The Medical Inheritance
Medical secrecy is the inheritance that does not survive Position 4 infrastructure.
A Letter in the British Medical Journal
On 27 January 2026, Tom Dolphin, chair of the BMA UK council, published a rapid response in the British Medical Journal.[1] He wrote that doctors working in the NHS ‘can no longer provide the tacit endorsement that using a product implies’.
He called on them to ‘immediately take steps to explore refusing any non-direct care usage of Palantir’s federated data platform, with a view to moving away from the platform entirely in time, when a suitable alternative can be put in place’. Europe’s medical profession is refusing infrastructure that cannot keep its patients’ rights.
Speaking to the BMJ in a follow-up interview, Dolphin put it more directly:
‘Given Palantir’s track record, including controversies in the US involving immigration enforcement and the risks to patient trust, data security, and NHS independence, we believe there must be a complete break from Palantir technologies in the NHS and no further contracts awarded.’[2]
The BMA represents over 200,000 doctors and is the recognised professional body of the UK medical profession. Its annual representative meeting in June 2025 had already passed a resolution declaring Palantir an ‘unacceptable choice of partner’ for the NHS.[3] The January 2026 BMJ letter was the escalation from lobbying to a call for refusal.
The Doctors’ Association UK made equivalent statements.[4] A DAUK-commissioned poll found that 48 per cent of the public would likely opt out of the Federated Data Platform if Palantir managed their data.[5] By February 2026, 47,000 NHS patients had emailed their local trust boards in protest.[6]
In March 2026, the health-worker coalition Medact published a detailed briefing urging NHS trusts not to implement the platform, endorsed by the Good Law
Project, Privacy International, Just Treatment, and Corporate Watch, and supported by Amnesty International.[7] On 16 April 2026, MPs in a Westminster Hall debate called the £330 million NHS contract ‘dreadful’ and ‘shameful’, with Junior Health Minister Zubir Ahmed telling the chamber that the February 2027 break clause ‘will be looked at’.[8]
One NHS staff member, speaking anonymously to the Financial Times, said: ‘It makes me feel sick every time I log into the thing and I know I’m not alone in that.’[9] The refusal has layered for a year. It is not confined to one profession or one vendor’s critics.
It has moved from professional resolutions to a published BMJ call to mass patient complaint to parliamentary debate to ministerial acknowledgement that the contract is open to review.
This Is About Rights
The BMA’s call concerns a category of argument different from procurement. It concerns rights. Doctors are refusing to lend their professional legitimacy to a tool whose use in other jurisdictions has been documented to harm patients.
The Inheritance
Medical confidentiality in Europe is a commitment layered across 2,400 years, each layer added because the one below proved insufficient.
The Hippocratic Oath, from around 400 BCE, contains the original clause: ‘What I may see or hear in the course of the treatment or even outside of the treatment in regard to the life of men, which on no account one must spread abroad, I will keep to myself holding such things shameful to be spoken about.’[10]
The obligation was professional, binding on the doctor by the authority of the profession. It made the patient’s body, and what the body disclosed, the property of the patient alone.
In 1810, Napoleon’s Penal Code converted the professional obligation into criminal law.
Article 378 made disclosure of professional secrets by doctors, pharmacists, and others a criminal offence punishable by imprisonment and fine.[11] Its modern successor is Article 22613 of the French Penal Code: one year’s imprisonment, €15,000 fine.[12]
The German equivalent followed in § 300 of the 1871 Penal Code, now § 203 of the Strafgesetzbuch (StGB), carrying up to one year’s imprisonment.[13] Cognate provisions were enacted across continental Europe.
In France and Germany, medical secrecy is ordre public: a matter of public order, unwaivable by the patient, surviving the patient’s death, the doctor personally liable under criminal law regardless of contract.
Then came the third layer, the one the European medical profession wrote itself. The Nuremberg Doctors’ Trial of 1946-47 tried twenty-three German physicians for experiments conducted on concentration camp prisoners. Seven were sentenced to death. The trial produced the Nuremberg Code: ten principles of ethical research, starting with the requirement of voluntary informed consent.[14]
The World Medical Association was founded in 1947. At its second General Assembly in Geneva in September 1948, it adopted the Declaration of Geneva, a modern reformulation of the Hippocratic Oath specifically written to prevent what had just happened.
It contained a commitment the classical oath had not needed: ‘I will not permit considerations of age, disease or disability, creed, ethnic origin, gender, nationality, political affiliation, race, sexual orientation, social standing, or any other factor to intervene between my duty and my patient.’[15]
The inheritance was thickened further over the decades that followed. The Declaration of Helsinki in 1964, covering medical research ethics.
The European Convention on Human Rights, Article 8: the right to respect for private life.[16]
The Oviedo Convention of 1997, legally binding on its signatories, prohibits financial gain from the human body (Article 21) and requires explicit consent for interventions on identifiable health data.[17]
This is what Tom Dolphin was standing on when he wrote that doctors ‘can no longer provide the tacit endorsement that using a product implies’. The post-war layer was added because the earlier layers had proved insufficient alone. The European medical profession wrote its own oath because 1947 showed it the one it had was not enough.
The inheritance is what the profession built to refuse the next reason for it. There is now a next reason.
The State’s Obligation
What the doctor promises, the state must build the conditions for. In 2008, the European Court of Human Rights decided I v. Finland.[18] A Finnish nurse, diagnosed as HIV-positive, was treated at the same public hospital where she worked.
The hospital’s electronic patient register granted access to any member of staff, and colleagues viewed her records; when she applied for a log of who had done so, none existed. Her fixedterm contract was not renewed. She lost her case in Finnish courts because the absence of the audit log meant she could not prove unlawful access.
The ECHR found Finland in violation of Article 8. The violation was the architecture. The hospital had built a system in which it was impossible to prove who had viewed her records. The state’s obligation under Article 8 extended beyond refraining from disclosure. It required building the architecture that prevented disclosure and made any breach traceable. I v.
Finland is the live doctrine here. Architecture is a rights question. A hospital record system that cannot, in principle, prevent or detect unauthorised access is a system that fails Article 8 at the design layer. The obligation is positive. The state cannot discharge it by promising to behave well. It must build infrastructure that does not require it to promise.
Every European medical record currently hosted on infrastructure compellable by a foreign state fails this test. The architecture cannot prevent what it has been designed to permit.
How We Got Here
The inheritance is being dismantled through accumulated decisions. Procurement officers, hospital administrators, health ministers, each signing individually rational contracts. No one signs the Azure agreement meaning to dissolve the inheritance.
No one procures Palantir meaning to hand patient data to a company whose co-founder has said the NHS ‘makes people sick’ and should be ‘rip[ped] from the ground’.[19] Each decision makes sense at its own scale. The aggregate makes no sense at all. It also costs money. European public money.
Tens of billions annually across member states and the UK, routed through American vendors who then use the revenue to extend their market position, lobby European governments, and acquire the European startups that might have become sovereign alternatives.
Palantir’s NHS contract runs to £330 million over seven years.[20] Palantir’s manifesto, published in April 2026, argues that ‘the postwar neutering of Germany and Japan must be undone’ and that ‘some cultures have produced vital advances; others remain dysfunctional and regressive’.[21]
The NHS is using British taxpayer money to fund a company whose published programme is the explicit reversal of the post-war settlement that built the NHS in the first place.
The funding pattern is worth holding on to throughout. Europe is actively financing the erosion of its own medical inheritance. Every public health euro that flows to an American vendor is a euro transferred from a social-democratic settlement into a commercial entity whose interests are, in some cases explicitly, opposed to that settlement. The receipt is a compliance certificate.
The Stack
The stack is the scaffolding. Each layer is procured separately by a different officer under different rules with different vendors. The pattern is the same.
Clinical Records
When a French oncologist writes a cancer diagnosis into her hospital’s electronic patient record, she enters it into a system that sits on Microsoft Azure.
Article 226-13 of the French Penal Code says the secret is absolute. The doctor is personally liable. The obligation survives the patient’s death. It cannot be waived.
In June 2025, Anton Carniaux, Microsoft France’s director of public and legal affairs, was called to testify under oath to the French Senate about Microsoft’s Health Data Hub contract.
Asked whether Microsoft could guarantee that French health data hosted on Azure would never be transmitted to US authorities without French authorisation, he replied: ‘I cannot guarantee it.’[22] Ten months later, in March 2026, the Conseil d’État, France’s highest administrative court, was asked to rule on the Health Data Hub arrangement.
It accepted that US access to French health data ‘cannot be excluded’ and permitted the arrangement anyway,
on the grounds that no European alternative was operational at the required scale.[23] Ten million French patients’ records.
The court knew the risk, knew the law, and permitted anyway because the infrastructure had already been built on the wrong side of the jurisdiction and unwinding it in the time available was impossible. That is legal theatre at the highest judicial level: a court which knows the law, knows the breach, and permits the breach because the alternative has not been built.
The German version is sharper because it is criminal. § 203 of the StGB makes disclosure of patient records by German doctors a criminal offence, with personal liability, punishable by imprisonment.[24]
In March 2026, the German legal technology site kleiboldt.de published an analysis arguing that a German doctor who enters patient data into a US cloud-based AI service is committing an offence under § 203 regardless of any contract the hospital has signed with the vendor. The contract cannot dissolve the criminal exposure. Only a sovereign infrastructure can.[25]
The Conseil d’État’s March 2026 ruling and the § 203 analysis are the same argument in two jurisdictions: the law binds, and the infrastructure has been built in a way that makes compliance impossible.
Jurisdiction follows the parent.
In September 2025, an Ontario court ordered a Canadian subsidiary of the French cloud provider OVHcloud to hand over subscriber data from servers located in France, the United Kingdom, and Australia to the Royal Canadian Mounted Police. OVH argued that compliance would breach French law. The Ontario court ordered compliance anyway.[26]
The case concerns commercial data, not health records, though the mechanism is identical. The parent’s jurisdiction reaches the subsidiary’s data, wherever it sits.
One point needs to be stated directly.
The CLOUD Act, which governs US law enforcement access to data held by US companies, cannot be mitigated by contractual arrangement.[27] It follows the parent corporation.
A French subsidiary of a US parent remains compellable.
A European operational wrapper over American technology remains compellable. Independent audit, European key management, European jurisdiction clauses in the service contract: none of these override US statute. The only architecture that eliminates compellability is a vendor whose parent is incorporated in a European jurisdiction with no US presence that creates US jurisdiction.
Every arrangement short of European ownership is mitigation.
Medical AI
In 2015, the Royal Free London NHS Foundation Trust transferred 1.6 million identifiable patient records to Google DeepMind for the development of Streams, an acute kidney injury monitoring app.[28] The records included HIV status, history of drug overdoses, and abortion history.
Patient consent was not obtained.
The Information Commissioner’s Office ruled the transfer unlawful in July 2017.[29] The National Data Guardian separately ruled the legal basis inappropriate.[30] A class action, Prismall v. Google UK Ltd, continues.[31]
The hospital and the vendor had both assumed that patient data was a commercial input available for research partnerships under a suitably worded data-sharing agreement. European law disagreed after the fact.
The assumption was embedded in the American vendor’s business model and matched, at the procurement stage, by the hospital’s operational willingness to treat identifiable patient data as exchangeable under contract. By the time the ICO ruled, the data had already been transferred. It could not be recalled. It could not be uncopied.
The Royal Free was the overt breach. The acquisition pattern scales it.
In November 2024, Oxford-based Exscientia, one of Europe’s most prominent AI drug-discovery companies, was absorbed into Salt Lake City’s Recursion Pharmaceuticals in an all-stock transaction valued at $688 million; Exscientia’s Nasdaq listing ceased the same day.[32]
Earlier in this series, the broader pipeline through which European medical AI capability is documented, together with its training data, its research partnerships, and its product roadmap, is acquired into American corporate jurisdiction one tranche at a time.
The Cloud Inside the Body
The dependency reaches into devices implanted in the patient. Pacemakers from Abbott[33] and Medtronic[34] operate on firmware update cycles authorised by an American regulator and coordinated through the manufacturer’s American servers. Continuous glucose monitors and other connected medical devices follow the same pattern.
The cloud has reached inside the body, on the same firmware update cycle as the electronic health record on Azure.
Genomic Data
When a European consumer buys a 23andMe kit at their local pharmacy, they transfer their own genetic data to an American commercial entity, and with it the genetic data of every biological relative they share DNA with. None of those relatives signed anything. In 2023, 23andMe suffered a breach affecting 6.9 million accounts.
Data curated by ethnicity, including an Ashkenazi Jewish list and a Chinese list, appeared for sale on BreachForums.[35] The UK Information Commissioner’s Office fined the company £2.31 million in 2025.[36] In March 2025, 23andMe filed for Chapter 11 bankruptcy. Fifteen million people’s genetic data entered a bankruptcy auction governed by US insolvency law.
The TTAM Research Institute acquired the assets for $305 million, over the formal objections of 28 state attorneys general.[37] The operational failure is the visible story. The category of transaction is the deeper one. French medical secrecy is ordre public. A French citizen cannot legally waive it. Oviedo Article 21 prohibits financial gain from the human body and its parts.
GDPR Article 9 treats genetic data as a special category requiring explicit, informed, specific consent. Several European jurisdictions treat genetic information as partially collective because the genome reveals biological relatives who cannot, in principle, consent to another person’s disclosure.
A European consumer clicking through the 23andMe terms of service cannot validly consent on behalf of their relatives. They cannot validly waive the collective dimension of genetic information that European bioethics explicitly recognises.
They cannot validly consent, in continental European legal terms, to the terminus of the commercial pathway, because that terminus (bankruptcy auction of the archive) was not foreseeable at the point of sale and was not disclosed.
Under a serious reading of European bioethics and data protection law, 23andMe’s direct-toconsumer model should never have been legally marketable to European consumers in the form it took. The kit in the pharmacy was a category of transaction that European law, taken at its word, does not permit.
European regulators permitted it anyway, through a combination of administrative consent theatre, category confusion (is 23andMe a medical service, a consumer product, a research entity, or a data controller?), and the standard enforcement gap at the retail layer. The erosion reaches the retail layer as well as the procurement layer.
European regulators permitted commercial categories of transaction that European bioethics should have precluded. The inheritance is being dismantled from above, through state procurement of American cloud infrastructure, and from below, through retail products that should never have been on European shelves.
Palantir
The layers so far document the pattern. Palantir documents it at its sharpest point.
What Palantir Is
Palantir is an intelligence contractor that sells commercial software on the side. Palantir was founded in 2003. Its founding capital came substantially from In-Q-Tel, the strategic venture capital arm of the US Central Intelligence Agency.[38] The company’s existence was underwritten, at the founding stage, by a US intelligence agency.
The majority of Palantir’s revenue throughout its history has come from US government contracts.[39] It holds major contracts with the Department of Defense, the Central Intelligence Agency, the Federal Bureau of Investigation, Immigration and Customs Enforcement, and the US Army.
In July 2025, Palantir signed a $10 billion contract with the US Army.[40]Its work is close to inseparable from US state operations. In April 2026, Palantir published on X a 22-point summary of The Technological Republic: Hard Power, Soft Belief, and the Future of the West, a book co-written by its CEO Alex Karp. The post reached over 21 million views within days.[41]
The core claims, in Palantir’s own voice:
‘Silicon Valley owes a moral debt to the country that made its rise possible.
The engineering elite of Silicon Valley has an affirmative obligation to participate in the defense of the nation.’
‘The postwar neutering of Germany and Japan must be undone.’
‘Some cultures have produced vital advances; others remain dysfunctional and regressive.’
‘The ability of free and democratic societies to prevail requires hard power, and hard power in this century will be built on software.’
Taken together (the CIA founding, the government contract majority, the explicit programme that software is hard power, the call for the reversal of the post-war settlement), the picture is unambiguous. Palantir describes itself, in writing, as an instrument of American state power.
When the NHS procures Palantir, it procures from an entity that has published, repeatedly and consistently, its own self-description as something other than a commercial software vendor. The question concerns European procurement, not Palantir’s candour. Palantir has spent a decade telling anyone who asks what its software is for.
European procurement officers have spent the same decade treating it as a commercial vendor. Peter Thiel, Palantir’s co-founder and largest individual shareholder, said at a 2023 Oxford Union debate that the NHS ‘makes people sick’ and that ‘in theory, you just rip the whole thing from the ground and start over’.[42]
Alex Karp, CEO, has said in public statements: ‘Palantir is here to disrupt … and, when it’s necessary, to scare our enemies and, on occasion, kill them.’43 The company running the NHS Federated Data Platform. The CEO says his company kills people. The co-founder says the NHS makes people sick.
Both statements are in the public record, attributable, dated, and said before paying audiences with media present.
Operations
Palantir’s operational record in 2025 and 2026 matches the published ideology. In 2025, US Immigration and Customs Enforcement expanded its use of Palantir’s platform substantially. The agency signed contracts totalling $145 million for what it calls the Immigration Case Management system, including a $30 million addition in April 2025 specifically for ImmigrationOS.[43]
Within the platform, a tool called ELITE (Enhanced Leads Identification and Targeting for Enforcement) pulls together data from multiple federal sources, including Medicaid administrative records, Department of Health and Human Services data, and commercial data brokers, to generate dossiers and confidence scores for ICE raid targeting.[44]
In July 2025, a data-sharing agreement was concluded between the Centers for Medicare and Medicaid Services (CMS) and the Department of Homeland Security, transferring the personal data of 79 million Americans receiving Medicaid assistance to the deportation agency.[45]
In December 2025, Judge Vince Chhabria of the Northern District of California allowed the sharing to continue over a legal challenge.47 The arrangement has been operational since.
A survey commissioned by the Kaiser Family Foundation and published with the New York Times in 2026 found that roughly half of immigrant adults were concerned about provider-toICE data sharing. Fourteen per cent reported they had avoided or delayed seeking medical care because of these concerns.[46] The chilling effect is documented. The platform is Palantir’s. The data is health data.
The use is state action against patients. The UN Special Rapporteur on the situation of human rights in the Palestinian territory, Francesca Albanese, published her report From economy of occupation to economy of genocide in July 2025 (A/HRC/59/23).[47]
Paragraph 42 names Palantir specifically:
‘There are reasonable grounds to believe Palantir has provided automatic predictive policing technology, core defence infrastructure for rapid and scaled-up construction and deployment of military software, and its Artificial Intelligence Platform, which allows real-time battlefield data integration for automated decision-making.’
Karp has publicly stated that Palantir software was used in the 2024 Lebanon pager attacks.[48] In April 2025, responding to accusations that Palantir had killed Palestinians in Gaza, Karp said, ‘mostly terrorists, that’s true.’[49] The underlying conflict is a separate question.
The structural fact, whatever one’s views, is that the analytics platform Palantir is selling to European health systems is the same analytics platform being used for US military target generation in an active international legal proceeding, for ICE raid targeting against US patients who are immigrants, and for US police surveillance found unconstitutional by the German Federal Constitutional Court in 2023.[50]
Analytics infrastructure is fungible.
The same pattern-matching engine that identifies deportation targets from Medicaid records, that identifies military targets in urban conflict, is the engine being sold to European hospitals to organise patient data.
European Resistance
Europe is not monolithic on this.
The Swiss Army rejected Palantir on sovereignty grounds. An internal Swiss Army report, revealed by a December 2025 investigation by WAV and Republik, expressed concerns that Palantir would permit US government and intelligence access to sensitive Swiss data.[51] A European state, examining Palantir in detail for procurement, said no. Refusal is not theoretical.
In February 2023, the German Federal Constitutional Court ruled that police use of Palantir’s Gotham software in Hesse and Hamburg was unconstitutional, on grounds that the automated data processing permitted by the software expanded police surveillance powers beyond constitutional limits.[52]
Sixteen German federal states use or have used Palantir software; the ruling forced a structural review. A European constitutional court, examining Palantir’s platform in operation, found it unconstitutional as applied. The Swiss investigation that documented the Army’s refusal also found Palantir using its NHS contracts as part of a lobbying pitch to Swiss health authorities.[53]
The BMA carries the profession’s voice because the BMA was the profession that spoke in January 2026. The continental dimension is carried by French courts, German constitutional law, Swiss state refusal, and the operational reach of the laws that have not changed.
The UK Procurement Pattern
Palantir’s NHS contract started at £1. In March 2020, during the first phase of the Covid-19 pandemic, NHS England contracted Palantir to help operate a Covid-19 Data Store for that amount.[54] The contract was due to expire in June 2020; a series of extensions kept it alive for three years.
In 2020-2021, a £23 million contract was awarded to Palantir under the then Health Secretary Matt Hancock, subsequently found by the courts to have been awarded unlawfully.[55] In November 2023, Palantir was awarded the Federated Data Platform contract at £330 million over seven years.[56] The contract documentation published at award included hundreds of pages of redactions.
The Good Law Project and Democracy for Sale have pursued multiple legal challenges seeking disclosure of the ministerial briefings that underpinned the award; the government has resisted disclosure on the basis that the documents fall under ‘policy development’.[57]
The Department of Health and Social Care awarded KPMG an £8 million contract to ‘promote the adoption’ of Palantir’s software inside NHS trusts. The details of the KPMG contract have been refused under Freedom of Information on commercial-sensitivity grounds.[58] Louis Mosley, Palantir’s UK executive vice president, donated £5,000 to the
Conservative Party on 2 January 2024, weeks after the £330 million contract was awarded.[59] In February 2025, Prime Minister Keir Starmer visited Palantir’s Washington headquarters accompanied by Peter Mandelson, who was then UK ambassador to the United States and who is a co-founder of Global Counsel, a lobbying firm whose client list has included Palantir and OpenAI.[60]
The Cabinet Office has confirmed it holds no minutes of the meetings that took place.
By January 2026, investigative journalists at The Nerve had documented Palantir’s UK state contracts at a total of at least £670 million across more than 34 current and past arrangements in 10 government departments, including a £240 million Ministry of Defence deal awarded in December 2025 without competitive tender.[61]
The procurement pattern fits the textbook case of the ‘land and expand’ model Palantir’s critics have described, with none of the features of arms-length commercial competition.
A minimal-value initial contract, extensions without competitive re-tender, escalation to fullscale procurement once workflows and data models are embedded, and price negotiated against switching cost rather than against market alternatives. The £330 million is the midpoint of a trajectory that started at £1 and has not finished.
The Ask
The recommendation reaches beyond procurement preference. European health sovereignty requires two acts: the enforcement of laws that already exist, and a commitment in law to Buy European procurement across the health stack. Together these constitute the inheritance operating in the digital layer. Separately, they are partial.
Comply
Europe does not need new rights. Europe needs to enforce the rights it already has. The European Convention on Human Rights Article 8 has positive-obligation doctrine (I v. Finland). The Oviedo Convention is binding on its signatories.
The GDPR, particularly Articles 9 (special categories of data) and 48 (transfers not authorised by Union law), contains the instruments required to prevent what is being permitted. French Article 226-13, German § 203 StGB, and their cognates across the continent make medical secrecy criminal law, personally binding on the doctor. The law is on the shelf. The jurisprudence has been written.
What has been missing is enforcement. Compliance is the form the enforcement gap takes. The Conseil d’État in March 2026 found US access cannot be excluded and permitted the Health Data Hub arrangement anyway. Every certification document was technically accurate. Every assurance was correctly worded. The outcome fails the law the certifications are supposed to secure.
The fix begins with enforcement of existing law against existing arrangements, backed by an alternative infrastructure that makes enforcement operationally possible. Without the second half, the first produces more rulings like the Conseil d’État’s.
Buy European
The only architecture that eliminates CLOUD Act compellability is European ownership. Every other arrangement is mitigation.
European health sovereignty therefore requires the health stack to be procured from European-owned vendors across the sovereign-essential layers: clinical records, population analytics, patient-identifying AI, genomic platforms, and the portion of medical device firmware that handles identifiable data. Other categories can be competitively procured without restriction.
The instrument is procurement policy. The precedent is American.
In 1933, the US Congress passed the Buy American Act, requiring federal government procurement to favour US-made products.[62] The Jones Act of 1920 requires US-flagged, US-crewed vessels for coastwise maritime trade.65 The Federal Acquisition Regulation embeds domestic preference across US federal procurement.
The principle, in American industrial policy, is uncontroversial: strategic sectors receive procurement preference, to ensure that strategic capability is built and retained domestically.
Europe needs a structurally more ambitious version of this policy, because Europe is further behind in scale, faces compounding vendor lock-in, and competes against American vendors that have been underwritten by decades of US government procurement (defence, NIH research, federal health contracts). The American version preserves existing capability. The European version has to build it.
The phrase is Buy European. The detailed design of the policy instrument sits in the procurement-mandate layer of this series. The principle is that Buy European is the only available architecture that makes enforcement of existing European medical rights operationally possible. Absent Buy European, every compliance ruling will sound like the Conseil d’État.
The Investment Objection, and SpaceX
The standard objection to Buy European is that European vendors do not exist at competitive scale and quality, so a procurement preference would lock in inferior products at inflated prices. The objection is correct in 2026 and will remain correct as long as there is no committed future demand for European vendors. It describes the trap, not the remedy.
The American precedent is clear: demand commitment precedes supply. In December 2008, NASA awarded its Commercial Resupply Services contract to SpaceX for $1.6 billion, at a point when SpaceX had just emerged from three successive launch failures of its Falcon 1 rocket.[63] The fourth launch, in September 2008, had succeeded by a matter of weeks.
SpaceX was close to bankruptcy. The COTS contract was specifically designed to prevent that outcome and to underwrite the company’s transition from startup to operational launcher. Without the contract, no SpaceX. The SpaceX case is one instance of a seventy-year American pattern.
NASA Commercial Crew, DARPA, DoD bio-defence contracting, the CIA’s In-Q-Tel, the Pentagon’s early Silicon Valley procurement in the 1960s and 70s: American industrial policy has been procurementled throughout. Government procurement commitments at sufficient scale, with sufficient lead time, transform what is investable. Venture capital prices risk.
A legal guarantee of future demand shifts the risk profile. The startup that is uninvestable in the absence of a committed market becomes investable once the market is committed.
A European medical AI company today looks uninvestable because there is no credible path to sustainable revenue. European hospitals procure American platforms. European governments treat medical infrastructure procurement as value-for-money comparison at the point of contract, excluding sovereignty externality. The European vendor runs out of runway before achieving scale.
The same company in a regime where Buy European is committed in law for post-2030 medical analytics procurement is a different bet. The demand signal exists. The investment thesis is underwriteable. The capital follows. Buy European functions as a demand-commitment instrument that de-risks private investment in European sovereign capability.
The cost to the public purse carries no additional line item; the redirection of procurement spend that currently flows to American vendors covers the bill. The remedy is free in aggregate. It redirects existing money from companies whose published ideology opposes the European social model to companies that are aligned with it, or at least not explicitly opposed to it.
The February 2027 NHS Break Clause
The Federated Data Platform contract contains a break clause scheduled for review in February 2027.[64] Junior Health Minister Zubir Ahmed has said the clause ‘will be looked at’. The recommendation to the UK government is straightforward.
Trigger the break clause, and pair it with a procurement commitment in law for NHS analytics procurement from 2030: Buy European, sovereignty-classified, with a rising share, sunset reviews, and matched public investment.
Three years from commitment (2027) to contract effect (2030) is adequate build time for European vendors that exist at smaller scale today and would scale against a guaranteed major-contract demand.
The same logic applies to the German medical AI market, to French clinical records (the Health Data Hub’s next procurement cycle), to Nordic genomic platforms, and to Italian hospital analytics. The Palantir break clause is a test case because it is the clearest.
Three Operational Principles
The full design belongs to the policy-design layer of this series and to the accompanying Policy Brief. Three principles frame the work.
Sovereignty classification. Critical health stack layers (clinical records, population analytics, patient-identifying AI, genomic platforms, firmware handling identifiable data) are classified as sovereign-essential and procurement-restricted to European ownership; other categories are procured competitively without restriction. Transition with sunset.
A rising share of sovereign-essential procurement is directed to European vendors across a five-year transition, with exception clauses where no viable European alternative exists and periodic review to prevent incumbent pricing abuse. Capital transfer transparency.
Every public health contract with a non-European vendor discloses, on the face of the contract, the aggregate capital transfer to non-European entities over the contract lifetime, making the transfer a political fact for which the signing officer is accountable.
The Refusal
The profession, then. The inheritance exists so that doctors can refuse. Hippocrates wrote the secrecy clause so the patient’s disclosure would not be the doctor’s property. Napoleon’s Article 378 put the clause in criminal law so the state could not compel disclosure even from doctors employed in state institutions.
The Declaration of Geneva, in 1948, added the commitment that no consideration (political affiliation, nationality, race) would intervene between the doctor’s duty and the patient. Each layer exists because the one below proved insufficient under specific pressure.
In January 2026, the profession exercised the inheritance in public. Tom Dolphin wrote in the BMJ that doctors could no longer provide the tacit endorsement.
David Wrigley, deputy chair of the BMA’s general practitioners committee, described Palantir, a company running surveillance for immigration enforcement and operating in active conflict zones, as ‘completely incompatible with the values we uphold in the delivery of care’.
From inside the NHS, Rhiannon Mihranian Osborne wrote in Hyphen that the use of Palantir software in the UK health system ‘frightens me’, and David Nicholl of the Doctors’ Association UK told reporters that the arrangement was ‘having an adverse effect on patient trust in how their data is handled’. Forty-seven thousand patients wrote to trust boards.
Members of Parliament called the contract ‘shameful’ in Westminster Hall. A minister acknowledged that the contract is open to review. These are different people, speaking from different positions, with different arguments.
What they share is the exercise of a specific capacity the inheritance was built to enable: the refusal to lend medical legitimacy to infrastructure that operates against the patient’s interest.
The profession recognises, on its own authority, that this tool is not an acceptable partner for the delivery of health care.
The vendor’s own CEO has said it is for scaring and killing enemies.
A UN human rights report has named it for its role in ‘unlawful use of force’.
A European constitutional court has ruled it unconstitutional as applied.
A peer European state’s military has refused it.
The BMA’s call did not need to spell this out. The tradition is the point. Palantir is the occasion. The NHS is one of the most European things about the UK.
Founded in 1948, three years after Nuremberg, on the same post-war social-model logic that produced the Declaration of Geneva, the ECHR, and the Oviedo Convention, the NHS is the institutional form the medical inheritance took in the UK. Bevan’s NHS and Oviedo are cousins.
A BMA defending NHS medical confidentiality against a company whose co-founder wants to rip the NHS from the ground is Europe’s inheritance in operation, on British ground. A secret the infrastructure cannot keep is not a secret. That is the condition the BMA has named and refused. The inheritance is 2,400 years old. The infrastructure it runs on was procured in the last twenty.
One of them is already giving way, and the profession has named which one. The profession has already made its call. What it needs next is an infrastructure that lets the refusal hold.
[1] Tom Dolphin, ‘Re: ICE and Palantir: US agents using health data to hunt “illegal immigrants”’, rapid response, BMJ, 27 January 2026, responding to BMJ 2026;392:s168, doi:10.1136/bmj.s168.
[2] Reported in ‘BMA calls for NHS doctors to reject using the FDP’, Digital Health News, 9 February 2026.
[3] British Medical Association, ‘ARM 2025: BMA passes resolution on Health Information Management and Information Technology’, bma.org.uk, June 2025.
[4] Doctors’ Association UK statements on Palantir FDP, 2025-26; David Nicholl, DAUK spokesperson, quoted in Middle East Eye, ‘Palantir: Why is the Israel-linked surveillance firm embedded in Britain’s NHS?’, 29 January 2026.
[5] DAUK-commissioned poll, reported in Middle East Eye, January 2026.
[6] Reported in Hyphen, ‘Why Palantir’s role in the NHS terrifies my patients’, 24 March 2026.
[7] Medact, ‘Briefing: Concerns Regarding Palantir Technologies and NHS Data Systems’, March 2026, medact.org/2026/resources/briefings/briefing-palantir-fdp; endorsed by Good Law Project, Privacy International, Just Treatment, Corporate Watch; supported by Amnesty International.
[8] ‘Palantir: MPs call for “shameful” NHS data deal to be scrapped’, BMJ, 17 April 2026; Westminster Hall debate, 16 April 2026, Hansard.
[9] ‘NHS staff resist using Palantir software’, The Register, 3 April 2026.
[10] Hippocratic Oath, c. 400 BCE, classical text; modern English translations vary, see Ludwig Edelstein, The Hippocratic Oath: Text, Translation, and Interpretation (Johns Hopkins, 1943).
[11] Code pénal (France), 1810, Article 378. Imposed a three-month to six-month imprisonment and fine on doctors, surgeons, and officers of health disclosing secrets confided to them.
[12] Code pénal (France), Article 226-13 (current): one year’s imprisonment and €15,000 fine. Code de la santé publique Article L.1110-4 codifies the professional medical secret as absolute, surviving the patient’s death, unwaivable.
[13] Strafgesetzbuch (Germany), § 203: Verletzung von Privatgeheimnissen, up to one year’s imprisonment or fine; applies personally to physicians, pharmacists, and others holding professional secrets.
[14] Nuremberg Military Tribunals, United States v. Brandt et al. (the ‘Doctors’ Trial’), 1946-47. The Nuremberg Code appears in the tribunal’s judgement, Volume II, pp. 181-82.
[15] World Medical Association, Declaration of Geneva, adopted September 1948, Second General Assembly; amendments through to 2017. Current text available at wma.net.
[16] European Convention on Human Rights, Article 8: ‘Everyone has the right to respect for his private and family life, his home and his correspondence.’
[17] Council of Europe, Convention for the Protection of Human Rights and Dignity of the Human Being with regard to the Application of Biology and Medicine (Oviedo Convention), ETS No. 164, 1997. Article 21: ‘The human body and its parts shall not, as such, give rise to financial gain.’
[18] European Court of Human Rights, I v. Finland, application no. 20511/03, judgement of 17 July 2008.
[19] Peter Thiel at the Cambridge Union / Oxford Union debate on the NHS, 2023; reported in The Guardian, ‘NHS England gives key role in handling patient data to US spy tech firm Palantir’, 20 November 2023.
[20] NHS England contract award notice, Federated Data Platform, November 2023; £330 million over seven years.
[21] Palantir Technologies, 22-point manifesto adapted from The Technological Republic: Hard Power, Soft Belief, and the Future of the West by Alex Karp and Nicholas Zamiska, posted on X, 18 April 2026.
[22] French Senate, Commission d’enquête sur la commande publique, audition of Anton Carniaux, Microsoft France, 10 June 2025; transcript available via the Senate.
[23] Conseil d’État, ruling on the Health Data Hub, March 2026; in the French specialist press.
[24] Strafgesetzbuch § 203, current text; see also German Medical Association, Muster-Berufsordnung für die in Deutschland tätigen Ärztinnen und Ärzte, § 9.
[25] kleiboldt.de analysis, March 2026, arguing that entering patient data into a US cloud-based AI service constitutes an offence under § 203 StGB regardless of contractual arrangements.
[26] Ontario Court of Justice ruling on OVHcloud Canada subsidiary, September 2025;.
[27] Clarifying Lawful Overseas Use of Data Act, 2018 (United States), 18 U.S.C. § 2713; permits US law enforcement to compel US-based companies to provide data held in servers anywhere in the world, subject to limited MLAT and comity exceptions.
[28] Royal Free London NHS Foundation Trust / Google DeepMind data-sharing arrangement, 2015; Streams app development.
[29] Information Commissioner’s Office ruling, July 2017: ‘Royal Free – Google DeepMind trial failed to comply with data protection law.’
[30] National Data Guardian letter on the Royal Free / DeepMind arrangement, 2017.
[31] Prismall v. Google UK Ltd representative action, ongoing.
[32] Recursion Pharmaceuticals and Exscientia plc announced a definitive agreement to combine on 8 August 2024, valued at approximately $688 million in an all-stock transaction; completion announced 20 November 2024, with Exscientia ADSs (Nasdaq: EXAI) ceasing to trade. See Recursion press releases, 8 August and 20 November 2024; Exscientia SEC Form 6-K, Q2 2024.
[33] US Food and Drug Administration recall of Abbott (formerly St Jude Medical) RF-enabled pacemakers, 29 August 2017; approximately 465,000 devices affected, firmware update requiring inperson visit.
[34] Medtronic CareLink platform; see Medtronic security bulletins and the 2019 ICS-CERT advisory on Conexus telemetry protocol vulnerabilities.
[35] 23andMe data breach, October-November 2023, affecting approximately 6.9 million accounts; data including ethnicity-labelled lists posted on BreachForums.
[36] UK Information Commissioner’s Office enforcement action, £2.31 million monetary penalty, 2025.
[37] 23andMe Chapter 11 bankruptcy filing, March 2025; TTAM Research Institute acquisition, $305 million, over the formal objections of a coalition of 27 state attorneys general and DC.
[38] Palantir Technologies founding, 2003; In-Q-Tel investment documented in Palantir’s own corporate history and in Time magazine’s 2025 profile of Alex Karp
[39] Palantir Technologies SEC filings; US government contracts as majority of revenue throughout company history.
[40] Palantir-US Army contract, $10 billion, July 2025.
[41] Palantir Technologies post on X, 18 April 2026; 22-point manifesto; over 21 million views within days.
[42] Peter Thiel, Oxford Union debate, reported in The Guardian, 20 November 2023. Alex Karp, various public statements; ‘Palantir is here to disrupt’ quote widely reported; see The Philosopher in the Valley: Alex Karp, Palantir and the Rise of the Surveillance State by Michael Steinberger, 2025.
[43] Palantir-ICE contracts: $30 million ImmigrationOS addition, April 2025; $145 million Immigration Case Management total.
[44] ELITE tool: sworn testimony, Oregon; 404 Media investigation, January 2026; BMJ 2026;392:s168.
[45] CMS-DHS data-sharing agreement on 79 million Medicaid recipients, July 2025. Judge Vince Chhabria, Northern District of California, ruling December 2025 allowing CMS-to-ICE data sharing to continue.
[46] Kaiser Family Foundation / New York Times survey, 2026; 14 per cent of immigrant adults report avoiding or delaying medical care.
[47] United Nations Human Rights Council, From economy of occupation to economy of genocide: Report of the Special Rapporteur on the situation of human rights in the Palestinian territories occupied since 1967, Francesca Albanese, A/HRC/59/23, July 2025, paragraph 42.
[48] Alex Karp public statement on Palantir software’s use in the 2024 Lebanon pager attacks; cited in Middle East Eye, 21 April 2026.
[49] Alex Karp, April 2025 response to accusations of Palantir’s involvement in Palestinian deaths, cited in UN A/HRC/59/23 paragraph 42.
[50] Bundesverfassungsgericht (German Federal Constitutional Court), 1 BvR 1547/19 and 1 BvR 2634/20, judgement of 16 February 2023, finding Hesse and Hamburg provisions permitting automated police data processing unconstitutional; ruling applied to Palantir Gotham as used in those states.
[51] WAV and Republik investigation, December 2025, reporting on the internal Swiss Army assessment of Palantir.
[52] Bundesverfassungsgericht judgement, 16 February 2023; see note 51.
[53] WAV and Republik investigation, December 2025.
[54] NHS England-Palantir Covid-19 Data Store contract, March 2020, £1.
[55] R (Good Law Project) v. Secretary of State for Health and Social Care and related proceedings on Covid-era contracts; Hancock-era £23 million contract challenged via judicial review by openDemocracy and Foxglove in 2021; government settled and committed not to extend without public consultation.
[56] NHS England-Palantir Federated Data Platform contract, November 2023, £330 million over seven years.
[57] Good Law Project and Democracy for Sale legal proceedings seeking disclosure of FDP-related ministerial briefings; government defence on ‘policy development’ grounds.
[58] KPMG contract with Department of Health and Social Care, £8.5 million, for promotion of FDP adoption; FOI responses declining disclosure on commercial-sensitivity grounds.
[59] Louis Mosley donation to the Conservative Party, £5,000, 2 January 2024; Electoral Commission register.
[60] Keir Starmer and Peter Mandelson visit to Palantir Washington headquarters, February 2025; Cabinet Office response to FOI confirming no minutes retained.
[61] The Nerve investigation, January 2026, documenting £670 million-plus in Palantir UK state contracts across 34+ arrangements; MoD contract, £240 million, December 2025.
[62] Buy American Act, 41 U.S.C. §§ 8301-8305, enacted 3 March 1933. Merchant Marine Act of 1920 (Jones Act), 46 U.S.C. Chapter 551.
[63] NASA Commercial Resupply Services contract award to SpaceX, December 2008, $1.6 billion; Falcon 1 launch history, 2006-2008.
[64] NHS England-Palantir Federated Data Platform contract, break clause February 2027.
Sign the Manifesto. The eight demands that follow from the case made in this paper and the twenty-seven others. Sign →