The UK Has a Foreign Vendor Problem. The Case Studies Are Piling Up.
The NHS, MoD, and Metropolitan Police have each built deep operational dependency on Palantir through contracts largely awarded without competitive tender. Parliament has called it "an unacceptable point of weakness," Sadiq Khan blocked a £50 million Met Police deal, and the pattern keeps repeating: enter below scrutiny thresholds, build dependency, make exit expensive. This piece breaks down what went wrong in each case, and why jurisdiction and auditability should be procurement questions from day one, not exit-strategy ones.

Key takeaways
- The UK has accumulated significant Palantir dependency across the NHS, Ministry of Defence (MoD), and Metropolitan Police, with the majority of contracts awarded without competitive tender.
- In May 2026, London Mayor Sadiq Khan blocked a Palantir contract worth £50 million with the Met Police. This block came after the force reportedly only engaged with one supplier and structured its pilot to come in just under the MOPAC oversight threshold.
- The UK parliament's Science, Innovation and Technology Committee has called Palantir's presence in the UK public sector an "unacceptable point of weakness" and recommended the NHS contract not be renewed at its 2027 break clause.
- The security risk not only comes from the procurement process and data ethics, but also the operational dependency on a foreign platform. Palantir's architecture cannot be independently audited, and its jurisdiction means that a foreign government could gain access rights.
- Extracting from a deeply integrated intelligence vendor is not data migration but rather a capability gap. The organisations now managing Palantir exits are learning this the hard way.
The UK's relationship with Palantir is the most instructive ongoing case study in what happens when foreign vendor dependency is not assessed at procurement. The NHS, MoD, and Met Police have each arrived at the same place: a dependency that is expensive to sustain, damaging to exit, and that raises security questions no contract can adequately answer.
The question is not whether Palantir's technology works. The question is whether the security architecture it creates is one a mature organisation should accept.
The NHS and MoD: Direct Awards, Deep Dependencies
The UK parliament's Science, Innovation and Technology Committee published a report on 3 June 2026 which highlighted Palantir as the most concerning technology provider in UK public sector. Specifically, the report called the company's increasing presence "an unacceptable point of weakness" (1). It recommended the government exercise the break clause in the NHS Federated Data Platform contract, which is worth £330 million over seven years, when it falls due in February 2027. From this, it recommended that the government seek either an in-house replacement or a UK-owned and UK-based alternative. The UK government has since confirmed it is reviewing the contract (2).
The MoD position is more concerning from a national security perspective. A separate Palantir enterprise agreement, which was also directly awarded, covers what the contract notice describes as "critical strategic, tactical, and live operational decision making across classifications" that is interoperable with NATO systems. As it is defence intelligence infrastructure running on a US-incorporated platform, it will thus become subject to CLOUD Act jurisdiction. The security architecture question it raises should have been the first one asked, not the last.
The Metropolitan Police: How the Pattern Reproduces Itself
The Met Police case shows how dependency replicates itself even when oversight structures are functioning.
In February 2026, the Met Police awarded Palantir a contract worth just under £500,000 to pilot AI-assisted assessment of officer conduct data. There was no open competition and no advertising for this contract, with it being awarded directly (3). The contract was priced precisely below the threshold above which MOPAC approval is required. Advocacy group Foxglove publicly described this as a classic "land and expand" strategy: offer limited pilot projects below scrutiny thresholds and then secure far larger contracts once operational dependency exists (4).
The full contract, which is worth £25.3 million for between 2026 and 2027 with an optional £24.8 million extension, would have automated criminal intelligence analysis and supported serious crime investigations. London Mayor Sadiq Khan blocked it on 21 May 2026, with the deputy mayor for policing describing the failure to submit a procurement strategy to MOPAC as a "clear and serious breach" of the rules. It was found that the Met Police had only seriously engaged with one potential supplier, with the contract value rising to the top of its estimated range through direct negotiation (5).
As a result, the security consideration involves criminal intelligence analysis, serious crime tracking and officer conduct data being the category of operational information that should not sit on a platform with opaque jurisdictional controls and whose architecture cannot be independently audited. The procurement failure matters but the security architecture question matters more.
What the Pattern Costs
Each case features the same sequence: entry below scrutiny thresholds or direct award, operational dependency creation, and extraction made expensive. By the time oversight arrives, the disruption of exit becomes its own argument for continuation.
Threat intelligence and operational security data describe an organisation's vulnerabilities, detection capability, and adversary knowledge. If a foreign government can compel a vendor to disclose that data, adversaries may be able to reach it. Extracting from a deeply integrated intelligence vendor is not a data migration issue. Workflows are embedded and analyst knowledge is platform specific. Additionally, integration points are numerous. It is a capability gap and organisations that asked the jurisdiction question at procurement will not face it.
What Good Looks Like
The direction of travel is unambiguous. The Dutch State Secretary for Defence confirmed on 2 June 2026 that a "fully fledged alternative" to Palantir must be available within two years, as part of a "two-track policy to reduce dependency" (6). Additionally, Germany's Bundeswehr cyber defence chief Vice Admiral Thomas Daum told Handelsblatt that awarding Palantir contracts is not anticipated. Daum stated that granting a private foreign company access to national databases is "simply inconceivable" (7).
For UK security leaders, the question is whether to get ahead of that direction or wait for the regulatory mandate. The organisations asking hard questions about their intelligence vendors now are the ones that will not face forced migrations under pressure later.
CYJAX is a UK-incorporated threat intelligence provider, certified to ISO 27001:2022, with an auditable platform and a commercial model that does not depend on entry-point lock-in. The security decision and the sovereignty decision are the same decision.
Sources
- The Register, June 2026 — UK lawmakers call on government to ditch Palantir NHS contract
- Engadget, June 2026 — The UK will review its NHS contract with US software firm Palantir
- Middle East Eye, May 2026 — Sadiq Khan cancels Met police Palantir contract
- Computing.co.uk, May 2026 — Sadiq Khan blocks Met’s £50m AI deal with Palantir
- AOL / PA Media, May 2026 — Met Police Palantir contract blocked by City Hall
- Euronews, June 2026 — Why are European governments reevaluating their agreements with US defence tech contractor Palantir?
- Harici, April 2026 — German military rejects Palantir partnership over data sovereignty concerns
- UK Defence Journal, February 2026 — MoD confirms Palantir contract was direct award
- The Register, January 2024 — NHS published redacted Palantir contract
- UK Parliament Early Day Motion, February 2026 — Government contract with Palantir Technologies
Get Started with CYJAX CTI
Empower Your Team. Strengthen Your Defences.CYJAX gives you the intelligence advantage: clear, validated insights that let your team act fast without being buried in noise.


