Category: Power & Accountability

UK politics, government contracts, lobbying, transparency, procurement, Power to the Minions, and holding systems to account.

  • Nothing to See Here: The NHS, Mythos, and the Closing of the Code

    Nothing to See Here: The NHS, Mythos, and the Closing of the Code

    On Monday 11 May 2026, hundreds of NHS computer code projects will go dark. Not deleted. Just hidden. The repositories will still exist, the same engineers will still maintain them, but the public will no longer be able to see them.

    The deadline is in seven days. Teams that want to apply for an exemption have until close of play tomorrow to make their case to the Engineering Board. Most won’t make it.

    The reason given, in an internal memo dated 29 April 2026 and leaked to the former head of open technology at NHSX, is that an artificial intelligence model called Mythos can read code very fast.1 Mythos was announced by an American AI company called Anthropic about a week before the memo was issued.2

    I want to talk about this. Not because I expect you to care about NHS code repositories specifically, but because what this story is actually about is much bigger than that. It’s about whether the public is allowed to see what’s being built with public money. And the timing, which I’ll get to, is suspicious enough that I think it’s worth a few minutes of your day.

    Editorial cartoon of a hospital corridor with a large bank of light switches on the wall labelled NHS REPOS. A figure in a suit is flipping the switches off one by one. Behind them, smaller figures are crowding in to watch through a small window before each light goes out.
    The view from outside.

    What’s actually happening, in plain English

    Open source code is code that anyone can read. The author publishes it on a website like GitHub, and anyone in the world can look at it, copy it, learn from it, or check whether it does what its authors say it does.

    The NHS publishes hundreds of code projects this way. Most of it is genuinely boring: design templates for NHS websites, code that publishes statistics, tools that help with vaccination schedules, the standard way the NHS labels and structures its own data. Some of it is more interesting: research code, tools developed during the pandemic, frontends for patient services. None of it, on the public’s view, is the kind of secret that would let a hacker bring down a hospital.

    For more than a decade, UK government policy has been that code paid for with public money should be available for the public to see. This isn’t an opinion that a couple of tech enthusiasts hold. It’s written into the Technology Code of Practice3, the government Service Manual4, the NHS Service Standard5, and the Department of Health’s Data Saves Lives6 strategy.

    The reasons for this policy are simple. Public money funded the work, so the public has a right to see it. Other NHS teams, other government departments, other countries can reuse the code, which saves money. And, crucially, the code being public is one of the few ways that ordinary people, journalists, and MPs can actually check what the NHS has built and how. Without it, everything is “trust us, it works.”

    Editorial cartoon of a large featureless black box sitting on a desk. There are no buttons, no screen, no labels. A small brass plaque on the front simply reads TRUST US, IT WORKS. Three people stand around the box looking at it: an NHS nurse, a journalist holding a notebook, and a member of the public holding a tax return. They all have identical baffled expressions. Behind the box, partly visible through a small gap, a tangle of colourful wires snakes out of the back of the box and disappears off the edge of the desk.
    The new transparency.

    What was issued on 29 April was an internal memo, formally numbered SDLC-8, telling every NHS England engineering team that all public code repositories must go private by Monday 11 May 2026. Teams must declare any need for an exemption to the Engineering mailbox by close of play 6 May. The memo overrides every one of the policies I just mentioned by internal decree.

    The story they’re telling

    The reason given in the memo is rapid advancements in AI models capable of large-scale code ingestion, inference, and reasoning. The memo specifically names Mythos, an AI model from Anthropic that the company announced in April 2026 with much fanfare and a partner programme called Project Glasswing2.

    Anthropic’s own framing is that Mythos is so good at finding software vulnerabilities that the company isn’t releasing it to the general public. They’re partnering with major tech firms (Amazon, Google, Microsoft, Apple, JPMorgan, the Linux Foundation, and around 40 others) to use it defensively, and they’re giving away $100 million in usage credits and $4 million in cash to open source security organisations.

    The press coverage was breathless. The cybersecurity industry obsessed. The American security writer Bruce Schneier, who is generally considered one of the most measured voices in the field, said in his initial commentary7: “This is very much a PR play by Anthropic, and it worked. Lots of reporters are breathlessly repeating Anthropic’s talking points, without engaging with them critically.”

    Whether or not Mythos is genuinely as scary as Anthropic says, this is what NHS England has cited as the reason for closing its repositories.

    Why the Mythos story doesn’t hold up

    I am not a cybersecurity expert. I am, however, capable of reading. So is Terence Eden, the former head of open technology at NHSX, who wrote about this in late April. His first post8 on the Mythos question, written before the SDLC-8 memo dropped, made the points that any honest analysis would make.

    The code has already been read. Anthropic, which trained Mythos, has been hoovering up open source code for years. So has every other AI company. So have hundreds of digital archives and individual hoarders. If Mythos can find vulnerabilities in the NHS code by reading it, Mythos has already read it. Closing the door now does nothing about a horse that left the field years ago.

    Editorial cartoon of a wide open farm gate with a small wooden sign hanging on it that reads NHS REPOS. The field beyond the gate is completely empty. A figure in a smart suit is carefully attaching a brand new heavy-duty padlock to the gate with a slightly proud expression. In the far distance, a horse is grazing happily in someone else's field, wearing a small label that reads ALREADY SCRAPED.
    Closing the gate.

    The code being closed source is not actually safer. The same AI tools work just as well on closed source software. They can analyse the binaries that run on a server. They can probe a live website. The premise that “if our code is private, AI can’t find bugs in it” is, on its face, not how any of this works.

    Neither the UK’s AI Safety Institute9 nor the NCSC10 has recommended that organisations close their open source code in response to Mythos. NHS England has done it on its own initiative, citing a threat that the country’s actual security experts have not endorsed.

    The biggest piece of evidence sits in living memory. The NHS COVID Contact Tracing app, the most scrutinised piece of NHS software in living memory, used by tens of millions of people, the target of every hostile cyber actor on the planet, was open sourced the day it launched. It produced exactly zero security incidents from the code being public. NHS England’s own engineers know this because they made that decision deliberately at the time.

    Eden has filed a Freedom of Information request11 asking NHSE for the technical reasoning behind SDLC-8. We will see what comes back.

    In the meantime, the simplest version of where we are: the official reason makes no technical sense, contradicts the country’s actual security expertise, and overrides at least five existing pieces of UK government policy on the open web. So the question isn’t “is Mythos really that scary?” The question is what story actually fits the facts.

    The story that actually fits

    On 22 December 2025, Digital Health News reported that NHS England had quietly deleted its open source policy pages12 from its website. No announcement. No consultation. The pages just disappeared. The clinician Marcus Baw, who has been writing about NHS digital policy for years, raised the alarm.

    NHS England’s official line was that the deletion was a routine clean-up exercise from the 2021 reorganisation when NHSX was folded into NHSE. A different NHSE source told the same journalist the real reasons were “security concerns and because NHSE does not believe it has the capacity to maintain” open source software. Note the date: 22 December 2025. Mythos didn’t exist yet. It would be announced four months later.

    Editorial cartoon of a hospital noticeboard. One side is labelled OFFICIAL REASONS and pinned with a small note saying Just a tidy-up. The other side is labelled QUESTIONS NOBODY ASKED and is overflowing with notes pointing in every direction. A cleaner walks past pretending not to notice.
    Just a tidy-up.

    The same week the policy pages came down, three other things happened. The Guardian published an investigation into UK Palantir contracts after MPs raised security concerns. Health Service Journal reported that Palantir’s £330 million NHS Federated Data Platform was reaching only a handful of trusts. And Health Service Journal reported that an AI tool inside that same platform was at the centre of a regulatory row.

    I want to be careful here. I cannot prove these are connected. I have no document showing “we are removing the open source policy because the Palantir contract is in trouble.” That kind of paper trail rarely exists, and when it does, it doesn’t survive long.

    What I can say is that the December 2025 retreat from open source policy preceded Mythos by four months. Mythos is the public justification for what NHS England is doing in May 2026. It is not the reason the direction of travel changed. The direction had already changed, in the same week as a Palantir story.

    And Mythos arrived just in time to provide an excuse that sounded better than “we don’t think we can keep up the policy.”

    Why this connects to Palantir

    I have written a few times about Palantir. The first time was the Seeing Stones piece13, on how a CIA-funded surveillance company ended up running the NHS’s data. The second was Land and Expand14, on how the same company moved from the NHS into the Financial Conduct Authority. The third was The Man Who Sold England’s Data15, on the man doing all the dinners and handshakes that made it happen. If any of this is new to you, those pieces are the background.

    The Federated Data Platform is the thing in the NHS that Palantir runs. It is a £330 million contract, signed in November 2023, designed to pull NHS data from across hospitals and other services into one system that helps with things like waiting lists, theatre scheduling, and discharge planning. The contract is controversial for many reasons: the company’s other clients (US Immigration and Customs Enforcement, the Pentagon, the Israeli Defence Forces, various intelligence agencies), the contract structure (which Liberal Democrat MP Martin Wrigley described in Parliament as “a permanent lock-in” with “no software, not one line”16 remaining with the NHS at the end), and the question of whether NHS data opt-outs even apply to it.

    Palantir’s own code was never on NHS GitHub. It was never going to be. Palantir is a private US company and its software is proprietary. You can’t see it.

    What was on NHS GitHub was the surrounding infrastructure: the data pipelines feeding the FDP, the integration code, the ways the NHS has had to bend its own systems to plug into Palantir’s. That code is what tells you, if you read it carefully, what’s actually being shared, with whom, and how. It’s the wiring diagram.

    Closing the repos doesn’t change the data Palantir gets. It changes what the public can see about how the wiring works.

    The Palantir contract is at its weakest point right now

    This bit matters because it explains why the timing isn’t just suspicious in the abstract. It’s suspicious in a very specific way.

    The Federated Data Platform is in trouble. By February 2025, NHS England was claiming 96 trusts (about 40%) had “signed up” to the platform. When Corporate Watch FOI’d them17, it turned out that only 34 trusts (about 15%) were actually using it. The other 62 had just “signalled their intent.”

    The reason most trusts haven’t adopted it is not technical mystery. The trusts have explained, repeatedly and on the record. Leeds Teaching Hospitals wrote to NHS England saying: “From the descriptions we have of these FDP products we believe we would lose functionality rather than gain it by adopting them.” Greater Manchester’s health authority wrote that there was nothing in the FDP that “exceeds the NHS Greater Manchester local capability.” NHS staff at multiple trusts have refused to use the system on ethical grounds, given Palantir’s other clients.

    The British Medical Association passed a motion against the FDP at its 2025 AGM. In February 202618 it went further and told doctors to limit their engagement with the platform, citing concerns about Palantir’s role in providing software to ICE.

    The Good Law Project’s “Say No to Palantir” campaign has had around 50,000 patients19 write to their local trust boards opposing the platform. A coalition of public interest groups, including the Good Law Project, Privacy International, Just Treatment, Corporate Watch, and Amnesty International, published a briefing through Medact20 in March 2026 urging trust boards not to adopt.

    The Department of Health quietly gave KPMG an £8 million contract to “promote adoption” of the platform. Take a moment with that. Eight million pounds of consultancy money to convince frontline NHS staff to use software the NHS has already paid £330 million for.

    Editorial cartoon of an NHS hospital corridor. On the left, a tired-looking nurse and doctor are leaning against a wall holding cups of tea. In front of them, three smartly dressed consultants in identical suits are standing in a row, holding flipchart easels. Each easel has a different bright marker drawing on it. The first reads ENGAGEMENT, the second reads JOURNEY, and the third just has a smiley face. A briefcase open on the floor between the consultants is overflowing with banknotes. Above the consultants is a small handwritten note pinned to the wall reading EIGHT MILLION POUNDS. The nurse is looking at the doctor with one raised eyebrow. The doctor is staring directly at the viewer.
    Engagement journey.

    And the break clause in the Palantir contract is live. Health Minister Zubir Ahmed has confirmed that the option to terminate the seven-year contract in early 2027 is, as he put it, “being weighed up as a possible option.”21

    So a contract that was sold to the public as transformative is, in fact, being rejected by the people who use it, the people whose data goes into it, and the trusts being told to adopt it. The political pressure is at its highest point ever. The break clause is being seriously considered. And right at this moment, the public’s main tool for scrutinising the NHS data architecture, the open source repositories, is being switched off.

    I am not going to sit here and tell you that’s definitely the reason. I genuinely don’t know what the reason is. What I’d say is: if you wanted to reduce public scrutiny of a specific contract at a specific moment, this is what doing that would look like.

    And there’s the small matter of NHS England being abolished

    Speaking of timing. On 13 March 2025, in a speech in the House of Commons22, the Health Secretary Wes Streeting announced that NHS England, the arms-length body that has run the NHS in England since 2013, would be abolished. The workforce is being halved from around 13,000 to 6,500. Functions are being absorbed back into the Department of Health and Social Care, which Streeting runs directly. The Institute for Government23 has been tracking the chaos of the transition for over a year.

    What this means in practice is that political accountability for NHS data decisions, including everything Palantir does, is shifting from an arms-length body to a politician. Wes Streeting personally, in due course, becomes the joint data controller for everything in the FDP. Decisions that used to sit with NHS England’s board now sit with the Secretary of State.

    This is the institutional context in which a memo overriding fifteen years of open source policy gets issued with seven days’ notice. NHS England is half-shut. Its leadership has been replaced. Its workforce is being cut. The Engineering Board issuing SDLC-8 is doing so during the most disorganised period in NHS England’s existence.

    If you wanted to make a major policy change with as little scrutiny as possible, this is when you’d do it.

    Why this matters even if you don’t care about code

    Most people don’t care about code. Most people shouldn’t have to. The reason this matters to people who don’t write software for a living is that open source is one of the few mechanisms that lets ordinary people see what’s been built with their money.

    If a small charity wants to know how the NHS records something. If a journalist wants to check whether a contract is actually doing what was promised. If an MP’s office wants to understand whether a system exists at all. If a researcher wants to study the digital infrastructure of British healthcare. If another country wants to learn from what works. All of that has, until now, been possible because the code was visible.

    When you turn it off, you don’t just affect developers. You blind everyone who funds the NHS. You also break the mechanism that prevents lock-in to a single supplier, because once nobody outside the NHS knows how the integration works, replacing the supplier becomes an act of archaeology rather than engineering.

    The Palantir contract is the textbook case for why open source matters in public infrastructure. Martin Wrigley made the point in Parliament in April: “All the specially written software and intellectual property rights belong to the supplier. The contract delivers no software, not one line, just a subscribed service; a permanent lock-in; a single point of failure.” The opposite of that, structurally, is open source. NHS open source has been one of the few practical bulwarks against the kind of contract that leaves the NHS owning nothing at the end. That bulwark is what’s being switched off on Monday.

    Editorial cartoon of a low stone wall labelled OPEN SOURCE separating two areas. On one side is a tidy garden with NHS staff working at desks, public visitors strolling around. On the other side is a polished glass tower marked PROPRIETARY with no windows. A figure in a hard hat is removing the wall stone by stone. A small sign next to them reads Temporary.
    Temporary, apparently.

    What’s going right (because there’s quite a lot)

    I always promise to leave readers with something to be hopeful about, and on this one there’s a lot to be hopeful about.

    The trusts have already been refusing the FDP. This is the most important thing in the story and it should be celebrated. Greater Manchester. Leeds. Guy’s and St Thomas’. UCLH. Royal Free. Sheffield Teaching Hospitals. Nottingham. Birmingham. Frimley. The biggest and best-resourced digital teams in the NHS have looked at the platform, looked at the company, looked at the contract, and said no. They are why the contract is in trouble. Their refusal has done more to protect the NHS data architecture than any minister.

    NHS staff are leaking. The SDLC-8 memo got to Eden because multiple people inside NHS England independently sent it to him. That’s not one disgruntled engineer. That’s a workforce. The institution is half-shut down, but the conscience of the people inside it is wide awake.

    The doctors are organising. The BMA’s February 2026 motion telling doctors to limit FDP engagement is a serious institutional act. So is the Medact briefing. So is the open letter. So is the Hansard debate.

    The patients are organising. Fifty thousand letters to trust boards is a real number. The Good Law Project’s “Say No to Palantir” campaign has built a coalition with Foxglove, Privacy International, Just Treatment, Corporate Watch, the United Tech and Allied Workers Union, Amnesty International and Keep Our NHS Public.

    The break clause is live. The Health Minister has confirmed it. Whether the government activates it is up to the political pressure between now and early 2027, and the political pressure is what gets generated by exactly this sort of public attention.

    The code is backed up. Eden and a network of volunteers have already mirrored every NHS open source repository. The licences allow it. If the originals go private on Monday, the public version persists somewhere on the open internet.

    And the petition exists. keepthingsopen.com is the campaign asking NHS England to reverse SDLC-8.

    Useful resources

    What you can do today

    If you have ten minutes:

    Sign the keepthingsopen.com petition. Email your MP through writetothem.com and tell them that you don’t want your NHS code closed off, especially given who’s now sitting inside it. Forward this article, or one of Eden’s two24 on the same subject, to anyone you know who works in tech, government, or healthcare. They will recognise what’s happening.

    If you have an hour, read the Palantir series on this site, beginning with The Seeing Stones13. The pieces about the FCA and Louis Mosley sit alongside it. None of this story is in isolation. It is a piece of a much bigger picture about what’s happened to British public infrastructure in the last few years.

    If you have actual power inside the NHS or DHSC and you’re reading this: you can refuse. The trusts already are. The doctors already are. The data analysts already are. You’re allowed to be one of them.

    Closing

    The reason Palantir is called Palantir is that the founders are Lord of the Rings fans. In Tolkien, a palantir is a seeing stone, an object that lets its holder see distant places and watch from afar. The dark joke of the company name has been pointed out for years: a surveillance company named after a magical surveillance object. Their seeing stones watch us.

    What’s been happening, less remarked on, is that the public had its own seeing stone. The open source policy was a way for ordinary people to look back. To see how the systems we paid for actually worked. To check the wiring. To watch the watchers, in a small but real way.

    On Monday, the public seeing stone goes dark. Theirs stays on. That isn’t, in my view, an accident of timing. And it certainly isn’t temporary in any meaningful sense, regardless of what the press release says, because the policies it overrides are not coming back without a fight.

    Editorial cartoon of two crystal-ball-like seeing stones sitting on plinths in a dim, slightly mystical-looking room with stone walls. The stone on the left is labelled OURS on a brass plaque on its plinth. It is dark and unlit, with a small dust sheet half-draped over it and a sign hanging from it that reads OUT OF ORDER. The stone on the right is labelled THEIRS on its plaque. It is glowing brightly with a soft inner light, and faint outlines of NHS hospital buildings, hospital beds, and a person's medical chart can be seen swirling inside it. A figure in a smart suit stands between the two stones, polishing the glowing one with a soft cloth and looking pleased. The dark stone behind them is gathering cobwebs.
    One sees. One doesn’t.

    The fight, fortunately, is already happening. It’s happening in the trusts that refuse to plug in. In the doctors saying no. In the engineers leaking memos. In the patients writing letters. In the MPs reading Hansard speeches. In a former NHS open source lead with an FOI form and a website. In the people who have already mirrored every single repository before the deadline.

    The view from outside might be about to go dark. The people inside aren’t going anywhere.

    References

    1. Terence Eden’s blog: NHS Goes To War Against Open Source, with leaked SDLC-8 memo image, 1 May 2026. https://shkspr.mobi/blog/2026/05/nhs-goes-to-war-against-open-source/
    2. Anthropic: Project Glasswing, official launch page, April 2026. https://www.anthropic.com/glasswing
    3. Gov.uk: Technology Code of Practice, point 3 “Be open and use open source”. https://www.gov.uk/guidance/the-technology-code-of-practice
    4. Gov.uk Service Manual: Making source code open and reusable. https://www.gov.uk/service-manual/technology/making-source-code-open-and-reusable
    5. NHS Service Manual: Service Standard point 12, Make new source code open. https://service-manual.nhs.uk/standards-and-technology/service-standard-points/12-make-new-source-code-open
    6. Department of Health and Social Care: Data Saves Lives strategy, commitment 601. https://www.gov.uk/government/publications/data-saves-lives-reshaping-health-and-social-care-with-data/data-saves-lives-reshaping-health-and-social-care-with-data
    7. Bruce Schneier: On Anthropic’s Mythos Preview and Project Glasswing, 13 April 2026. https://www.schneier.com/blog/archives/2026/04/on-anthropics-mythos-preview-and-project-glasswing.html
    8. Terence Eden’s blog: Does Mythos mean you need to shut down your Open Source repositories?, 24 April 2026. https://shkspr.mobi/blog/2026/04/does-mythos-mean-you-need-to-shut-down-your-open-source-repos/
    9. UK AI Safety Institute: Evaluation of Claude Mythos Preview’s cyber capabilities, April 2026. https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capabilities
    10. NCSC: Why cyber defenders need to be ready for frontier AI, 2026. https://www.ncsc.gov.uk/blogs/why-cyber-defenders-need-to-be-ready-for-frontier-ai
    11. WhatDoTheyKnow: Eden FOI request to NHS England re SDLC-8 guidance. https://www.whatdotheyknow.com/request/information_relating_to_guidance_2
    12. Digital Health News: NHS England quietly removes open source policy web pages, 22 December 2025. https://www.digitalhealth.net/2025/12/nhs-england-quietly-removes-open-source-policy-web-pages/
    13. chloegeorge.co.uk: The Seeing Stones: How a CIA-Funded Surveillance Company Ended Up Running the NHS, March 2026. https://chloegeorge.co.uk/palantir-nhs-seeing-stones/
    14. chloegeorge.co.uk: Land and Expand: How Palantir Swam Into the FCA’s Data Lake, March 2026. https://chloegeorge.co.uk/palantir-fca-data-lake/
    15. chloegeorge.co.uk: The Man Who Sold England’s Data (And Got a Seat on the Board), April 2026. https://chloegeorge.co.uk/louis-mosley-palantir-uk/
    16. Hansard: NHS Federated Data Platform debate, 16 April 2026, including Martin Wrigley MP intervention. https://hansard.parliament.uk/commons/2026-04-16/debates/2FDCA71C-D0C1-4738-BEE8-A4BDA311DB99/NHSFederatedDataPlatform
    17. Corporate Watch: FOI requests reveal Palantir’s NHS FDP rollout failures, August 2025. https://corporatewatch.org/foi-requests-reveal-palantirs-nhs-fdp-rollout-failures/
    18. Digital Health News: BMA calls for NHS doctors to reject using the FDP, February 2026. https://www.digitalhealth.net/2026/02/bma-calls-for-nhs-doctors-to-reject-using-the-fdp/
    19. The Lowdown NHS: Palantir, the controversy, the contracts and the campaign, April 2026. https://lowdownnhs.info/topics/accountablility/palantir-the-controversy-the-contracts-and-the-campaign/
    20. Medact: Briefing on Palantir Technologies and NHS Data Systems, March 2026. https://www.medact.org/2026/resources/briefings/briefing-palantir-fdp/
    21. TechRadar: Palantir could be forced to exit NHS after pushback from staff, MPs, unions and pressure groups, April 2026. https://www.techradar.com/pro/security/nhs-users-report-that-it-is-awful-to-use-palantir-could-be-forced-to-exit-nhs-after-pushback-from-staff-mps-unions-and-pressure-groups-over-federated-data-platform
    22. Gov.uk: NHS England, Health and Social Care Secretary’s statement, 13 March 2025. https://www.gov.uk/government/speeches/nhs-england-health-and-social-care-secretarys-statement
    23. Institute for Government: One year on from the decision to abolish NHS England, 26 March 2026. https://www.instituteforgovernment.org.uk/comment/one-year-abolish-nhs-england
    24. Terence Eden’s blog: collected coverage on the NHS open source closure. https://shkspr.mobi/blog/tag/open-source/
  • The Man Who Sold England’s Data (And Got a Seat on the Board)

    The Man Who Sold England’s Data (And Got a Seat on the Board)

    I’ve written about Palantir twice now. The first time, I traced how a CIA-funded surveillance company ended up running the NHS’s data. The second time, four days later, I followed the same company into the Financial Conduct Authority, the body that regulates every bank and financial firm in the UK. Both pieces were about how a single American company has quietly embedded itself into one British public institution after another, until removing it becomes almost impossible.

    This one is about the person who made that happen. Because somebody had to do all the dinners and the handshakes and the parliamentary appearances, and in Palantir’s case that somebody has a name, a column in a political magazine, and a grandfather who looms somewhat larger in British history than most people’s grandfathers do.

    His name is Louis Mosley. And he’s been having quite a year.

    Who is Louis Mosley?

    Louis Mosley is 43, London-based, and holds the title of Executive Vice President of Palantir Technologies. He leads the company’s UK and European operations. In practical terms, this means he is the person who turned a £1 pandemic contract into roughly £900 million of public sector deals across health, defence, policing, and financial regulation in about six years. If you work in sales, that’s the kind of performance that gets you a glass award at the annual conference. If you work in public accountability, it’s the kind of performance that gets you a parliamentary inquiry. He appears to have got both.

    He is also the grandson of Oswald Mosley, leader of the British Union of Fascists. His father is Oswald Alexander Mosley, Oswald’s son by his second wife Diana Mitford. His uncle was Max Mosley, the former president of the FIA, the body that governs Formula 1. Tatler profiled him as part of its “meet the Mitfords” feature, noting that “politics has run through his family for generations.” It’s a family that tends to generate footnotes.

    Here is everything that is publicly known about Louis Mosley’s life before Palantir: he graduated from the University of Oxford in 2006. Before joining Palantir, he “worked in finance.” That’s it. No school named. No Oxford college. No subject studied. No detail about what “finance” means, which bank or which fund. No visible LinkedIn profile. No Wikipedia page. For a man who gives evidence to parliamentary select committees, writes for the Spectator, appears on the BBC, runs nearly a billion pounds of UK government contracts, and sits on the MoD’s industry board, his pre-Palantir biography is three facts long. Think about how unusual that is. One prime minister couldn’t eat a bacon sandwich. Another one’s naughtiest confession was running through wheat. Another allegedly put part of himself into a dead pig. A chancellor got fined for birthday cake. An energy secretary went to prison over speeding points. A health secretary got caught snogging on his own CCTV. A foreign secretary got sacked for making up a quote. We know which PM played guitar in a band called Ugly Rumours. We even know the current chancellor padded her CV. British public life is forensic. Social media even more so. And yet the man running Palantir UK doesn’t appear to have a LinkedIn profile. For Louis Mosley, head of Palantir UK, grandson of the leader of the British Union of Fascists, the man who manages nearly a billion pounds of public contracts across the NHS, the Ministry of Defence, the police, and the financial regulator, we know: Oxford. 2006. Finance. That’s it. No school. No college. No subject. No career detail. No LinkedIn. No Wikipedia page. Try finding another person in British public life with that much power and that little biography. You won’t. That gap is not an accident.

    What we do know is that before Palantir, he had a political career. In 2011, he stood as a Conservative candidate in a Kensington and Chelsea council by-election. Local residents were uncomfortable with the Mosley name. Jewish residents in the ward wanted him to publicly condemn his grandfather’s antisemitism. When asked, he told journalists he didn’t really know much about his grandfather’s career. By 2017, he was chairman of the Hackney Conservative Association and speaking at the Conservative Party conference. He was also shortlisted for the Northampton South parliamentary seat. He was, in other words, actively trying to get into the British state through the front door of electoral politics. It didn’t work out. He found a much more effective entrance through procurement.

    I want to be clear about something. I’m not suggesting Louis Mosley shares his grandfather’s ideology. I have no evidence of that and I’m not making that claim. Nobody should be defined by their grandparents. But there is an irony here that’s hard to ignore. Oswald Mosley tried to take control of the British state through politics and failed. His grandson tried the same route, standing for council, chairing a local Conservative association, getting shortlisted for Parliament, and that didn’t work out either. What did work was procurement. Palantir now sits inside the NHS, the MoD, the police, the FCA, and the nuclear submarine programme. Nobody voted for that. The result, a single organisation embedded in the most sensitive institutions of the British state, is remarkably similar. The method is just quieter.

    The man on the panel shows

    Until recently, Mosley operated with the kind of low visibility that tends to accompany people who are very effective at getting what they want. That changed in early 2026, when the £240 million MoD contract made the news and Mosley started appearing on Sunday morning political television. He gave evidence to the Science, Innovation and Technology Committee. He wrote for the Spectator. He started saying things publicly that were previously the kind of thing said over watermelon cocktails in private dining rooms.

    When the committee chair asked him directly whether offering the NHS £1 during a pandemic was essentially buying Palantir’s way into being a long-term provider, Mosley said he “strongly rejected” the critique. It was a national emergency. They were invited. They helped. The fact that the £1 gesture subsequently became hundreds of millions of pounds of contracts awarded without competitive tender was, presumably, just one of those things. Worth noting, though, that in 2021, before the big NHS contract was awarded, Bloomberg obtained an internal Palantir email from Mosley with the subject line “Buying our way in…!” In it, he outlined a plan to buy up small companies that already worked with the NHS, in order to, in his words, “take a lot of ground and take down a lot of political resistance.” He strongly rejects the critique. He also wrote the email.

    He also confirmed, quite calmly, that all NHS data processed by Palantir sits in Amazon’s data centres in London and is “not exported elsewhere.” Which sounds reassuring. But there’s a US law called the CLOUD Act, passed in 2018, which says that American authorities can legally force any US company to hand over data it holds, no matter where in the world that data is physically stored. Amazon is a US company. Palantir is a US company. The data might be in London, but the legal power to demand access to it sits in Washington. Mosley did not mention this. The committee did not ask about it. Sometimes the most interesting part of parliamentary evidence is the question nobody thinks to ask.

    The revolving door that lost its hinges

    A “revolving door” is what people call it when officials move between government jobs and the private companies they’re supposed to be overseeing. It happens a lot. I covered the Mandelson connection and the broader picture in the FCA piece, so I won’t go through it all again. But there’s one detail about Mosley specifically that I keep coming back to.

    According to gwallter.com’s investigation, four Ministry of Defence officials left the MoD and joined Palantir before the major defence contract was awarded. Then, after his company got the contract, Mosley himself was given a seat on the MoD’s Industrial Joint Council. That’s the body where the Ministry of Defence sits down with the defence industry to discuss future work. In other words: Palantir’s UK boss now sits at the table where the MoD decides what to buy next.

    I’m going to let that sit for a moment. The head of a company that just received a £240 million no-competition contract from the Ministry of Defence then joined the Ministry of Defence’s own industry board. That’s not a revolving door. A revolving door implies the door is still there. This is more like someone removed the wall.

    The claims that didn’t survive the morning

    In early 2026, Mosley posted on social media that Palantir’s software had helped reduce domestic murders in Bedfordshire to zero over the previous 12 months. Bedfordshire, he said, typically sees five or six domestic murders a year. Thanks to Palantir identifying more than 1,000 at-risk women and alerting them to danger, the number had dropped to none. The Observer ran it. It looked like the future of policing.

    AOAV (Action on Armed Violence) looked into it. The claim fell apart in two separate ways.

    First, the basic facts. In January 2026, a 46-year-old woman called Beata Szauer was found dead in her home in Luton with stab wounds. Three men were arrested on suspicion of her murder. So the central claim, zero domestic murders in the past 12 months, was wrong. A woman had been killed. In the area Mosley was talking about. During the period he was talking about.

    Second, even if the numbers had been accurate, the logic wouldn’t hold. The Office for National Statistics, which is the government body that tracks crime data, says murder figures are “relatively low-volume” and that changes from one year to the next “need to be interpreted with some caution.” When the numbers are this small, a county going from six murders to zero in a given year could just be chance. It doesn’t automatically prove that anything you did worked. AOAV also pointed out that Mosley couldn’t even prove his own starting figure: Bedfordshire recorded eight murders in total in 2023-24, across all types, not just domestic cases. So where does “five or six domestic murders a year” come from? It’s not clear. On top of that, domestic abuse is massively underreported: fewer than a quarter of cases ever come to official attention, which means any system trained on police records is only seeing a fraction of the problem. Palantir published no analysis showing that its software, rather than the social workers, victim support teams, and safeguarding programmes already operating in Bedfordshire, caused any change at all. What remained, as AOAV put it, was a police chief justifying his own decision to use a controversial American company’s software. And a tech executive using the claim to sell more of it.

    A man made a claim on social media about saving women’s lives. The claim was channelled, uncritically, into a double-page spread in the Observer, which Carole Cadwalladr later described as Palantir spin presented without robust interrogation. Cadwalladr’s own reporting found at least two Bedfordshire women murdered in their homes during the relevant period. The post is still up. Nobody at Palantir has corrected it. The Observer hasn’t updated the story. I find that I keep thinking about Beata Szauer when I read Mosley’s posts about how AI is making everyone safer. I think somebody should.

    When journalists from Declassified UK spotted Mosley walking towards the BAFTA drinks reception in February, where Palantir was celebrating the £240 million MoD deal with politicians and military officials, they called out and asked whether the technology he’d just sold to the British military had been battle-tested through Palantir’s partnership with the Israeli defence ministry. He didn’t say yes. He didn’t say no. He walked into the party. Protesters gathered outside in the rain. Inside: canapés.

    Editorial cartoon showing a figure in a suit walking into a grand building for a private drinks reception while a journalist and protesters stand outside in the rain. A brass plaque by the door reads Private Function.

    What Mosley and his boss actually think

    In February 2026, Mosley published an essay in the Spectator, a right-wing political magazine, about what AI will do to the people who work in offices. His argument boils down to this: all the people who currently do admin, HR, compliance, and paperwork in government are about to be replaced by AI. He calls them “the lanyard class,” which is the kind of phrase someone uses when they want to sound like they’re on the side of ordinary workers while running a company worth over $200 billion. Once AI takes over the desk jobs, he says, the real workers, the ones who do physical things with their hands, will finally be valued. And because so much of what government actually does is admin and paperwork, if AI can do all of that, you don’t need the departments or the people who currently do it. Government gets smaller and smaller. Eventually, he reckons, there’s barely anything left. The state basically disappears on its own.

    To back this up, he quoted a 19th-century communist philosopher called Friedrich Engels, who once predicted that the state would “wither away.” A man who runs a surveillance company used a communist thinker to argue that government is doomed, in a conservative magazine. I want you to know that I’ve read this essay several times now and it doesn’t get less strange.

    A few weeks later, his boss went further. Palantir’s CEO Alex Karp went on CNBC, the American business channel, and said something quite extraordinary. AI, he explained, would weaken the influence of “highly educated, often female voters” and boost the economic power of “vocationally trained, working-class, often male, voters.” If you didn’t see this coming, he added, you belonged in an “insane asylum.” To be clear about what just happened there: the chief executive of a company that the Labour government has given over a billion pounds of public contracts to went on television and said his technology will specifically weaken the economic power of university-educated women, who are, according to YouGov’s analysis of the 2024 election, one of Labour’s strongest voter groups. Nobody in government has publicly responded to this. I’m genuinely not sure they’ve noticed.

    But here’s the thing about Mosley’s essay that I keep coming back to. Think about what Palantir actually sells. It sells software that organises and analyses huge amounts of data for big organisations. Its customers are the NHS, the Ministry of Defence, the police, the FCA. Those are all, by definition, enormous government bureaucracies full of data and paperwork. That’s the entire reason Palantir has a business. If you genuinely got rid of all the admin, all the regulations, all the back-office jobs, Palantir wouldn’t have anyone to sell to. As one commentator pointed out, Mosley is arguing for the death of the very thing that keeps his company alive.

    What’s actually happening is simpler and less revolutionary than he makes it sound. The paperwork isn’t disappearing. It’s just being done by Palantir’s software instead of a person. The NHS still needs to track patients. The MoD still needs to analyse intelligence. The regulations still exist. The data still gets processed. The only thing that changes is who gets paid for doing it: instead of a civil servant on a government salary, it’s an American tech company charging hundreds of millions of pounds. The admin doesn’t go away. It just gets privatised.

    Scotland Yard’s quiet experiment

    In February 2026, a detail emerged that got less attention than it deserved. Scotland Yard had been using Palantir’s AI tools to monitor its own police officers: tracking how often they called in sick, how much overtime they worked, and their patterns of absence. When someone filed a freedom of information request asking about this, which is the legal mechanism anyone can use to ask a public body what it’s doing, the Metropolitan Police refused to confirm or deny whether it had used Palantir’s technology since 2021.

    Refused to confirm or deny. That’s a phrase the police normally use when you ask about undercover operations or counter-terrorism intelligence. They used it here about whether they’re running an American tech company’s software on their own staff. That is a sentence I typed and then stared at for a while.

    Other forces have been similarly secretive. Leicestershire police quietly removed details of a contract worth over £800,000 for an “intelligence and investigation platform” from the public record entirely. Forces across the UK have been accused of hiding their dealings with Palantir, citing national security concerns. It’s hard to hold a company accountable for how it handles public data when the public institutions using it won’t even admit they’re using it.

    The resistance (it’s bigger than you think)

    I wrote about what you can do in both the NHS piece and the FCA piece, so I won’t repeat the full list here. But the picture has shifted since I wrote those, and it’s shifted in a direction that gives me genuine hope.

    People are saying no. 200,000 doctors. 50,000 patients. The Welsh NHS. The Scottish NHS. Leeds Teaching Hospitals. Green Party MPs. Labour backbenchers. Investigative journalists at The Nerve, Declassified UK, AOAV, Liberty Investigates, and the Good Law Project. And the NHS contract comes up for review in February 2027.

    The British Medical Association, the union that represents doctors, has told its members to limit their involvement with Palantir’s NHS data system and called for a “complete break” from the company. That’s 200,000 doctors. The entire medical profession saying: we do not trust you with our patients’ data. Leeds Teaching Hospitals told NHS England privately that adopting some of Palantir’s tools would cause them to lose functionality. Not gain it. Lose it. The technology being sold as the future of the NHS was, in at least one major hospital, worse than what they already had. I’d like you to read that sentence again.

    Fifty thousand patients wrote to their local hospital trust boards through the Good Law Project’s campaign. Green Party MPs demanded an immediate inquiry. Labour MP Clive Lewis called The Nerve’s investigation a “scandal.” And Lord Vallance, the government’s science minister, told a parliamentary committee in March 2026 that the government wants to change how it buys technology. Politicians say they want to change things all the time, of course. It’s sort of the main thing they do. But a government minister publicly distancing himself from the way Palantir got its contracts, while Palantir’s own CEO is on American television saying his technology will weaken the people who vote for that government, is, at minimum, a situation that someone should probably resolve.

    Wales said no. They’re building their own system. Scotland kept Palantir out of its NHS entirely. Nobody had to give Peter Thiel’s company the keys to find out how many beds are free in Edinburgh or Cardiff. The alternative exists. It’s not theoretical. It’s being built next door.

    And there’s a date that matters. The NHS contract comes up for review in February 2027. That’s less than a year away. Which means the decisions being made right now, by doctors, by trust boards, by patients writing letters, will directly shape whether Palantir stays embedded in the health service or whether the government looks for an alternative. This is also, by the way, the same company whose software powers the US Immigration and Customs Enforcement agency’s deportation operations under Donald Trump. The technology processing your NHS data and the technology identifying people for immigration raids in America is made by the same company, sold by the same man.

    The man in the middle

    I’ve been writing about Palantir for three articles now, and in each one Louis Mosley appears at the centre of the story. He’s the one who hosted the dinners. He’s the one who gave evidence to parliament. He’s the one who joined the MoD’s advisory board. He’s the one who wrote the Spectator piece about how the state will wither away while his company bills the state hundreds of millions. He’s the one who made the debunked claim about saving women’s lives in Bedfordshire. And he’s the one who walked past the journalists and into the party when asked about Gaza.

    He is, by any reasonable measure, extremely good at his job. I say that without irony. Getting from £1 to £900 million in six years while crossing two governments, surviving the Mandelson scandal, and picking up a seat on your biggest client’s own advisory board is an objectively remarkable achievement. If I could do sales like that I wouldn’t be writing blog posts at midnight in Somerset.

    But here’s the thing I keep coming back to. All of this, every contract, every expansion, every quiet appointment to an advisory board, happened on behalf of a company whose co-founder, Peter Thiel, wrote in 2009 that he no longer believes democracy and freedom are compatible. Whose CEO just went on television and said his technology will reduce the power of educated women. And whose software is embedded in the Israeli military’s operations in Gaza while simultaneously running the NHS, the MoD, the police, and the financial regulator.

    And when a journalist asked Louis Mosley about the Gaza connection, outside the BAFTA building where Palantir was celebrating its latest Ministry of Defence contract, he said nothing. He just walked into the party.

    I think we deserve an answer. And I think we should keep asking until we get one.

    A note on transparency: I use Claude, made by Anthropic, to help with research and writing. Anthropic has a formal partnership with Palantir, which was the first company to bring Claude into classified environments. I think you should know that.

    I also think it’s worth knowing what happened next. In early 2026, the Pentagon tried to blacklist Anthropic after the company refused to give the US military unrestricted access to Claude. Anthropic had two red lines: no autonomous weapons and no domestic mass surveillance. The Pentagon wanted those limits removed. When Anthropic said no and went public about it, the Trump administration declared the company a national security threat. A federal judge blocked the blacklisting, ruling that it violated the First Amendment, which is the bit of the US constitution that says the government can’t punish you for saying things it doesn’t like. The judge called it “classic illegal First Amendment retaliation” and wrote that nothing in the law supports “the Orwellian notion that an American company may be branded a potential adversary and saboteur of the U.S. for expressing disagreement with the government.” In other words: you can’t label someone a threat to national security because they told you no and then told the press about it. Apparently that needed saying.

    I mention this because it matters for how you read this article. AI is going to be used in government whether we like it or not. The question is whether the companies building it have any guardrails at all. Anthropic drew a line and got punished for it. OpenAI stepped in hours later and signed a deal with the Pentagon that its own CEO admitted was “definitely rushed.” OpenAI says it has similar red lines, but as MIT Technology Review pointed out, the key difference is that where Anthropic wanted explicit contractual bans, OpenAI’s approach relies on trusting that the government will follow the law. Which is reassuring until you remember that the US government’s own mass surveillance programme, which secretly collected millions of Americans’ phone records, was ruled unlawful by the US Court of Appeals only after Edward Snowden exposed it in 2013. Some OpenAI staff publicly said the deal wasn’t worth it. Caitlin Kalinowski, OpenAI’s head of robotics, resigned, saying that “surveillance of Americans without judicial oversight and lethal autonomy without human authorization are lines that deserved more deliberation than they got.”

    And then something happened that I think is genuinely important, especially for anyone who has ever felt like ordinary people can’t change anything. ChatGPT uninstalls surged by 295% in a single day. Over 1.5 million people joined a boycott called QuitGPT. Claude, the tool I’m using to write this, hit number one on the Apple App Store for the first time, overtaking ChatGPT. Anthropic’s revenue jumped from $14 billion to $19 billion annualised in a single month. People voted with their wallets, and it actually worked. A company said no to the most powerful military on earth, and millions of ordinary users backed them up overnight. That is power to the minions, right there.

    Palantir, meanwhile, which has no red lines at all, partnered with the Israeli military and powers ICE deportation raids without hesitation. I’d rather use a tool made by a company that got sued by the Pentagon for saying no to something than one made by a company that has never said no to anything. Better the devil with boundaries than the one without.

    Sources and citations

    1. Yahoo News UK: Who is Palantir UK boss Louis Mosley and why is he everywhere? (January 2026)
    2. UK Parliament: Oral evidence from Louis Mosley to the Science, Innovation and Technology Committee
    3. gwallter.com: Who is Louis Mosley? (February 2026)
    4. Government Transformation Summit: Louis Mosley speaker bio
    5. Wikidata: Louis Mosley (born 1983, parents identified)
    6. From the Hornets Nest: The Elephant in the Committee Room (June 2011, Kensington & Chelsea by-election)
    7. HuffPost UK: Louis Mosley at Conservative Party conference (October 2017)
    8. Conservative Home: Louis Mosley shortlisted for Northampton South (May 2017)
    9. Sunder Katwala on Bluesky: Tatler’s “meet the Mitfords” profile of Mosley (April 2025)
    10. Hansard: Ministry of Defence Palantir Contracts debate (February 2026)
    11. The Spectator: AI is coming for the lanyard class, by Louis Mosley (February 2026)
    12. Bloomberg via Yahoo Finance: Peter Thiel’s Palantir Had Secret Plan to Crack UK’s NHS: ‘Buying Our Way In’ (September 2022)
    13. US Congress: CLOUD Act (H.R.4943) (2018)
    14. openDemocracy: Four MoD officials joined Palantir before record defence contract
    15. AOAV: Louis Mosley’s claim about Bedfordshire domestic murders contradicted by facts (March 2026)
    16. ONS: Homicide in England and Wales, year ending March 2025 (February 2026)
    17. Carole Cadwalladr / The Nerve: The broligarchy’s war on journalism (March 2026)
    18. Declassified UK: Palantir UK chief walks away from Gaza genocide questions (February 2026)
    19. Bloomberg: Palantir, Israel agree strategic partnership for battle tech (January 2024)
    20. Futurism: CEO of Palantir says AI will seize power away from college-educated women (March 2026)
    21. YouGov: How Britain voted in the 2024 general election (July 2024)
    22. View from Cullingworth: How AI won’t fix the world’s problems with bureaucracy (February 2026)
    23. Wikipedia: Palantir Technologies (Met Police profiling detail)
    24. Novara Media: What is Palantir? How a US spytech firm penetrated the British state (February 2026)
    25. The Small Business Cybersecurity Guy: Palantir UK contracts risk 2026 (February 2026)
    26. Lowdown NHS: Palantir, the controversy, the contracts and the campaign (April 2026)
    27. The Nerve: Palantir deals with UK state total at least £670m (February 2026)
    28. The Register: UK to rethink tech buying after Palantir contracts (March 2026)
    29. Cato Unbound: The Education of a Libertarian, by Peter Thiel (2009)
    30. Chloe George: The Seeing Stones: How a CIA-Funded Surveillance Company Ended Up Running the NHS (March 2026)
    31. Chloe George: Land and Expand: How Palantir Swam Into the FCA’s Data Lake (March 2026)
    32. CNBC: Anthropic wins preliminary injunction in DOD fight as judge cites ‘First Amendment retaliation’ (March 2026)
    33. CNN: Judge blocks Pentagon’s effort to ‘punish’ Anthropic by labeling it a supply chain risk (March 2026)
    34. CNBC: OpenAI strikes deal with Pentagon, hours after rival Anthropic was blacklisted by Trump (February 2026)
    35. MIT Technology Review: OpenAI’s ‘compromise’ with the Pentagon is what Anthropic feared (March 2026)
    36. CNN: Some OpenAI staff are fuming about its Pentagon deal (March 2026)
    37. TechCrunch: ChatGPT uninstalls surged by 295% after DoD deal (March 2026)
    38. Futurism: Humongous numbers of people are uninstalling ChatGPT (March 2026)
    39. South China Morning Post: NSA mass spying exposed by Snowden was illegal, US court rules (September 2020)
    40. TechCrunch: OpenAI hardware exec Caitlin Kalinowski quits in response to Pentagon deal (March 2026)
  • Land and Expand: How Palantir Swam Into the FCA’s Data Lake

    Land and Expand: How Palantir Swam Into the FCA’s Data Lake

    Four days. I published The Seeing Stones, a 5,000-word investigation into how a CIA-funded surveillance company ended up running the NHS, and four days later the Guardian broke a story that made me need to write another one.

    On 22 March 2026, we learned that Palantir has been awarded a contract by the Financial Conduct Authority to analyse the regulator’s internal intelligence data.[1] Case files. Fraud reports. Phone call recordings. Emails. Social media posts. Consumer complaints. The entire investigative toolkit of the body responsible for overseeing 42,000 financial firms, from high street banks to crypto exchanges. Handed to Peter Thiel’s company for a three-month trial at more than £30,000 a week.[2]

    When I added an update to the NHS piece, I thought a paragraph would do it. It didn’t. Because the FCA deal isn’t just another contract. It’s the piece that makes the whole picture visible. Palantir now sits inside the NHS (your health data), the Ministry of Defence (national security), police forces across England (criminal intelligence), and the Financial Conduct Authority (your financial life). That’s not a collection of separate deals. That’s an operating system. And the man running Palantir’s UK operation already told us that’s exactly what he wants.

    What’s actually in the data lake?

    The FCA describes its repository as a “data lake.” It’s a technical term for a large store of raw data, but it’s also accidentally the most honest piece of branding anyone involved in this story has produced. A data lake is murky. Things sink into it and become hard to retrieve. The boundaries are unclear. And once something swims in, it tends to stay.

    Cartoon of a murky lake with a wooden sign reading FCA Data Lake. Filing cabinets, phones, and email envelopes float in the water. A glowing orb sinks in the centre. A figure in a business suit stands calmly on the shore holding a fishing rod. Caption reads Just a trial.

    According to multiple news outlets reporting on the Guardian’s investigation, the data Palantir will access includes: case intelligence files marked as highly sensitive; information on what the FCA calls “problem firms”; reports from banks and lenders about proven and suspected frauds; consumer complaints to the financial ombudsman; recordings of phone calls; swathes of emails; and social media monitoring data.[8][4][5] This isn’t a spreadsheet. It’s the entire investigative brain of the UK’s financial regulator.

    Palantir will apply its Foundry platform, the same software it uses for the NHS and the MoD, to sift through all of this and look for patterns of financial crime: fraud, money laundering, insider trading.[5] The idea, on paper, is straightforward: AI is better at spotting patterns across massive datasets than humans are. The FCA oversees 42,000 firms. It needs better tools. Nobody serious disputes that.

    But here’s the thing. The FCA chose to test this system using real data, not synthetic datasets. That decision raised eyebrows even among people sympathetic to the project, because testing AI systems on dummy data is standard practice precisely to avoid handing your most sensitive information to a contractor before you know whether the arrangement works.[5] The FCA went straight to the real thing. As Christopher Houssemayne du Boulay, a barrister at Hickman and Rose, told the Guardian: the FCA can compel firms to hand over vast quantities of data during investigations. “We could be talking about hundreds of whole email accounts and full financial records. Many innocent people will be caught up in that and the data may contain bank account details, email addresses, telephone numbers and other personal information.”[6]

    The procurement that wasn’t quite

    The FCA says it ran “an open, competitive procurement process.”[7] That phrase is doing a lot of heavy lifting, because according to Yahoo News UK, reporting on the Guardian’s investigation, there was only one other competitor for the contract.[8] One. Unnamed. In a market with dozens of data analytics firms.

    If you’ve read the NHS piece, this will feel familiar. The pattern goes: small entry, prove value, become impossible to remove. Palantir’s NHS involvement started with a £1 contract during Covid, expanded to £60 million without competitive tender, then became a £330 million seven-year deal.[9] The MoD relationship started with a £75 million enterprise agreement in 2022, then grew to a £240 million contract in December 2025, awarded directly by the Defence Secretary with no competitive process.[10] As MPs noted in a February 2026 Hansard debate, the pattern is consistent: “Its £1 Covid contract with the NHS expanded to a £330 million contract under the last Government, and its Ministry of Defence contract tripled in size to £240 million, without due process or competition.”[11]

    The FCA deal is positioned as a three-month trial. Just a trial. Like the £1 NHS contract was just a gesture of pandemic goodwill. Like the MoD enterprise agreement was just a modest partnership. I don’t know about you, but when a company with a documented track record of turning three-month trials into decade-long dependencies tells me this one is just a trial, I find myself checking whether any watermelon cocktails were involved in the decision.

    The common operating system (they told us this was the plan)

    Simple outline map of the UK pinned to a wall with seven glowing dots connected by lines, labelled NHS, MoD, Police, FCA, Children's Services, Nuclear Subs, and Cabinet Office. A hand reaches in from the corner holding a felt-tip pen, about to add another dot. Caption reads Common operating system.

    In his evidence to the UK Covid-19 Inquiry, Palantir’s UK chief Louis Mosley urged the government to invest in a “common operating system” that would bring together data from “across local and central government, healthcare and other bodies of national strategic importance.”[12][13] He wasn’t being subtle. He was pitching.

    Let’s map what that operating system looks like today. The NHS Federated Data Platform: health records, waiting lists, patient data across tens of millions of people.[9] The Ministry of Defence: strategic, tactical and live operational decision-making, including services to the navy’s nuclear-powered submarines.[14] Police forces in the East of England, Leicestershire and Bedfordshire: criminal intelligence, including, according to Liberty Investigates, data on political opinions, health records, sexual orientation and trade union membership.[15] Coventry City Council: children’s services and social care data.[6] The Cabinet Office. DEFRA. The Homes for Ukraine scheme. And now the FCA: financial crime intelligence, fraud detection methods, and the personal financial data of anyone caught up in an investigation.

    The Nerve’s investigation in February 2026 found that Palantir’s deals with the UK state total at least £670 million across 34 contracts with ten government departments, police authorities and local councils.[14] And that was before the FCA deal was announced.

    Mosley told a parliamentary select committee that each sector operates independently. That what happens in the US doesn’t affect the UK business. That Palantir has worked for administrations “of every colour.”[16] When asked whether the company was buying its way into being an NHS provider, he said he “strongly rejected” the critique.[16] But the map speaks for itself. Health. Defence. Policing. Financial regulation. Children’s services. Nuclear submarines. If this isn’t a common operating system, it’s doing an extremely convincing impression of one.

    Professor Levi’s question (and the one the FCA asked internally)

    Professor Michael Levi is a specialist in financial crime at Cardiff University. He told the Guardian that there has been “serious under-exploitation” of regulatory data, and that AI could genuinely improve how we detect financial crime.[6] He’s not an anti-tech campaigner. He’s a pragmatist. Which makes his question all the more pointed: “What are the protocols agreed between the FCA and Palantir about the onward use of things that they have learned in that process?”[6]

    That’s the question. Not “is AI useful?” (it is) but “what happens to the knowledge?” When Palantir’s engineers learn how the FCA detects money laundering, that knowledge doesn’t vanish when the contract ends. You can delete the data. You can’t delete what people understood.

    An FCA source put it more bluntly. Speaking to the Guardian, as reported by Yahoo News UK, they asked: “Once Palantir understands how we detect money-laundering threats, how do we know that they are ethically reliable enough not to share that information?”[8]

    That’s an FCA employee. Not a campaigner. Not an opposition MP. Someone inside the organisation, asking whether the company they’ve just hired can be trusted with the methods they use to catch financial criminals. It’s the kind of question that, if it doesn’t keep you awake at night, should at least make you put the kettle on and have a think.

    Now add the context. Palantir was co-founded by Peter Thiel, a prominent donor to Donald Trump.[8] Its technology has been used by the Israeli military and by US Immigration and Customs Enforcement.[17] According to Byline Times, reporting on the Epstein files, Thiel’s venture capital firm Valar Ventures had Jeffrey Epstein as a limited partner; a claim Thiel’s spokesperson disputed in terms of characterisation but confirmed in substance.[18] Palantir’s lobbying firm in the UK was Global Counsel, co-founded by Peter Mandelson, who while serving as UK ambassador arranged a visit by the Prime Minister to Palantir’s Washington headquarters. No minutes of that meeting have been published.[19][20] At the time, Mandelson held a shareholding of around 28% in Global Counsel, which listed Palantir as a client.[21][22] Mandelson was subsequently fired as ambassador by Starmer in September 2025 following revelations about his relationship with Epstein.[23] In February 2026 he was arrested on suspicion of misconduct in public office, and as of March 2026 remains released under investigation.[24][25] He has denied wrongdoing. Global Counsel has since collapsed into administration.[26] Palantir still has all its UK government contracts.

    This is the company that now has access to the FCA’s financial crime detection methods. The contract says the data stays in the UK, that Palantir is merely a “data processor”, that encryption keys are retained by the FCA, that everything gets deleted afterwards.[7] Those are important safeguards. They are also exactly the same type of assurances given for every other Palantir contract.[2] And every other Palantir contract is still running.

    The revolving door (it spins faster than you think)

    Cartoon of a revolving door between buildings labelled Government and Palantir. Five figures walk through in single file, each carrying a different item: a military briefcase, a stethoscope, a police badge, a rolled-up protest placard reading People's Vote, and a civil service lanyard. A sign on the door reads Business appointment rules apply. Please spin gently.

    If you want to understand how Palantir wins contracts, don’t look at the procurement notices. Look at the people.

    OpenDemocracy reported that Palantir hired four former Ministry of Defence officials in 2025, before winning its record £240 million defence contract in December of that year.[10] One of them, Barnaby Kistruck, left his role as the MoD’s director of industrial strategy, prosperity and exports, and joined Palantir as senior counsellor just nine days later. OpenDemocracy reported that Kistruck played a key role in writing the UK’s Strategic Defence Review, which recommended an increased role for AI in defence.[10] The other three hires were two senior civil servants, Laurence Lee and Damian Parmenter, and former Conservative armed forces minister Leo Docherty.[10] OpenDemocracy noted there was no suggestion of wrongdoing on Kistruck’s part, and the MoD placed restrictions on his new role.[10]

    Byline Times documented how Matthew Swindells, former deputy chief executive of NHS England, joined Global Counsel in September 2019, just two months after leaving his NHS role. He then became chair of Palantir’s health advisory board while simultaneously serving as joint chair of NHS hospital trusts, including Chelsea and Westminster, which was the first trust to pilot Palantir technology. The trust said Swindells was excluded from Palantir-related decisions.[18]

    And then there’s Tom Watson. According to Democracy for Sale, the former Labour deputy leader (now Baron Watson of Wyre Forest) was recruited by Palantir; health campaign group Medact has listed him among former government officials “employed or consulted by” the company.[9][36] I’ll be honest, this one stung. I saw Watson in a London pub during one of the big anti-Brexit marches. He was one of the loudest voices for the People’s Vote. He did genuinely important work on the phone-hacking scandal. He felt like someone on the right side. And maybe he still is, in all sorts of ways. People are complicated. But the person you cheered at the march is now advising the surveillance company, and that’s not a contradiction Palantir minds at all. It’s the whole strategy. You don’t build a revolving door that only swings one way. Watson (Labour), Docherty (Conservative), Kistruck (senior civil servant). The point is that every door leads to Palantir.

    I’m not suggesting anything illegal about any of these appointments. Business appointment rules exist. Cooling-off periods are applied. But the cumulative effect is that Palantir builds its client relationships by hiring people who understand those clients from the inside. Four MoD hires in a single year, before the biggest MoD contract in the company’s history, is a pattern that raises legitimate questions about how competitive these procurements really are.

    I haven’t found evidence of a similar revolving door at the FCA. That doesn’t mean there isn’t one. It means we should be asking the question now, before the three-month trial becomes a three-year contract becomes a permanent dependency.

    The AI underneath keeps changing (and that should worry you)

    Here’s something that hasn’t had enough attention. Palantir’s Foundry platform uses large language models, AI systems built by other companies, to power its analysis. Until very recently, the most important of those models in Palantir’s US defence work was Claude, made by Anthropic.[27]

    On 27 February 2026, the Trump administration blacklisted Anthropic. The Pentagon designated it a “supply chain risk,” a label normally reserved for foreign adversaries like Huawei.[28] The reason? Anthropic’s CEO Dario Amodei refused to remove safeguards that prevented Claude from being used for mass domestic surveillance or fully autonomous weapons. Trump called Anthropic staff “leftwing nut jobs” and directed federal agencies to stop using their technology.[28]

    Palantir CEO Alex Karp confirmed that Claude is still running inside Palantir’s tools, even as the company plans to swap to other models. “Our products are integrated with Anthropic, and in the future, it will probably be integrated with other large language models,” he told CNBC.[29] According to Reuters, Palantir’s Maven Smart Systems, used for US military intelligence and targeting, were built using Claude’s coding tools. Rebuilding those workflows will take time and money.[30] The same Foundry platform is being deployed at the FCA.

    So here’s the question nobody has answered: which AI model is powering Palantir’s analysis of the FCA’s data? If it’s Claude, what happens when the model swap takes place? If it’s something else, which something else? And what does it mean for the reliability and consistency of financial crime detection when the intelligence layer underneath your entire system is being ripped out and replaced because of a political dispute between a US president and an AI company over whether machines should be allowed to kill people without human approval?

    I appreciate that’s a long sentence. It’s a long situation.

    The sovereignty contradiction

    The timing of the FCA contract is, to put it diplomatically, interesting. On 20 March 2026, just two days before the Guardian broke the FCA story, Lord Vallance told a parliamentary committee that the government was pursuing “a very different way of doing contracts: putting British companies there and procuring innovation here.”[31] Liberal Democrat MP Martin Wrigley responded that existing contract break points “must be exploited to move to UK solutions, sovereign solutions, otherwise we just continue doing the same stuff.”[31]

    The government has launched a Sovereign AI Unit with £500 million. The Prime Minister says the UK should be “an AI maker, not an AI taker.”[32] A House of Commons Library briefing published in March 2026 documented growing concern about over-reliance on US tech firms.[32] An Early Day Motion in Parliament warned that “government services, democratic functions and critical infrastructure increasingly depend on a small number of external digital suppliers.”[33] A Westminster Hall debate on technology sovereignty was scheduled for the same month.[32]

    And in the middle of all this, the FCA handed another sensitive system to Palantir.

    I keep thinking about Wales. When the rest of the UK went with Palantir for NHS data, Wales said no. It’s building its own system, the National Data Resource, with data staying under public control.[34] That model exists. It’s not theoretical. It’s being built right now, by people who decided that sovereignty isn’t just a word you put in a policy document.

    What you can actually do

    I know how this reads. Overwhelming. Tentacular. Depressing. But there are things that are genuinely happening, and things you can do. The FCA contract is three months. It hasn’t become permanent yet. If enough people raise concerns now, during the trial, it might not.

    Five things you can do right now

    1. Write to your MP about the FCA contract. That sounds like a thing people say when they’ve run out of useful suggestions, but in this case, parliamentary pressure is genuinely building and cross-party. The Hansard debates in February 2026 show MPs from Labour, the Conservatives, the Liberal Democrats and the Greens all asking the same questions.[11] Your voice adds to that.

    Find and write to your MP via WriteToThem

    2. Support the organisations doing the legal heavy lifting. Foxglove forced the publication of the NHS contract and is campaigning for full transparency on all Palantir deals. The Good Law Project has been pursuing FOI requests and legal challenges for years.

    Support Foxglove’s campaign
    Support the Good Law Project

    3. Back the push for digital sovereignty. The Open Rights Group is campaigning for a UK digital sovereignty strategy that would reduce dependency on a small number of foreign tech vendors across critical public services.[35]

    Open Rights Group

    4. If you work in the NHS, sign the Medact petition. Health workers are campaigning to cancel the NHS Federated Data Platform contract with Palantir when it comes up for review. The break clause exists. It just needs enough pressure to be used.[6]

    Medact: No Palantir in the NHS

    5. Share this article. Not because I want the clicks (although, you know, hello). But because this story only works if enough people can see the pattern. One contract is a procurement decision. Thirty-four contracts across health, defence, policing, financial regulation and children’s services is a strategy. The more people who can see it, the harder it is to keep doing it quietly.

    You can also just pay attention. Because the next contract is always just a trial. The next expansion is always just an extension. The next dataset is always just a pilot. And by the time anyone notices the pattern, the common operating system is already built.

    The seeing-stones keep multiplying

    Cartoon showing a timeline of growing trees. On the left, a tiny seed labelled NHS £1 contract 2020 grows into a medium tree labelled NHS £60m, then an enormous tree with deep roots labelled NHS £330m. In the middle, a seedling labelled MoD £75m grows into a large tree labelled MoD £240m. On the far right, a brand new tiny seed has just been planted, labelled FCA £30k/week, with a watering can beside it and a sign reading Just a trial.

    In my first piece, I wrote that “the seeing-stone serves whoever holds it.” Tolkien’s palantíri were neutral technology. They could be used for good or ill. The danger wasn’t in the stones themselves but in who held them, and what they wanted to see.

    Palantir now holds seeing-stones pointed at your health, your security, your neighbourhood, and your finances. The company says it’s just a data processor. Just providing tools. Just helping catch criminals. And maybe that’s true today. But the question was never about today. It was always about what happens when the contract is permanent, the dependency is total, the revolving door has spun one more time, and someone in Washington, or in a boardroom, or at a dinner with exotic cocktails, decides they’d like to see something different.

    The FCA’s own staff are asking whether this company can be trusted. The least we can do is listen.

    A note on transparency: I’m a tech entrepreneur who builds legal technology. I have no commercial interest in Palantir’s competitors. I do have a strong interest in who gets to see my data, and yours. This article is based on publicly available sources, parliamentary records, and investigative journalism. All sources are cited below. Where claims are contested or attributed to specific outlets, I have noted this. Palantir has consistently maintained that it takes a “rigorous approach” to human rights and that its technology is used within strict contractual safeguards. Mandelson has denied wrongdoing in relation to the police investigation. No suggestion of illegality is made against any individual named in this article unless explicitly stated otherwise.

    Sources and citations

    1. The Guardian, “Palantir extends reach into British state as it gets access to sensitive FCA data,” 22 March 2026. Reported via The Register, City AM, LBC, Yahoo News UK, and others.
    2. The Register, “Palantir trial plugs into UK financial watchdog’s data trove,” 23 March 2026.
    3. Finextra, “FCA criticised over using sensitive data in AI trial with Palantir,” 23 March 2026. Reports data contents, Houssemayne du Boulay privacy concerns, and contract terms.
    4. NewsBytesApp, “AI firm Palantir can now access UK’s financial data,” 23 March 2026.
    5. FStech, “Palantir wins FCA contract to analyse sensitive UK data,” 23 March 2026.
    6. Computing.co.uk, “UK financial watchdog taps Palantir for data analysis,” 23 March 2026. Quotes Prof Michael Levi (Cardiff University), Christopher Houssemayne du Boulay (Hickman and Rose), and notes Zack Polanski break clause call and Coventry Council contract.
    7. LBC, “Palantir to access sensitive UK financial data,” 23 March 2026. FCA spokesperson quoted: “We ran an open, competitive procurement process and have strict controls in place to ensure data is protected.”
    8. Yahoo News UK, “Palantir given access to highly-sensitive UK financial data,” 23 March 2026. Reports one unnamed competitor, FCA source ethics quote, and Peter Thiel as Trump donor. Reporting on the Guardian’s investigation.
    9. Democracy for Sale, “Palantir’s NHS data platform rejected by most hospitals,” May 2025. Documents “land and expand” strategy (quoting Foxglove), £1 to £330m NHS trajectory, and political recruitment.
    10. openDemocracy, “Palantir hired four ex-Ministry of Defence officials before winning record defence contract,” 24 January 2026. Documents Barnaby Kistruck (director of industrial strategy, prosperity and exports), Laurence Lee, Damian Parmenter, Leo Docherty. £240m contract awarded without tender December 2025. “openDemocracy is not suggesting any wrongdoing on Kistruck’s part.”
    11. Hansard, “Ministry of Defence: Palantir Contracts,” 10 February 2026. Cross-party debate. Quote: “Its £1 Covid contract with the NHS expanded to a £330 million contract.” Global Counsel links discussed. 34 contracts figure cited.
    12. Prospect Magazine, “How Palantir infiltrated the state.” Documents Mosley’s “common operating system” pitch.
    13. The Register, “Palantir suggests ‘common operating system’ for UK govt data,” 25 March 2025. Confirms Mosley’s Covid inquiry witness statement.
    14. The Nerve / Carole Cadwalladr, “Revealed: Palantir deals with UK state total at least £670m,” 7 February 2026. Documents £388m MoD, £244m+ NHS, nuclear submarine services, 34 contracts.
    15. Liberty Investigates / i newspaper, “UK police working with controversial tech giant Palantir on real-time surveillance network,” June 2025. Documents police data categories including political opinions, health records, sexual orientation, trade union membership.
    16. UK Parliament oral evidence, Science, Innovation and Technology Committee, Louis Mosley testimony. “Strongly rejected” buying-in critique; “administrations of every colour” quote.
    17. Novara Media, “What Is Palantir?,” 19 February 2026. Documents Israeli military use, ICE contracts ($200m+).
    18. Byline Times, 19 February 2026. Reports Valar Ventures / Epstein limited partner status (Thiel spokesperson disputed “co-ownership” characterisation but confirmed Epstein’s role). Documents Swindells revolving door. Notes trust said Swindells excluded from Palantir decisions.
    19. Good Law Project, “Mandelson’s embassy fixed Starmer’s visit to spytech firm,” April 2025.
    20. Hansard, “Lord Mandelson,” 4 February 2026. Documents Washington visit not in PM’s register, no minutes.
    21. Bloomberg, September 2025. Documents Mandelson’s 28% shareholding in Global Counsel.
    22. CIPR, 5 February 2026. Confirms Global Counsel registered with ORCL, lists Palantir as client.
    23. CNN, 23 February 2026. Confirms Mandelson fired as ambassador in September 2025 by Starmer following Epstein email revelations.
    24. Al Jazeera, 24 February 2026. Mandelson arrested on suspicion of misconduct in public office, released on bail. Also reported by CNN, PBS, NPR.
    25. ITV News, 6 March 2026. Mandelson released under investigation, no longer on bail, passport returned.
    26. Bloomberg, 19 February 2026. Global Counsel entered administration. Also Yahoo Finance / Sky News, 19 February 2026.
    27. CNBC, “Anthropic was the Pentagon’s choice for AI. Now it’s banned,” 9 March 2026.
    28. Axios, “Trump moves to blacklist Anthropic’s Claude from government work,” 27 February 2026.
    29. CNBC, “Palantir is still using Anthropic’s Claude as Pentagon blacklist plays out, CEO Karp says,” 12 March 2026.
    30. Reuters / Marine Corps Times, “Hegseth wants Pentagon to dump Claude, but military users say it’s not so easy,” 19 March 2026.
    31. The Register, “UK promises procurement shift after Palantir deals,” 20 March 2026.
    32. House of Commons Library, “Digital sovereignty,” Research Briefing CBP-10547, March 2026.
    33. UK Parliament Early Day Motion 65087, “UK digital sovereignty strategy.”
    34. Gwallter, “Who is Louis Mosley?” Documents Wales NHS decision to build National Data Resource without Palantir.
    35. The Register, “UK urged to cut out US Big Tech for sake of digi sovereignty,” 6 January 2026.
    36. Medact, “Health workers confront NHS leaders at closed-door Palantir meeting,” March 2026. Lists Lord Tom Watson among “former UK government officials now employed or consulted by Palantir.”
  • The Seeing Stones: How a CIA-Funded Surveillance Company Ended Up Running the NHS

    The Seeing Stones: How a CIA-Funded Surveillance Company Ended Up Running the NHS

    Coming up in today’s show and tell…

    • Palantir, a surveillance company co-founded by Peter Thiel with CIA seed money, now holds over £500 million in UK government contracts, including a £330 million deal to run an NHS data platform covering tens of millions of patients.
    • The contract grew from a £1 pandemic “freebie” to £60 million without any competitive tender. When the £330 million contract was finally published, 71% of it was blacked out because the data protection terms hadn’t been agreed yet.
    • Palantir’s lobbyist was Peter Mandelson’s firm Global Counsel. Mandelson held a ~21% shareholding while arranging meetings between Palantir’s CEO and the Prime Minister. He has since been sacked as ambassador and is under police investigation. Palantir still has all its contracts.
    • The NHS’s own chief data officers said their existing tools were better than what Palantir was offering. Scotland kept Palantir out entirely. The government is paying KPMG £8 million to persuade hospitals to use software they don’t want.
    • Tim Berners-Lee’s Solid project offers an alternative model where data stays under the control of the people it belongs to. The NHS chose the opposite approach. The contract comes up for review in February 2027.

    Update, 23 March 2026

    Four days after this article was published, the Guardian reported that Palantir has been awarded a contract by the Financial Conduct Authority to analyse its internal intelligence data, including case files, emails, call recordings, and reports of suspected financial crime across 42,000 firms. Palantir now holds contracts covering NHS patient data, Ministry of Defence operations, police systems, and financial regulation. The cross-departmental infrastructure this article warns about isn’t a future risk. It’s being built right now, one contract at a time. A full investigation into the FCA deal is coming.

    I fell down a rabbit hole this week. It started with a question about what Tim Berners-Lee thinks of Palantir, and it ended with me staring at a Hansard transcript at midnight going “no, but seriously, WHAT?” I need to tell you about it, because it’s one of those stories where the more you find out, the more unbelievable it gets, and I think more people should know.

    Fair warning: this starts with Tolkien, takes a detour through watermelon cocktails, and ends with your medical records. Stay with me. I promise it’s worth it.

    A quick word about seeing-stones

    In Tolkien’s Lord of the Rings, a palantír is a seeing-stone. Think crystal ball, but instead of a fortune teller at a village fete telling you you’ll meet a tall stranger, it lets you spy on people across vast distances. The Elves made them for good reasons. Then the bad guys got hold of them, and it all went sideways. Saruman used one and thought he was gaining power. He was actually being controlled. Denethor used one and it drove him to despair. The palantír is Tolkien’s cautionary tale about what happens when surveillance technology ends up in the wrong hands.

    In 2003, the billionaire investor Peter Thiel co-founded a data analytics company. He named it Palantir. He also named his offices after Middle-earth locations: Gondor, Rivendell, the Shire. His venture fund Founders Fund bankrolled a weapons company called Anduril (Aragorn’s sword), founded by former Palantir executives. He co-founded a separate venture fund called Mithril (the magic armour metal). You have to admire the commitment to the theme, if nothing else.

    Now, I want to believe he just really liked the books and thought “seeing-stone” sounded cool. But Thiel studied philosophy at Stanford. He’s not a man who picks names carelessly. And I think if you name your surveillance company after a fictional device whose entire literary purpose is to warn you about the dangers of surveillance, you probably understood the assignment. You just disagreed with the conclusion.

    That company now holds over £500 million in UK government contracts, including a £330 million deal to run a data platform for the NHS. Your NHS. Your data. And the story of how that happened is genuinely one of the most extraordinary things I’ve ever tried to write down.

    The £1 contract (or: how to buy the NHS with watermelon cocktails)

    Cartoon of two people at a dinner table with watermelon cocktails, a napkin reading NHS Patient Data 57 million records, and a £1 coin being slid across the table. Caption: Just a casual dinner.

    The version of this story most people know goes like this: pandemic hits, NHS needs help, generous tech company steps in for £1, everyone claps. It’s a lovely story. It’s also not quite what happened.

    The Bureau of Investigative Journalism found that Palantir had been courting the NHS for months before Covid was a thing. In July 2019, Palantir’s UK boss Louis Mosley hosted a dinner with the chair of NHS England. The email chain, which I have read more times than is probably healthy, mentions “exotic drinks” and “watermelon cocktails.” Over these watermelon cocktails, they discussed potential uses of NHS data. The chair emailed afterwards: “If you can see ways where you could help us structure and curate our data… do be in touch.”

    Just a nice dinner. Just some cocktails. Just the beginning of what would become half a billion pounds in government contracts. As you do.

    By January 2020, two months before the pandemic, Palantir’s London team were already building a product “exclusively focused” on the UK healthcare market. So when Covid arrived and they offered to help for £1, that wasn’t a random act of kindness. That was the free sample outside a shop. The first one’s always free.

    And oh, did it work. £1 became £1 million by July 2020. Then £23 million by December. That £23 million contract was awarded without competition. Through various extensions, Palantir won £60 million from the NHS without ever competing against another company. Sixty million quid and not a single tender. I once had to fill in a 12-page form to get a £500 council grant for a community project, so apparently there are different processes depending on how many zeros are involved.

    Cartoon of a man sliding a £1 coin across an NHS reception desk while behind him sit increasingly enormous money bags labelled £1M, £23M, £60M, and £330M. Caption: Just getting my foot in the door.

    In 2021, openDemocracy and the legal campaign group Foxglove sued the government over it. The government’s legal position was, and I am not making this up, that “citizens have no right to a say in major NHS contracts” with big tech firms. Your health data. No say. They actually argued that. In a court. With lawyers and everything. Faced with a judicial review, they caved and promised not to extend Palantir’s role without consulting the public.

    They broke that promise two years later. In March 2023, leaked documents showed NHS bosses had quietly ordered hospitals to upload patient data to a new Palantir-run database, without the public consultation they’d committed to. Their own internal documents acknowledged this was “likely to be perceived by some privacy campaigners as contentious.” I admire the understatement.

    Then came the big one. November 2023: a £330 million, seven-year contract to build something called the Federated Data Platform (which is the kind of name that sounds important enough that most people stop asking questions, which I suspect is the point). When the contract was made public, it was released on the last working day before Christmas, and 417 of its 586 pages were completely blanked out.

    I should explain what “blanked out” means here, because it’s actually worse than it sounds. “Redacted” means the pages existed but their contents were hidden with black boxes on the version published for the public to see. So journalists, MPs, campaign groups, your GP, you: none of us could read what was in 71% of the contract. Government policy says public bodies have to give reasons when they redact contracts. No reasons were given.

    The Good Law Project launched legal proceedings to find out what was underneath all that black ink. And what they discovered was, if anything, more alarming than what anyone had guessed. The pages weren’t redacted for national security reasons or commercial sensitivity in the usual sense. They were blanked out because those sections, including the data protection clauses, hadn’t actually been agreed yet. NHS England’s own lawyers admitted the provisions were still “subject to commercial negotiation.”

    Let me just make sure that’s landed. NHS England awarded Palantir a £330 million contract to handle the health data of tens of millions of people. They signed it. Then they continued negotiating the terms afterwards. Including the bit about how your medical records would be protected. And when they published the contract, they hid the unfinished bits by blacking them out and releasing it on the day everyone was wrapping presents. The Good Law Project said this was potentially unlawful, not least because once you’ve signed, you’ve given away your negotiating power. Palantir already had the deal. What incentive did they have to agree to stronger privacy terms at that point?

    I’ll just leave that there for a moment while we all process it together.

    Cartoon of a woman reading a thick document where every page is covered in black redaction bars. She has reached page 417. A mug on the desk reads Transparency. Caption: The public version.

    Then, within weeks of signing, Palantir secretly hired a Tory-linked PR agency to pay social media influencers to promote the platform. The briefing asked the influencers not to mention Palantir by name. The NHS investigated it as a potential contract breach. It’s like watching someone trip over their own shoelaces at a job interview. Except the job is running the health data of everyone in England.

    Wait, but what does the NHS actually need this for?

    Before I go any further, I want to be fair about something. The NHS has a real problem, and Palantir offered a real solution to it. If I don’t explain that, this whole piece sounds like conspiracy thinking, and it isn’t. The problem is genuine. It’s who we chose to fix it that’s the issue.

    Here’s the thing about the NHS: it’s enormous, and it’s fragmented. There are around 200 hospital trusts in England, plus integrated care boards, GP practices, mental health trusts, ambulance services, and community health providers. Each one has its own IT systems. Many of those systems are, to put it diplomatically, not new. Some of them can’t talk to each other at all. Your GP records are in one system. Your hospital records are in another. Your outpatient appointments might be in a third. Your prescription history could be somewhere else entirely.

    If you’ve ever turned up at A&E and the doctor has asked you questions that you know are already in your medical records somewhere, you’ve experienced this problem personally. If you’ve ever been referred to a specialist and had to explain your entire history from scratch because they couldn’t see your GP notes, that’s the same problem. It means duplicated tests, missed information, delayed discharges, and longer waiting lists. People genuinely suffer because NHS data systems don’t join up. Better data integration could genuinely save lives. Nobody disputes this.

    The Federated Data Platform was supposed to fix it. The idea was to link up all that fragmented data so the NHS could see, in real time, how many beds are available across a region, where waiting lists are longest, where ambulances are being held up, and where discharge bottlenecks are causing problems. At a trust level, it would help hospitals manage patient flow and theatre scheduling. Perfectly reasonable goals. Genuinely useful. The kind of thing you’d want your health service to be doing.

    So the question isn’t: did the NHS need better data infrastructure? It did. The question is: did the NHS need this company to build it? A company founded with CIA money, whose main clients are military and intelligence agencies, whose co-founder has documented ties to a convicted sex offender, and whose lobbyist is under criminal investigation? When the NHS’s own chief data officers wrote an open letter saying they already had tools that exceeded what the FDP was offering? When Leeds Teaching Hospitals said adopting it would mean losing functionality? When the contract was awarded through a process involving £60 million in uncontested deals, broken consultation promises, and privacy clauses that weren’t finished when the thing was signed?

    The NHS needed a better filing system. What it got was a surveillance platform with a lobbying operation, a Tolkien fixation, and a founder who thinks democracy is overrated. Which, as solutions go, is a bit like calling a plumber and getting a submarine. Technically it involves pipes, but it’s not quite what you had in mind.

    If the product isn’t better, what’s actually going on?

    This is the bit where I need to be really careful, because I’m going to lay out a set of documented facts and then ask an open question, and I want to be clear about which is which.

    Here are the facts. Scotland kept Palantir out of NHS Scotland entirely. Their data systems work. Their patients are being treated. The sky did not fall in. The NHS’s own chief data officers said their existing tools were better than what Palantir was offering. Leeds Teaching Hospitals said adopting the platform would mean losing functionality. Most trusts don’t want it. The government is paying KPMG £8 million to persuade hospitals to adopt it. If you’re paying a consultancy firm eight million pounds to convince your own customers to use your product, the product is not selling itself.

    So why is it still happening? Let me show you what the public record says about who benefits.

    Palantir paid Global Counsel, Mandelson’s lobbying firm, from 2018 onwards. The fee has never been publicly disclosed. Mandelson retained a roughly 21% shareholding in Global Counsel while simultaneously facilitating meetings between Palantir and the Prime Minister. That means he had a direct financial interest in Palantir winning UK government contracts. That’s not speculation. That’s Companies House filings and Hansard.

    The Good Law Project noted that the head of Palantir’s UK operation made a donation to a Conservative minister. The revolving door between the NHS and Palantir is documented too: openDemocracy found that at least three former NHS data experts left the health service and joined Palantir, including Indra Joshi, who was the NHS’s head of AI and helped launch the Covid-19 datastore, the first NHS project to use Palantir’s software, before leaving the health service and joining the company in 2022. Imagine being the person responsible for introducing a company’s product into your workplace, then going to work for that company. It’s technically legal. It doesn’t look great.

    Cartoon showing a revolving door between three buildings labelled NHS, Palantir, and Government, with people carrying boxes of belongings walking calmly between them in a circular pattern while a cleaner mops the floor unbothered.

    On the political side, the Good Law Project found that Health Secretary Wes Streeting has accepted up to £372,000 from companies and individuals with links to private healthcare since entering parliament in 2015, representing more than 60% of his total registered donations. Nobody is suggesting that money was specifically in exchange for the Palantir contract. But when a Health Secretary who has received hundreds of thousands of pounds from private health interests is privately briefed that a private health contractor’s reputation is damaging delivery, and his response is to press on with the contract anyway, it’s reasonable to ask what’s shaping his priorities.

    I want to be honest: nobody has produced a smoking gun showing someone received a brown envelope in exchange for this contract. That’s not how it works at this level, and expecting it to look like that is how it keeps working. What the public record shows is lobbying fees, shareholdings, political donations, a revolving door of staff, dinner party networks, and the kind of access that money buys but never explicitly pays for. It’s structural, not transactional. The money doesn’t flow in a straight line from A to B. It flows in a circle, where relationships become contracts become jobs become donations become access become relationships again.

    I don’t know exactly who benefits from this arrangement or by how much. But I know that when a product the customers don’t want is being sold to them with £8 million of public money, by a company whose lobbyist had a financial stake in the outcome, whose staff are recruited from the very organisation they’re supposed to be serving, and whose contract was signed before the privacy terms were even agreed… “sorting out the NHS’s data” probably isn’t the whole story.

    The man behind the seeing-stone

    To understand how we got here, you need to know a bit about Peter Thiel. He studied philosophy at Stanford, which I mention because his philosophy is genuinely built into Palantir’s DNA, and it’s… well. It’s a lot.

    He co-founded PayPal. He was the first outside investor in Facebook. He created Palantir with seed funding from In-Q-Tel, which is the CIA’s venture capital arm (the CIA has a venture capital arm! I didn’t know that either, and I sort of wish I still didn’t). His biographer Max Chafkin describes his thinking as “bordering on fascism”. He’s written openly that he no longer believes freedom and democracy are compatible. In his book Zero to One, he argues companies are better run than governments because they have a single decision-maker. A dictator, essentially, though he’s too polished to use that word.

    His political network is vast. JD Vance, the current US Vice President, is Thiel’s protégé: mentored by him, employed by him, and bankrolled with $10 million for his Senate run. More than a dozen people with ties to Thiel sit inside the Trump administration, including former Palantir staff in the Department of Health, the Treasury, and DOGE. Stephen Miller, the architect of America’s mass deportation policy, personally owns more than $100,000 of Palantir stock. Palantir makes the software that ICE (Immigration and Customs Enforcement, the US agency currently carrying out mass deportation raids under Trump) uses to find people. I’m not going to draw you a diagram. You can see it.

    And then there’s the Epstein connection. Byline Times documented that Thiel maintained a business relationship with convicted sex offender Jeffrey Epstein through a venture fund called Valar Ventures, from 2014 until Epstein’s final arrest in 2019. Former Israeli PM Ehud Barak described Thiel and Epstein as “co-owners” of the fund. Thiel’s spokesperson denied the “co-owner” bit but confirmed Epstein was a limited partner. The distinction may matter to some people. I will let you decide if you’re one of them.

    The man actually running it

    Thiel is the co-founder and chairman. But the person running Palantir day to day is Alex Karp, and he’s arguably even more interesting, because he’s the contradiction that makes the whole thing work.

    Karp and Thiel met at Stanford Law School. Karp then went off and got a PhD in social theory from Goethe University in Frankfurt. He grew up in a leftist family with activist parents. He describes himself as “progressive but not woke” and has donated to Biden and Kamala Harris. On paper, he’s the political opposite of Thiel. And yet they co-founded the same surveillance company, and they’ve been running it together for over 20 years. Funny how that works.

    In 2024, Karp was the highest-paid CEO of a publicly traded company in the United States, with compensation of almost $6.8 billion. That’s billion with a B. For context, the entire £330 million NHS contract, the one that’s supposed to transform healthcare data for the whole of England, is roughly 3% of what Karp personally earned in a single year. I don’t know what to do with that information. I’m just putting it there.

    He’s also been saying some very interesting things out loud recently. On CNBC last week, he said “what makes America special right now is our lethal capabilities, our ability to fight war.” He’s described himself as “exceedingly proud” of Palantir’s work supporting Israel. And in the same interview, he said that AI technology will reduce the economic power of “highly educated, often female voters, who vote mostly Democrat” while increasing the power of “working-class, often male” voters. Which is, I think, a remarkably candid thing for a self-described progressive to say about his own product. The New Republic described it as a direct pitch to the Republican Party from a CEO whose company is already embedded in the Pentagon.

    So that’s Palantir’s leadership. The co-founder believes democracy is incompatible with freedom. The CEO describes himself as progressive while running a surveillance company that aids deportation raids, supports military operations, and whose product he cheerfully admits will undermine the economic power of educated women. They present as opposites but they built the same machine and it serves the same ends. The difference is that Thiel is honest about his philosophy. Karp wraps the same outcomes in nicer language.

    The Mandelson web (where it gets really wild)

    OK. This is where the story goes from “that’s concerning” to “are you actually serious.” I need you to stay with me because every single thing I’m about to say is documented, sourced, and on the public record, even though it reads like the plot of a thriller that would be rejected for being too far-fetched.

    In 2018, Palantir hired Global Counsel, the lobbying firm co-founded by Peter Mandelson. The goal was to make Palantir look like a respectable partner for the UK government. At this point, both Thiel and Mandelson were connected to Jeffrey Epstein. Thiel through Valar Ventures. Mandelson through a personal relationship that continued after Epstein’s 2008 conviction for sex offences against children. The man hired to make the surveillance company look respectable, and the man who founded the surveillance company, were both connected to the same convicted sex offender.

    I’ve typed that sentence several times now and it still doesn’t feel real. But it is.

    Global Counsel got busy. In February 2023, they hosted a dinner where the NHS’s chief data officer was listed as the “guest of honour”. Nine months later, Palantir won the £330 million contract. I’m sure that’s a coincidence.

    When Mandelson became UK Ambassador to the US, civil servants warned him that his interest in Global Counsel “would have to cease”. He didn’t comply. He kept his roughly 21% shareholding. While still ambassador, still holding those shares, he arranged a meeting between Palantir’s CEO and Keir Starmer at Palantir’s US headquarters. The meeting didn’t appear on the PM’s register of visits.

    Shortly after, the MoD awarded Palantir a contract worth roughly £250 million. Directly. Without competition. MPs asked for the documents from the Starmer-Palantir meeting. The government refused, saying it was “too expensive to find them”. The minutes of a meeting between the Prime Minister and a surveillance company that just received a quarter-billion-pound defence contract. Too expensive to locate. I’ve lost socks that were easier to find.

    Mandelson has since been sacked as ambassador, forced to resign from Labour and the House of Lords, and is under Metropolitan Police investigation. Global Counsel has gone into administration. But Palantir still has every single one of its contracts.

    Byline Times asked the question that I think deserves a proper answer: if Mandelson’s links to Epstein disqualify him from holding power, why does the company controlled by Epstein’s business partner still have access to the UK’s most sensitive infrastructure? Nobody’s answered that yet. I’d genuinely love to hear someone try.

    Why your NHS data matters more than you think

    Here’s where we need to talk about what Palantir’s software actually does, because it’s not just a fancy spreadsheet.

    Palantir’s Foundry platform is designed to link datasets that weren’t previously connected, find patterns between them, and build profiles. That’s the product. That’s what it does for the CIA. That’s what it does for ICE (Immigration and Customs Enforcement, the US agency carrying out mass deportation raids under Trump), combining immigration records with financial data and phone records to track people. That’s what it does for the military, fusing satellite imagery with intercepted communications to generate targets. Palantir’s CEO said last week that “what makes America special right now is our lethal capabilities, our ability to fight war.” Charming.

    That same cross-referencing engine now sits on top of the NHS.

    The NHS holds structured health data on the population of England. Your GP visits, your prescriptions, your mental health records, your sexual health, your pregnancies, your addiction history. Linked to your postcode and date of birth. Ernst & Young estimated in 2019 that this data is worth £9.6 billion a year: about £5 billion to commercial organisations who could profit from the patterns, and £4.6 billion in benefits to patients through better outcomes.

    I want to pause on that framing for a second, because it bothers me. The NHS wasn’t built as a data asset. It was built to look after people. The data exists because doctors and nurses care for patients. The fact that someone put a commercial price tag on it, and bundled “value to pharmaceutical companies” together with “benefits to sick people” into one headline number, tells you something about how this conversation has already been quietly shifted underneath us.

    A report from health justice group Medact, backed by Amnesty International, Privacy International, and the Good Law Project, just laid out why the next shift should worry us. Medact warned that the platform could enable government departments like the Home Office and police to access patient data. Palantir’s own UK executive has argued publicly for a “common operating system” linking NHS, DWP, and other public data. And Reform UK has explicitly pledged to “automatically share data between the Home Office, NHS, HMRC, DVLA, banks and the police” to find and deport people. The infrastructure for that is being built right now. That’s not a conspiracy theory. It’s in their policy document.

    The chilling effect is already measurable. During the pandemic, around 57% of migrants avoided seeking healthcare because they feared being reported to the Home Office. Put a surveillance company’s cross-referencing engine in the middle of that system and people who need medical help will stop asking for it. That’s not hypothetical. That’s maths.

    Meanwhile, fewer than a quarter of England’s 215 hospital trusts were actually using the platform by the end of 2024. Leeds Teaching Hospitals told NHS England it would “lose functionality rather than gain it”. The response from government? They paid KPMG £8 million to “promote the adoption” of software that hospitals don’t want. Eight million pounds of public money on what is essentially a marketing campaign for a product the actual customers are politely declining. That’s a sentence I didn’t expect to write today, and yet here we are.

    Cartoon of a man in a suit enthusiastically presenting a laptop labelled Platform to tired NHS staff in scrubs, one of whom is holding their own laptop with a sticky note reading Already works. A banner behind reads Adoption Campaign £8m budget.

    Tim Berners-Lee and the road not taken

    Right. Here’s the bit that turns this from infuriating to properly heartbreaking. Because there was always another way, and it was right there.

    Tim Berners-Lee invented the World Wide Web in 1989 and gave it away for free. No patent. No licensing fee. Because he believed information should be open and accessible to everyone. I wrote my university dissertation about him in 2002 (specifically about whether Flash animation would be the future of the web, which in hindsight was not my strongest prediction), and I’ve been banging on about his vision ever since. But his recent work is what matters here.

    He’s been building a project called Solid, which does exactly what the NHS needed: it keeps data under the control of the people and institutions it belongs to, with access granted on a permission basis. No centralised platform. No vendor lock-in. No surveillance company required.

    Split panel cartoon. Left side labelled The Seeing Stone, Palantir: a man sits alone in an armchair clutching a glowing orb with tiny people visible inside it. Right side labelled The Web, Given away free 1989: a diverse group of people each hold their own small glowing orb, smiling.

    Speaking in Barcelona on 3 March, he demonstrated an AI assistant called Charlie that pulls from a user’s own data store, not a corporate database. He said: “Claude doesn’t understand anything about you, but Charlie does.” Because Charlie has permission to use your data, on your terms. That’s the model. That’s what was always possible.

    The NHS’s own people knew this. The NHS Chief Data and Analytical Officer Network wrote in an open letter that they “already have similar tools in use that presently exceed the capability” of what the Federated Data Platform was offering. They didn’t need Palantir. They needed investment in what they already had.

    Berners-Lee and Thiel are almost perfect philosophical opposites. One built the web and gave it away because he believed it belonged to everyone. The other built a surveillance company and named it after Tolkien’s cautionary tale about surveillance. One believes you should own your own data. The other believes exceptional individuals should control it. The NHS chose Thiel’s model. Nobody asked us which one we preferred.

    What can actually be done (the hopeful bit)

    I promised myself I wouldn’t write one of those pieces that makes you feel terrible and then stops. So here’s the constructive bit, and I mean it.

    The political picture isn’t great right now. Wes Streeting was privately briefed that Palantir’s reputation was hindering the platform’s delivery and pressed on. In private WhatsApp messages to Mandelson, he conceded Israel was “committing war crimes before our eyes”, while publicly dismissing concerns about Palantir’s NHS involvement. It’s fair to say the political class, across parties, has not covered itself in glory on this one.

    But there are real pressure points, and real people applying real pressure. The contract comes up for review in February 2027. The BMA has formally called for the contract to end. Medact’s report is backed by Amnesty International, Privacy International, and the Good Law Project. Scotland has kept Palantir out of NHS Scotland entirely, which proves it’s possible. Local campaigns are fighting trust by trust, ICB by ICB.

    And here’s the thing I keep coming back to, the thing that actually gives me hope, although I want to be honest about the limits of that hope because I think you deserve that. Every single fact in this article comes from a public source. Companies House filings. Contracts Finder. Hansard. The lobbying register. FOI responses. Investigative journalism built on publicly available records. The information is all there. It’s just scattered across dozens of databases that don’t talk to each other, which means connecting it all up currently requires months of work by specialist journalists and lawyers with resources most of us don’t have. Most of us are trying to get through Tuesday.

    So I’ve been thinking: what if there were a tool where you could type in any company’s name and see, in one place, what public contracts they hold, who their directors are, who lobbied for them, and what political donations are connected? Not opinion. Not editorialising. Just public data, linked up and searchable. The kind of thing that currently takes an investigative team months, available to anyone with a browser and a cup of tea.

    I’m calling the project Power to the Minions, because I’m a mum of four who lives in Frome and I think naming things should be fun, and also because that’s literally what it is: giving ordinary people access to information that currently only well-resourced professionals can piece together.

    Now. Before I get carried away with my own pitch, let me be the first to say: I’m not going to pretend a search tool fixes democracy. If it were that simple, someone would have done it by now, and we’d all be living in a utopia where government contracts were awarded on merit and dinner party invitations had no bearing on procurement decisions. Clearly, we are not living in that utopia. I checked.

    The investigative journalists who broke this story are brilliant. openDemocracy, the Bureau, Byline Times, Foxglove, the Good Law Project: they’ve done extraordinary work over six years. And Palantir still has its contracts. So why would a tool help where journalism hasn’t?

    Here’s my honest answer: journalism produces stories. Stories have news cycles. They peak, they get shared, people are outraged for a week, and then everyone moves on to the next thing. The Palantir-NHS story has been broken repeatedly since 2020. Each time there’s a flurry of attention. Each time it fades. The contracts remain. That’s not a failure of journalism. That’s the nature of how attention works. A story is a photograph of a problem. What doesn’t exist yet is a window.

    The difference between a photograph and a window is that the photograph gets looked at once and then goes in a drawer. The window means anyone can look, any time, for as long as the building stands. A tool that connects Companies House data with Contracts Finder with Hansard with the lobbying register isn’t a photograph. It’s a window. It doesn’t need a news cycle to work. It’s just there, permanently, for anyone who wants to look through it.

    Cartoon of a woman holding a cup of tea, looking through a window at an illuminated web of connections linking nodes labelled Contract, Director, Donation, Lobbyist, Minister, and Dinner. Caption: What if the light was just always on?

    Does it stop Palantir on its own? No. Of course not. A window doesn’t stop a burglar. But it does mean the neighbours can see what’s happening. And it means the next time someone awards a contract to a company whose lobbyist is under criminal investigation and whose founder has documented business ties to a convicted sex offender, the connections are visible within minutes instead of months. That changes who can ask questions, how quickly, and how often. It doesn’t replace the journalists and lawyers. It gives them (and everyone else) a head start. Instead of spending three months finding the web, they can spend three months acting on it.

    Also, and this is the bit that quietly matters most: it changes the calculation for the people doing the dodgy deals. Right now, if you’re awarding a contract to a friend of a friend after a nice dinner, you know it’ll take years for anyone to connect the dots. If the dots connect automatically the moment the contract hits Contracts Finder? You might reconsider whose dinner invitation you accept. Transparency doesn’t just expose problems. It prevents some of them from happening in the first place, because the humans involved are, at bottom, quite keen on not being caught.

    I know what I’m describing sounds like it might already exist. There are good tools out there. OpenCorporates makes Companies House data searchable. They Work For You makes Hansard searchable. But nobody’s built the connective layer between them. You can look up a company. You can search for contracts. You can check the lobbying register. You can search Hansard. What you can’t do, anywhere, is go from “this company got this contract” to “and here’s who lobbied for it, and here’s where the directors sit on other boards, and here’s who donated to which politicians” in one search. That’s the gap. And it’s the gap where the story lives.

    The elephant in the room: they already have our data

    I can hear the question, because I asked it myself: even if we get Palantir out at the 2027 review, haven’t they already had access to our data since 2020? What’s done is done, surely?

    Fair point. And I want to be honest about it rather than do the thing where you pretend there’s a magic undo button and everyone goes home happy. Yes, Palantir has been processing NHS data for over five years. The structural knowledge they’ve gained, the patterns they’ve identified, the architecture they’ve built: that institutional learning doesn’t evaporate when a contract expires. Nobody’s invented Ctrl+Z for corporate knowledge. That’s a real and uncomfortable truth.

    But ending the contract still matters. A lot. It stops the ongoing, daily access to live patient data. It prevents the Federated Data Platform from becoming the permanent infrastructure through which a future government could do cross-departmental surveillance. It breaks the vendor lock-in before it becomes irreversible. And it sends a signal, to Palantir and to every other company watching, that there are consequences for how you behave, who you associate with, and whose data you handle. Consequences are underrated. We should have more of them.

    Scotland proves it’s possible. They kept Palantir out of NHS Scotland entirely. The sky didn’t fall in. Their data systems still work. The patients are still being treated. The lesson is clear: you don’t need a CIA-funded surveillance company to manage healthcare data. You need investment in your own people and your own infrastructure. Which is, funnily enough, what the NHS’s own data chiefs were saying all along, to anyone who was listening, which apparently did not include the people signing the contracts.

    There’s something Tim Berners-Lee said that I think about a lot: the web was designed, which means it can be redesigned. The same is true of the systems that currently protect opacity. They were built. They can be rebuilt. And you don’t need to be an investigative journalist or a lawyer to help. You just need the data to be findable.

    The seeing-stone serves whoever holds it

    Cartoon of a glass orb on a desk with GP records, Prescriptions, Mental health, Postcode, and Date of birth written inside it. Two hands reach for it from opposite sides: one with an NHS cross on the cuff, the other with an eye symbol cufflink. Caption: One seeing-stone to rule them all.

    I keep coming back to Tolkien, because the metaphor really is almost annoyingly perfect.

    The palantír isn’t dangerous because the bad guys built it. The Elves built it, for perfectly good reasons. It’s dangerous because once it exists as a centralised tool of seeing, it serves whoever holds it. The Federated Data Platform is the same. The NHS built it to manage waiting lists. Reasonable goal. But once it exists as a single connected data layer across the entire health system, run by a company whose core business is cross-departmental surveillance, you’ve created something whose potential uses extend well beyond anything the NHS intended.

    A future government that wants to cross-reference your health data with your immigration status, your benefits claims, or police intelligence doesn’t need to build anything new. The pipes are already laid. They just need to turn the taps.

    Cartoon of an NHS building with coloured pipes labelled GP Records, Prescriptions, Mental Health, Sexual Health, and Immigration Status all feeding into a single tap controlled by a suited hand, dripping into a bucket labelled TBD. A diverse group of patients watches from outside. Caption: The plumbing is already done.

    Tim Berners-Lee closed his Barcelona talk with something that I think is worth finishing on: “Imagine apps which are collaborative, which are creative, which are compassionate. Imagine this world, and do whatever you can to get towards that world.”

    I reckon “whatever you can” is the important bit. Not everyone can sue the government or fund a legal challenge. But we can build tools that connect public data. We can support the people doing the hard work: openDemocracy, Foxglove, the Good Law Project, Medact. We can pay attention. We can refuse to let complexity be the thing that shields power from accountability.

    The man who invented the web gave it away because he believed it belonged to everyone. The man who founded Palantir named it after a fictional surveillance device because, I suspect, he understood exactly what he was building.

    I know which vision I’d rather build towards. And if you’ve read this far, I’m guessing you do too.