The Vendor
In 2015, the International Atomic Energy Agency paid Palantir Technologies fifty million dollars for a software platform called Mosaic. Mosaic was a predictive-analytics engine designed to help IAEA inspectors plan 'unscheduled probes,'…

In 2015, the International Atomic Energy Agency paid Palantir Technologies fifty million dollars for a software platform called Mosaic. Mosaic was a predictive-analytics engine designed to help IAEA inspectors plan “unscheduled probes,” surprise visits, at suspected nuclear sites inside Iran. The platform ingested approximately four hundred million data objects, including translated Persian-language social-media content scraped from inside Iran, and produced ranked recommendations about which sites the inspectors should walk into unannounced.
The technical platform was called Foundry.
In 2022, the Centers for Disease Control and Prevention paid Palantir Technologies four hundred forty-three million dollars, with a four-hundred-million-to-six-hundred-nineteen-million-dollar follow-on, for a “Common Operating Picture,” a predictive-analytics engine designed to help the CDC plan disease-surveillance responses. The platform ingested hospital admission data, wastewater testing data, syndromic surveillance feeds, and produced ranked recommendations about which regions the CDC should focus on.
The technical platform was called Foundry.
In 2023, the National Health Service of the United Kingdom paid Palantir Technologies three hundred thirty million pounds for a Federated Data Platform, a predictive-analytics engine designed to help NHS administrators triage patients across up to two hundred forty NHS organizations. The platform ingested electronic health records, bed-occupancy data, surgical-scheduling data, and produced ranked recommendations about which patients should receive care, in what order, with what resources.
The technical platform was called Foundry.
In 2025, U.S. Immigration and Customs Enforcement paid Palantir Technologies thirty million dollars for a system called ImmigrationOS, a predictive-analytics engine designed to help ICE plan deportation operations. The platform ingested visa records, address histories, social-media presence, and produced ranked recommendations about which individuals should be removed, in what order, with what level of force.
The technical platform was called Foundry.
In February 2026, the Department of Homeland Security awarded Palantir Technologies a one-billion-dollar Blanket Purchase Agreement for an omnibus surveillance-fusion platform. The platform ingested everything the previous platforms ingested, plus the data sets of every component agency under DHS, plus the data sets DHS holds under data-sharing agreements with seventeen other federal agencies.

The technical platform was called Foundry.
It is the same platform. The customer changes; the architecture does not. The Ontology layer — the schema that defines what the data means in a given deployment — gets re-keyed each time. But the predictive engine the IAEA used to plan unscheduled probes in Iran is structurally identical to the engine ICE uses to plan removal operations and NHS uses to triage patients.
Alex Karp, the CEO of Palantir, was asked about this on the BBC in 2024. He answered, on the record, in his own voice: “Our product is used, on occasion, to kill people.”
He was not bragging. He was, by his own framing, defending the work. Western civilization requires the willingness to do what its enemies will not flinch from, was the substance of his argument. He had said versions of it on investor calls and at Davos and in the books he had written. He said it again on the BBC because it was, in his understanding, an honest answer to an honest question.
The product that is used, on occasion, to kill people is the same product that is used, every day, to decide which Palestinian gets included in a kill list, which Kenyan asylum-seeker gets visited by ICE, which Boston-area Medicaid recipient gets denied a wheelchair, which Iranian site gets a no-notice inspection, which NHS patient gets triaged out of an operation. The product does not know which use case it is performing. The product is the same product.
This is not a metaphor. The singleton is not coming. The singleton exists. It is a single SKU, sold under different names, deployed across the institutional surface of late liberal democracy. The companies that buy it disclose it to their shareholders. The agencies that buy it disclose it in their procurement filings. The whole thing is on the record. The institutions did not intend to confess. They published what they were legally required to publish.
The confession is in the cross-reference.
To understand how one SKU ends up under the IAEA, the CDC, the NHS, ICE, and DHS, it helps to know what the SKU actually is. Palantir builds four principal platforms, and it describes them itself, in language filed under penalty of perjury with the Securities and Exchange Commission.
Gotham, built first, is the one the company says “enables users to identify patterns hidden deep within datasets, ranging from signals intelligence sources to reports from confidential informants, and facilitates the hand-off between analysts and operational users, helping operators plan and execute real-world responses to threats.” It descends from PayPal-era fraud detection and a 2005 investment from In-Q-Tel, the CIA’s venture arm. Its customers are defense, intelligence, and federal law enforcement. ICE’s case-management and targeting systems sit inside the Gotham product line. ICE markets them by their own internal names.
Foundry is the one the company calls “the foundational data operations platform.” It started as a Gotham fork built to serve commercial customers — Airbus, Merck, BP — and was then folded back into the dual line. It is what gets sold to civilian government and allied states under bespoke names. “Federated Data Platform” to the NHS. “Common Operating Picture” to the CDC. The load-bearing piece is what Palantir calls the Ontology, the proprietary semantic layer that decides what a row of data means: that this object is a patient, that one a shipment, that one a unit, that one a mission, that one an immigrant. Model your operations against the Ontology and the data stops being data. It becomes a thing the software can reason about.
Apollo is the delivery layer, the part that lets the platform run “in the cloud, on-premises, or more rugged environments.” That is the company’s phrase for the air-gapped classified networks where the rest of the stack would otherwise not be allowed to go.
AIP, the Artificial Intelligence Platform, is the newest. It is not a model. It is, in Palantir’s words, a layer providing “secure connectivity to third-party-provided large language models” plus “a development toolchain for building AI-powered agents and automations.” It takes whatever frontier model the customer has chosen — GPT-class, Claude, Gemini, Mistral — and binds it to the Ontology so the model can take actions against the modeled world. The commercial pitch is that AIP turns a chatbot into an enterprise agent that can act on supply-chain objects. The defense pitch is the same sentence with kill-chain targets where the supply-chain objects used to be.
Palantir states the whole thing in one line in the same filing: “AIP provides an integrated architecture to Gotham and Foundry that can bring AI to every decision, and these platforms, backed by Apollo, can be deployed in almost any environment.”
That sentence is the marketing thesis. It is also the structural reason the singleton exists. The same stack runs ICE and the NHS and the CDC and Maven and Mosaic. Only the Ontology differs.
The clearest place to watch the architecture decide what it is doing is a Pentagon program called Maven.
Maven was not born a kill chain. It started in April 2017 as the Algorithmic Warfare Cross-Functional Team, a research project to point machine learning at drone full-motion video from the anti-ISIS campaign and label what it saw. Google held the contract. It declined to renew in June 2018, after roughly four thousand of its own employees signed an internal protest and about a dozen resigned. Google published a set of AI Principles pledging not to build AI for weapons. The work was re-let, primarily to Palantir and Anduril, with Booz Allen Hamilton on the integration phase.
What happened next is visible entirely in the contract record. That is the point. In May 2024 Palantir won the Maven Smart System prime: a five-year contract with a $480 million ceiling. In May 2025 the Pentagon raised that ceiling to $1.3 billion, citing demand: more than twenty thousand active users across thirty-five-plus tools. In March 2026 the Defense Department’s acquisition chief, Steve Feinberg, issued a memorandum directing Maven Smart System to become an official program of record by 30 September 2026. A second memo designated AI-enabled decision-making, via Maven, as “the cornerstone” of the Pentagon’s all-domain command-and-control effort. NATO’s Allied Command Operations adopted the same system for its planning function in April 2025, the first non-US force to field it.
The Army did the same thing to its own contracting that the Pentagon did to Maven’s mission. In July 2025 it consolidated seventy-five separate software contracts — fifteen prime and sixty related — into a single ten-year enterprise agreement with a $10 billion ceiling, with one vendor. There is a name for collapsing seventy-five procurement decisions into one. It is the singleton, written down by its customer.
The 2024 description of Maven was modest: it helped find targets; humans approved them. By 2026 the description had moved. Reporting on the Iran air campaign that began in February 2026 — a thirty-eight-day operation the Pentagon’s Chief Digital and AI Officer said involved thirteen thousand targets — describes Maven generating strike packages, ranking targets by strategic importance, and attaching automated legal justifications drafted by the underlying language model. During that operation the system’s classified usage surged eighty-nine percent and peak daily token consumption rose to roughly twenty billion tokens a day. The officer’s word for the demand was “insatiable.”
The human-in-the-loop, in that description, has thinned from “humans approve targets” to “humans approve strike packages.”
In Gaza, the equivalent system was reported to give its human reviewer about twenty seconds.
The architecture has a sibling abroad.
In Gaza, the Israeli military operated a system reported by +972 Magazine and Local Call in April 2024 as Lavender: a database that ranked roughly thirty-seven thousand Gazan men on a one-to-one-hundred scale for suspected militancy, with an acknowledged false-positive rate of around ten percent. A companion system, Habsora — “The Gospel” — generated bombing targets at a reported rate of up to a hundred a day. Lavender identified the who. Habsora identified the where.
Palantir did not build Lavender. The company says its technology was “independent of” the Israeli targeting systems and predates its 2024 partnership with Israel’s defense ministry, and no public record contradicts that.
What Palantir did do is sign, on 12 January 2024, a “Strategic Partnership for Battle Tech” with the Israeli Ministry of Defense, announced during a board meeting the company held in Tel Aviv “in solidarity” three months after October 7. An executive vice president, Josh Harris, said on the record that “both parties have mutually agreed to harness Palantir’s advanced technology in support of war-related missions.” Which deployed systems, and which integration points, have not been disclosed.
So the claim of this chapter is not that Palantir built the Israeli kill list. It is narrower and worse. Lavender and Habsora are structurally the same machine as Maven: aggregate the dataset, let a model nominate the target, hand it to an operator for confirmation. The pattern Palantir pioneered — Ontology, fusion, AI-recommended action — has become the default template for the global kill chain, on both sides of an alliance and across an adversary line. The architecture is indifferent to flag. It is a shape, and the shape has propagated.
The shape produces outcomes the documentary record can name. In Iraq, on 2 February 2024, a US strike wave that a CENTCOM official told Bloomberg was helped by Project Maven killed Abdul-Rahman al-Rawi, a twenty-year-old student. The US military later acknowledged he was killed unintentionally and sent his family a letter of condolence; when Airwars pressed CENTCOM to confirm whether AI specifically contributed to that strike, the spokesperson said it “could not determine.” On the first day of the Iran campaign, a US Tomahawk struck a building in Minab that intelligence had tagged as a factory or arms depot. It was the Shajareh Tayyebeh Elementary School. The reported dead numbered a hundred fifty-six, of whom a hundred twenty were children.
The same architecture has a happier-looking deployment, and it belongs in the chapter for exactly that reason.
In Ukraine, Palantir’s systems do something the company is glad to talk about. MetaConstellation fuses commercial satellite, drone, and sensor data into a single targeting picture, pointing constellations at a specific square to answer a specific question, such as what has changed along a railway line since midnight. Alex Karp flew to Kyiv in June 2022, the first Western chief executive to do so after the invasion, and has said publicly that Palantir software is “responsible for most of the targeting in Ukraine.” In May 2025 the company launched the Brave1 Dataroom, giving more than a hundred Ukrainian firms access to real battlefield data to train better than eighty models.
This is the steel-man, and it should be steel. A smaller country, invaded, used the singleton to see the battlefield and survive on it. The same Ontology that ranks Gazan men and tags Iranian schools also helps clear mines, plan reconstruction, and collect war-crimes evidence in Ukraine. The product does not know which of these it is doing. It is the same product. That is the case for it and the case against it in a single clause.
It showed up before Foundry had a name anyone outside the company would recognize, in the affair that taught the public the word for harvested data.
During 2013 and 2014, a Palantir employee in the company’s London office worked with Cambridge Analytica’s data scientists on the Facebook-harvested-data project that Aleksandr Kogan facilitated. Palantir’s own characterization is that the employee did so “in an entirely personal capacity.” The whistleblower Christopher Wylie told a UK parliamentary committee that “there were Palantir staff that would come into the office and work on that data” and that they “helped build the models we were working on.” The connection was reportedly introduced through Sophie Schmidt, daughter of the then-CEO of Google. Palantir confirmed the staff link and said it would look into it; Facebook opened an investigation into whether Palantir had improper access to user data. No formal corporate sanction followed.
The relevant fact is not the scandal. The relevant fact is the shape of the work: take a large population, build models that score each individual, and hand the scores to someone who wants to act on them. In 2014 the action was a targeted political advertisement. The customer changed. The architecture did not.
Most of what is publicly known about how these systems behave in the field is known because somebody sued, or filed, or pried it loose. The record is therefore lopsided in an instructive way. The parts that are disclosed are disclosed because the law required it. The parts that are redacted are redacted in shapes that are themselves legible.
EPIC sued ICE between 2017 and 2020 to obtain records on ICE’s use of the Palantir databases. The litigation settled. The produced documents revealed that ICE’s case-management system linked phone records, GPS data, and social networks, and that it had been used to place data on children at the border into the system during a 2017 operation. A redaction error in one production exposed the value of a then-new contract. In 2019, documents obtained through Mijente and reported by Slate showed Palantir software being used operationally in deportations, contradicting the company’s public statements that it was not used “for deportations.”
The Mijente coalition filed more than two hundred FOIA requests on Operation MEGA, ICE’s September 2017 mass raid, and published the result as a report titled “Blueprint for Terror.” ICE produced a guidance template, but the operational sections were redacted nearly in full. The redactions did the confirming the documents would not: the shape of what was blacked out matched the shape of the case-management-and-targeting pipeline. The NHS, for its part, published its £330 million Federated Data Platform contract in January 2024 under freedom-of-information pressure. The released version was heavily redacted around exactly the terms a customer would want to read before signing: commercial pricing, performance standards, and the exit clauses.
There is a wrongful-arrest case people reach for in this context, and it is worth noting only to set it aside. Robert Williams was arrested in Detroit on a facial-recognition false match; he sued, and the case settled in June 2024 with what the ACLU called the strongest US police facial-recognition policy. The matching software was DataWorks Plus. It was not Palantir. The honest version of this chapter does not borrow other vendors’ body counts.
The other place the record opens up is the securities docket, because a public company owes its shareholders a kind of candor it owes no one else.
Cupat v. Palantir, a securities class action in the District of Colorado over the company’s direct-listing disclosures, ran into the Supreme Court’s Slack v. Pirani decision, which a court found in April 2025 “likely forecloses” the suit. An earlier 2022 class action, filed by Bernstein Liebhard in the Southern District of New York, alleged that Palantir failed to disclose how its marketable-securities holdings would hit earnings and overstated the sustainability of its government-segment growth. And in October 2025, after an internal Army memo described a joint Palantir-Anduril battlefield communications system as carrying a “very high risk” of allowing adversaries “persistent undetectable access,” the stock fell 7.5 percent in a day. Securities-fraud firms opened fresh investigations.
The complaints from outside — from EPIC, from Mijente, from Amnesty, which in April 2025 demanded Palantir cease its immigration-enforcement work — can be filed under the heading of people who were always going to object. The Army memo cannot. It is the singleton’s own customer, in writing, documenting that the singleton is breakable.
The man at the top of all of it has never been coy, which complicates the usual story about a quiet vendor and makes him useful as his own witness.
Alex Karp has referred to himself, by his own account reported in the press, as a socialist and even a neo-Marxist. He has written a book, The Technological Republic, arguing that “hard power in this century will be built on software” and that “the question is not whether AI weapons will be built; it is who will build them and for what purpose.” On investor calls he has said Palantir exists “to scare enemies and on occasion kill them.” To the New York Times he explained the strategy as making adversaries “wake up scared.” At Davos in January 2026 he called Palantir “the most important protector of the Fourth Amendment.” A few weeks later he told Fortune that “there was never a sense” that Palantir’s AI products would be used for domestic surveillance.
These are not contradictions he is hiding. He says them all, in public, on the record, sometimes in the same week. The BBC quote that opened this chapter — “our product is used, on occasion, to kill people” — is of a piece with the rest. He is the rare executive who will tell you the load-bearing fact about his product without being subpoenaed for it. The disclosures the lawsuits pried loose, he volunteers.
It would be a tidier story if Palantir were the only firm that could do this. It is not, quite. The shape of the competition tells you something about why the lock-in holds anyway.
Anduril, founded by Palmer Luckey, is the most-cited partner-competitor. Its Lattice software is the defense-domain analogue to the Palantir Ontology, and the two were joint primes on the battlefield-comms program the Army flagged as high-risk. Scale AI won the prime on Thunderforge, a theater-planning prototype where Palantir was absent, though Scale is a data-labeling and model-tuning shop that eats the training-pipeline layer of the stack and not the operational-ontology layer. Booz Allen Hamilton is the classic alternative when an agency wants Foundry-equivalent capability without a single-vendor dependency. It also partners with Palantir on other work, competing for primes and teaming on subs in the same season. Accenture Federal Services wins contracts on Palantir’s natural turf and sits under Palantir in the NHS consortium. IBM, which once offered the most prominent health-data-fusion competitor, divested Watson Health in 2022.
The competition is real at the margin — new starts, fresh prototypes, the next prime. It is not real at the core. Once a customer has modeled its operations against Palantir’s semantic layer, the cost of leaving is the cost of re-modeling its entire operational picture from scratch, and almost nobody pays it. This is what the ICE sole-source justification means when it states that “Palantir remains the sole provider capable of meeting the specific needs and requirements of ICE,” citing “deep institutional knowledge.” It is what the Army’s seventy-five-to-one consolidation means. The lock-in is not a conspiracy. It is an Ontology, and a switching cost, working exactly as designed.
The one place the architecture has visibly failed to install is the NHS. Eighteen months into the £330 million contract, fewer than a third of England’s hospital trusts — seventy-two of roughly two hundred fifteen — were using the Federated Data Platform. Internal user reports described it as “awful to use,” and a UK health minister signaled a possible early exit at the contract’s spring 2027 break clause. It is the first time the singleton has been documented publicly failing to take.
Here is what the public record will not tell you, because no filing requires it.
The IAEA used the platform to decide which Iranian site to walk into unannounced. The CDC used it to decide which region to surge testing into. The NHS used it, where it used it at all, to decide which patient moved up the queue. ICE uses it to decide which person to come for, and in what order, and with how much force. DHS now holds a billion-dollar agreement to run all of it across seventeen agencies’ worth of data at once. Each customer disclosed its own contract. Each disclosed it to the people the law said it owed a disclosure. The confession is in the cross-reference, and the cross-reference is something only an outsider, reading all the filings at once, ever actually performs.
The customers do not read each other’s filings. The IAEA does not subscribe to FedScoop. The CDC does not track NHS Contracts Finder. ICE does not attend the IAEA’s safeguards briefings. They share one vendor, one architecture, one Ontology engine, one underlying language model on a given day, and one structural blind spot, which is each other.
So the question that ends this chapter is not whether the platform kills people. Its chief executive answered that one on the BBC, on the record, in his own voice, and the answer was yes, on occasion.
The question is whether any of them — the IAEA, the CDC, the NHS, ICE, DHS — has ever picked up the phone and asked another what it was like to operate the thing.
There is no filing that would tell us. There is no record that any of them ever did.