Guides
    7 min read

    France Drops Palantir for ChapsVision: What Europe's Sovereignty Reset Means for Your Stack

    Last reviewed: 27 July 2026

    In June 2026, France's domestic intelligence agency announced it would replace the US firm Palantir with the French company ChapsVision for its mass-data analysis. The trigger was a fresh reminder that foreign-controlled tools can be switched off by a foreign government: days earlier, US export controls had temporarily cut European access to the most advanced AI models. For any organisation running its business on US software, it is a preview of a risk that used to be theoretical.

    Here is what happened, why it happened, and what it means for the tools your own business depends on.

    What did France actually announce?

    On 16 June 2026, French Prime Minister Sébastien Lecornu said the DGSI, France's domestic intelligence service, will move its mass-data analysis off Palantir's platform and onto software from ChapsVision, a French firm founded in 2019 that now employs more than 1,000 people. Lecornu framed it plainly, saying France "cannot rely on tools developed by foreign powers" and must avoid new strategic dependencies in the digital sphere.

    France is not alone. Germany's domestic security service, the BfV, had already selected ChapsVision over Palantir the previous month. And Paris is backing the shift with money: a €655 million package for sovereign AI, with public-sector staff moving to an assistant powered by the French model-maker Mistral. Two French suppliers, one political message: sensitive analysis on ChapsVision, general AI on Mistral.

    Why now? The export-control trigger

    The timing is the part worth sitting with. The DGSI has used Palantir since 2016, in the aftermath of the November 2015 Paris attacks, and renewed that contract as recently as late 2025. So what changed?

    Days before the announcement, US Department of Commerce export controls led Anthropic to temporarily suspend access to its newest AI models for affected users, before the controls were lifted and access was restored on 1 July 2026. It was a short, compliance-driven suspension rather than a permanent ban. But the lesson landed hard in European capitals: if a foreign government's export policy can interrupt access to a critical tool, then that tool is a dependency, not just a purchase. Lecornu made exactly that argument, warning against relying on the goodwill of partners who can, in effect, turn off the tap. (Anthropic's own account of the suspension and its restoration is here.)

    This is the important distinction, and it is not about any single company. The suspension was temporary and quickly reversed. The structural point European governments drew from it is permanent: control of the off-switch sits with the vendor's home jurisdiction, not with you.

    Why it matters for digital sovereignty

    For years, "digital sovereignty" was mostly a debate about where data physically sits. This episode reframes it around a sharper question: who can restrict your access, and under whose laws?

    Data residency, the location of your data, is not the same as jurisdiction, the legal control over it. A US-headquartered vendor remains subject to US law, including export controls and compelled-disclosure regimes, no matter which region hosts the servers. France's move treats that jurisdictional exposure as an operational risk to be engineered out, not a compliance footnote to be managed.

    It is worth being fair about the trade-off, because the French government's critics are too. Swapping a mature platform like Palantir for a younger domestic one is not a like-for-like technical swap, and the real test is whether ChapsVision matches Palantir's capability under load. Sovereignty, in other words, has a cost and a break-in period. France has decided that cost is worth paying. Whether the tooling keeps up is the open question that the next year will answer.

    The wider wave

    France and Germany are not outliers. In the UK, the NHS's £330 million Palantir data contract is under political review, London's mayor blocked a proposed Metropolitan Police deal, and Germany's military has said it will stop using Palantir products. Across the G7, the temporary AI-model access cut has visibly accelerated a "sovereign alternative" conversation that was already simmering. The direction of travel in European public-sector procurement is now unmistakable: reduce single points of foreign control.

    What it means for your organisation

    You are not a national intelligence agency, but the underlying exposure is identical in shape. Ask three questions of your own stack:

    • Which of our critical tools are controlled from a single foreign jurisdiction? Email, chat, storage, analytics, AI, and your identity provider are the usual suspects.
    • What happens to us if access is restricted, even temporarily? If the answer is "we stop operating," that is a dependency worth pricing.
    • Is there a credible European or self-hostable alternative, and what would switching actually cost?

    The point is not to rip everything out. It is to know, deliberately, where your sovereignty risk sits, so the choice to accept it or reduce it is a decision rather than an accident.

    Is your own stack exposed?

    The tools in this story, and the ones your business runs on every day, carry very different levels of sovereignty risk. You can score any tool free with SovereigntyScore, or get a full Full Stack Audit for €99: a complete risk breakdown, scored European alternatives, and a step-by-step migration plan for each tool.

    Score a tool free  |  Get your Full Stack Audit for €99

    Related reading: The Fable 5 Shutdown: What a 19-Day AI Blackout Taught Europe About Sovereignty · The EU's €30bn AI Gigafactory Plan · What is European Digital Sovereignty? · Sovereignty Risk in SaaS Procurement · OpenAI vs Mistral: Sovereignty Comparison · AWS vs OVHcloud and Scaleway.

    Sources: The Guardian, Computing, and Anthropic. This article is independent analysis and does not constitute legal advice.

    Frequently Asked Questions

    Why is France replacing Palantir with ChapsVision?

    To reduce dependence on US-controlled technology. Prime Minister Lecornu framed the June 2026 decision as avoiding "strategic dependencies," after US export controls briefly limited European access to advanced AI models showed how foreign policy can interrupt critical tools.

    What is ChapsVision?

    A French software company founded in 2019, now with over 1,000 employees, that collects, prepares and analyses large volumes of data. Its capabilities overlap with Palantir's; the difference France is buying is jurisdiction, a French vendor outside US legal control.

    Did the US actually ban access to AI models?

    Not permanently. In June 2026, US export controls led to a temporary suspension of access to Anthropic's newest models for affected users; access was restored on 1 July 2026. The episode was brief, but it demonstrated the dependency risk European governments then acted on.

    Does moving data to an EU region make a US tool sovereign?

    No. Data residency (where data sits) is not the same as jurisdiction (who legally controls it). A US-headquartered vendor stays subject to US law regardless of hosting region, which is the exposure this whole story turns on.

    Key Takeaways for Technical Leaders

    • •France's DGSI is replacing Palantir with French firm ChapsVision, following a similar move by Germany's BfV
    • •The trigger was a temporary US export-control suspension of access to Anthropic's newest AI models in June 2026
    • •Data residency is not sovereignty: US vendors remain subject to US law regardless of where servers sit
    • •The sovereignty question is who controls the off-switch, not just where the data physically resides
    • •European public-sector procurement is visibly shifting toward reducing single points of foreign control
    • •Private organisations face the same structural risk in miniature — email, chat, storage, analytics, AI, and identity are the usual exposure points

    Audit your technology stack

    This guide covers one topic. Your Technology Stack Audit scores your entire technology stack as one system, ranks what to fix first, and maps how your tools depend on each other. One-off €99.

    Audit my technology stack — €99