The UK government is facing mounting pressure to reconsider its reliance on American technology providers, specifically regarding the digital infrastructure of the National Health Service (NHS). A recent report from the House of Commons Science, Innovation and Technology Committee has called for a strategic pivot, urging ministers to end a major contract with the US-based data analytics firm Palantir. This development highlights the growing global debate over digital sovereignty and the risks associated with outsourcing critical public sector data processing to foreign corporations.
The committee’s report, released in the final quarter of 2024, explicitly warns that the increasing presence of Palantir across the UK public sector represents an “unacceptable point of weakness.” Lawmakers argue that the government’s dependence on a single US entity for managing sensitive health data could create systemic vulnerabilities. The Commons Science, Innovation and Technology Committee underscored that while AI and advanced analytics are essential for modernizing the NHS, the current procurement strategy lacks the necessary diversification to protect national interests.
For those of us following the intersection of data privacy and government procurement, This represents a significant escalation. Palantir, a company founded by Peter Thiel, has long been a fixture in defense and intelligence circles, but its expansion into civilian healthcare—most notably through the NHS Federated Data Platform (FDP)—has drawn scrutiny from privacy advocates and now, parliamentary oversight bodies. The core of the issue is not merely the technical capability of the software, but the geopolitical implications of entrusting a foreign-owned firm with the medical records of millions of British citizens.
The Scope of the Palantir Contract
The contract in question is the NHS Federated Data Platform, a multi-year project valued at approximately £330 million, which is intended to consolidate patient data across different hospital trusts to improve operational efficiency and clinical decision-making. Palantir Technologies was awarded the lead contract for this platform in November 2023, beating out several competitors in a move that the government described as a vital step toward digitizing the health service. The project is designed to reduce backlogs and streamline resource management by providing real-time data insights to NHS staff.
However, the Science, Innovation and Technology Committee’s latest findings suggest that the government may have underestimated the risks of “vendor lock-in.” By relying on a proprietary system, the NHS could find it increasingly difficult to migrate to other platforms in the future, effectively tethering the health service’s digital evolution to the commercial interests and stability of a single US-based provider. This concern is compounded by the fact that Palantir is subject to US law, specifically the Clarifying Lawful Overseas Use of Data (CLOUD) Act, which raises complex questions regarding data access and jurisdictional control over information stored by a US company, even when that data is hosted within the UK.
Sovereignty and Security Concerns
The debate surrounding Palantir is part of a broader, ongoing conversation about digital sovereignty. As nations become more dependent on cloud computing and AI, the ability to control and secure national data has become a pillar of national security. Critics of the current agreement argue that the UK should prioritize domestic alternatives or open-source solutions that offer greater transparency and autonomy. The committee’s report specifically points to the lack of a clear exit strategy as a major oversight, suggesting that the government should have mandated more interoperability from the start.
In response to these concerns, the government has consistently maintained that the NHS retains full control over its data. According to official NHS England guidance, the data held within the FDP remains under the strict control of the health service, and Palantir acts merely as a data processor, not a data owner. Despite these assurances, the committee argues that the operational dependence created by the contract is so profound that the technical control mechanisms are insufficient to mitigate the risk of a strategic disruption.
What Happens Next?
The government is now under pressure to provide a formal response to the committee’s recommendations. While the committee does not have the power to force the termination of the contract, its findings carry significant political weight and could influence future procurement decisions. The current contract for the Federated Data Platform is set to run for several years, with options for extensions, meaning any decision to pivot away from Palantir would involve significant legal and financial complexities.
Moving forward, the Department of Health and Social Care is expected to address these findings in an upcoming session of Parliament. Observers will be looking for signs of a new, more diversified digital strategy—perhaps one that incorporates a mix of providers or places a greater emphasis on sovereign cloud infrastructure. For the healthcare sector, the goal remains the same: to harness the power of AI to improve patient outcomes, but the method for achieving that goal is clearly undergoing a rigorous, and perhaps overdue, re-evaluation.
As this story develops, we will continue to monitor the official responses from the UK government and any updates regarding the procurement process for future phases of the NHS digital transformation. If you have thoughts on the balance between innovation and national security in our public services, please join the conversation in the comments section below. Your insights are a valuable part of this ongoing global dialogue.
Related reading