The Exit That Isn't: Germany's Palantir Bill

The Exit That Isn't: Germany's Palantir Bill

Auf Deutsch lesen →

Listen to this article
Speed

AI narration · automatically generated

Subscribe as a podcast
Personal note

Stored only locally in your browser — nothing is sent.

There’s a curious division of labour in this country: on Sundays we talk about digital sovereignty, on weekdays we sign Palantir contracts. In 2026 the tide seemed to turn. Federal Justice Minister Stefanie Hubig (SPD) declared in January: “I don’t see Palantir coming for the federal authorities” — against the explicit intent of Federal Interior Minister Alexander Dobrindt (CSU) to examine its use. This followed a Campact campaign with more than 450,000 supporters. In May it emerged that the Federal Office for the Protection of the Constitution (BfV) is procuring the French platform ArgonOS from ChapsVision — a European Palantir alternative already running at France’s domestic service DGSI. BfV President Sinan Selen justified it by saying that security decisions must be “geostrategically correct.”

That sounds like an exit. But look closely and it is, above all, a relocation. And because I think the “buy European” chants tend to obscure the real bill rather than draw it up, here is my attempt to add it up cleanly.

The exit is at the federal level, the use is in the states

The first crack in the narrative: what’s been stopped is the federal rollout. The state-level applications carry on — and these are no footnotes. Bavaria runs VeRA, an analysis platform costing roughly 25 million euros; Hesse has used hessenDATA (built on Palantir Gotham) since 2017, with around 15,000 queries a year; North Rhine-Westphalia operates DAR, a system worth at least 39 million euros whose contract runs to October 2026. These are the long-term users.

Baden-Württemberg, often treated as an established case, is in truth the most recent addition: the state parliament passed the legal basis only on 12 November 2025 (Green-Black coalition, Interior Minister Thomas Strobl, CDU), deployment from the second quarter of 2026, a contract of around 25 million euros over five years — signed before the law was in place, accompanied by a petition with 13,000 signatures. So BW isn’t a symbol of legacy use but of the current escalation.

Above all of this stands the Federal Constitutional Court. On 16 February 2023 the First Senate declared the legal bases for automated data analysis in Hesse and Hamburg unconstitutional — not because Palantir is banned, but because the powers were framed too openly and set no sufficient intervention threshold. What the constitution requires is a “concretised danger to especially weighty legal interests.” On 23 July 2025 the Society for Civil Rights (GFF) filed a constitutional complaint against Bavaria’s VeRA together with eight individual complainants; the Chaos Computer Club supports it. It hasn’t been decided. So the dispute is neither banned nor resolved — it’s pending.

Two problems that almost no one separates cleanly

Here’s the point where most debates get tangled. Replacing Palantir is a data-fusion problem, not a language-model problem. What Gotham-class systems deliver is linkage: searching existing police databases — persons, vehicles, crime scenes, cases — making relationships visible, visualising networks. That’s graph analysis and OSINT, not generative AI.

And this is exactly where Europe can deliver. Alongside ArgonOS (with the German integration partner Rola Security Solutions), there’s the sovereign in-house development “Europa-VeRA,” on which Baden-Württemberg is working with Airbus Defence and Space and Schwarz Digits — designed as a Palantir replacement over the medium term. And on 3 June 2026 Neo4j acquired the London-based GraphAware and positions its graph-based platform explicitly “as a trustworthy alternative to Palantir Gotham.” The problem that sounds hard — the replacement — is technically the readily solvable one.

The open problem is smaller than the hype claims

That leaves generative AI — the layer that turns data into summaries, hypotheses, text. Do you even need it for data fusion? Not necessarily; it’s optional. But if you do, Europe really is dependent here — only the gap in 2026 is single-digit and by no means insurmountable. Mistral Large 3 (675 billion parameters total, 41 billion active, mixture-of-experts, Apache 2.0 licence, released 2 December 2025) ranks, by Mistral’s own placement, second among open non-reasoning models and sixth among all open models on LMArena. That’s not the absolute top — Qwen and open reasoning models sit ahead there — but it’s a self-hostable, licensing-clean path.

The publicly funded route openGPT-X / Teuken-7B (Fraunhofer, all 24 EU official languages, open licence) works as a sovereign building block for multilingualism — but at 7 billion parameters it’s no frontier replacement. In short: the LLM problem is real, but it’s the smaller one. Anyone who believes sovereignty founders on it has the priorities reversed.

The trust anchor stays US silicon

Now comes the layer the dependency is shifted onto — the one that almost always drops out of the origin debate. Even the most sovereign European software stack runs on American hardware. With “Mistral Compute,” Mistral is building its own data centres in France and Sweden for around 4 billion euros — explicitly with Nvidia processors. Nvidia dominates the market for AI accelerators; the CUDA software stack binds the entire industry. The trust anchor of the future isn’t the software maker but the silicon beneath it.

That’s exactly the same logic I described on the topic of confidential computing: the technology solves real confidentiality (data-in-use), but not automatically sovereignty — because the hardware-based trust anchors Intel, AMD and Nvidia are US companies, and the CLOUD Act doesn’t hinge on where the server sits but on control by a US company. Whoever provides the chips and the attestation services holds part of the chain in hand, no matter where the VM stands.

And it goes one layer deeper still, into corporate structure. Germany’s long-touted “AI hope,” Aleph Alpha, will — following the transaction announced on 24 April 2026 (not yet completed, still to be cleared by regulators and shareholders) — combine with the Canadian company Cohere. Structurally this is a Cohere takeover (Cohere shareholders around 90 percent, Aleph Alpha around 10 percent), even if it’s communicated as a “merger”; the Schwarz Group put in around 600 million US dollars in Cohere’s funding round. Cohere CEO Aidan Gomez phrased it as a “Canadian-German company.” The European champion is no longer purely European afterwards. Sovereignty is relocated, not gained.

“From Europe” is no fundamental-rights seal

That leaves the most uncomfortable line item, and for me the most important. Suppose all of this succeeded: European graph software, a European model, European data centres. Would the problem be solved?

No. netzpolitik.org nailed it in February 2026: automated data linkage that enables total population transparency is, as a concept, fraught regardless of the national owner — algorithmic rather than human generation of suspicion, mission creep, the abuse risk under a future government that might be authoritarian. A “Palantir made in EU” answers the question of origin. It does not answer the question of fundamental rights. Mass analysis remains mass analysis.

That the distrust of the US provider isn’t mere paranoia can be shown — cleanly, without conspiracy rhetoric. Peter Thiel, co-founder, chairman and largest shareholder of Palantir, wrote in a 2009 Cato essay: “I no longer believe that freedom and democracy are compatible.” That’s a verbatim quote, not an attribution. The labels others build from it — “techno-fascism,” say — are others’ value judgements [CONTEXT] and belong marked as such, not asserted as fact. In the US, a government context points in the same direction: an executive order on cross-agency data fusion (March 2025), a 30-million-dollar contract for the ICE system “ImmigrationOS,” an Army framework contract worth up to 10 billion dollars. In fairness, this belongs with it: that a finished “master database of all Americans” exists is not substantiated — Palantir has publicly disputed the corresponding report. What’s substantiated are the contracts and the documented criticism, no more.

This, by the way, is the same pattern as with the Chinese models I wrote about recently: with DeepSeek and Qwen the censorship sits in the weights themselves — it persists even under local self-hosting. A system’s origin reveals something about the values coded into it, but it doesn’t replace the question of what the system does. “Made in China” doesn’t make a model safe; “made in EU” doesn’t make a surveillance architecture compatible with fundamental rights.

What this means for us

Germany’s Palantir bill has three line items, and only the first is being settled right now. The software can be replaced with European offerings — the graph problem is solvable. The model is a smaller, single-digit gap that can be closed self-hosted. But the hardware and the control structure remain US-anchored for now, and the fundamental-rights question is answered by no change of vendor. Anyone who celebrates the exit and sees only the first item mistakes a rebooking for a repayment.


For me the real point is this: “sovereignty” has shrunk to a seal of origin — and a seal clarifies where something comes from, not whether it may exist. The question I ask myself isn’t “whose software?” but “which threshold, which control, which judicial reservation?”


Sources (selection):