- Palantir Italia closed 2024 with about 1.28 million euros in revenue and 2025 with about 864 thousand, with four employees; its known contracts with the Defence Ministry’s IT directorate are worth about 2.5 million over ten years. Facts from filings and public records, not a judgment.
- “Enterprise” data protection and the EU data boundary of cloud tools do not amount to suitability for classified information: the documentation itself says so.
- The 2026 AI and Defense Strategy asks for open architectures and no lock-in; EDIP asks for component origin. Both presuppose a capacity map, and the map is strategic data.
- The map must stay in the country: inspectable code, company-owned nodes, a federated layer. The four sovereignty tests apply to any vendor, Yempik included.
What the filings and the records say, before any opinion
Palantir, headquartered in Denver, is the name that comes up in every Italian discussion on AI and defense. The public facts are few and worth lining up. The Italian subsidiary closed 2024 with about 1.28 million euros in revenue and 2025 with about 864 thousand, down 32%, and has four employees, according to the filed accounts reported by Money.it. Its known public contracts with the Defence Ministry’s IT directorate, Teledife, reconstructed by Startmag, total about 2.5 million euros over ten years: 1.3 million in 2015, 148 thousand in 2021, one million for licenses in 2024. In March 2026, according to Il Messaggero, the government stalled a twenty-million proposal and asked for a tender.
These numbers do not say whether the product is good or bad: they say the industrial presence in Italy is small and the known contracts are small. The L3Harris case, cited in the third piece as proof that component provenance can be rebuilt from documents, remains a fact in favor of this series’ thesis. The point of this piece lies elsewhere: in who can switch the system off, in who sees the code, and in what remains with the company when the contract ends. The vendor’s nationality, on its own, answers none of the three questions.
“Enterprise data protection” means something else
Many supply-chain companies answer the sovereignty question with one word: “enterprise.” The cloud tool they use has enterprise data protection and the EU data boundary, so the data stays in Europe and is protected. Microsoft’s documentation describes precisely what this covers: ordinary company data, processing inside a European boundary, no training on content. The same documentation does not say, and cannot say, that the tool is fit for classified or export-controlled information, because that fitness is certified by an authority, and a vendor cannot grant it to itself.
The distinction matters because it is the same one the AI Act makes: it excludes military uses, it includes the same company’s management uses. An enterprise tool is perfectly fine for the internal class, and the restricted class needs something else: that is the classification grid of the second piece, and it is the first sovereignty test.
Open architectures, no lock-in, and the origin of every component
The Ministry’s 2026 AI and Defense Strategy is clear on two points: open, modular architectures against lock-in, and a first year devoted to data consolidation, with an explicit role for Italian mid-sized technology companies. EDIP adds the 35% rule on non-EU components. Together, the two texts presuppose something that does not exist today: the map of how much the national supply chain can produce, with which components, and from where.
Commissioner Kubilius’s number, four million versus two, measures how much that map is missing. But such a map, once built, is itself the most sensitive information in the system: it tells whoever reads it where a country’s bottlenecks are. That is why the question “where does the map live” comes before “how much does it cost” and “who builds it.”
The map of how much a country can produce tells you where its bottlenecks are. It is the most sensitive information in the system, and it must stay in the country.
Inspectable code, company nodes, a federated layer
That the map must stay in the country follows from what it contains, before it is a position. Three conditions make it sovereign. The code must be inspectable, by whoever uses it or by a third party they choose, because a system that decides the production priorities of a supply chain cannot be a closed box. The nodes must be owned by the companies, each with its data and its rules, because no SME will hand its numbers to a customer or a competitor. And the layer that connects them must be federated, as described in the third piece: the buyer sees the status, how much and when and from where, without seeing the content.
It applies to any vendor, and it applies to us. Yempik builds systems with code owned by the client, data at rest in Europe, and replaceable models; it is the thesis we wrote about data sovereignty, applied to a sector where the risk is tangible. But a thesis is worth as much as the tests that verify it, and the tests are four.
Passes if
Inside the company perimeter or on European infrastructure whose operator you know, with a contract that says so.
Fails if
The answer is “in the vendor’s cloud,” and the contract points to terms the vendor can change.
Passes if
Only you. The system keeps working if the vendor shuts down, changes owner, or changes country.
Fails if
A revoked license, a sanction, or a commercial decision thousands of kilometers away stops the factory.
Passes if
You, or a third party you choose: the code can be inspected, and the models can be replaced.
Fails if
How it works is a closed box and the only guarantee is the vendor’s reputation.
Passes if
Data, rules, configurations, and accumulated know-how in open formats, owned by the company, reusable by someone else.
Fails if
A partial export and the memory of whoever worked on it.
Four questions to ask any vendor, us included
Where the data lives, with a contract that says so and not a brochure. Who can switch the system off, and what happens to the factory if a license is revoked thousands of kilometers away. Who sees the code, and whether the models can be replaced without losing the context. What remains with the company if the vendor disappears: data, rules, configurations, and know-how in open formats, or a partial export. They are the same four questions as the NIS2 questionnaire read from the company’s side, and they are the opening chapter of The invisible Arsenal program.
A vendor that passes the four tests can sit in Denver, Milan, or Rome: the address becomes a detail. A vendor that fails them remains a risk even with an Italian VAT number. The map, though, is a case apart: it holds a country’s bottlenecks, and for the map the answer to the first test allows only one geography.
Industrial data sovereignty, in practice
Why can’t the production capacity map live in Denver?
Because the map of how much a country can produce holds its bottlenecks: it is the most sensitive information in the system. It must stay in the country with inspectable code, company-owned nodes, and a federated layer. For other tools the vendor’s address matters less than the four tests: where the data lives, who can switch it off, who sees the code, what remains.
What do Palantir Italia’s filings say?
According to the filed accounts reported by Money.it, the Italian subsidiary closed 2024 with about 1.28 million euros in revenue and 2025 with about 864 thousand, with four employees. Its known public contracts with Teledife, reconstructed by Startmag, total about 2.5 million euros over ten years. These are facts, not a judgment on the product.
Does “enterprise” data protection make a tool fit for classified data?
No. Vendor documentation describes protection of ordinary company data, processing inside a European boundary, and no training on content. Fitness for classified or export-controlled information is certified by an authority, and the documentation does not claim it.
What does the 2026 AI and Defense Strategy ask of companies?
Open, modular architectures against lock-in, a first year devoted to data consolidation, and a role for Italian mid-sized technology companies. Together with EDIP’s 35% rule on non-EU components, it presupposes a national production capacity map that does not exist today.
What are the four sovereignty tests?
Four questions to ask any vendor, Yempik included: where the data lives, with a contract that says so; who can switch the system off; who sees the code and whether the models can be replaced; what remains with the company if the vendor disappears. The answers belong in the contract, not in the brochure.
Sources
- [1]Money.it, “Palantir Italia in crisi? Ricavi crollati del 32% nel 2025”, filed accounts. www.money.it
- [2]Startmag, “Ecco come e quanto istituzioni e aziende italiane si affidano a Palantir”. www.startmag.it
- [3]Il Messaggero, “Palantir offre il suo software all’Italia. Lo stop del governo: serve una gara”, March 2026. www.ilmessaggero.it
- [4]Microsoft Learn, “Enterprise data protection in Microsoft 365 Copilot”. learn.microsoft.com
- [5]EUR-Lex, Regulation (EU) 2024/1689 on artificial intelligence (AI Act). eur-lex.europa.eu
- [6]Agenda Digitale, “Strategia IA e Difesa 2026: cosa cambia per imprese, filiere e sovranità tecnologica”. www.agendadigitale.eu
- [7]Council of the EU, “European Defence Industry Programme: Council gives final approval”, December 8, 2025. www.consilium.europa.eu
- [8]EU Perspectives, “Kubilius: we ask defence industry to speed up”, April 2026. euperspectives.eu
- [9]L3Harris, “Palantir and L3Harris: reindustrializing defense through AI”, December 16, 2025. www.l3harris.com
This page is written by Raffaele Zarrelli, founder of Yempik, with editing done with Claude. It is the sixth piece in the series and the opening chapter of “The invisible Arsenal” program. The figures on Palantir Italia are those reported by the linked outlets from the filed accounts and public records; Palantir is cited for the facts, and the piece passes no judgment on the product. Yempik is a vendor and the four tests apply to us too. It is not legal advice.
Run the four tests on your vendor. On us too.
If you run a defense SME and want the answers written into the contract, where the data lives, who can switch it off, who sees the code, what remains, write to us. We answer in writing, before any proposal.