In September 2026, the UK government declared the occupation of the West Bank unlawful and announced what foreign secretary Ed Miliband called a “step change” in its treatment of Israeli settlements. A new sanctions regime will stop UK companies assisting in settlement construction, and a trade ban will target settlements while leaving Green Line Israel untouched. Miliband says the government should have acted earlier, and that it took “a new prime minister to come in” to do so.
The measures are real, but they are deliberately narrow. The new powers reach only companies that “provide services such as construction, infrastructure, financing, or real estate for settlement expansion”. They do not touch technology. There is no software ban, no cloud ban, and no prohibition on supplying the checkpoints, population registries and permit systems that administer the occupation itself.
That asymmetry is part of this story. The UK bans the supply of enterprise software and cloud to anyone connected with Russia, yet it sanctions illegal settlements and not the wider mechanism of occupation. Meanwhile, the UK declares the occupation unlawful and sanctions illegal settlements – while its own public sector runs on the same hyperscalers the occupation depends on. A further question here is, to what extent is that a risk to the public sector?
The double standard
The contrast with Russia is stark and, some lawyers argue, indefensible. Britain’s Russia sanctions include a sector-wide prohibition on supplying software and technology – enterprise resource planning, business management and cloud-hosted services – to anyone connected with Russia. Schedule 3IA to the Russia Regulations makes it an offence to make such software available, directly or indirectly, for use in Russia. The aim is to deny the Russian economy and its military-industrial complex access to commercial technology.
No equivalent exists for Israel or the occupied Palestinian territories. The September 2026 package reaches construction, infrastructure, financing and real estate – not the databases, cloud regions and movement-control systems that technology companies supply to Israeli military and civil administration bodies across the West Bank. Despite Miliband’s new sanctions, a British firm can legally sell to the Israeli state the same enterprise software it is barred from selling to Russia.
Andrew Sanger, an associate professor of international law at the University of Cambridge and a barrister at Matrix Chambers, argues the distinction has no footing in law. “There is no convincing basis for treating Russia and Israel differently,” he says.
The relevant test, he explains, is not whether a state is under sanctions, but what international law requires of third states where serious breaches of peremptory norms are at issue – an obligation not to render aid or assistance in maintaining an unlawful situation. The International Court of Justice’s (ICJ) 2024 advisory opinion, he notes, directs states to “abstain from entering into economic or trade dealings with Israel” that may entrench its unlawful presence, and to take steps to prevent trade or investment that assists the occupation.
West Bank specifics
The concrete answer to what the hyperscalers supply is a set of interoperable systems that together form a digital architecture of population control. Four suppliers converge on the same permit regime that governs whether Palestinians can work – including in the settlements – cross a checkpoint, or leave the country.
The Al Munasseq app, developed by the Israeli military and running on Microsoft Azure, is the entry point. Palestinians must install it to hold a work or movement permit and a biometric smart card; it collects name, ID and phone number and seeks access to location, device ID, camera and files, with the data shared with Israeli security authorities. Google hosts the app on its Play store.
Meanwhile, Microsoft’s Rolling Stone system maintains the military’s registry of the Palestinian population and its movement through checkpoints in the West Bank and Gaza. Oracle runs Matash, the system that issues employer permits for Palestinian workers in Israel and in the settlements. IBM operates the national population registry – the Eitan/Aviv system, worth about NIS840m (about $233m) – used to enforce the permit regime, with a copy held in the Beit El settlement and deployed at the Allenby and Erez crossings.
Beyond the permit regime, the companies’ individual commitments stand out:
Microsoft supplies Copilot, CRM and Office to the Israeli Civil Administration and COGAT, the military’s civil-affairs arm in the West Bank, and gives the Ariel University settlement free Office 365 and Teams.
Google supplies cloud, AI and language model services to the Civil Administration in the West Bank, alongside the Play store hosting of Al Munasseq.
Amazon Web Services (AWS) sells products from the Achdut-Achva settlement factory and in November 2019 began offering free shipping to settlers while charging Palestinian residents – a policy it reversed in March 2020 after the Financial Times exposed it and the Palestinian Authority complained.
Oracle’s reach extends to the demolition mechanism. Its servers run the Civil Administration’s monitoring of “illegal construction” – the process through which Palestinian homes are demolished – while the Rotem-Reut border system, which runs on Oracle databases, operates at 25 crossings, including West Bank checkpoints and the Allenby Bridge.
All of this is documented in Who Profits’ Digitizing occupation report (June 2026), a study of eight technology companies – Amazon, Cisco, Dell, Google, IBM, Microsoft, Oracle and Palantir – and their supply of cloud, AI and surveillance infrastructure to Israeli military and security bodies. Who Profits reports that none of the eight companies responded to it before publication.
Nimbus as procurement case study
The flagship contract is Project Nimbus, the Israeli government’s multi-year, multicloud migration. AWS and Google won it in 2021. Google’s own announcement describes a “four-phase project” with a seven-year initial term that can stretch to 23 years; the initial investment is NIS 4bn (about $1.2bn), and the tender runs from 2021 to 2028 with a 132-month extension option. AWS separately announced about $7.2bn of planned investment in its Israeli cloud region. IBM’s Red Hat unit, which was not part of the Nimbus award, provides the OpenShift platform behind the military’s separate operational cloud, used by the IDF’s Mamram computing unit.
Nimbus is, at root, a data sovereignty play. The tender documents for Central Tender 01-2022 define an “Israeli region” – public cloud regions that AWS and Google build inside Israel itself, under Israeli jurisdiction – and distinguish it from the “overseas regions” the same providers run elsewhere (such as AWS’s eu-west-1 in Ireland; Google’s europe-west-4 in the Netherlands, etc).
What is quite remarkable about the Nimbus project is that its $1.2bn agreement uniquely overrides Google and Amazon’s standard terms of service and acceptable use policies, and grants the Israeli government unprecedented exemptions from typical tech platform rules.
Key elements of this arrangement include:
No service bans or restrictions: The contract strictly bars the tech giants from restricting, suspending, or cutting off cloud access for Israeli government agencies, security services, or military units.
Policy immunity: Providers cannot penalise or discontinue services due to internal policy updates or violations of standard terms (such as human rights safeguards), with severe breach-of-contract penalties enforced against the companies if they attempt to do so.
The “Winking Mechanism”: To bypass standard legal gag orders regarding foreign court subpoenas or data requests, the agreement reportedly utilises a workaround where companies must subtly notify the Israeli government using coded financial transaction amounts based on international dialling codes.
The migration is not merely administrative. AWS and Google each operate a local cloud region – Google’s since October 2022, AWS’s since August 2023 – and both sell AI and machine learning services to the defence establishment. Google won a NIS150m (about $43m) government advertising campaign on YouTube in 2025.
Microsoft as the divergence case
Microsoft is the one supplier that has drawn a public line, and it shows what a single company can do – and how little. In September 2025, after the Guardian revealed that Microsoft’s Azure cloud stored a mass surveillance programme in which Unit 8200 collected Palestinian phone calls at a scale its own staff summarised as “a million calls an hour” – as much as 8,000TB (terabytes) held in a Dutch datacentre – Microsoft terminated the unit’s access to some Azure and AI services. A Microsoft executive told Israel’s defence ministry that the company is “not in the business of facilitating the mass surveillance of civilians”.
But the line was partial. Microsoft stressed that its wider relationship with the Israeli military is unaffected, and that Unit 8200 retains access to other services. According to the Guardian, the unit planned to move the surveillance data to AWS; neither the Israel Defense Forces nor Amazon responded. The same report records that the surveillance material was used in the Gaza offensive to help prepare airstrikes – one of the points where the West Bank story and the far larger Gaza story converge, and a subject that deserves its own examination.
Google has its own active controversy. In August 2025, a former employee filed a complaint with the US Securities and Exchange Commission alleging that Google helped CloudEx, an Israeli military contractor, use its Gemini model to analyse drone surveillance footage in Gaza. Google denied any violation, describing a low-spend account and routine helpdesk support.
The UK dependence angle
The exposure to UK public money is where the story turns from a foreign policy critique into a procurement risk. In August 2026, Al Jazeera reported that at least 17 companies linked by the UN to illegal settlements hold 125 active UK public sector contracts worth more than £2.1bn. The headline figure, however, is dominated by one technology group: Motorola Solutions’ UK subsidiaries – led by Airwave Solutions, which holds a £1.56bn Home Office contract for the Emergency Services Network – account for £1.7bn of it.
Crucially, none of the three hyperscalers appears in the UN’s business database. The OHCHR (Office of the United Nations High Commissioner for Human Rights) database, updated in September 2026, lists 214 enterprises, but its mandate is deliberately narrow and focuses on companies involved in building, servicing or profiting from settlements. General-purpose cloud and data hosting for the wider Israeli state falls outside its criteria. That is not a clean bill of health; more of a definitional gap. The hyperscalers’ exposure rests on what they facilitate – the permit regime, the registries, the military cloud, rather than a UN flag.
The UK figures tell their own story. In Tussell data of the top UK public sector technology suppliers for 2024-25, the seven Who Profits technology firms that appear – IBM (£475m), Oracle (£381m), Amazon (£333m), Dell (£225m), Microsoft (£155m), Palantir (£48m) and Cisco (£44m) – hold about £1.66bn between them. Add Motorola’s £487m and the eight firms approach £2.15bn. Google does not appear in the top 200, so its UK public sector exposure must be measured separately. These are single-year, supplier-level figures; they almost certainly understate the total, because hyperscaler software also flows into government through resellers such as Bytes, Softcat and Computacenter, which together account for another £2.4bn.
The dependence runs deeper than contract value. Computer Weekly’s own data dives have found that the UK public sector is thoroughly entangled with US hyperscaler infrastructure, with the “big three” supplying cloud services to more than 90% of the UK public sector. That dependence is not an accident. It traces back to a UK cloud strategy critics say was hijacked by a hyperscaler duopoly, and it persists even though the Department for Business, Innovation, Science and Trade has still not settled on a definition of data sovereignty.
Here the legal risk sharpens. Sanger argues there are “very good arguments” that the UK is in breach of its third-state obligations by contracting with firms that provide the infrastructure for the occupation. The Procurement Act 2023, he notes, provides only a discretionary exclusion for professional misconduct, not an automatic bar – and it should be tightened. The gap is real: the government’s own Overseas Business Risk guidance warns British businesses away from the settlements, yet nothing in UK procurement law automatically prevents a public body from buying from the companies that digitise them.
In September 2026, the Scottish Parliament went further than Westminster. By 63 votes to 25, with 31 abstentions, it resolved that a company’s involvement in illegal Israeli settlements constitutes “grave professional misconduct” and should automatically disqualify it – together with its parents and subsidiaries – from Scottish public procurement and support. It adopts, in principle, the automatic disqualification that Westminster has resisted. Whether it bites is less clear. Amendments to the motion acknowledge that trade sanctions and export controls remain reserved to the UK government, and rather than a binding mechanism, they call on public bodies to update their due diligence processes and on Scottish Enterprise to report back. But Holyrood has voted to close the gap; Westminster has not.
The question to Whitehall
The case for action is now a matter of public record. A senior academic in the field says there is no convincing legal basis for the Russia/Israel asymmetry. The UN’s database, the ICJ’s advisory opinion and the UK’s own sanctions all point in one direction, while UK procurement law points in another.
The question for the Foreign, Commonwealth and Development Office, the Department for Business and Trade, and the Treasury’s sanctions office is the same one the story begs: if the UK bans enterprise software and cloud for Russia, why does it allow the same hyperscalers to run the occupation’s digital infrastructure – and its own? (See box below).

