UK Government Rejects Lords' Bid to Bring AI Vendors Under Cyber Security Bill

Minister argues regulating AI providers would not prevent hostile misuse; peers warn of dangers from unchecked AI development

edit
By LineZotpaper
Published
Read Time2 min
The UK government has rejected proposals from the House of Lords to bring AI vendors within the scope of the Cyber Security and Resilience (Network and Information Systems) Bill, with Cybersecurity Minister Baroness Lloyd of Effra arguing that such regulation would not prevent hostile actors from misusing AI products.

Addressing the Grand Committee on Tuesday, Baroness Lloyd said: "Bringing providers of AI services, those companies which are at the cutting edge of frontier AI development and their products, into the scope… would not address the harms that can be posed by some AI products and services, or specifically, it would not prevent their misuse by hostile actors." The minister instead pointed to alternative government initiatives, including the AI Security Institute (AISI) which tests models before release, and the voluntary AI Cyber Security Code of Practice, which informed the first global AI cybersecurity standard, ETSI EN 304 223. "This demonstrates our global leadership and commitment to shaping international technical standards which go wider than some of the issues raised in this bill," she said.

Peers in the Lords offered numerous arguments for including AI in the bill. They cited reports of rogue agentic behavior involving Anthropic and OpenAI, and Bill Gates' concerns that commercial incentives are pushing AI development without adequate safeguards. Baroness Kidron, a Crossbench peer and online safety campaigner, questioned: "Have we not learned from countless experiences before in online safety, privacy, and in AI itself that allowing tech companies to set and mark their own homework endangers the public and our national security?" Lord Tarassenko, a veteran AI researcher, pointed to a recent open letter from OpenAI warning that AI-orchestrated cyberattacks may soon become too prevalent to handle.

Kidron and Lloyd clashed after the minister used a hypothetical healthcare organization to illustrate how regulated bodies must secure systems containing AI. Kidron asked if the NHS must protect itself but the AI attacking it would have no duties under the bill. Lloyd maintained the bill is technology-agnostic, imposing stricter cybersecurity on key organizations rather than individual technology providers. The minister rejected several other amendments, including one requiring AI vendors to demonstrate their products could not cross specified red lines, and a proposal to grant the Secretary of State last-resort powers to shutdown a datacenter or AI system during an emergency. Lloyd said the government could instead direct regulated entities, including datacenters.

§

Analysis

Why This Matters

  • The debate reflects a growing global tension between fostering AI innovation and ensuring robust cybersecurity safeguards, with the UK's choices likely to influence regulatory approaches elsewhere.
  • If AI vendors remain outside the bill's scope, critical infrastructure may face increased risk from AI-powered attacks that regulated entities cannot fully defend against alone.
  • The outcome will test whether voluntary codes of practice and pre-release testing can effectively address AI-specific cyber threats, or if binding regulation becomes inevitable.

Background

The Cyber Security and Resilience (Network and Information Systems) Bill updates the UK's NIS regulations, which impose cybersecurity requirements on operators of essential services and digital service providers. The bill is currently passing through Parliament. The government has resisted expanding its scope to cover AI vendors, preferring to rely on the AI Security Institute and a voluntary code of practice that led to the ETSI EN 304 223 international standard. Critics argue that voluntary measures have historically failed to prevent harms from large technology companies.

Key Perspectives

[UK Government / Minister Baroness Lloyd]: Regulating AI vendors in the bill would not prevent hostile misuse; alternative channels like AISI and voluntary standards are more effective. The bill should remain technology-agnostic and focus on regulated entities. [House of Lords Peers (Kidron, Tarassenko)]: Self-regulation by AI companies has failed in the past; the bill should impose duties on AI providers to ensure products are secure before deployment. Recent examples of rogue AI agent behavior and warnings about AI-driven cyberattacks strengthen the case for mandatory oversight. [Critics of the Government's Position]: Voluntary standards are insufficient and can be rewritten by companies at will. The government's rejection of red-line requirements and emergency shutdown powers leaves dangerous gaps in national security.

What to Watch

  • Whether the Lords reintroduce similar amendments in later stages of the bill's passage, potentially forcing a government compromise.
  • How the AI Security Institute's model testing evolves and whether it gains binding authority over time.
  • Uptake of the voluntary AI Cyber Security Code of Practice by frontier AI developers and any major incidents that could shift the political calculus.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.