You are the IT director at a German federal agency. On Wednesday morning, your inbox contains three things: a press summary of the Politico interview Karsten Wildberger gave around mid-April 2026, a memo from your procurement office about three projects in your 2026/27 roadmap that fall above €500,000 per year, and a note from your AI strategy lead asking whether the mandatory federal AI platform applies to the deployment you have been planning for Q3. The three documents are connected. The connection is the question this article exists to answer.

Wildberger named four decisions in the interview. Microsoft and Palantir are reduction targets — not diversification, reduction. The federal AI platform KIPITZ becomes mandatory for federal authorities. A European Palantir alternative is given a two-to-three-year timeline. And the Federal Ministry for Digital and State Modernisation (BMDS) receives de facto veto rights over IT projects of other ministries above €500,000 per year or €3 million in total project costs.

The political framing was sovereignty. The structural framing should be that this is the largest centralisation of federal IT authority since the original IT-Konsolidierung programme of 2015 — and your roadmap is now subject to it.

This article is the audit of what the veto threshold actually catches, what mandatory KIPITZ actually constrains, whether the Bundeswehr’s Palantir alternatives are operationally ready, and the question your next project budget submission has to answer before it reaches the veto desk.

What the veto actually catches

The veto right applies to IT projects above €500,000 per year or €3 million in total project cost. The threshold is set carefully. It captures enough to shape federal IT direction without provoking immediate constitutional questions about ministerial autonomy under the Ressortprinzip.

In practice, the threshold catches all federal-level cloud and platform decisions, major application procurements, AI platform decisions (which default to KIPITZ regardless), and identity-and-access-management projects. It does not catch sub-€500k departmental tooling, existing contract renewals at the same scope and price, or embedded technology in specialised systems — most importantly, classified Bundeswehr and intelligence-service architecture.

For a federal agency’s typical roadmap, this means most strategic decisions land above the line and most tactical ones below. The first practical consequence: project structure now matters more than it did. A €750,000 project that could plausibly be split into a €400,000 base contract plus a €350,000 follow-on falls below the veto on each component. Some of that splitting is legitimate phasing; some of it is the kind of procurement engineering that BMDS will, on the first cycle, learn to detect. The early cases will set the precedent.

The second practical consequence is that the justification attached to a roadmap item now has a new reader. Until April 2026, the audience for a €600,000 procurement justification was the ministry’s own controller and the Bundesrechnungshof. From May 2026, the audience includes BMDS architects whose framework for evaluating the request is sovereignty-direction-of-travel. A justification that reads as “continue existing vendor relationship” will trigger questions a justification that reads as “named non-EU vendor with a defined two-year exit path” will not. The early submissions will reveal what BMDS reads as serious and what it reads as performative.

Microsoft as a usage curve, Palantir as a binary

Microsoft is a usage curve. The federal administration paid €481.4 million for Microsoft licences in 2025 — the figure Lenhard’s parliamentary question to Parliamentary State Secretary Thomas Jarzombek extracted in February. “Less Microsoft” is therefore measurable. Wildberger has not given a specific reduction target in public, but a usage curve produces an annual data point against which the framing can be tested.

Palantir is binary. By May 2026, Vice Admiral Thomas Daum — head of the Bundeswehr’s Cyber and Information Domain Service — had said in public what Wildberger had said in private. Palantir, Daum told reporters, was “not being considered at all right now” because Germany would not permit employees of an American private company access to national defence data. The Bundeswehr was already evaluating three replacement vendors: Almato in Stuttgart, Orcrist in Berlin, and ChapsVision in Paris. Contract awards were expected by year-end 2026.

What this means for federal-adjacent IT planning depends on which side of the procurement line the reader sits. For agencies considering Palantir-class data-fusion platforms in non-classified contexts, the Bundeswehr’s reasoning generalises: a US-headquartered vendor whose employees would need access to your sensitive operational data is now a procurement risk that has to be defended in writing rather than assumed. For vendors and integrators currently selling Palantir Foundry into the federal-adjacent market, the next two years are a closing window in which alternative-vendor expertise is the most valuable thing to develop.

The European alternative timeline is the most fragile element of the package. On the current funding trajectory, two-to-three years is rhetoric. If it is rhetoric, then Palantir reduction without a credible replacement means the Bundeswehr loses data-fusion capability it currently has — which is the part of Wildberger’s framing that has not survived contact with the operational layer.

The Bundeswehr alternatives: what they can ship in 2026

The named alternatives — Almato, Orcrist, ChapsVision — are not a like-for-like Palantir replacement, and the public discussion has not always made this clear.

Almato (Stuttgart) is the most established of the three: a German systems integrator with deep automation tooling, expertise in process orchestration, and an existing public-sector client base. Its data-fusion capabilities are real but oriented toward administrative workflows rather than operational intelligence. For Bundeswehr logistics, personnel management and supply-chain analysis, Almato can ship a credible offering in 12 months. For real-time tactical-intelligence fusion of the kind Palantir Gotham provides, Almato is not currently in scope, and the public material does not suggest a roadmap in that direction.

Orcrist (Berlin) is the closest to a Palantir-tier architecture conceptually. Founded with explicit ambitions in the data-fusion space, with strong personnel from the German defence-tech ecosystem. The maturity gap relative to Palantir is real and visible: Orcrist has not, to date, deployed at the scale of a national defence ministry, and the engineering surface that ships in production today is narrower than Palantir Foundry. The honest assessment is that Orcrist is a credible 2027–2028 product if funded at the scale the Bundeswehr award would imply. As a 2026 deliverable, it is a pilot, not a production system.

ChapsVision (Paris) is the unusual member of the shortlist: a French vendor whose inclusion signals that the Bundeswehr is treating European-sovereignty more broadly than German-only. ChapsVision has existing French-defence contracts and a more mature product than Orcrist. For Bundeswehr roles where French-supplied software is politically acceptable, ChapsVision is the lowest-risk delivery option of the three. For roles where it is not, the choice narrows.

The implication for the broader federal IT readership is that the Bundeswehr award, when it lands at year-end 2026, will signal which sovereignty trade-off the procurement layer is willing to make. An Almato award signals administrative-fusion-first, defer-tactical-fusion. An Orcrist award signals strategic-capability-investment, accept-near-term-gap. A ChapsVision award signals European-sovereignty-broadly-defined. A split award — most likely outcome — signals all three at once, which is also a decision about how much capability the Bundeswehr is willing to maintain while it builds.

The single-point-of-capture problem with mandatory KIPITZ

KIPITZ is the third lever, and the one that has the least public scrutiny. If federal authorities must use it for AI workloads — not should but must — then federal AI infrastructure is centralised at ITZBund regardless of ministerial preference. The infrastructure layer is being built on the €250 million federal AI cloud contract awarded to the T-Systems and SAP consortium. ChatGPT and equivalent commercial systems remain excluded for data-protection reasons. So far, so coherent.

The architectural concern is concentration. Mandatory KIPITZ creates a single point at which a future political shift — a different coalition, a supplier with extraordinary influence, a security incident — can affect federal AI use across all authorities at once. Single-vendor architectures have well-documented failure modes, even when the vendor is federally owned. The €250 million T-Systems/SAP contract is the supplier side of that vendor relationship. The federal authorities depending on it become operationally invested in its continued health regardless of whether better alternatives emerge in 2027 or 2028.

For an IT director planning AI deployments under the new mandate, the practical consequence is that KIPITZ becomes a non-negotiable substrate for federal-data workloads, but the integration architecture above it remains your responsibility. A deployment that treats KIPITZ as a black box and builds everything else portable across substrates preserves the option to migrate when migration becomes viable. A deployment that takes deep dependencies on ITZBund-specific KIPITZ features — which the platform will encourage — locks the agency into the substrate as tightly as the M365 contracts the directive is meant to reduce dependence on. The methodological lesson from twenty years of public-sector vendor lock-in applies here regardless of the vendor’s federal ownership.

Sovereignty is not a procurement directive

This is the reframe the package makes hard to avoid.

Wildberger’s interview produced four mechanisms — veto thresholds, mandatory KIPITZ, Palantir rejection, Microsoft reduction — that operate at the procurement layer. The political framing presented them as sovereignty. The architectural framing has to acknowledge that procurement direction is not sovereignty. Mandatory KIPITZ replaces Microsoft 365 dependence with ITZBund dependence — both are substrates whose continued availability is not under the using agency’s control. The Palantir rejection replaces a US data-fusion vendor with an as-yet-undelivered European vendor whose continuity is contingent on funding cycles that will outlast the current government. The Microsoft reduction is a usage curve that can be reversed by the next budget cycle if the political weather changes.

Sovereignty, properly framed, is the property of being able to continue operating when any single piece of the supply chain becomes unavailable. None of the four mechanisms in Wildberger’s package produces that property at the agency level. They produce a different dependency, with different jurisdictional exposure. That is a meaningful improvement on the CLOUD Act question — federal data on ITZBund infrastructure is not subject to a US Congressional subpoena — but it is not a meaningful improvement on the supply-chain-continuity question, which is the harder problem and the one your agency’s own architecture has to solve regardless of which substrate the procurement directive points at.

The practical consequence: your next procurement submission to BMDS will be evaluated as sovereignty even when it is, structurally, vendor substitution. Submissions that acknowledge this distinction explicitly — “we treat KIPITZ as a mandatory substrate and design portable above it”, “we select Orcrist for the data-fusion roles where European-vendor maturity is acceptable and defer the rest” — will read as serious to the BMDS architects whose veto your roadmap depends on. Submissions that treat the procurement directive as if it were a sovereignty answer will read as performative, regardless of which vendor name appears on the line.

What this article is not

Anyone reading this analysis as a claim that the veto framework is wrong or that KIPITZ is the wrong AI platform has missed the point — federal IT direction has been incoherent across ministries for two decades, a central coordinator with substantive authority is a defensible response, and federal AI infrastructure is necessary if commercial generative AI is to stay out of federal workflows. The analysis operates one layer deeper: at the observation that the package’s procurement mechanisms and its sovereignty claim sit on different layers. Assumptions about the motivations of individual actors are outside the scope of the investigation. For IT directors whose roadmaps now have to navigate both layers, this analysis does not substitute for procurement-law or information-security advice.

The signal in the budget

The signal worth watching, over the next twelve months, is the relationship between the BMDS veto cycle and the federal budget cycle. The veto threshold catches projects at submission. The budget cycle determines what gets resourced. If projects above the threshold systematically receive BMDS sovereignty-direction recommendations that survive into the funded budget, the package is operational policy. If the recommendations are made and the budget reverts to the procurement-as-usual baseline, the package is a press cycle that produced a press cycle. The early evidence will be in the autumn 2026 budget submissions.

For your three projects above the line: file two with sovereignty-direction language and one as-is, and the comparison will tell you which framework you are operating in.

Sources


Topic overview: Digital Sovereignty in Europe Related articles: The file by autumn, Sovereignty on Microsoft’s servers