Operational notes Observatory

Palantir and ICE: the ImmigrationOS contract that split Silicon Valley

5 min read

Facade of a modern institutional building with a dome-shaped surveillance camera on the corner
Every technology contract also brings home the history — and the reputation — of whoever signs it on the other side.

There is a contract worth roughly $30 million that has, for over a year, forced the technology world to argue with itself. In April 2025 ICE — the US federal agency for immigration and customs enforcement — awarded Palantir Technologies the development of ImmigrationOS, a platform designed to speed up the identification, prioritisation and logistics of deportations. Since then there has been a public letter from former employees, an open clash between the founder of Y Combinator and the company’s leadership, protests outside its offices, and an unyielding defence from CEO Alex Karp. The case is not just about Washington: it says something precise to anyone, including in Europe, who buys critical technology. First the verified facts, then the lesson.

The facts, in order

  • The contract: in April 2025 ICE modified an existing contract with Palantir worth roughly $30 million, tasking it with building the “Immigration Lifecycle Operating System”. Three functions were stated in the documents: prioritising the identification of people to be deported (the agency cites violent criminals, gang members, overstayed visas), tracking “self-deportations” with “near real-time visibility”, and making removal logistics more efficient. It was a direct award, without a tender, with explicit reference to presidential executive orders; a prototype was due by 25 September 2025, with the contract running until September 2027.
  • The tech world’s reaction: Paul Graham, founder of Y Combinator, publicly accused the company of building “the infrastructure of the police state”, urging top engineers to work elsewhere and asking Palantir for a public commitment not to help the government violate the Constitution.
  • The company’s response: Ted Mabrey, global head of commercial, defended the collaboration with homeland security — which began, he recalled, after the murder of federal agent Jaime Zapata — called Graham’s demand “made in bad faith”, arguing that such a commitment “has already been made in every possible way”, and added that he expected new job applications precisely because of the controversy.
  • The former employees: in May 2025 thirteen former employees — engineers, managers, one person from the privacy and civil liberties team — signed an open letter accusing the company of having dismantled its own ethical guardrails and of normalising, through its work for the administration, practices that its internal code of conduct was supposed to prevent.
  • Karp’s line: the CEO has never backed down. In his letter to shareholders he argued that the company’s software is “equally capable of preventing an unconstitutional intrusion by the state into citizens’ private lives”; in February, in an interview with CNBC, he turned the critics’ argument on its head: “If you’re critical of ICE, you should be protesting for more Palantir” — meaning more traceability and constraints on who operates it.
  • The scope grows: in September 2025 a second order worth roughly $30 million arrived for licences and maintenance; the protests, inside and outside the industry, stopped neither the programme nor the share price.

No authority has found any wrongdoing by the company, which maintains that its work is lawful and useful. But for anyone watching from the buyer’s side of the table, the point is not to decide who is right, Graham or Karp. It is to understand what this clash changes in contracts.

Lesson one: a supplier’s reputation is part of the customer’s risk

Every organisation that adopts a platform also imports into its risk register the reputation of whoever sells it: its other contracts, its public clashes, the resignations and open letters of its former employees. This is not a moral question, it is an operational one: boards, unions, customers and talent ask questions, and “we didn’t know” is not an answer. Due diligence on a critical supplier cannot stop at balance sheets and certifications: it must cover the client portfolio, litigation and governance. That is one of the reasons why, in our approach, the choice of technology components is a documented decision, with criteria set in writing beforehand — not justified after the fact.

Lesson two: ethical criteria are entering tender specifications

The American case shows a trend that in Europe is already becoming standard practice: alignment of values and governance is turning into a purchasing criterion, alongside price and performance. The EU AI Act requires human oversight and transparency for high-risk systems, and public tender specifications are starting to ask where the data sits, who sees it, and which uses are excluded. For the public sector — but increasingly for regulated companies too — writing these criteria into the tender is the way to avoid having to improvise them in the middle of a media storm. Compliance stops being an attachment and becomes part of the technical specification.

Lesson three: usage limits must be written down, not assumed

ImmigrationOS was born as an evolution of an investigative case-management system: a tool built for one purpose was extended to a different one, through a contract amendment. This is the dynamic to keep watch over in every technology contract, in both directions: what the supplier can do with your data, and how far the use of the tool can be pushed without a new, explicit decision. Clauses on usage limits — permitted purposes, excluded uses, a requirement for written consent before any extension, human control over decisions that affect people — matter as much as the clauses on price. They are negotiated at signature, or they do not exist at all.

What to do, if you are choosing a critical supplier

  1. Carry out reputational due diligence: client portfolio, litigation, public positions taken by leadership — and review it at every renewal.
  2. Write ethical criteria into the tender: excluded uses, transparency, governance requirements. Before signature, not after the controversy.
  3. Ask for usage limits in writing: which purposes, which data, which extensions require fresh consent.
  4. Demand documented human control over decisions that affect people: who validates them, with what evidence, with what audit trail.
  5. Keep the exit ready: exportable data, complete documentation, known migration costs — a supplier’s reputation can change faster than a multi-year contract.

Want to assess a critical technology supplier — or put ethical criteria and usage limits into your next tender? Half an hour with one of our experts to set up the framework.

Sources