Curated Intelligence
The Watcher And The Watched
In Tolkien’s legendarium, the seven palantíri were not built to surveil. They were instruments of coordination allowing the scattered kingdoms of Middle-earth to consult, share intelligence, and act in concert across vast distances. They worked as intended for an age.
Then Sauron recovered one.
The story is told most fully through Saruman. A mind of formidable analytical power, he used the Orthanc-stone to do what any intelligent administrator would do with access to superior intelligence: he looked. He gathered knowledge about his enemies; he watched the movements of power across great distances and calculated his position within them. He believed, for a long time, that he was the one doing the watching.
He was not. Sauron, possessing the Ithil-stone, could see through any palantír Saruman consulted. What Saruman received as intelligence, Sauron had curated as influence. By the time Saruman understood his visions had been selected for him, he was already under the spell.
The seeing stone had not lied to him, for that was precisely how it worked.
Palantir Technologies takes its name from those stones and makes the same promise: surveillance at scale, patterns made visible, threats identified before they materialize. What Tolkien understood, and what Switzerland’s military analysts arrived at through a different route, is that visibility tends to serve whoever controls the view.
Quis Custodiet
There is an argument implicit in the logic of surveillance technology: that observation produces accountability. If you can see everything, you can govern everything. The premise has a distinguished philosophical genealogy, from Bentham’s panopticon to Foucault’s elaboration of it as the organising principle of modern disciplinary society. ¹ There is something to this. But taken seriously, the argument proves too much. The premise is symmetry. If visibility produces better behaviour, it should apply to everyone, including those who operate the surveillance system.
Palantir’s code is proprietary. The governments and police forces using it cannot audit what it does, how its correlations are drawn, or what it chooses to surface and what it suppresses. The algorithmic logic determining who becomes visible, and why, is not available for inspection by the client. Governance, genuine governance as distinct from mere control, is the exercise of power constrained by accountability: to law, to affected parties, to some mechanism of redress. A surveillance system that is structurally opaque to those it serves functions less as a governance tool than as a tool of power.
In Tolkien’s account, Denethor was not a weak man. He was, by most measures, an exceptional one, a steward who held Gondor together under impossible pressure for years. The palantír did not defeat him by lying. It showed him the Black Fleet approaching and said nothing about the army marching under its flags. The stone produced no mechanism of appeal: the curator of the view was accountable to no one who depended upon it.
Seven Years Of No
When the Swiss Army commissioned an internal review of Palantir Technologies in late 2024, the conclusion was unambiguous. The software was impressive—“impressive” was the word the report used—but the risks were unacceptable. Chief among them: “there is a possibility that sensitive data could be accessed by the US government and intelligence services.”
This was not a single decision they arrived at quickly. According to an investigation by Republik magazine, based on 59 freedom-of-information requests filed with Swiss federal authorities, Palantir made at least nine documented approaches across the federal administration between 2018 and 2024—pandemic contact tracing, anti-money laundering systems, military intelligence. Each time, it was turned away.³
The reasons varied but formed a coherent pattern. The Federal Office of Public Health concluded that working with Palantir was “too sensitive” from a communications standpoint—reputational risk preceding any legal analysis. The Money Laundering Reporting Office found no legal basis for the required data exchanges. The Swiss Army’s report identified three compounding risks: foreign intelligence access to sensitive military data; vendor lock-in since Palantir’s architecture requires its own specialists to be permanently on-site making independent operation impossible; and the risk of “unintentional targeting”—that statistical correlations would implicate uninvolved people in the data sweep. When Republik published its findings, Palantir sued—not for defamation, not disputing any specific factual claim, but arguing that the magazine had denied it sufficient right of reply under Swiss media law. In June 2026, the Zurich Commercial Court dismissed 22 of 23 counterstatement requests. ⁴
Same Questions
The questions Switzerland was asking have since surfaced across Europe, through different institutional channels and at different speeds. The answers have not always been the same but the questions increasingly are. In Germany, three federal states—Bavaria, Hesse, and North Rhine-Westphalia—adopted Palantir's Gotham platform for police data analysis. In February 2023, Germany's Federal Constitutional Court ruled that the Hesse and Hamburg police laws authorising dragnet data analysis were unconstitutional: dragnet data analysis by algorithmic association violated the right to informational self-determination—the principle that individuals should retain meaningful control over information about themselves.⁵ The ruling is notable less as a rebuke than as a demonstration of institutional self-correction: the question Switzerland's procurement process raised was, in Germany, resolved through constitutional review. A fresh complaint against Bavaria's framework was filed in 2025.⁶
In the United Kingdom, similar deliberation is underway through different channels. Palantir holds contracts valued at approximately £670 million across civil and defence engagements, including a £330 million deal for the NHS federated data platform.⁷ In June 2026, a cross-party House of Commons committee called for the NHS contract to be reconsidered when it expires in 2027.⁸ That same year, London's Mayor declined a proposed £50 million deal between Palantir and the Metropolitan Police on procurement grounds.⁹ These are active deliberations, the kind that democratic oversight is designed to produce.
In France, the DGSI announced replacing Palantir's Gotham platform with ChapsVision, a French alternative, framing the decision explicitly in terms of sovereignty rather than performance.¹⁰ In July 2026, Spain issued a directive prohibiting state-controlled companies from contracting with Palantir, the sixth European country this year to reach a version of that judgment.¹¹ Six countries in a single year is not yet a trend. But across these cases, courts, committees, executives, and procurement reviews—the questions converging are recognisably the same. Who can access this data, on what legal basis, and what oversight does the client actually retain? The institutional channels may differ, but the underlying question does not.
The Architecture
Standard procurement frameworks evaluate cost, technical capability, and interoperability. They were not designed to ask: if this technology is turned against us, by the company, its home government, or a third actor, what recourse do we have? That is not a criticism of the people using them, but rather a description of their design. Expecting a cost-and-capability checklist to catch sovereignty risks is asking an institution to operate beyond its mandate.
The legal architecture sitting beneath Palantir’s contracts is not obscure. The CLOUD Act, signed in 2018, allows US law enforcement to compel US-incorporated companies to produce data held on their servers regardless of where those servers are physically located—including in allied European countries. ¹² FISA provides parallel authority for intelligence purposes. Neither statute includes a carve-out for NATO members, close trading partners, or states that have hosted American military bases for eighty years.
In 2013, documents disclosed by Edward Snowden indicated that the NSA had monitored the personal mobile phone of German Chancellor Angela Merkel, one of the United States’ closest European allies. The Obama administration subsequently stated that the US was not monitoring Merkel’s communications and would not do so going forward, a formulation that did not deny the practice had previously existed.¹³
What has changed since is the willingness to maintain the fiction that the architecture would not be activated. Trade tariffs deployed against historical allies as instruments of leverage, public questioning of NATO commitments, the explicit use of economic interdependence as a coercive tool between states that share intelligence arrangements and military infrastructure—these are not aberrations from an otherwise intact order.¹⁴ They are evidence that the order was perhaps more conditional than its participants were willing to acknowledge.
In this context, Switzerland’s question—who can access this data, and by what right—is not the question of a paranoid neutral. It is the question that results from reading the contract, and then reading the law of the jurisdiction that governs it, and then looking at the last five years of intergovernmental relations. Palantir is incorporated in the United States. Its data obligations run to US law, no matter what its sales materials say about sovereignty. Whether the incorporation question becomes a standing feature of how the next vendor is evaluated, rather than a correction applied after the fact, remains to be seen.
The Mantis And The Stone
China has a complementary parable, older still. In the writings of Zhuangzi, a young man with a sling spots a yellow bird in the branches of a tree. He raises his weapon and in doing so fails to see that the yellow bird is itself stalking a mantis, which is stalking a cicada. 螳螂捕蝉, 黄雀在后. The mantis stalks the cicada, unaware of the oriole behind. Each actor is wholly absorbed by its quarry. None sees the larger predatory chain of which it is a part. The young man, eyes fixed upward, steps into a fish trap. The parable warns against a specific kind of myopia: the blindness that attends confident surveillance. You see what you are hunting. You miss what is hunting you.
Switzerland’s question—who can access this, and by what right—did not begin as an AI governance question. It began as a procurement question, then became a constitutional one, then a geopolitical one. The trajectory matters. The same dynamics that made Swiss military analysts uneasy about Palantir’s data obligations will not become easier to navigate as the systems in question grow more capable: systems that can draft policy, assess threats, and advise on the use of force, at speeds and scales that outpace the institutional architectures designed to constrain them.
The CLOUD Act does not have a carve-out for language models. FISA does not distinguish between a database and a reasoning system. The jurisdictional asymmetries are structural, and they are not going away. The institutions being designed to govern frontier AI are only beginning to reckon with this. The question of whose data, under whose jurisdiction, auditable by whom is not a peripheral design consideration. It is the foundational one. Any governance architecture that cannot answer the question Switzerland answered through its procurement process—not as a paranoid edge case but as a basic threshold—will find itself, eventually, looking into a stone whose master it cannot name.
Implications for Institutional Design
What the Palantir cases illustrate, across different national contexts and institutional channels, is a structural lag: governance questions about AI surveillance tend to arrive after deployment, through courts, committees, and executive reviews designed to correct rather than anticipate. This is not a failure of those institutions—constitutional review, parliamentary oversight, and procurement controls are functioning as designed. The question is whether they are sufficient for the systems now being built.
Frontier AI systems will be more capable, more deeply embedded in civic and administrative life, and harder to audit than the surveillance platforms currently under review. The jurisdictional asymmetries that allow US authorities to compel disclosure of data held by any US-incorporated vendor are structural and will apply equally to language models, reasoning systems, and the governance infrastructure those systems will increasingly inform. For institutions now designing frameworks to govern this, the Palantir cases point to a single design constraint: the sovereignty and accountability threshold cannot be answered after deployment. It must be built into governance architecture before the systems it governs become the systems on which democratic life depends.
Path:OS works at the intersection of governance, systems change, and civic capacity. This piece reflects the analytical perspective of the practice. Empirical claims are sourced; where the evidence thins, the text says so.
Notes & Sources
Jeremy Bentham, Panopticon; or, The Inspection-House, 1787. Michel Foucault, Discipline and Punish: The Birth of the Prison, Gallimard, 1975, Part Three: "Panopticism." The extension of panopticon logic to modern governance is Foucault's; Bentham's original design was a prison reform proposal.
Swiss Army internal report, December 2024, obtained under freedom-of-information requests. All quotations from the report cited in this piece appear as published in the original investigation: Adrienne Fichter, Marguerite Meyer, Lorenz Naegeli, Balz Oertli, Jennifer Steiner, "How tenaciously Palantir courted Switzerland," Republik / WAV, December 8, 2025 (English translation February 18, 2026). The report was not independently accessed. republik.ch/2026/02/18/how-tenaciously-palantir-courted-switzerland
Republik / WAV, "How tenaciously Palantir courted Switzerland" (59 FOI requests; at least nine documented rejections across Swiss federal agencies; seven-year timeline). See footnote 1.
Palantir Technologies v. Republik AG, Zurich Commercial Court, judgment of June 12, 2026 (22 of 23 counterstatement requests dismissed; Palantir ordered to bear 95% of court costs). SWI swissinfo.ch, "Palantir loses legal challenge against Swiss investigative magazine," swissinfo.ch/eng/swiss-politics/palantir-loses-legal-challenge-against-swiss-investigative-magazine/91582700. See also: International Press Institute, "Switzerland: IPI welcomes court ruling dismissing Palantir lawsuit against Republik," ipi.media.
Federal Constitutional Court of Germany (Bundesverfassungsgericht), judgment of February 16, 2023, 1 BvR 1547/19 and 1 BvR 2634/20 (Hesse and Hamburg police data analysis laws held unconstitutional). bverfg.de
GFF (Gesellschaft für Freiheitsrechte), constitutional complaint against Article 61a of the Bavarian Police Tasks Act, filed 2025. freiheitsrechte.org
UK public contracts with Palantir totalling at least £670 million across roughly 34 engagements in ten-plus government departments — spanning NHS, Ministry of Defence, police, and Financial Conduct Authority work — as documented by The Nerve (investigation led by Carole Cadwalladr), February 2026. These include the NHS Federated Data Platform (NHS England, November 2023; valued up to £330 million over seven years; a Palantir-led consortium with Accenture, PwC, NECS, and Carnall Farrar) and a £240.6 million Ministry of Defence data-analytics contract (December 2025, awarded without competitive tender). MoD contract confirmed by TechRadar, "Palantir to continue UK Ministry of Defense work in new three-year deal," and by the parliamentary record (Hansard, HC Deb, 10 February 2026). The £670 million figure predates the December 2025 MoD contract; the documented total is now higher.
UK House of Commons Science, Innovation and Technology Committee, June 2026. Reported in: Euronews, "Why are European governments reevaluating their agreements with US defence tech contractor Palantir?" June 5, 2026. euronews.com/next/2026/06/05/why-are-european-governments-reevaluating-their-agreements-with-us-defence-tech-contractor
Mayor's Office for Policing and Crime (MOPAC), letter from deputy mayor for policing Kaya Comer-Schwartz to Metropolitan Police Commissioner Sir Mark Rowley, May 2026. Reported in: The Guardian, "London mayor Sadiq Khan blocks Met police deal with Palantir," May 21, 2026. theguardian.com
Euronews, "Why are European governments reevaluating their agreements with US defence tech contractor Palantir?" June 5, 2026. euronews.com/next/2026/06/05/why-are-european-governments-reevaluating-their-agreements-with-us-defence-tech-contractor
The six countries are Switzerland, France, Germany (federal agencies), the Netherlands, Denmark, and Spain. On France, the Netherlands, and the broader pattern: Euronews, "Why are European governments reevaluating their agreements with US defence tech contractor Palantir?" June 5, 2026. euronews.com/next/2026/06/05/why-are-european-governments-reevaluating-their-agreements-with-us-defence-tech-contractor. On the Netherlands: Dutch State Secretary for Defense Derk Boswijk, statement to the House of Representatives, June 2, 2026, reported in Cybernews, "The Dutch defense ministry is looking for Palantir alternatives." cybernews.com/tech/dutch-defense-palantir. On Denmark: Radar.dk, "Denmark to build homegrown Palantir alternatives for surveillance and warfare." radar.dk/artikel/denmark-build-homegrown-palantir-alternatives-surveillance-and-warfare. On Spain: El Confidencial (original reporting), reported in English by LBC, "Spanish government 'quietly bans use of Palantir' in critical state systems over fears of national security leaks." lbc.co.uk/article/spanish-bans-palantir-national-security-5HjdcNp_2
Clarifying Lawful Overseas Use of Data Act (CLOUD Act), Pub. L. 115–141, enacted March 23, 2018. The Act includes a framework for bilateral executive agreements with allied countries; as of this writing, a small number have been concluded, but these govern the terms of access rather than its availability.
The Guardian / Der Spiegel, October 2013, reporting based on Snowden documents. The Obama administration subsequently stated that the US was not monitoring Merkel's communications and would not do so going forward—a formulation that implied the practice had previously existed. The German government filed a formal diplomatic protest.
Two documented instances: (i) In January 2026, the Trump administration threatened tariffs on Denmark, Norway, France, Germany, the UK, the Netherlands, and Finland contingent on support for US efforts to acquire Greenland — Carnegie Endowment for International Peace, "Trump Turns NATO into a Tool of Coercion," May 2026. carnegieendowment.org. (ii) In May 2026, the US announced withdrawal of 5,000 troops from Germany and cancelled a pre-planned 4,000-troop deployment to Poland — Clingendael, "Coercive Extractivism: The mechanics of Trump's transactional approach to Europe." clingendael.org. Both are characterised in the analytical literature as "coercive extractivism."