serve mistralai/Shieldstral-1.0-3B with a max model length of 32768. llama.cpp and Transformers are both documented on the model card as well.

Is Shieldstral actually better than a 20B guard model?

On Mistral's own numbers it ties rather than wins. Shieldstral averages 84.9 F1 on text safety, the same figure Mistral reports for GPT-OSS-Safeguard-20B. It leads clearly on multimodal safety at 83.8 against 77.6 for OmniGuard-7B, and it loses on policy adaptability at 91.3 against 94.1. The achievement is the size, not the ceiling.

Can Shieldstral explain why it flagged something?

No, and that is the main practical objection. The model emits a single token, so what you get is a probability, not a reasoning trace you could show a user who appeals a decision. If you need an audit trail, you either pair it with a larger model on the flagged subset or keep humans on the ambiguous band.

Tags: ailocal-aimistralmoderationnewsopen-source
Share196Tweet123
stephane

stephane

  • Trending
  • Comments
  • Latest
Answer card: Proton Lumo 2.0 is private by policy, not by locality. Saved history is locked so even Proton cannot read it, but the prompt is decrypted on a Proton EU server to answer it, then forgotten.

Proton Lumo 2.0 review: how private is it, really?

3 September 2026
Google's official announcement image for the release, reading Introducing Gemini 3.8 Flash and 3.8 Flash Cyber in black type over a pale blue background with a blurred white chevron and the four colour Gemini spark below.

Gemini 3.8 Flash keeps the price and the 1 January cliff

3 September 2026
Answer card stating that Anthropic announced Enterprise Frontier Safeguards on 1 September 2026, that activity data used for misuse monitoring moves into cloud storage the customer controls under the customer own encryption keys, that Anthropic charges nothing for the feature while the cloud provider bills storage and egress, and that the phased rollout starts later in autumn 2026 with interim zero data retention on Fable 5 and Fable 5.1 for eligible customers.

Anthropic moves retention into your own cloud, for 30 days

3 September 2026
Answer card: JWTs are not encrypted, anyone can read them; the signature proves who issued the token, not who may read it.

Are JWTs encrypted? No, and the difference will bite you

0
Answer card: a random 8 character password falls in under 2 hours offline, while 16 random characters hold for 1.4 trillion years at the same speed.

How long does it take to crack a password in 2026?

0
Answer card: three DNS records decide if your mail lands or bounces; SPF lists allowed senders, DKIM signs messages, DMARC sets the failure policy.

SPF, DKIM and DMARC explained: the records your email needs

0
Answer card stating that Mullvad announced on 3 September 2026 that it is shutting down its public encrypted domain name system servers on 2 November 2026 and sponsoring the Quad9 Foundation instead, with 194.242.2.2 and its five sibling addresses all going away, and virtual private network customers unaffected.

Mullvad’s DNS servers go dark on 2 November, and Quad9 blocks no ads

5 September 2026
OpenAI announcement image for GPT-6 Astra, a spiral galaxy of white, blue and amber points of light curling around a bright core on a near black star field.

GPT-6 Astra lists at $10 and $50, 2.5x what GPT-5.6 Sol costs

6 September 2026
Google's official announcement image for the release, reading Introducing Gemini 3.8 Flash and 3.8 Flash Cyber in black type over a pale blue background with a blurred white chevron and the four colour Gemini spark below.

Gemini 3.8 Flash keeps the price and the 1 January cliff

3 September 2026
  • About
  • Contact
  • Privacy
  • Legal

Copyright © 2026 Stephane Cardon.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Articles
    • Security
    • Network
    • Dev
    • Sysadmin
    • SEO
    • Email & DNS
  • Tools
    • Network tools: free, fast, no signup
    • Security tools: free, fast, no signup
    • Developer tools: free, fast, no signup
    • Sysadmin tools: free, fast, no signup
    • SEO tools: free, fast, no signup
    • Email & DNS tools: free, fast, no signup
  • Download
  • About

Copyright © 2026 Stephane Cardon.