Palantir Undermines UK Data Sovereignty

Palantir Undermines UK Data Sovereignty

Palantir's MoD Contract Creates Infrastructural Capture

In December 2025, Palantir won a three-year, £240 million Ministry of Defence contract awarded without competitive tender, using a defense and security exemption. This was documented by Progressive International, The Slow AI, Johan Osteyn, and The Small Business Cybersecurity Guy. npj Urban Sustainability found that some NHS data analysts believe their specialized work on the FDP would be lost without continued access to Palantir's specific architecture. LSE blogs, Authors Unavailable, and The Slow AI detail how this technical lock-in translates into "infrastructural capture," where a private corporate layer gains unprecedented influence over essential public services. Reuters, The Guardian, the Science, Innovation and Technology Committee, and Sky News report that lawmakers have labeled the UK government's heavy reliance on a single vendor for critical functions an "unacceptable weakness."

Swiss Military: Palantir Cannot Prevent US Access

The Slow AI and The Small Business Cybersecurity Guy explain that the US CLOUD Act mandates US technology companies disclose data regardless of its physical location, creating a direct legal pathway for US authorities to compel access to data held by companies like Palantir and override UK contractual terms. Progressive International, The Slow AI, Johan Osteyn, and The Small Business Cybersecurity Guy reported that the Swiss military formally concluded in December 2204 that Palantir's proprietary architecture cannot technically prevent US government access to sovereign data. This legal architecture surrounding the US CLOUD Act and UK GDPR creates a structural dependency that compromises UK data sovereignty. The Register documented that the US-UK CLOUD Act agreement was formalized via four specific exchanges of letters signed on October 3, 2019, between US Attorney General William P. Barr and UK Home Secretary Priti Patel, explicitly detailing the legal authorities underpinning this pathway. The Slow AI highlights that intelligence professionals warn the "mosaic effect" allows individual unclassified data points, when combined by Palantir's platforms, to become highly sensitive and reveal critical information.

Dozens of NHS Trusts Avoid FDP Apps

The Guardian revealed that internal usage data showed dozens of NHS trusts had not logged into a single FDP app in the past year, and the "Cancer 360" tool was used by only six out of approximately 200 trusts in its first nine months. Progressive International documented that a former MoD director of industrial strategy joined Palantir nine days after leaving the civil service, months before the company secured a £240 million no-bid contract. The Guardian also found that Palantir hired Peter Mandelson's lobbying firm, Global Counsel, for a monthly retainer exceeding £30,000 to position the company as a government partner. LSE blogs, The Guardian, and Medact observed that these connections coincided with "pandemic opportunism" and questionable procurement practices. The Slow AI and The Small Business Cybersecurity Guy explained that the NHS FDP contract followed an initial £1 emergency contract in 2020 that was extended without competitive tender to £23.5 million and then £11.5 million.

Medact and The Slow AI explain that the interoperability of the Foundry platform, used for the NHS FDP, with the military-focused Gotham software enables data transfer between civilian and military systems, causally facilitating mission creep and pulling public healthcare and social service data into defense and policing logic. This restructures public accountability by subordinating civilian welfare metrics to state security priorities. Medact further states that Palantir's interoperable "drag-and-drop" data architecture between civilian (Foundry) and military/intelligence (Gotham) platforms causally facilitates mission creep, pulling public healthcare and social service data into defense and policing logic. Medact and The Slow AI indicate that this technical linkage allows government departments such as the Home Office and police forces to more easily access confidential patient information from the NHS. Medact and The Small Business Cybersecurity Guy documented that the British Medical Association has opposed the FDP due to Palantir's intelligence ties and human rights record.

German Courts Ruled Palantir Use Unconstitutional

npj Urban Sustainability, Medact, and The Small Business Cybersecurity Guy found that Palantir's predictive policing operated covertly in New Orleans from 2012 to 2018 without immediate public or legislative scrutiny, demonstrating how public oversight mechanisms are largely reactive and structurally hindered. Medact and The Small Business Cybersecurity Guy reported that while German courts ruled the police use of Palantir software unconstitutional in February 2023, halting its deployment, this occurred through judicial rather than legislative action and after entrenchment. Such instances highlight how public oversight mechanisms are largely reactive and structurally hindered, making it difficult to correct flawed deployments before institutional lock-in becomes irreversible. The Guardian reported that early NHS FDP implementation gaps were significant, with dozens of trusts not logging in and clinicians reporting the software was slower than existing technology, yet the £330 million rollout continued.

Palantir and CLOUD Act Threaten UK Data Control

Without immediate intervention, the UK risks permanently ceding control over its most sensitive public data to a foreign commercial entity, a structural dependency arising from its reliance on proprietary systems like Palantir's and its exposure to mandates such as the US CLOUD Act. This structural dependency diminishes the UK government's capacity for independent decision-making and data governance.


Download the full research report (PDF)