
MIAMI, FLORIDA – APRIL 7: Peter Thiel, co-founder of PayPal, Palantir Technologies, and Founders Fund, holds hundred dollar bills as he speaks during the Bitcoin 2022 Conference at Miami Beach Convention Center on April 7, 2022 in Miami, Florida. The worlds largest bitcoin conference runs from April 6-9, expecting over 30,000 people in attendance and over 7 million live stream viewers worldwide.(Photo by Marco Bello/Getty Images)
Getty Images
Britain wants to become a digital state. Increasingly, some of the technology needed to make that ambition possible is being supplied by a relatively small group of private companies.
In June, Parliament’s cross-party Science, Innovation and Technology Committee warned that the UK’s growing reliance on major technology providers including Microsoft, Amazon Web Services and Palantir had created a vulnerability. Palantir received particular attention, with MPs describing its expanding presence in the public sector as an “unacceptable point of weakness” and warning that dependence on a small number of US suppliers could leave Britain exposed to foreign actors.
The issue is how much control Britain still has over the technology it increasingly relies on. Governments have always bought products and services from private companies, but digital infrastructure is different. Complex public services, data systems and operational processes can become difficult and expensive to move once they are built around a particular platform.
Britain therefore needs to retain practical control over the systems on which it increasingly depends.
Palantir Across Government
Palantir is now involved in some of the most sensitive areas of the UK government, with contracts or projects spanning health, defence and financial regulation.
In November 2023, NHS England awarded Palantir Technologies UK the contract for its Federated Data Platform, designed to bring together information used to manage and plan health services.
The contract is often described as being worth £330 million, although the procurement documents give a more precise picture. The awarded value was £182.24 million, while NHS England said expenditure could eventually rise to a forecast £330 million depending on consumption. The procurement notice states that the higher figure is not a committed amount. Seven tenders were received through a competitive dialogue process.
Palantir’s relationship with the Ministry of Defence is much larger. A three year enterprise agreement signed in December 2025 is worth £240.6 million and runs from April 2026 until March 2029. The procurement notice says the technology supports data analytics used for strategic, tactical and live operational decision-making across security classifications and interoperates with systems used by NATO and allied nations.
The contract is part of Palantir’s growing role across the UK government. In September 2025, the government announced a strategic partnership with Palantir under which the company said it would invest up to £1.5 billion in the UK, establish Britain as the European base for its defence business and work with the military on AI-enabled capabilities covering areas including data analysis, intelligence, decision support and targeting. The government also said Palantir would continue supporting implementation of the Ministry of Defence’s Digital and Data Strategy.
The Ministry of Defence told Forbes that all data used and developed in Palantir software deployed across the department remains sovereign and under MoD ownership. It said contractual controls ensure the MoD retains control of the data systems on which Palantir software operates and that no changes can be made without its consent. The department added that the platforms support human decision making rather than replace it.
The MoD did not directly address questions about what alternatives would be available if it chose to move away from Palantir, how easily systems and data could be transferred to another provider, or whether it retains sufficient internal technical capability to replace or rebuild those systems.
The company has also moved into financial regulation. In January 2026, the Financial Conduct Authority awarded Palantir a £375,001 proof-of-concept contract to test enterprise search across structured, semi-structured and unstructured FCA data.
The FCA told Forbes that the 12-week trial is still running and that no decision has been made about any longer-term use of Palantir. It described the project as an evaluation rather than a commitment to a particular supplier or solution.
According to the regulator, it was the highest scoring bidder following a competitive procurement process. During the trial, the company acts as a data processor rather than a controller, while the FCA retains control of the encryption keys. The data is hosted in the UK, cannot be used by Palantir to train its own products and will be deleted when the pilot ends.
These are separate contracts with different organisations, but they show how far Palantir’s role now extends across the UK government.
Its appeal lies in the ability to bring complex datasets together and support decision making across sensitive and operationally important environments.
Palantir rejected the suggestion that its growing role creates a point of weakness for the UK public sector. A Palantir spokesperson told Forbes that organisations working with the company remain in full control of their data, with the company acting as a data processor rather than a controller. The company said customers determine how their data is used and who can access it.
The company also disputed concerns about vendor lock-in, saying interoperability is built into its software and that code can be exported to other platforms with only minor changes. It pointed to the Ministry of Housing, Communities and Local Government and the Cabinet Office as examples of departments that had moved away from its software and taken their data and intellectual property elsewhere “without difficulty”.
Inside the NHS Data Layer
The NHS contract shows how closely Palantir is involved in the operation of the platform.
NHS England remains responsible for the data processed through the Federated Data Platform and says Palantir acts as a processor under its instructions. Its published privacy information says supplier access is controlled, monitored, role-based and limited to the purposes required to operate the system.
In 2026, NHS England disclosed that a small number of Palantir staff have administrative access to the National Data Integration Tenant, which forms part of the Federated Data Platform. NDIT processes a wide range of national health datasets, including Hospital Episode Statistics, emergency care information, diagnostic imaging data, medicines data and information from the Personal Demographics Service.
NHS England says the Palantir staff with administrative access manage the platform’s settings, security and configuration, while other Palantir engineers and third-party suppliers have more limited access to specific projects and datasets. Access is subject to NHS instructions, security clearance, contractual controls and monitoring.
Palantir said this type of administrative access is normal for government technology suppliers and that its access is limited to what the NHS authorises. It said the platform has granular access controls and full auditability, with every access logged.
The company does not own NHS patient data, and its employees are not free to use the information for their own purposes. However, some Palantir engineers require privileged access to keep parts of the infrastructure operating, showing how dependent the system has become on an external supplier. This is the kind of dependency Parliament is now questioning.
The Risk of Vendor Lock-In
The Metropolitan Police offers another example. Earlier this year, the Met sought approval for a proposed £50 million contract to automate parts of intelligence analysis used in criminal investigations. The Mayor’s Office for Policing and Crime refused to approve the award.
City Hall said there were “serious concerns” about how the procurement had been handled and described a “clear and serious breach” of procurement rules because Palantir was the only supplier seriously considered. It also said the Met had failed to demonstrate value for money.
The Met told Forbes that Palantir has been awarded a 12 month contract following a procurement process. It said it is also working with MOPAC on a longer term procurement strategy that will “evaluate the marketplace for these types of technologies” before a supplier is appointed. A Met spokesperson said a “swift resolution to this dispute” would allow the force to “move forward to procure the technology we need”.
The Met said it would not comment on the specific allegations while court proceedings are ongoing. It did not address why Palantir was the only supplier seriously considered in the earlier procurement or whether it accepts MOPAC’s concerns about the process and value for money.
Public bodies need effective competition when buying systems that may become central to their operations. They also need a realistic ability to change suppliers if circumstances change.
Parliament has raised the same concern. The Science, Innovation and Technology Committee said vendor lock-in should not be accepted as inevitable and called on the government to reduce its reliance on a small number of foreign technology suppliers, diversify procurement and develop domestic alternatives in strategically important areas.
On the NHS contract, the committee urged the government to consider using the 2027 break clause and either develop an alternative capability internally or find another UK provider.
The test is whether the government could replace an important supplier without disrupting the service built around its technology. If replacing a platform becomes prohibitively difficult, legal ownership of the underlying data does not necessarily mean the government holds the leverage.
NHS England did not respond to a request for comment.
The Revolving Door
People and expertise also move between the public sector and the technology companies supplying it.
Damian Parmenter, formerly Director General for AUKUS at the Ministry of Defence, left government in July 2025 and took up a role as Senior Counsellor at Palantir. The Advisory Committee on Business Appointments reviewed the overlap between his former responsibilities and Palantir’s work and imposed restrictions on the appointment.
Laurence Lee, a former Foreign Office Director General and Second Permanent Secretary at the Ministry of Defence, also joined Palantir as a geostrategic adviser to its chief executive.
The committee said Lee had overseen digital transformation across defence, security and resilience, had met Palantir while in public service and had been involved in work connected to a Ministry of Defence contract with the company. It identified a perceived risk that his appointment might be associated with decisions taken while he was in public service, while also recording the department’s reasons for rejecting that interpretation.
Officials with specialist knowledge are naturally attractive to companies working in the same field. Technical knowledge, procurement experience and an understanding of public systems are valuable to both sides.
As more technology is bought from external suppliers, dependence can extend beyond software to the expertise needed to understand and manage it.
Who Holds the Leverage?
UK policy has placed growing emphasis on sovereign technological capability. Its Digital and Technologies Sector Plan says changing geopolitical conditions have increased the importance of strategic capabilities, including sovereign AI, cyber security, semiconductors and advanced connectivity. Its Digital Standards Strategy also links AI, cyber security and advanced connectivity to UK security and sovereignty.
Technological sovereignty does not require the government to develop every database, cloud service or analytical tool in-house. Private companies often have technology and expertise that would take the public sector considerable time and money to recreate. Using an American supplier does not necessarily mean Britain has lost control of its systems.
The UK needs enough technical understanding of the technology it relies on to set the rules around its use, move its data safely, maintain credible alternatives and replace a supplier when circumstances change.
Parliament’s warning suggests those safeguards are not strong enough. Palantir is the most visible example because of the scale and sensitivity of the systems it supports, but the committee also raised concerns about reliance on Microsoft and Amazon Web Services.
The Department for Science, Innovation and Technology did not respond to questions about supplier dependence, vendor lock-in and how the government defines technological sovereignty in practice.
As Britain becomes more digital, its reliance on these suppliers will become harder to ignore. The government’s technology strategy supports working with business while building more strategic capability in the UK.
Britain’s digital infrastructure should not become dependent on a handful of private suppliers. That means maintaining competitive procurement, credible alternatives and enough technical expertise to change providers when needed.
If public bodies cannot realistically switch suppliers, dependence stops being a procurement problem and becomes a question of control.