Four days. I published The Seeing Stones, a 5,000-word investigation into how a CIA-funded surveillance company ended up running the NHS, and four days later the Guardian broke a story that made me need to write another one.
On 22 March 2026, we learned that Palantir has been awarded a contract by the Financial Conduct Authority to analyse the regulator’s internal intelligence data.[1] Case files. Fraud reports. Phone call recordings. Emails. Social media posts. Consumer complaints. The entire investigative toolkit of the body responsible for overseeing 42,000 financial firms, from high street banks to crypto exchanges. Handed to Peter Thiel’s company for a three-month trial at more than £30,000 a week.[2]
When I added an update to the NHS piece, I thought a paragraph would do it. It didn’t. Because the FCA deal isn’t just another contract. It’s the piece that makes the whole picture visible. Palantir now sits inside the NHS (your health data), the Ministry of Defence (national security), police forces across England (criminal intelligence), and the Financial Conduct Authority (your financial life). That’s not a collection of separate deals. That’s an operating system. And the man running Palantir’s UK operation already told us that’s exactly what he wants.
What’s actually in the data lake?
The FCA describes its repository as a “data lake.” It’s a technical term for a large store of raw data, but it’s also accidentally the most honest piece of branding anyone involved in this story has produced. A data lake is murky. Things sink into it and become hard to retrieve. The boundaries are unclear. And once something swims in, it tends to stay.

According to multiple news outlets reporting on the Guardian’s investigation, the data Palantir will access includes: case intelligence files marked as highly sensitive; information on what the FCA calls “problem firms”; reports from banks and lenders about proven and suspected frauds; consumer complaints to the financial ombudsman; recordings of phone calls; swathes of emails; and social media monitoring data.[8][4][5] This isn’t a spreadsheet. It’s the entire investigative brain of the UK’s financial regulator.
Palantir will apply its Foundry platform, the same software it uses for the NHS and the MoD, to sift through all of this and look for patterns of financial crime: fraud, money laundering, insider trading.[5] The idea, on paper, is straightforward: AI is better at spotting patterns across massive datasets than humans are. The FCA oversees 42,000 firms. It needs better tools. Nobody serious disputes that.
But here’s the thing. The FCA chose to test this system using real data, not synthetic datasets. That decision raised eyebrows even among people sympathetic to the project, because testing AI systems on dummy data is standard practice precisely to avoid handing your most sensitive information to a contractor before you know whether the arrangement works.[5] The FCA went straight to the real thing. As Christopher Houssemayne du Boulay, a barrister at Hickman and Rose, told the Guardian: the FCA can compel firms to hand over vast quantities of data during investigations. “We could be talking about hundreds of whole email accounts and full financial records. Many innocent people will be caught up in that and the data may contain bank account details, email addresses, telephone numbers and other personal information.”[6]
The procurement that wasn’t quite
The FCA says it ran “an open, competitive procurement process.”[7] That phrase is doing a lot of heavy lifting, because according to Yahoo News UK, reporting on the Guardian’s investigation, there was only one other competitor for the contract.[8] One. Unnamed. In a market with dozens of data analytics firms.
If you’ve read the NHS piece, this will feel familiar. The pattern goes: small entry, prove value, become impossible to remove. Palantir’s NHS involvement started with a £1 contract during Covid, expanded to £60 million without competitive tender, then became a £330 million seven-year deal.[9] The MoD relationship started with a £75 million enterprise agreement in 2022, then grew to a £240 million contract in December 2025, awarded directly by the Defence Secretary with no competitive process.[10] As MPs noted in a February 2026 Hansard debate, the pattern is consistent: “Its £1 Covid contract with the NHS expanded to a £330 million contract under the last Government, and its Ministry of Defence contract tripled in size to £240 million, without due process or competition.”[11]
The FCA deal is positioned as a three-month trial. Just a trial. Like the £1 NHS contract was just a gesture of pandemic goodwill. Like the MoD enterprise agreement was just a modest partnership. I don’t know about you, but when a company with a documented track record of turning three-month trials into decade-long dependencies tells me this one is just a trial, I find myself checking whether any watermelon cocktails were involved in the decision.
The common operating system (they told us this was the plan)

In his evidence to the UK Covid-19 Inquiry, Palantir’s UK chief Louis Mosley urged the government to invest in a “common operating system” that would bring together data from “across local and central government, healthcare and other bodies of national strategic importance.”[12][13] He wasn’t being subtle. He was pitching.
Let’s map what that operating system looks like today. The NHS Federated Data Platform: health records, waiting lists, patient data across tens of millions of people.[9] The Ministry of Defence: strategic, tactical and live operational decision-making, including services to the navy’s nuclear-powered submarines.[14] Police forces in the East of England, Leicestershire and Bedfordshire: criminal intelligence, including, according to Liberty Investigates, data on political opinions, health records, sexual orientation and trade union membership.[15] Coventry City Council: children’s services and social care data.[6] The Cabinet Office. DEFRA. The Homes for Ukraine scheme. And now the FCA: financial crime intelligence, fraud detection methods, and the personal financial data of anyone caught up in an investigation.
The Nerve’s investigation in February 2026 found that Palantir’s deals with the UK state total at least £670 million across 34 contracts with ten government departments, police authorities and local councils.[14] And that was before the FCA deal was announced.
Mosley told a parliamentary select committee that each sector operates independently. That what happens in the US doesn’t affect the UK business. That Palantir has worked for administrations “of every colour.”[16] When asked whether the company was buying its way into being an NHS provider, he said he “strongly rejected” the critique.[16] But the map speaks for itself. Health. Defence. Policing. Financial regulation. Children’s services. Nuclear submarines. If this isn’t a common operating system, it’s doing an extremely convincing impression of one.
Professor Levi’s question (and the one the FCA asked internally)
Professor Michael Levi is a specialist in financial crime at Cardiff University. He told the Guardian that there has been “serious under-exploitation” of regulatory data, and that AI could genuinely improve how we detect financial crime.[6] He’s not an anti-tech campaigner. He’s a pragmatist. Which makes his question all the more pointed: “What are the protocols agreed between the FCA and Palantir about the onward use of things that they have learned in that process?”[6]
That’s the question. Not “is AI useful?” (it is) but “what happens to the knowledge?” When Palantir’s engineers learn how the FCA detects money laundering, that knowledge doesn’t vanish when the contract ends. You can delete the data. You can’t delete what people understood.
An FCA source put it more bluntly. Speaking to the Guardian, as reported by Yahoo News UK, they asked: “Once Palantir understands how we detect money-laundering threats, how do we know that they are ethically reliable enough not to share that information?”[8]
That’s an FCA employee. Not a campaigner. Not an opposition MP. Someone inside the organisation, asking whether the company they’ve just hired can be trusted with the methods they use to catch financial criminals. It’s the kind of question that, if it doesn’t keep you awake at night, should at least make you put the kettle on and have a think.
Now add the context. Palantir was co-founded by Peter Thiel, a prominent donor to Donald Trump.[8] Its technology has been used by the Israeli military and by US Immigration and Customs Enforcement.[17] According to Byline Times, reporting on the Epstein files, Thiel’s venture capital firm Valar Ventures had Jeffrey Epstein as a limited partner; a claim Thiel’s spokesperson disputed in terms of characterisation but confirmed in substance.[18] Palantir’s lobbying firm in the UK was Global Counsel, co-founded by Peter Mandelson, who while serving as UK ambassador arranged a visit by the Prime Minister to Palantir’s Washington headquarters. No minutes of that meeting have been published.[19][20] At the time, Mandelson held a shareholding of around 28% in Global Counsel, which listed Palantir as a client.[21][22] Mandelson was subsequently fired as ambassador by Starmer in September 2025 following revelations about his relationship with Epstein.[23] In February 2026 he was arrested on suspicion of misconduct in public office, and as of March 2026 remains released under investigation.[24][25] He has denied wrongdoing. Global Counsel has since collapsed into administration.[26] Palantir still has all its UK government contracts.
This is the company that now has access to the FCA’s financial crime detection methods. The contract says the data stays in the UK, that Palantir is merely a “data processor”, that encryption keys are retained by the FCA, that everything gets deleted afterwards.[7] Those are important safeguards. They are also exactly the same type of assurances given for every other Palantir contract.[2] And every other Palantir contract is still running.
The revolving door (it spins faster than you think)

If you want to understand how Palantir wins contracts, don’t look at the procurement notices. Look at the people.
OpenDemocracy reported that Palantir hired four former Ministry of Defence officials in 2025, before winning its record £240 million defence contract in December of that year.[10] One of them, Barnaby Kistruck, left his role as the MoD’s director of industrial strategy, prosperity and exports, and joined Palantir as senior counsellor just nine days later. OpenDemocracy reported that Kistruck played a key role in writing the UK’s Strategic Defence Review, which recommended an increased role for AI in defence.[10] The other three hires were two senior civil servants, Laurence Lee and Damian Parmenter, and former Conservative armed forces minister Leo Docherty.[10] OpenDemocracy noted there was no suggestion of wrongdoing on Kistruck’s part, and the MoD placed restrictions on his new role.[10]
Byline Times documented how Matthew Swindells, former deputy chief executive of NHS England, joined Global Counsel in September 2019, just two months after leaving his NHS role. He then became chair of Palantir’s health advisory board while simultaneously serving as joint chair of NHS hospital trusts, including Chelsea and Westminster, which was the first trust to pilot Palantir technology. The trust said Swindells was excluded from Palantir-related decisions.[18]
And then there’s Tom Watson. According to Democracy for Sale, the former Labour deputy leader (now Baron Watson of Wyre Forest) was recruited by Palantir; health campaign group Medact has listed him among former government officials “employed or consulted by” the company.[9][36] I’ll be honest, this one stung. I saw Watson in a London pub during one of the big anti-Brexit marches. He was one of the loudest voices for the People’s Vote. He did genuinely important work on the phone-hacking scandal. He felt like someone on the right side. And maybe he still is, in all sorts of ways. People are complicated. But the person you cheered at the march is now advising the surveillance company, and that’s not a contradiction Palantir minds at all. It’s the whole strategy. You don’t build a revolving door that only swings one way. Watson (Labour), Docherty (Conservative), Kistruck (senior civil servant). The point is that every door leads to Palantir.
I’m not suggesting anything illegal about any of these appointments. Business appointment rules exist. Cooling-off periods are applied. But the cumulative effect is that Palantir builds its client relationships by hiring people who understand those clients from the inside. Four MoD hires in a single year, before the biggest MoD contract in the company’s history, is a pattern that raises legitimate questions about how competitive these procurements really are.
I haven’t found evidence of a similar revolving door at the FCA. That doesn’t mean there isn’t one. It means we should be asking the question now, before the three-month trial becomes a three-year contract becomes a permanent dependency.
The AI underneath keeps changing (and that should worry you)
Here’s something that hasn’t had enough attention. Palantir’s Foundry platform uses large language models, AI systems built by other companies, to power its analysis. Until very recently, the most important of those models in Palantir’s US defence work was Claude, made by Anthropic.[27]
On 27 February 2026, the Trump administration blacklisted Anthropic. The Pentagon designated it a “supply chain risk,” a label normally reserved for foreign adversaries like Huawei.[28] The reason? Anthropic’s CEO Dario Amodei refused to remove safeguards that prevented Claude from being used for mass domestic surveillance or fully autonomous weapons. Trump called Anthropic staff “leftwing nut jobs” and directed federal agencies to stop using their technology.[28]
Palantir CEO Alex Karp confirmed that Claude is still running inside Palantir’s tools, even as the company plans to swap to other models. “Our products are integrated with Anthropic, and in the future, it will probably be integrated with other large language models,” he told CNBC.[29] According to Reuters, Palantir’s Maven Smart Systems, used for US military intelligence and targeting, were built using Claude’s coding tools. Rebuilding those workflows will take time and money.[30] The same Foundry platform is being deployed at the FCA.
So here’s the question nobody has answered: which AI model is powering Palantir’s analysis of the FCA’s data? If it’s Claude, what happens when the model swap takes place? If it’s something else, which something else? And what does it mean for the reliability and consistency of financial crime detection when the intelligence layer underneath your entire system is being ripped out and replaced because of a political dispute between a US president and an AI company over whether machines should be allowed to kill people without human approval?
I appreciate that’s a long sentence. It’s a long situation.
The sovereignty contradiction
The timing of the FCA contract is, to put it diplomatically, interesting. On 20 March 2026, just two days before the Guardian broke the FCA story, Lord Vallance told a parliamentary committee that the government was pursuing “a very different way of doing contracts: putting British companies there and procuring innovation here.”[31] Liberal Democrat MP Martin Wrigley responded that existing contract break points “must be exploited to move to UK solutions, sovereign solutions, otherwise we just continue doing the same stuff.”[31]
The government has launched a Sovereign AI Unit with £500 million. The Prime Minister says the UK should be “an AI maker, not an AI taker.”[32] A House of Commons Library briefing published in March 2026 documented growing concern about over-reliance on US tech firms.[32] An Early Day Motion in Parliament warned that “government services, democratic functions and critical infrastructure increasingly depend on a small number of external digital suppliers.”[33] A Westminster Hall debate on technology sovereignty was scheduled for the same month.[32]
And in the middle of all this, the FCA handed another sensitive system to Palantir.
I keep thinking about Wales. When the rest of the UK went with Palantir for NHS data, Wales said no. It’s building its own system, the National Data Resource, with data staying under public control.[34] That model exists. It’s not theoretical. It’s being built right now, by people who decided that sovereignty isn’t just a word you put in a policy document.
What you can actually do
I know how this reads. Overwhelming. Tentacular. Depressing. But there are things that are genuinely happening, and things you can do. The FCA contract is three months. It hasn’t become permanent yet. If enough people raise concerns now, during the trial, it might not.
Five things you can do right now
1. Write to your MP about the FCA contract. That sounds like a thing people say when they’ve run out of useful suggestions, but in this case, parliamentary pressure is genuinely building and cross-party. The Hansard debates in February 2026 show MPs from Labour, the Conservatives, the Liberal Democrats and the Greens all asking the same questions.[11] Your voice adds to that.
Find and write to your MP via WriteToThem
2. Support the organisations doing the legal heavy lifting. Foxglove forced the publication of the NHS contract and is campaigning for full transparency on all Palantir deals. The Good Law Project has been pursuing FOI requests and legal challenges for years.
Support Foxglove’s campaign
Support the Good Law Project
3. Back the push for digital sovereignty. The Open Rights Group is campaigning for a UK digital sovereignty strategy that would reduce dependency on a small number of foreign tech vendors across critical public services.[35]
4. If you work in the NHS, sign the Medact petition. Health workers are campaigning to cancel the NHS Federated Data Platform contract with Palantir when it comes up for review. The break clause exists. It just needs enough pressure to be used.[6]
Medact: No Palantir in the NHS
5. Share this article. Not because I want the clicks (although, you know, hello). But because this story only works if enough people can see the pattern. One contract is a procurement decision. Thirty-four contracts across health, defence, policing, financial regulation and children’s services is a strategy. The more people who can see it, the harder it is to keep doing it quietly.
You can also just pay attention. Because the next contract is always just a trial. The next expansion is always just an extension. The next dataset is always just a pilot. And by the time anyone notices the pattern, the common operating system is already built.
The seeing-stones keep multiplying

In my first piece, I wrote that “the seeing-stone serves whoever holds it.” Tolkien’s palantíri were neutral technology. They could be used for good or ill. The danger wasn’t in the stones themselves but in who held them, and what they wanted to see.
Palantir now holds seeing-stones pointed at your health, your security, your neighbourhood, and your finances. The company says it’s just a data processor. Just providing tools. Just helping catch criminals. And maybe that’s true today. But the question was never about today. It was always about what happens when the contract is permanent, the dependency is total, the revolving door has spun one more time, and someone in Washington, or in a boardroom, or at a dinner with exotic cocktails, decides they’d like to see something different.
The FCA’s own staff are asking whether this company can be trusted. The least we can do is listen.
A note on transparency: I’m a tech entrepreneur who builds legal technology. I have no commercial interest in Palantir’s competitors. I do have a strong interest in who gets to see my data, and yours. This article is based on publicly available sources, parliamentary records, and investigative journalism. All sources are cited below. Where claims are contested or attributed to specific outlets, I have noted this. Palantir has consistently maintained that it takes a “rigorous approach” to human rights and that its technology is used within strict contractual safeguards. Mandelson has denied wrongdoing in relation to the police investigation. No suggestion of illegality is made against any individual named in this article unless explicitly stated otherwise.
Sources and citations
- The Guardian, “Palantir extends reach into British state as it gets access to sensitive FCA data,” 22 March 2026. Reported via The Register, City AM, LBC, Yahoo News UK, and others.
- The Register, “Palantir trial plugs into UK financial watchdog’s data trove,” 23 March 2026.
- Finextra, “FCA criticised over using sensitive data in AI trial with Palantir,” 23 March 2026. Reports data contents, Houssemayne du Boulay privacy concerns, and contract terms.
- NewsBytesApp, “AI firm Palantir can now access UK’s financial data,” 23 March 2026.
- FStech, “Palantir wins FCA contract to analyse sensitive UK data,” 23 March 2026.
- Computing.co.uk, “UK financial watchdog taps Palantir for data analysis,” 23 March 2026. Quotes Prof Michael Levi (Cardiff University), Christopher Houssemayne du Boulay (Hickman and Rose), and notes Zack Polanski break clause call and Coventry Council contract.
- LBC, “Palantir to access sensitive UK financial data,” 23 March 2026. FCA spokesperson quoted: “We ran an open, competitive procurement process and have strict controls in place to ensure data is protected.”
- Yahoo News UK, “Palantir given access to highly-sensitive UK financial data,” 23 March 2026. Reports one unnamed competitor, FCA source ethics quote, and Peter Thiel as Trump donor. Reporting on the Guardian’s investigation.
- Democracy for Sale, “Palantir’s NHS data platform rejected by most hospitals,” May 2025. Documents “land and expand” strategy (quoting Foxglove), £1 to £330m NHS trajectory, and political recruitment.
- openDemocracy, “Palantir hired four ex-Ministry of Defence officials before winning record defence contract,” 24 January 2026. Documents Barnaby Kistruck (director of industrial strategy, prosperity and exports), Laurence Lee, Damian Parmenter, Leo Docherty. £240m contract awarded without tender December 2025. “openDemocracy is not suggesting any wrongdoing on Kistruck’s part.”
- Hansard, “Ministry of Defence: Palantir Contracts,” 10 February 2026. Cross-party debate. Quote: “Its £1 Covid contract with the NHS expanded to a £330 million contract.” Global Counsel links discussed. 34 contracts figure cited.
- Prospect Magazine, “How Palantir infiltrated the state.” Documents Mosley’s “common operating system” pitch.
- The Register, “Palantir suggests ‘common operating system’ for UK govt data,” 25 March 2025. Confirms Mosley’s Covid inquiry witness statement.
- The Nerve / Carole Cadwalladr, “Revealed: Palantir deals with UK state total at least £670m,” 7 February 2026. Documents £388m MoD, £244m+ NHS, nuclear submarine services, 34 contracts.
- Liberty Investigates / i newspaper, “UK police working with controversial tech giant Palantir on real-time surveillance network,” June 2025. Documents police data categories including political opinions, health records, sexual orientation, trade union membership.
- UK Parliament oral evidence, Science, Innovation and Technology Committee, Louis Mosley testimony. “Strongly rejected” buying-in critique; “administrations of every colour” quote.
- Novara Media, “What Is Palantir?,” 19 February 2026. Documents Israeli military use, ICE contracts ($200m+).
- Byline Times, 19 February 2026. Reports Valar Ventures / Epstein limited partner status (Thiel spokesperson disputed “co-ownership” characterisation but confirmed Epstein’s role). Documents Swindells revolving door. Notes trust said Swindells excluded from Palantir decisions.
- Good Law Project, “Mandelson’s embassy fixed Starmer’s visit to spytech firm,” April 2025.
- Hansard, “Lord Mandelson,” 4 February 2026. Documents Washington visit not in PM’s register, no minutes.
- Bloomberg, September 2025. Documents Mandelson’s 28% shareholding in Global Counsel.
- CIPR, 5 February 2026. Confirms Global Counsel registered with ORCL, lists Palantir as client.
- CNN, 23 February 2026. Confirms Mandelson fired as ambassador in September 2025 by Starmer following Epstein email revelations.
- Al Jazeera, 24 February 2026. Mandelson arrested on suspicion of misconduct in public office, released on bail. Also reported by CNN, PBS, NPR.
- ITV News, 6 March 2026. Mandelson released under investigation, no longer on bail, passport returned.
- Bloomberg, 19 February 2026. Global Counsel entered administration. Also Yahoo Finance / Sky News, 19 February 2026.
- CNBC, “Anthropic was the Pentagon’s choice for AI. Now it’s banned,” 9 March 2026.
- Axios, “Trump moves to blacklist Anthropic’s Claude from government work,” 27 February 2026.
- CNBC, “Palantir is still using Anthropic’s Claude as Pentagon blacklist plays out, CEO Karp says,” 12 March 2026.
- Reuters / Marine Corps Times, “Hegseth wants Pentagon to dump Claude, but military users say it’s not so easy,” 19 March 2026.
- The Register, “UK promises procurement shift after Palantir deals,” 20 March 2026.
- House of Commons Library, “Digital sovereignty,” Research Briefing CBP-10547, March 2026.
- UK Parliament Early Day Motion 65087, “UK digital sovereignty strategy.”
- Gwallter, “Who is Louis Mosley?” Documents Wales NHS decision to build National Data Resource without Palantir.
- The Register, “UK urged to cut out US Big Tech for sake of digi sovereignty,” 6 January 2026.
- Medact, “Health workers confront NHS leaders at closed-door Palantir meeting,” March 2026. Lists Lord Tom Watson among “former UK government officials now employed or consulted by Palantir.”










