A woman views a digital workflow with AI, security checks, and cloud-connected European data systems.
Microsoft has added Mistral Medium 3.5 to Copilot Studio’s external-model picker, giving early-release tenants a new experimental option for building and orchestrating agents. The May 28 announcement matters most to Copilot Studio administrators in Europe: Microsoft’s current regional availability table lists the model as available in Europe without the cross-geo label, while nearly every other listed commercial region carries that warning.

But the practical governance boundary is narrower than Microsoft’s “in-region” framing can suggest. Mistral Medium 3.5 is hosted by Mistral rather than Microsoft, remains classified as experimental as of September 16, and requires customers to accept Mistral’s own terms for data handling. For an IT team, this is a pilot model that can be geographically useful in Europe, not a drop-in extension of Microsoft’s normal data-residency and compliance commitments.

Microsoft detailed the Copilot Studio integration, while Mistral’s own May release describes Medium 3.5 as a 128-billion-parameter model designed for long-running, tool-using coding and productivity work. The combination makes the model a plausible candidate for agents that must execute multi-step workflows, but Microsoft’s current documentation supplies several deployment constraints missing from the original product post.

The European availability claim has an important boundary​

Microsoft’s announcement says EU organizations can keep processing in-region when using Mistral Medium 3.5. Its current Copilot Studio model-availability documentation supports the regional part of that statement: the model is marked “Experimental” in Europe excluding the UK, whereas the model is marked “Experimental (cross-geo)” in Asia, Australia, Brazil, Canada, India, Japan, Korea, Saudi Arabia, Singapore, South Africa, the UK, and the United States.

That designation is significant because Microsoft defines cross-geo as processing or storing data outside an organization’s geographic boundary. In the European region, the absence of that tag indicates that the model is available without that particular cross-region warning.

It does not mean that Mistral processing occurs inside Microsoft’s compliance perimeter. Microsoft’s separate Mistral connection guidance says Mistral models are hosted outside Microsoft and that choosing the provider means sharing organization data with Mistral to operate Copilot Studio features. The same guidance says Microsoft customer agreements, the Data Processing Addendum, Microsoft data-residency commitments, audit and compliance requirements, service-level agreements, and the Customer Copyright Commitment do not apply to the Mistral service.

This is the operational distinction administrators need to put in their approval record. A European tenant may avoid a regional transfer indicated by Copilot Studio’s availability table, but it is still sending data to an external provider operating under its own contractual terms. Microsoft has not published, in the material reviewed here, a specific Mistral processing country, retention period, or a statement that would make the service equivalent to an EU Data Boundary workload under Microsoft’s agreements.

For organizations with data-classification policies built around approved subprocessors, that is a legal and security review—not a routine model-selection change.


Medium 3.5 is still an experimental pilot, four months after launch​

The original Microsoft post described Mistral Medium 3.5 as available in early-release environments and advised against production use. That has not changed in Microsoft’s current model table: the model remains tagged Experimental in every public region where it is listed.

Microsoft’s documentation is explicit about what that label entails. Experimental models are intended for exploration and testing, may have limitations in performance, response quality, latency, availability, and message consumption, and are not recommended for production workloads. Microsoft also warns that an experimental or preview model may time out or become unavailable.

This is more than standard preview boilerplate for an agent platform. An agent powered by a model that is withdrawn or disabled needs a fallback plan. Microsoft says that when an administrator removes an external model after enabling it, agents using it attempt to switch to another suitable internal model. If no suitable internal model exists, the agent errors and its maker must select an internal model.

That makes model portability a design requirement. Teams piloting Mistral Medium 3.5 should retain their evaluation prompts, ground-truth answers, tool-call tests, and success criteria in a form that can be rerun against Microsoft’s managed models. An agent that works only with one experimental external model is difficult to operate, support, or roll back.

Mistral’s release provides a credible reason to test the model rather than deploy it blindly. The company positions Medium 3.5 for structured output, configurable reasoning effort, tool calling, agentic coding, and long-horizon tasks; it says the model has a 256,000-token context window and powers its own Vibe coding agents and Le Chat Work mode. Those are vendor claims, however, and Microsoft has not published Copilot Studio-specific benchmarks showing whether Medium 3.5 improves grounding, tool reliability, latency, or total message consumption against GPT-4.1, GPT-5 Chat, or Claude models in the Copilot Studio harness.

The sensible pilot target is therefore a bounded workflow: a test agent that retrieves approved knowledge, performs a limited set of actions, produces a structured response, and has a human approval point before consequential changes. It is not a good candidate yet for unattended ticket closure, privileged administration, financial decisions, or a customer-facing agent with strict availability requirements.

Enabling it involves more than putting a model in a dropdown​

Microsoft’s announcement correctly describes a two-part control path. An administrator must first allow the Mistral provider in the Microsoft 365 admin center, accepting the provider terms and choosing eligible users or groups. The administrator must then enable external model providers in the Power Platform admin center for the relevant environment or environment group.

Current Microsoft Learn guidance adds two constraints that can explain why the model does not appear after those steps. Because Medium 3.5 is experimental, the environment must permit preview and experimental AI models. And because the model is marked cross-geo outside Europe, those environments also need the setting that allows data movement across regions. Microsoft says that control is managed at the environment level in the Power Platform admin center.

In practice, admins should treat the rollout as a set of policy gates:

  • The Microsoft 365 tenant must allow Mistral, with access scoped to named users or Microsoft Entra ID security groups.
  • The Power Platform environment must allow external large language models.
  • The environment must allow preview and experimental AI models because Medium 3.5 has not reached general availability.
  • Outside the European availability scope, the environment must permit cross-region data movement before the model can be exposed.

The first control is particularly useful because it applies at the provider level across Microsoft Copilot and Copilot Studio experiences. A tenant can therefore start with an evaluation group rather than enabling Mistral broadly for every licensed Copilot user. Microsoft says it can take several hours for either enablement or disablement to take full effect, so emergency revocation should not be modeled as an instantaneous kill switch.

There is also a licensing omission in the short launch post. Microsoft’s Mistral connection documentation says users need a Microsoft 365 Copilot license before they can use Mistral models. A Copilot Studio maker may be able to configure an agent in the intended environment, but the organization still needs to validate whether the eventual user population has the necessary entitlement for the planned experience.

“More model choice” shifts vendor accountability, too​

Mistral Medium 3.5 joins an external-model roster that Microsoft documents as including Anthropic, Mistral, and xAI. The architecture gives Copilot Studio customers model choice while leaving the agent’s orchestration, connectors, lifecycle management, and environment controls in Microsoft’s platform.

That separation is useful: makers can test a model tuned for a specific workload without moving their entire agent implementation to a new application stack. Yet it also separates the place where an agent is built from the party that processes prompts and responses. A Copilot Studio audit trail or governance policy does not, by itself, extend Microsoft contractual protections to Mistral’s service.

Mistral’s standalone API pricing—$1.50 per million input tokens and $7.50 per million output tokens, according to Mistral—is not a reliable estimate of what a Copilot Studio deployment will cost. Microsoft’s documentation says published agents using experimental or preview models are billed at established rates, but the materials do not provide a Medium 3.5-specific Copilot Studio cost comparison. Administrators should measure message consumption and latency in their own tenant before assuming that a lower standalone token price produces a cheaper agent.

The immediate value of the release is choice for controlled evaluation, especially for European organizations that need a non-cross-geo experimental option for agent tests. The concrete limitation is just as clear: Mistral Medium 3.5 remains an externally hosted preview service, so production deployment should wait until Microsoft changes its experimental designation and the organization has accepted the separate data, support, and compliance posture that comes with it.