Operational notes Observatory

AI procurement: writing a tender that survives a protest — the DIA ASTRA case

6 min read

Reinforced concrete structure under construction, with props and formwork on the top slab, in black and white
Building from scratch when something ready already exists: in public procurement that choice has to be justified by law.

On 24 July 2026 the Defense Intelligence Agency, the Pentagon’s military intelligence agency, withdrew the ASTRA solicitation: the procurement to have a software platform for technical intelligence analysis custom-built. It did so four days after Palantir Technologies filed a pre-award protest with the Government Accountability Office, arguing that the requirement breached a 1994 statute — the one obliging federal agencies to buy commercial solutions where they exist rather than build from scratch. Bloomberg, which broke the news, places the system within what sits “at the heart of lethal targeting”. For anyone writing or assessing requirements, the case says one thing: the weakest point in a technology purchase is not the price, it is how the requirement is written.

The facts, in order

  • The container: ASTRA (Advanced Systems for Technical Research and Analysis) is a task order under SITE III, the ten-year, $12.6 billion framework through which the DIA and the National Geospatial-Intelligence Agency consolidated IT purchasing into one vehicle with 144 admitted suppliers.
  • 20 July 2026: Palantir files the pre-award protest. By law the GAO decides within one hundred days (31 U.S.C. § 3554): the deadline fell on 28 October 2026.
  • The argument: the requirement calls for custom software development where — the company contends — a suitable commercial product already exists. The statute invoked is the Federal Acquisition Streamlining Act of 1994, codified for defence at 10 U.S.C. § 3453 (formerly § 2377): requirements must be stated “in terms of functions to be performed, performance required, or essential physical characteristics”, defined so that commercial products can meet them.
  • 24 July 2026: the solicitation is withdrawn at the agency’s own request, confirmed by a spokesperson. Palantir stock rises about 1% pre-market.
  • The back story: on 18 May 2026 Palantir had filed an earlier protest, and on 21 May Axios revealed the dispute over the modernisation of MARS, the intelligence repository meant for eight years to replace a Cold War-era platform. The company’s case: the DIA “is wasting taxpayer money, and flouting the law”. At the time the DIA did not reply publicly and Palantir declined to comment; a White House official said the administration backs broader competition.
  • Not the first time: on 30 June 2025 Palantir challenged a sole-source award planned by the same agency (the Prometheus programme), invoking the Competition in Contracting Act and the same FASA; docket B-423684.1, dismissed on 30 July 2025.
  • The precedent: in 2016 the Court of Federal Claims enjoined the Army’s DCGS-A Increment 2 solicitation for breaching § 2377; the Federal Circuit affirmed on 13 September 2018 (case 17-1465). Federal growth followed: from 92nd among contractors in 2021 to 40th in 2026, over a billion dollars in prime contracts.
  • The non-answers: no public reasoning for the withdrawal beyond the spokesperson’s confirmation, no Palantir statement, no comment from other bidders; the GAO does not publish pre-award protest files before it decides.

One point the coverage skips: we do not know why the agency withdrew the solicitation. It could be a concession on the merits, a rewrite of the requirements or a change of priorities: no public source distinguishes them. The public record measures outcomes — solicitation published, protest filed, solicitation withdrawn — not the internal causes of an organisation nobody observes from the inside.

Lesson 1: the requirement is the real exclusion clause

In the United States the commercial preference is a duty with a legal remedy attached: if the requirement describes an architecture instead of a need, whoever is left out can stop it. In Europe the same mechanism exists with the sign reversed. Directive 2014/24/EU, art. 42, prohibits technical specifications that have the effect of favouring or eliminating particular undertakings or products; and for Italian public-sector software, art. 68 of the CAD (Legislative Decree 82/2005) requires a comparative technical and economic assessment across six options — bespoke development, reuse, open source, cloud, proprietary licence, combinations — against the criteria in paragraph 1-bis: total cost (acquisition, implementation, maintenance, support), open standards and interoperability, security guarantees, data protection and service levels. Paragraph 1-ter adds the part almost nobody puts on file: a proprietary licence is permitted only where the comparison demonstrates, with stated reasons, that solutions already available in the public sector or open source cannot be used. In the US the burden is to justify bespoke work; in Italy, proprietary software. Either way, an undocumented choice is a contestable choice.

Lesson 2: a supplier who can stop your tender is already a dependency

Palantir is using a lawful instrument, and in 2016 a judge found for it on the merits. But the effect on a buyer is a reset timetable: one hundred days of GAO review in the US; in Italy thirty days to bring a procurement challenge (art. 120 of the Code of Administrative Procedure, Legislative Decree 104/2010), plus interim relief that can suspend everything. A supplier able to block the procedure is a dependency that materialises before any contract exists — the same asymmetry that emerged when London called its supplier a “point of weakness” in its public infrastructure — and it belongs on the risk register alongside contractual lock-in.

Lesson 3: with no documented assessment there is no defence

The GAO report on 44 federal AI contracts that we analysed two days ago showed the same gap from another angle: no systematic documentation of the lessons learned from earlier purchases. Here the gap costs an entire tender. Market research, a comparison of available solutions, the reason none meets the need: without those three documents, building bespoke is indefensible not because it is wrong, but because it is unprovable. In a company it is the same, with a board in place of the GAO.

What to do

  1. Write requirements by function and performance, not by architecture. “Must correlate entities from heterogeneous sources while preserving provenance traceability” is a requirement; “must implement a proprietary ontology graph” is a supplier’s fingerprint.
  2. Put the comparative assessment on file before deciding: for public bodies, with the criteria in art. 68, paragraph 1-bis of the CAD and the reasoning required by paragraph 1-ter; for companies, with the same structure — purchase due diligence done properly.
  3. Build the litigation window into the timetable and check whether shortlisted suppliers have a history of challenging bodies that excluded them.
  4. Insist on reversibility: data, ontology and operating model exportable in documented formats, so that in three years the buy-or-build choice can be made again.

Buying a ready platform or building one has to be assessed, not decided out of habit. The criterion we follow: ready on the method — data, a shared operating model, agents, a human operator at the point of decision — and bespoke only on the client’s domain, the one unrepeatable part. Data stays inside the perimeter in both delivery modes: on-premise in the client’s environment, or a dedicated cloud in a data centre in Italy staffed directly by us, accessed over a private VPN.

Do you have to write or assess an AI specification and want to know whether it would survive a challenge? Thirty minutes with one of our experts for a review of your requirements and comparative assessment.

Sources