← All company positions
Palantiragenda

OSTP RFI: Regulatory Reform on Artificial Intelligence, Docket ID number OSTP-TECH-2025-0067

Published October 23, 2025 · Printed at the top of page 1 of the letter, below the public-dissemination notice and above the address block (National Coordination Office, 2415 Eisenhower Avenue, Alexandria, VA). The appendix (attachment_2.pdf) carries no date of its own. The PDF metadata gives a creation date of 23 October 2025, matching the printed date.

Not law. This is a company's own public position on AI regulation. It is not law, and it carries no legal force.

What it argues for

This is Palantir Technologies' answer to the White House Office of Science and Technology Policy's September 2025 request for information on which federal rules hold back AI, filed on the public docket OSTP-TECH-2025-0067 as a letter to the National Coordination Office with a separate appendix on Privacy Act reform. Its organising principle is stated in the opening: "AI Systems must be evaluated and regulated in their domain", and "Treating regulatory challenges as a question about AI divorced from the context of application is a perennial failure mode in the AI policy and ethics discourse." Palantir is not deregulatory across the board: it says "AI systems with wide-reaching impact ought to be deployed alongside rigorous testing and evaluation" frameworks, with pre-deployment testing and post-deployment monitoring, and asks for "a stable regulatory environment while drafting new standards and requirements mandating these practices." On harms it wants no new AI statute yet: "existing tort law, especially products liability, should in the short term determine where actual harms and negligence are present", because "Waiting to introduce larger legislation will allow industries to experiment safely". Its one legal-reform ask outside procurement is privacy: "Training data used to build LLMs lacks a clear modern legal foundation", so the Privacy Act's "record" and "system of records" definitions and 32 CFR Part 310 should be modernised, and the appendix argues that "A revised Privacy Act should abandon the record concept and focus instead on PII as a general and perhaps more fluid concept". Most of the letter, though, is about how the government buys software: it asks for AI funding that is "“color of money” agnostic", for enforcement of the existing commercial-first rules (FASA, the Software Acquisition Pathway, Commercial Solutions Openings and Other Transaction Authority), and argues that "the adoption of AI is most significantly hindered not by regulatory ambiguity but by outdated or stale organizational paradigms within the acquisition workforce" — proposing to "increase the cost of not choosing commercial software" and to tie acquisition officials' promotions to commercial buying. It names two defence programmes built on a non-commercial, cost-plus basis (DIA's MARS and the NBIS vetting system) as examples, and closes by asking for more in-house technical expertise in government.

Stated positions (16)

  • AI should be regulated by domain of use, not as a technology in the abstract: "AI Systems must be evaluated and regulated in their domain", and "AI cannot be separated from its domain of application and systems-level integration context."
  • Testing and evaluation should be required for impactful systems: "We believe that AI systems with wide-reaching impact ought to be deployed alongside rigorous testing and evaluation (“T&E”) frameworks, including pre-deployment testing and post deployment monitoring and auditing capabilities."
  • Palantir asks for mandated practices within a stable framework rather than for deregulation: "We encourage maintaining a stable regulatory environment while drafting new standards and requirements mandating these practices."
  • AI should be treated as a product under existing liability law: "AI systems are products that should be subject to existing context-specific liability", with "existing tort law, especially products liability" determining harms and negligence in the short term.
  • New AI legislation should wait: "Waiting to introduce larger legislation will allow industries to experiment safely and allow for an understanding of where new regulations may be needed."
  • Privacy law has not caught up with AI training data: "Training data used to build LLMs lacks a clear modern legal foundation", and without a fix "any AI system built today may become legally untenable in the future".
  • Short of a statutory overhaul, the executive branch should act: "the administration ought to consider updating 32 CFR Part 310 and other similar agency guidelines to more closely match modern models of data and data storage to support innovation."
  • The appendix asks Congress to rebuild the Privacy Act around personal data rather than records: "A revised Privacy Act should abandon the record concept and focus instead on PII as a general and perhaps more fluid concept", and adds that "The Privacy Act should be updated to mitigate against the risks of de-anonymization in large datasets."
  • The appendix rejects a trade-off between privacy and AI use, urging "renouncing the presumption of an unavoidable tradeoff between offering greater data privacy safeguards and employing AI to carry out government agency missions", and states that "Palantir has historically supported – and continues to support – robust and evolving legal and regulatory safeguards".
  • NIST should lead on federal privacy standards: "NIST should play the primary role in promoting privacy across the federal government, including through standards-setting."
  • Federal software and AI funding should not be split by appropriation type: "Establish funding sources for software and AI systems that are “color of money” agnostic", because "Allowing for software to be funded by a colorless appropriation would prevent contracts for AI capabilities being held up over disagreements on which color of money to use".
  • The acquisition tools already exist and are underused: "The tools necessary to ensure AI adoption across government already exist today", pointing to the March 2025 memorandum that makes the Software Acquisition Pathway, Commercial Solutions Openings and Other Transaction Authority the defaults.
  • The main barrier is the acquisition workforce, not regulation: "the adoption of AI is most significantly hindered not by regulatory ambiguity but by outdated or stale organizational paradigms within the acquisition workforce".
  • Choosing custom development over commercial software should be made harder: "One solution to this problem would be to increase the cost of not choosing commercial software", including by making "commercial procurement proficiency a prerequisite for Senior Executive Service (SES) positions and GS-14/15 promotions".
  • Names a competing government-built programme as a cautionary example: of DIA's MARS system, "After seven years and almost $1 billion awarded already, MARS is still not at full operational capability."
  • Government needs its own technical staff to work with vendors: "Upskilling of the current workforce and additional full-time personnel are needed to ensure that there are employees who have the appropriate capacity to engage with end-to-end AI workflows."

About this document

A 7-page PDF letter filed as public comment OSTP-TECH-2025-0067-0158 on regulations.gov, with a 9-page second attachment headed "Appendix: Supplementary Material on Privacy Act Reform". The letter has no title line: each page opens with a notice that it "contains no business -proprietary or confidential information" and may be reused in work on the OSTP RFI, and it is addressed "To Whom It May Concern" and written in the name of Palantir Technologies Inc.; there is no signature block and no individual byline. After a one-page introduction it answers five of the RFI's numbered questions — (i), (ii), (iii), (v) and (vi) — each with a bold "Recommendation:" line, and ends with six endnotes citing press reports on the March 2025 Hegseth software-acquisition memorandum, a National Research Council report, the eCFR and the Stanford AI Index 2025. The appendix is a series of headed recommendations on the Privacy Act (record definitions, data minimisation, SORNs, de-identification, intra-agency sharing, NIST's role, oversight bodies). The PDF's internal title field reads "final_trahan_privacyactrfi.pdf" on both attachments, suggesting the appendix was reused from an earlier Privacy Act submission. The letter calls the NBIS programme's agency both "Defense Security Cooperation Agency (DSCA)" and "DCSA" in consecutive sentences.

How this sits against AI law

Each stance compared with what EU and US instruments actually require. Where no instrument addresses a theme, that gap is shown rather than hidden.

AI regulated within its domain of application rather than as a technology in itself

AI systems must be evaluated and regulated in their domain, through the rules that already govern each sector and context of use; treating AI "divorced from the context of application" is described as a perennial failure mode.

European UnionContradicts

The AI Act is a single horizontal regulation that applies across sectors, creates AI-specific obligations for providers and deployers and an EU-level AI Office; its high-risk tier is defined by use in listed areas and by reference to existing product-safety law, so it does account for context, but it regulates AI as such rather than leaving it to each sector's own rules.

United StatesAligned

The March 2026 legislative recommendations say "Congress should not create any new federal rulemaking body to regulate AI, and should instead support development and deployment of sector-specific AI applications through existing regulatory bodies with subject matter expertise and through industry-led standards" — the same domain-by-domain approach.

RAI-US-NA-USNATIO-2026Status: Adopted.

Mandatory testing and evaluation, before and after deployment, for impactful AI

AI systems with wide-reaching impact should be deployed with rigorous testing and evaluation frameworks, including pre-deployment testing and post-deployment monitoring and auditing, and new standards and requirements mandating these practices should be drafted within a stable regulatory environment.

European UnionAligned

For high-risk AI systems the Act already requires a risk-management system that includes testing before the system is placed on the market, and a post-market monitoring system once it is in use.

United StatesAligned

OMB M-25-21 requires federal agencies to carry out impact assessments and pre-deployment testing for high-impact AI and to provide human oversight and ongoing risk management; it covers only the government's own use, and no federal instrument imposes such testing on private deployers.

Existing tort and product liability, not new AI legislation, should govern AI harms for now

AI systems are products and should be subject to existing context-specific liability; existing tort law, especially products liability, should determine harms and negligence in the short term, and larger legislation should wait until litigation shows where gaps exist.

European UnionAligned

The revised Product Liability Directive keeps strict, no-fault liability for defective products and expressly extends the definition of product to software, including AI systems, treating their developers as manufacturers; the Commission withdrew the separate AI Liability Directive (RAI-EU-NA-PANCLXX-2025). The EU thus handles AI harm through product liability, as Palantir proposes, though by updating that law rather than leaving it untouched.

United StatesNo equivalent law

No federal US statute or order sets liability rules for AI, so existing tort law applies by default. The closest statement is in the March 2026 legislative recommendations, which ask Congress to "avoid setting ambiguous standards about permissible content, or open-ended liability, that could give rise to excessive litigation" — written in the child-safety context, not as a general liability policy.

RAI-US-NA-USNATIO-2026Status: Adopted.

Modernising privacy law for AI training data and government data systems

Training data lacks a clear modern legal foundation: the Privacy Act's definitions of "record" and "system of records" and 32 CFR Part 310 should be updated, and a revised Privacy Act should be built around PII, data minimisation tailored to each agency, better notice, de-identification safeguards and limits on intra-agency sharing, with NIST leading on standards.

European UnionAligned

The EU already governs personal data used in AI training, including by public bodies, through the GDPR, and the Commission's November 2025 Digital Omnibus package proposes clarifying the data-processing rules for AI model training; that package is still under review, not law.

RAI-EU-NA-DOPSEXX-2025Under Review — not binding law today.
United StatesNo equivalent law

No instrument in the corpus amends the Privacy Act of 1974 or 32 CFR Part 310. The March 2026 legislative recommendations touch training data only to ask Congress to affirm that existing child privacy protections apply to AI, "including limits on data collection for model training".

RAI-US-NA-USNATIO-2026Status: Adopted.

Commercial-first federal acquisition of AI software

The government should buy commercial AI software rather than build its own: fund software and AI with appropriations that are not split by "color of money", enforce the commercial-first rules already on the books (FASA, the Software Acquisition Pathway, CSOs and OTAs), require higher approval for internal builds, and tie acquisition officials' promotions and awards to commercial buying.

European UnionNo equivalent law

The AI Act does not govern how public bodies fund or procure AI; it treats a public authority using a high-risk system as a deployer with obligations, including a fundamental-rights impact assessment for bodies governed by public law.

United StatesAsks for more

OMB M-25-22 sets a lifecycle process for federal AI acquisition, favours a competitive market and US-developed AI, and requires contract terms on government data rights, portability and limits on training commercial models with non-public government data. It creates no colourless appropriation (a matter for Congress), no penalty for building in-house and no link between commercial buying and promotion.

In-house technical expertise in government

Government should invest in its own technical staff — upskilling current employees and hiring full-time data scientists — so that agencies can work with vendors on end-to-end AI workflows rather than depend on outside consultants.

European UnionAsks for more

The Act requires Member States to give their national competent authorities adequate technical, financial and human resources, including staff with AI expertise, but that duty covers the authorities that supervise AI, not the agencies that buy and use it.

United StatesAligned

The Action Plan calls for a talent-exchange programme allowing rapid details of federal staff to agencies that need specialised AI talent (data scientists and software engineers) and for access to, and training on, frontier models for federal employees whose work could benefit.

Palantir's core idea — regulate AI through the rules of each domain, rely on existing product liability, and hold off on new AI legislation — is close to where US federal policy has landed: the White House's March 2026 legislative recommendations tell Congress not to create a new federal AI rulemaking body and to work through existing sector regulators instead. The EU took the opposite route with a single horizontal AI Act, although the Act's high-risk tier is itself defined by context of use, and on liability the EU did what Palantir recommends in substance: it dropped the dedicated AI Liability Directive and instead brought software and AI systems within its revised strict product-liability directive. On testing and monitoring Palantir is closer to the EU than its deregulatory reputation suggests: it asks for "new standards and requirements mandating these practices", which the AI Act already imposes on high-risk systems and which US federal policy imposes only on agencies' own high-impact AI. Its privacy ask — rebuild the Privacy Act around personal data rather than "records" — has no US counterpart in force; the EU already regulates personal data in training sets under the GDPR and is debating clarifications for AI training in its Digital Omnibus package. The procurement agenda, which is most of the letter, has no EU equivalent at all.

Source

https://downloads.regulations.gov/OSTP-TECH-2025-0067-0158/attachment_1.pdf
Date on the page:
October 23, 2025
Source checked:
opened and confirmed on 2026-09-30