Tuesday, July 28, 2026

Palantir & UK Surveillance under the scanning mandate & the CLOUD act. This is the third piece I’ve written on the Government’s on-device scanning mandate. If you haven’t read the first two: A Scanner in Every Pocket and The Strongest Case For Scanning. The short version is on June 8th 2026, the Prime Minister handed Apple and Google a three month ultimatum to embed OS-level scanning into every smartphone and tablet in the United Kingdom. I think it is technically illiterate, constitutionally dangerous, and structurally irreversible. I’ve explained why at length.

This post is different. This one is about what happens when you try to get your elected representative to engage with it.

I wrote to my MP
I wrote to Louise Sandher-Jones, the Member of Parliament for North East Derbyshire. I tried to be measured. I explained my professional background, outlined the technical objections, and asked her to seek independent briefings, to challenge the Home Office on scope, and to oppose any legislation that would codify this mandate into law.

Her reply thanked me for the perspective I bring as a professional. It noted that child protection remains a government priority. It said that the Government does not accept these measures are equivalent to a surveillance state. It told me that future changes to any powers would require parliamentary approval. That was it.
No engagement with the technical arguments. No response to the specific concerns I had raised. A restatement of the Government’s position, dressed up as a reply.

I wrote back
The same morning I read her reply, two documents were published that I thought she should know about, both produced by people her Government appointed.

The first was a submission from the Biometrics and Surveillance Camera Commissioner, Professor William Webster, to the Independent Review of Police Force Structures. He flagged, in writing, that police forces are already buying biometric and AI technologies without fully understanding what they do or what deploying them means. He found no evidence that forces used the national decision making model in procurement. The very institutions that would operate any scanning regime are, on the Commissioner’s own account, already acquiring surveillance tools they don’t understand, without proper process.

The second was the result of a four year, £4.2 million study by Northumbria University and five partner institutions, mapping 70 AI tools already deployed or in development across policing and the criminal justice system. Its finding, adoption is outpacing governance. The principle of a human in the loop, the idea that a person remains accountable for what AI decides, often exists in name only, providing false assurance rather than real oversight.
I asked whether she had been aware of either before she sent her reply.

The question her letter didn’t touch

There is a dimension to this debate that barely features in political coverage, and it is the one I find most troubling. Who actually builds and runs the infrastructure, and under whose laws does it operate?

The UK Government has awarded over £900 million in contracts to Palantir Technologies. Palantir is a US headquartered company, co-founded with CIA seed funding, that also provides software to US Immigration and Customs Enforcement and the Israeli Defence Forces. At least 34 UK state contracts across 10 government departments have been identified, including a £240 million MoD contract awarded in December 2025 without competitive tender.

Because Palantir is a US company, it is subject to the CLOUD Act. That law allows the US Government to compel American technology companies to produce data they hold, regardless of where in the world it is physically stored. When this has been raised in Parliament, the Government’s response has been that it retains data ownership and Palantir is merely a processor. Legal experts and the Open Rights Group argue that distinction offers no meaningful protection under US law. And CLOUD Act orders come with gag orders attached they are legally prohibited from notifying the person whose data was accessed. You would never know it had happened.

The Swiss Armed Forces formally evaluated Palantir’s systems and concluded that data leaks cannot be technically prevented as a fundamental architectural issue, and that no legal contract can fully resolve the sovereignty risk of using a US company. The UK awarded £900 million anyway.

A Parliamentary select committee has itself warned that the UK’s reliance on a small number of US technology providers, including Palantir, creates dangerous supplier lock-in, systemic fragility, and real exposure to data access by the US Government under the CLOUD Act.

The Government is proposing to build infrastructure that could, through a chain of entirely legal steps, expose that information to states that would weaponise it. Nobody consented to that risk. Nobody should be required to accept it.
Has anyone in Government actually thought about those people? Because the policy as framed gives no indication that they have.

I put five direct questions to my MP. I am publishing them here because I think they are the right questions, and because anyone writing to their own representative should feel free to use them.

Have you sought technical briefings on on device scanning from people independent of government, such as academic cryptographers or the Information Commissioner’s Office?

What legal limits exist on what a future government could instruct this infrastructure to scan for, beyond its original stated purpose?

What specific protections would prevent a US CLOUD Act request from reaching data processed through a US-headquartered vendor within this scanning regime, and what stops that data from reaching third-party governments through intelligence sharing?

What assessment has the Government made of the risk this poses to British citizens whose protected characteristics could endanger them in countries they travel to?

How do you intend to vote if this is brought to a division?

What I’d ask you to do
Write to your MP. Not because you’re certain it will change anything, but because the record matters. If this legislation passes without meaningful scrutiny, it should pass over a visible pile of correspondence from people who understood what they were voting for and said so clearly.

You do not need to be a security professional to write a credible letter. You need to be a constituent. That is enough.

Have any thoughts?

Share your reaction or leave a quick response — we’d love to hear what you think!

This website uses cookies to improve your experience. We'll assume you're ok with this, you can opt-out if you wish. Accept Read More

Privacy & Cookies Policy