Grand Committee

Tuesday 1st September 2026

(1 day, 17 hours ago)

Grand Committee
Read Full debate Read Hansard Text
Tuesday 1 September 2026
Committee (1st Day)
Northern Ireland, Scottish and Welsh legislative consent sought. Relevant documents: 3rd Report from the Constitution Committee, 7th Report from the Delegated Powers Committee.
15:45
Clause 1 agreed.
Clause 2: Overview of Act
Amendment 1
Moved by
1: Clause 2, page 2, line 13, leave out “on the Secretary of State”
Member's explanatory statement
This amendment is consequential on my new Clause (Functions under this Part).
Baroness Lloyd of Effra Portrait The Parliamentary Under-Secretary of State, Department for Business, Innovation, Science and Trade and Department for Digital, Culture, Media and Sport (Baroness Lloyd of Effra) (Lab)
- Hansard - - - Excerpts

My Lords, I will also speak to the other amendments in my name in this group. I thank noble Lords for their constructive engagement on this topic over the Summer Recess. I particularly thank the noble Viscount, Lord Camrose, and his colleagues for sending their questions in advance. I will seek to address those in my opening remarks.

This package of amendments introduces new powers that will enable the UK to address vendor-related cyber risks in our critical infrastructure. The principal new clause introduces a new direction power. It enables the Secretary of State to direct entities in scope of the power where they are using, or may potentially use, vendor-supplied goods, services or facilities in connection with their network and information systems that could create national security risks.

It is becoming increasingly clear that there are axes of cyber risks that the Government need to address. These risks arise from goods or services supplied by another company being harnessed as tools for sabotage, surveillance or espionage. But they also exist where goods or services constitute critical points of failure due to their defective design or vulnerabilities. Noble Lords would have had some sense of these risks from debates during this Bill—in particular, discussions about remote access in embedded products such as cellular modules and the scope for hostile interference and control.

GCHQ has also raised escalating concerns about supply-chain vulnerabilities in the wider geopolitical context. The director of GCHQ explicitly called out those risks in her annual lecture in May this year when discussing the challenges posed by a relationship with China and the threats posed by Russian cyber operations. That is why we have tabled Amendment 102 to tackle decisively these risks and protect our national security. Our intention is to limit the use of this power to operators of essential services in the first instance, although we will review the case for bringing other entities into scope in the future.

Supplementary amendments contain the mechanisms needed to operationalise the power. They enable the Secretary of State to set statutory timeframes for decision-making, to specify and update which entities are in scope of the vendor-related direction power and to introduce mandatory procurement screening should this ever be considered necessary to protect national security. They also introduce a power to bring more entities into scope of the existing direction power in Clause 43.

The powers to bring entities into scope of this framework are rightly restricted. To be brought into scope, the Secretary of State or Chancellor of the Duchy of Lancaster must be satisfied that the entity is essential to the economy or the day-to-day functioning of society in all or part of the UK. This is consistent with the Bill’s definition of essential activity in Clause 24. Either Minister can exercise the power. It has been drafted like this to accommodate machinery of government changes.

The decision to introduce the amendments has not been taken lightly. The Bill already includes important national security powers to direct regulated entities whose systems have been compromised, or which are at risk of being compromised, by hostile actors. This new power allows the Government to act before vendors become embedded in supply chains and before taking action becomes costly and disruptive. It will give operators greater confidence in their procurement planning and avoid the need for costly interventions down the line.

Crucially, we are not proposing to introduce these powers in isolation. They will be part of a broader framework which will also include procurement guidance for operators and a voluntary referral route into government where operators have identified potentially risky procurements. The voluntary self-referral route will enable the Government to assist operators with vendor-related concerns, provide them with guidance on how to proceed and, where necessary, inform decisions about the issuing of a direction.

We intend to consult on the implementation of the framework in due course. This will include the criteria for referral and how the mechanism will work in practice. In the event that this Government ever determined a mandatory referral scheme was necessary, we would intend to consult on the definition of a “qualifying transaction” before laying the necessary secondary legislation. However, I emphasise that it is not our current intention to set up a mandatory scheme.

Ultimately, we expect this wider framework will minimise the need for formal interventions using the new powers. However, it is crucial that the power is in place as a backstop to guarantee the Government’s ability to protect the UK’s national security. I beg to move.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, I assume that there are no Back-Bench contributions at this point, so I will speak on behalf of the Liberal Democrats to this very significant group of amendments tabled by the Minister as recently as 24 August. I thank her for her introduction today and for her brief meeting shortly after their tabling.

At the outset, from these Benches we express our strong concern about the timing and the sheer scale of the Government’s package of new amendments. To drop 65 amendments of this nature on the eve of Committee, which will completely reshape the architecture of this Bill, after its passage through the Commons, is a major challenge to effective parliamentary scrutiny. The Minister’s letter, also dated 24 August, came alongside these 65 new amendments, so we have had very little time to consider them. As far as I can see, a full Ministerial Statement did not accompany them; we had to rely on the coverage of Computer Weekly to understand the Government’s motives.

The Government have quietly established a major parallel high-risk vendor regime. Under Amendments 102 and 103, the Secretary of State—and now, crucially, under Amendment 101, the Chancellor of the Duchy of Lancaster—are granted unilateral powers to issue vendor-related directions. They can legally order an organisation to prohibit, restrict, remove, disable or modify any software, hardware or digital facility supplied by a designated high-risk vendor. Furthermore, under Amendment 105 they are given the power to establish a mandatory referral scheme, legally forcing companies to submit technology procurement contracts to the Cabinet Office for security clearance before signing.

Let us look closely at the operational mechanism in Amendment 103, which ISC2 has rightly highlighted. The proposed new clause mandates that a company appoints a “skilled person” to oversee compliance and, under subsection (5) of the proposed new clause, permits the Secretary of State to rely on a list of persons published by GCHQ. I ask the Minister: what is this list? Is it public or classified? What objective criteria will govern inclusion? How will conflicts of interest be avoided, and how will independent professional competence be assured? To create statutory compliance roles backed by secret lists is entirely unacceptable.

Under Amendment 108, the Secretary of State can make regulations bringing any specific company into the scope of the Clause 43 directions without bringing them into the NIS regulations as a whole. Under Amendment 127, the Government will insert an emergency “made affirmative” procedure allowing regulations and vendor bans to take effect immediately without prior parliamentary debate. Furthermore, under Amendment 148 the Secretary of State can prohibit a company disclosing that they have received a direction or are in consultation, backed by civil penalties of up to £10 million or £50,000 per day.

There is also a second critical implication—the backdoor regulation of advanced artificial intelligence systems. At Second Reading, the Minister assured the House that advanced AI systems and LLMs were out of scope. These amendments appear to reverse that position. Under Amendment 108, any entity providing essential goods or services can be specified. As our critical infrastructure increasingly integrates agentic AI models, such as GPT-5 or Anthropic’s Mythos, these developers become points of supply chain risk concentration. It seems that, under Amendment 102, the Government can designate AI developers as high-risk vendors and mandate pre-procurement vetting. Is that the case and, if so, why not say so?

The Government will no doubt resist the transparent, legally bounded emergency shutdown power proposed by Amendment 84, with its High Court backstops and seven-day parliamentary reporting, yet here the Government demand sweeping, secretive executive powers to ban software, veto procurement and gag businesses with zero judicial checks. These Benches cannot give these 65 government amendments a free pass. I remind the Minister that, in Grand Committee, unanimity is required for amendments to carry. We insist that the Government come back on Report with strict guardrails and clear limits on executive market intervention without parliamentary consent before these new powers can be exercised.

Quite apart from that, both the Constitution Committee and the Delegated Powers and Regulatory Reform Committee had something to say about the existing powers in the Bill, but neither committee has had a chance to look at these amendments. I am sure that they will have comments to make in due course.

Lord Holmes of Richmond Portrait Lord Holmes of Richmond (Con)
- Hansard - - - Excerpts

My Lords, I apologise for not speaking before the Liberal Front Bench, but the great news for everybody in Grand Committee is that I am not the Conservative Front Bench. That is good to know. I declare my relevant technology interests as adviser to the Crown Estate and to Simmons & Simmons LLP.

I have just a few questions for the Minister, most of which revolve around what was known when the Bill was in the Commons and what has become known since it was in your Lordships’ House at Second Reading that have required this raft of amendments to come forward over August. The Minister, in her opening, described defective by design; this is an interesting principle, which could have broad applicability, but, as the noble Lord, Lord Clement-Jones, said, we were clearly told at Second Reading that AI and all therein were not in the scope of this Bill. Does this raft of government amendments change that fundamentally? Is it a nod or hint to it? Is this a large, fundamental change in the Government’s policy approach to large language models and enhanced AI, as covered by this raft of proposed amendments?

Is the Minister’s view that changes to the machinery of government will not be complete and clear by the time the Bill completes its passage through your Lordships’ House, hence the need for the reference to the Secretary of State or the Chancellor of the Duchy of Lancaster? Is there a broader issue on that point, worth the Committee considering, on how the shuffling of departmental deckchairs ahead of the Summer Recess is going down? How long will this take to be settled? Could the Minister update the Grand Committee on what is happening with clarity on where every last element of science, innovation and technology policy now rests? Do they all have a clear, identified home and ministerial responsibility?

In later groups we will come on to talk about AI and the deafening silence on AI—until this raft of amendments. Perhaps the Minister would like to comment, in responding, on whether the Government have had a significant change of direction on these technologies, as illustrated by these amendments, or whether they have not. Thus, what will the Government’s response be when these issues are discussed in later groups, compared to the response that they gave at Second Reading?

16:00
Lord Birt Portrait Lord Birt (CB)
- Hansard - - - Excerpts

My Lords, I think that this is profoundly unsatisfactory. It is not good parliamentary procedure to table so many amendments radically different from anything that we have seen before, which I, for one, have seen only at the last minute, so to speak—I have read them, but I will not claim to have studied them. I do not altogether know what I think, but I readily accept that the noble Lord, Lord Clement-Jones, has had a chance to scrutinise them in a lot more detail than I have.

I do not have anything substantial to say, but I would like to ask the Minister a question. Manifestly, there is a national security risk, which we would all recognise, and we all recognise that something needs to be done about it. But, if this is a national security issue, perhaps the Minister could explain to us why it cannot be dealt with under existing national security procedures. I have had time to go on to the GCHQ website, where one finds an impressive and considered approach to handling different security issues of this kind called the “equities process”—I did not know about it until the weekend, but it is impressive to read. I just do not understand why you would lodge such a set of issues with DCMS rather than the Cabinet Office. DCMS seems to me completely the wrong home for identifying, weighing and working out what to do about things that have such profound ramifications. Perhaps the Minister could explain to us why existing procedures, which are well tested and, by and large, involve GCHQ with a lot of consent in other areas of government activity, cannot be applied here with the same sensitivity that GCHQ has shown on other occasions. We cannot have a meaningful discussion about this today, but I think that the Minister has to think about how we can have a meaningful discussion before we reach the next stage of the Bill.

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - - - Excerpts

My Lords, if I may, I will reiterate points that the noble Lord, Lord Birt, has made. A number of us are struggling to keep up. Much of what the noble Lord, Lord Clement-Jones, said made a lot of sense, but I certainly do not feel sufficiently sighted on the amendments and I would like to request from the Minister a proper briefing as soon as we possibly can. We have multiple days in Committee and I feel that we will keep going round the issue of how AI is being addressed in the Bill. At the core, we are all trying to stand on both sides of the fence: we are very nervous of these powers, which appear to have been snuck in without much scrutiny, but, on the other hand, at Second Reading many of us were clear that we want to see AI captured in the Bill. I am very much in two minds and would welcome a proper briefing from the experts.

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

My Lords, I thank the noble Baroness the Minister for introducing this debate and for her helpful advance briefings on these amendments. I also welcome all noble Lords back for what, I am sure, will be a productive Committee stage. It is worth noting at the start of Committee that, sadly, our cyber adversaries did not take the summer off. In July, a small power generator was attacked and, in August, an attack on Manchester Airports Group compromised the data of 8.7 million of its customers.

That said, I begin by saying that we on these Benches support the intention behind the Government’s amendments. I absolutely recognise the concerns expressed by all the other speakers thus far; procedurally, this is a very unusual way to go about it, but we support the intention. We have been calling for an increase in the scope of the Bill and for cyber security measures to be undertaken by businesses and individuals, rather than the Government, where possible. We feel that these new amendments go some way to achieving that.

However, while we support the intentions, the context around them remains challenging. The difficulty that we face when trying to scrutinise and improve this Bill—and I am sure that we will return to this—is that it essentially exists, at least for now, in a vacuum. The Government’s goals are the right ones and their intentions seem to be clear, but we lack the overall holistic framework that is so important for systemic, strategic approaches to cyber security. Perhaps when the Minister stands up she can provide an update on the publication date of the national cyber action plan because, as I said at Second Reading, a cyber Bill can stand or fall only in the context of an overall cyber defence strategy, and we need to see it.

Most evident is that this currently seems to be a Bill without a department. The amendments delegating and separating powers between the Secretary of State and the Chancellor of the Duchy of Lancaster reflect this. I am really concerned—I would appreciate some reassurance from the Minister on this—that the decision to scrap DSIT, the Department for Science, Innovation and Technology, has left this Bill in limbo. A minimum of 30 teams are being split across at least three departments, and this seriously important Bill, which we are all counting on to protect us from enemies known and unknown, is adrift between departments. At the very least, the Government should set out as soon as possible who will have lead responsibility when this Bill is passed.

I thank the Minister for her clarifying remarks on the referral schemes that her amendments introduce. As I have noted, we support the attempt to expand the scope of this Bill and give businesses the ability to be self-sufficient. That support extends to the establishment of a voluntary referral scheme. However, this new voluntary scheme needs to have a clear and accessible framework and a timeline for implementation. If it is to act as an extra layer of security outside the Government’s immediate remit, vendors must know what they are expected to report and the mechanisms for doing so. There is little use setting it up if these are not made explicit at the earliest opportunity. The consultation is welcome, but some idea as to the form the Government intend this scheme to take would be helpful, alongside an indication on timing. I hope the Minister can give more clarity in her closing remarks. If not, I hope she will be able to write to me and all Members of this Committee.

I was originally going to make the point that the mandatory referral of a vendor outside current NIS regulations will necessarily be ad hoc and that, as such, defining “qualifying transactions” would not be proper. Instead, Amendment 153 was an attempt to provide clarity for decision-making without inhibiting the Government’s ability to act. However, given that the Minister said in opening that the Government have no intention of setting up a mandatory referral scheme, we must question why they feel the need to give themselves the powers to do so. Powers should not be granted and come into existence if they are never to be used. At the very least, given that the Minister has now said that the Government would consult on the definition of a qualifying transaction before any scheme is established, the amendment should ensure as much. The Government will now have the opportunity to bring these amendments back on Report. The mandatory referral scheme should be redrafted to reflect the Minister’s statement and be conditional on the defining of qualifying transactions. I hope the Minister will agree to this.

Finally, let me make a general point about the definitions used in these amendments and throughout the Bill. The proposed criterion of being “essential to the economy” is unworkably vague. It is not an adequate representation of the different types and scales of risks. I suggest, for example, the Cyber Monitoring Centre’s five-level severity scale as a model more reflective of the grades of threats facing the United Kingdom. I am not arguing that it is necessarily the right model, but it is at least tested and quantifiable. I look forward to the Minister’s response.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank noble Lords for their comments, views and questions, and I will endeavour to respond to them.

In respect of why the power is being granted to the Secretary of State or the Chancellor of the Duchy of Lancaster, it is to anticipate any unforeseen machinery of government changes. It is nothing more than that—to avoid future changes that would be needed when government departments change. On the skilled persons list, I am advised that that is currently available on the NCSC website, so it is accessible to all.

I come back to the heart of the questions: why is this power needed? It is needed because, even though we are taking powers on critical suppliers, it can be the case that vendors have the capability and intent to cause harm, particularly where they have a link to a third country. That is the element I would highlight today. It is through such vendors that a third country can gain access to or control of critical systems, enabling disruption to UK national infrastructure, surveillance through access to data at scale or espionage through access to sensitive information. The risk landscape is evolving quickly, which is why we are taking action now. On the questions posed by the noble Viscount, Lord Camrose, this is very much in the context of all the other things we are doing—all the other powers in the Bill, the scope of the Bill and the Government’s cyber action plan. This is an additional power focused in particular on being able to act earlier in a preventive manner.

On the definition of “qualifying transactions”, the amendment contains a power to create a statutory referral system. This system would need to state which procurements or transactions were in its scope, but, as the noble Viscount mentioned, we do not anticipate needing to do that now. The process of the Bill is such that we will enact both the mechanisms in the Bill and the voluntary referral mechanism. We will then be able, in the period of assessing the effectiveness of the Bill, to look at the effectiveness of the voluntary referral route. Should we need to introduce a mandatory route—obviously, we have done this in different areas of national security—we will be able to do so.

On scrutiny by Parliament, I appreciate that the fact that we tabled these amendments over the summer has meant that not everybody has been able to familiarise themselves with them and we have not been able to have as many in-depth discussions as we would normally when Parliament is sitting. I would be extremely happy to meet noble Lords with officials so that, after Committee, we can go through all the questions and points of detail that have been raised in this session on how these powers will be enacted, parliamentary scrutiny, the consultation process and all the elements that we have set out in our amendments.

A few noble Lords focused on AI. The power could be extended to high-risk AI models that are procured by operators of essential services. The test for using the vendor power direction does not specify or distinguish particular types of goods or services, in keeping with the technology-agnostic approach of the Bill. If an operator of an essential service were using a vendor-supplied AI model in connection with its network and information services, and this would give rise to a national security risk, it could be in scope of the power. That is very much in keeping with what I believe I said at Second Reading about other areas of connection with network and information services in the rest of the Bill and where that may apply to AI.

With that, I beg leave to withdraw—

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

Before the Minister sits down, I note that there are a lot of “just in case” elements of the Bill; to me, it feels that there are rather too many. For example, I refer the Minister back to the Chancellor of the Duchy of Lancaster v the Secretary of State. Any department is, at any time, subject to machinery of government changes, but never in any Bill that I have seen—admittedly, I have not seen that many—have both been specified, so why is it so in this Bill? Why do this now? Why not simply make a choice and amend later if necessary?

16:15
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I am very happy to look at the points that noble Lords have raised in the course of this discussion. I believe that elements such as the consultation and the process of scrutiny are well thought out. I believe that in terms of the elements of subsequent parliamentary scrutiny—the reports that will be made both on the application or when the direction is affected—this is very much in keeping with other national security legislation which has been agreed by this and previous Governments. Many of these elements are very akin to processes that are operational in other areas of government. However, I am very happy to look at, and indeed will look at, all the points that noble Lords have raised. We will discuss them in subsequent meetings, and we will revert to them on Report.

Lord Birt Portrait Lord Birt (CB)
- Hansard - - - Excerpts

Can the Minister explain why GCHQ is not the right home to exercise these powers? I am sure we will all agree that national security is a significant issue, but it is being lodged in departments that have no prior experience of it. What is wrong with existing GCHQ procedures, which are respected and trusted?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I will need to write to the noble Lord on that specific question of how GCHQ’s powers are executed in respect of operational decisions such as this. I am aware that in other areas they are within Secretary of State responsibility, whether they are exercised by a Secretary of State, advised by GCHQ or whether, as the noble Lord suggests, they are actually undertaken by GCHQ.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, I thank the Minister for her gracious, intended withdrawal of Amendment 1, and I am sure we will have a much better debate on Report as a result, particularly once we have had a chance to read her remarks on both interventions today. However, I hope she will agree with me, especially in terms of what she said about being technology agnostic through the Bill, that we will have a much better debate as we come to talk about specific AI issues as a result of not having already incorporated those in the Bill. So, all the way around we will have a much better debate about the proper shape of the Bill as a result of those amendments being withdrawn.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

With that, I believe now is the time where I beg to leave to withdraw Amendment 1.

Amendment 1 withdrawn.
Amendment 2 not moved.
Clause 2 agreed.
Clause 3 agreed.
Clause 4: Data centres to be regulated as essential services
Amendment 3
Moved by
3: Clause 4, page 3, line 18, at end insert—
“(3A) A data centre also meets the threshold requirement in this paragraph, regardless of its rated IT load, if the Office of Communications considers that an incident affecting the data centre would be likely to have a significant impact on the economy or the day-to-day functioning of society in the United Kingdom or any part of it, having regard in particular to the data centre’s customer base and level of interconnection with essential services.”Member’s explanatory statement
The amendment seeks to add a risk-based designation criterion alongside the existing megawatt thresholds for operators of essential services.
Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - - - Excerpts

My Lords, I am very sorry that I missed the early part of that debate because I feel it might impact on some of the things I say. However, when I read the government amendments, I could not see anything in them that made the amendments unnecessary, so I will read carefully all aspects of the first group but I intend to progress with the amendments that I have tabled. I will speak to Amendments 3, 8 and 13 in my name and in the names of the noble Baronesses, Lady Harding, Lady Berger and Lady Morgan. Together, they would expand the scope of services in the Bill so that so-called “small but risky” services were included.

Amendment 3 stipulates that smaller data centres could be included if Ofcom considers that an incident affecting the data centre would have a significant impact on the economy or on the day-to-day functioning of society in the UK, taking into account the data centre’s customer base and its role supporting other essential services. Currently, data centres that are for an enterprise purpose only are covered in the Bill only if the rated IT load is 10 megawatts or greater. This is a mid-size data centre. However, there are commercial data centres that can be much smaller than this and are threatening. Perhaps most notable is a recent example from Denmark where the small cloud hosting providers, CloudNordic and AzeroCloud, suffered a ransomware attack that resulted in the paralysing of all company systems and the servers being shut down. Their hundreds of customers lost all their data, and it was unrecoverable. “Customers” is a bland word, but imagine that you are a hospital treating patients, a university conducting years of scientific research or a small business with its entire operation at stake: the loss of your data risks lost livelihoods, and possibly even lives.

Meanwhile, many experts are calling for an expansion of smaller data centres. They are less taxing on the natural and local environment, more embedded in local communities and are in contrast to mid and large centres, whose environmental costs hit local communities, use up water, increase the strain on the grid, are possibly noisy and ugly and favour the hyperscale business models of big tech. If smaller data centres are an attractive alternative to unpopular larger ones, it is even more essential that they are in scope of these regulations.

Amendment 8 stipulates that a relevant digital service provider would be included if the ICO or AISI determines that the provision of a service poses a risk to public safety, national security or the security of network and information systems. Amendment 3 would do something similar for relevant managed service providers, with the ICO establishing whether a managed service provider poses a risk. Currently, services are excluded if they have fewer than 50 employees and a turnover equivalent to below £8.5 million—it is actually given in euros. I anticipate that the reasoning is not wanting to impose unnecessary burdens on small and micro-sized businesses with fewer employees and resources. I recognise that that is as a concern, but it is equally important to understand that small businesses of all kinds, including those that host critical services and infrastructure in the UK, are regularly victims of cyber attacks. The Government’s own Cyber Security Breaches Survey for 2025-26 records that 42% of micro-sized business and 46% of small businesses in the UK have been the target of cyber attacks. It is simply not the case that small means that risks are contained. The Government’s own figures show that, of the more than 100,000 UK tech companies, 95% have fewer than 50 employees.

These amendments would replicate the rationale of amendments to the then Online Safety Bill from the noble Baroness, Lady Morgan, on Report. I know that she would have liked to be here to speak to them, but she is unable to be here today. Her amendments stipulated that services under the Online Safety Bill should be categorised by risk or size. I will not rehearse what noble Lords have heard many times, but the lesson of that Bill is that the Government of the day got it wrong, as did the regulator. In the connected world, a small component of a global system can cause havoc.

When this Bill first entered the other place, I went to a briefing by Politico where its four experts spoke repeatedly about how narrow the Bill was and how focused it was on providing for a small subset of issues relating to cyber security and safety with a vision of hyperscale vendors. They were a combination of exasperated and incredulous that, even as we saw the increasing cost to the economy, the damage to businesses caught up in it and the devastation to individuals, as well as what all agreed was a national security threat, the Government had not sought to offer a vision for how all these might be protected. When it came to questions, the first was to ask why the experts thought the Government had been so unambitious. The answer was unedifying: to prevent the Lords hijacking the Bill.

I hope that the new Administration who start today have moved on and that we will have a more collegiate approach. I have read all the amendments currently laid, including the ones in this group, and in almost all cases they seek to do what is the stated intention of the Bill: to make the country more resilient. In the world of cyber security, size is not a proxy for risk; it is much more complex than that. The amendments in my name and those of others seek to ensure that we learn lessons from the Online Safety Act. I beg to move.

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - - - Excerpts

My Lords, I support Amendments 3, 8 and 13 in the name of the noble Baroness, Lady Kidron, to which I have added my name. I will not repeat too much all her comments on our learning from the Online Safety Act that small does not mean low risk. However, it should not be a surprise that those of us who championed that amendment to the then Online Safety Bill have again put our names to it. We have learned the hard way that, in online safety, risk can come from the smallest providers.

I have learned it personally. I retired from TalkTalk 10 years ago and I remember, what must have been 11 years ago—I promise this is not a cyber attack story—a mapping exercise across all the telcos, mobile and fixed, looking at our even then incredibly complex data centre networks across Europe. I am sure this has all changed and is much more complex, but I remember discovering, as a result of that exercise, that all of us were routing traffic through the same small data centre in central Europe and none of us was aware that we were doing so. These networks are expanding so fast and data centres and managed service providers are growing so fast that it is impossible for people to retain perfect knowledge 100% of the time, so a small provider really can be a node that brings down the whole network. It is not just in child safety that we have learned that small can mean very risky; it is also the case in the world of physical digital infrastructure, which we have known for some time in telecoms. That is why these amendments are so important.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, these amendments confront us immediately with some of the Bill’s most fundamental potential structural weaknesses—the danger of a static, arbitrary and pre-digital scope. The Government appear to have conceded this point already by tabling those infamous 65 high-risk vendor amendments in the previous group. Let us look first at Amendment 3 in the name of the noble Baroness, Lady Kidron, which I would have signed if there had been room.

As drafted, the Bill brings data centres into scope, relying entirely on rigid physical megawatt thresholds—specifically a rated IT load of 1 megawatt, or 10 megawatts for enterprise facilities. In the modern cloud ecosystem, physical power load is a crude and unreliable proxy for risk. A highly dense, interconnected facility drawing under 1 megawatt can host the critical patient records of multiple NHS trusts, emergency dispatch telemetry or core local government routing directories. If that facility is compromised, the societal and economic devastation will be catastrophic, regardless of how much electricity it pulls from the grid—the noble Baroness drew the parallels with NHS data centres.

Amendment 3 would provide the essential statutory fix. It would empower Ofcom to apply a risk-based designation that looks beyond physical power to evaluate the customer base, data sensitivity and critical interconnectivity. I listened with considerable interest and sympathy to what the noble Baronesses, Lady Kidron and Lady Harding, had to say about parallels with the Online Safety Act, which is engraved on our hearts.

16:30
This is reinforced by Amendment 8, also in the name of the noble Baroness, which tackles the arbitrary SME exemption for digital service providers. A micro-entity or 10-person software house might develop and maintain a proprietary algorithmic routing tool or specialised API that underpins an entire national utility network. Under the Bill’s blunt size thresholds, that entity sits completely outside the statutory duties. Amendment 8 would ensure that, where a small provider poses a systemic risk to public safety, national security or essential infrastructure, regulators can bring it into scope.
This scope gap is made even more glaring when we look at the omission, broadly, of local government from this Bill. The newly published “Analogue 72” Green Paper from the Cyber Centre of Excellence highlights that across four annual cycles of external passive scans, including their latest July 2026 data, UK local authorities show rising external vulnerabilities. Councils hold the electoral registers, child safeguarding files and social care records of millions of citizens, yet they remain entirely excluded from direct statutory duties under this Bill. The Government expect resilience to be delivered from the bottom up but plan entirely from the top down, leaving local government without statutory baseline funding or standards.
Finally, Amendment 14 in my name would provide a vital refinement to the definition of “managed services” in Clause 9. As currently drafted, Clause 9 defines a managed service so broadly that it in effect acts as a legal dragnet, capturing any service provided under contract for ongoing IT management, support, maintenance or other activities. This threatens to pull thousands of small, non-critical IT consultancies, training providers, software licensing agents and basic help desks into heavy NIS registration and turnover-based penalties. My Amendment 14 would establish a clear statutory boundary: if an IT provider does not possess ongoing privileged administrative access to configure, alter or control a customer’s live network, it is excluded from the managed service provider regime. This would protect small businesses and tech companies and include only those that present genuine systemic threats. I urge the Government to accept this balanced package of risk-based, future-proofed definitions.
Lord Markham Portrait Lord Markham (Con)
- Hansard - - - Excerpts

I add my thanks to the noble Baroness, Lady Kidron, and other noble Lords for trying to make sense of what we all agree is a very difficult area. We are trying to come to a definition of high-risk areas. As we have heard in the examples today, you cannot limit it to size or certain criteria, but we all recognise that you need some sort of risk-based approach for who we really need to be watching out for, for want of a better phrase.

In some ways, I come back to the suggestion from my noble friend Lord Camrose. In its severity scale, the Cyber Monitoring Centre has tried to set up such a mechanism. It looks at having a separate grid system which considers, on the one hand, the financial, pound-note impact and, on the other hand, the impact on members of the population. It is a really difficult exercise to define exactly what should and should not be in it, but in using a scale such as this and asking companies or entities to assess themselves, if they come up with a “0” or “1”, then it is less of a concern and, if they come up with a “3” or “4”, it is more of a concern. I accept that some of them will game it and might not treat it honestly, but a lot of them might not.

To go to my noble friend’s example of that one small data centre, probably only the centre itself knew at that time that it was pivotal to so many other people. The centre having to make an assessment on where it comes on this severity scale, involving at least the executive team, and having a non-executive board asking, “Are you sure you’re only a 1 or 2? Surely, from what you were telling me the other day about everything we look after, it means we should be 3 or 4” is important because we start to get a criterion that we can look at in all this. Trying to define it by ruling in different entities according to size and certain criteria will be well-nigh impossible. So I welcome the Minister’s thoughts on whether we can take a system that seems to be working, to a degree, today and think about it between now and Report stage in terms of whether that is a relevant criterion we could use.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank the noble Baroness, Lady Kidron, for her introduction and my noble friend Lady Harding for setting out the motivation for ensuring that we have the right balance of risk and regulation here. The amendments from the noble Baroness, Lady Kidron, seek to allow for the designation of systemically important data centres, RDSPs and RMSPs which do not already meet the threshold. The Government have considered this issue in the development of the regime and have taken an approach which reflects the markets of the various digital services in scope of the regime.

In respect of data centres, the Government agree that a data centre’s significance is not determined solely by size and recognise that smaller facilities may play an important role in supporting the economy and wider society. For that reason, the Bill already provides a route for such operators to be brought into scope outside the standard threshold requirements. The competent authority, Ofcom, has powers to gather information from operators and assess whether designation is appropriate in individual cases.

However, with respect to the RDSP and RMSP measures, the existing small and micro-enterprise exclusions have been designed to be proportionate and avoid imposing undue burden on entities with limited resources and market coverage, while focusing on providers whose disruption would have significant societal impact or economic risk to the UK. Although many small and micro-enterprises operate in the digital and managed services market, large MSPs hold a disproportionate share of market value. The largest MSPs account for 86% of revenue in the UK, despite representing just 4% of all MSPs. It is the disruption of these services that is most likely to cause significant harm to the UK.

The Bill also has measures in place to bring small or micro digital or managed service providers into the scope of the Bill if they are considered to provide a critical service to a regulated entity. If these entities meet the designation criteria, they can be designated as a critical supplier and be subject to mandatory cyber security and resilience requirements. I assure the noble Baroness that I recognise the discrepancy between these two regimes and her concerns, and I am content to explore this, and the points made by the noble Lord, Lord Markham, further, and to provide a more detailed response on Report.

On the issue raised by the noble Lord, Lord Clement-Jones, for his amendment which would amend the relevant managed services definition by excluding specific services, I take seriously the importance of providing clear definitions in the Bill. That is why the definition in the Bill is designed to capture services posing a risk to the UK economy and society, both today and beyond. I reassure the noble Lord that the relevant managed services that would be excluded by this amendment are already likely to be excluded by virtue of them not meeting the definition in the Bill. However, we cannot and should not list every service not in scope or we risk providing a definition that quickly becomes outdated and fails to accommodate new trends in both technology and services—a point frequently made by noble Lords in respect of the development of technology and online services. The Bill requires a delicate balance to ensure that the definition includes the right level of detail. The regulator, the Information Commission, will provide guidance on the application of the regulations prior to commencement of the RMSP provisions, including elements of the RMSP definitions.

On the point raised by the noble Lord, Lord Clement-Jones, on privileged access, MSPs pose risks because they provide ongoing management of customers’ IT services and often have deep and broad access to the networks, infrastructure and data those customers rely on, so the Bill focuses on any connection or access to network and information systems relied on by the customer rather than only access whether privileged or administrative. That is because requiring privileged access would narrow the definition and include some firms we intend to regulate as providers composed of cyber risks through non-privileged access without holding elevated administrative rights. For that reason, I caution against adding these exclusions to the definition of a managed service.

Finally, Amendments 4 and 5 are tabled in my name. They are targeted and technical amendments that improve the clarity and consistency of the Bill by strengthening the definition of load control in Clause 6. They clarify that the relevant activity must be carried out for system balancing purposes. System balancing purposes are defined as purposes which contribute to the,

“balancing, flexibility, security or stability of the electricity system”.

The policy intention has not changed. This amendment simply provides greater clarity about the activities the regime is intended to capture. It will reduce the risk of misinterpretation, provide greater certainty for industry and regulators and support effective regulatory oversight. This will ensure that the regime captures the activities intended to fall within scope and reduces the risk of inadvertently capturing activities that are not relevant to the operation and resilience of the electricity system.

Regarding the questions about the further scope of the Bill in respect of local government and the Government’s cyber action plan, I believe we will return to that in later groups.

Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - - - Excerpts

I am very grateful to the Minister for suggesting that there will be some consideration of the gap, as she put it, and I look forward to that. I want to raise one thing, which is that I was very struck by her reference to a small number of companies having 86% of the market. In a sector that is dominated by the concentration of power in very small numbers of companies owning many pieces of the stack, is she not worried that making those companies protected and safe and the smaller ones not may further serve to increase the concentration of power and market concentration? Is that not a problem for the future?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

The purpose of the Cyber Security and Resilience (Network and information Systems) Bill is to further enhance the scope and powers we have to protect essential services connected through network and information services. The market as it exists today is as I described. What is within the scope is not the totality of our approach to supporting the further cyber resilience of the UK economy. That is why, for example, we have CRCs locally to support SMEs so that whatever size they are, they can get assistance on the best cyber protection they can take. It is why we have Cyber Essentials and why the NCSC provides advice—all that the economy needs to take appropriate action to be secure. That is one aspect. The second aspect is that small and micro digital managed service providers are in scope of the Bill if they are considered to provide a critical service to a regulated entity, so even very small entities could possibly be in scope if they are so designated.

The last point I shall make—and I am sure we will come on to this further when we come to talk about AI—is that the Government are doing a huge amount in regulation and funding through public finance institutions to support the development of UK technology companies and UK innovators and to ensure that they have the right procurement contracts with the public sector so that they can grow and so that the entirety of our companies can benefit from the best global managed service providers and the best UK managed service providers.

Amendment 3 withdrawn.
Clause 4 agreed.
Clause 5 agreed.
16:45
Clause 6: Designation of large load controllers as operators of an essential service
Amendments 4 and 5
Moved by
4: Clause 6, page 4, line 31, after “controller” insert “—
(a) which carries on activities for system-balancing purposes (whether or not it also carries on other activities), and”Member’s explanatory statement
This amendment would ensure that the threshold requirement relating to the essential service of load control, inserted by Clause 6 of the Bill, applies only to organisations which carry out activities for system-balancing purposes.
5: Clause 6, page 5, line 5, at end insert—
“(za) an activity is carried on for “system-balancing purposes” if it is carried on with a view to contributing to the balancing, flexibility, security or stability of the electricity system as a whole or a significant part of it;”Member’s explanatory statement
This amendment would set out when an activity is carried on for “system-balancing purposes” for the purposes of my other amendment to Clause 6.
Amendments 4 and 5 agreed.
Clause 6, as amended, agreed.
Clause 7: Digital services
Amendment 6
Moved by
6: Clause 7, page 6, line 31, after “engine” insert “, an AI product or service”
Member’s explanatory statement
This amendment probes whether the definition of “relevant digital service” being inserted into the NIS Regulations by this bill includes generative-AI models, including but not limited to AI agents and large language models.
Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - - - Excerpts

My Lords, in moving this amendment, I shall speak also to Amendment 75 in my name; I thank those noble Lords who have added their names in support. I was glad to add my name to Amendments 12, 85 and 86 in the name of the noble Lord, Lord Tarassenko, and Amendment 84 in the name of the noble Lord, Lord Clement-Jones.

At the heart of these amendments is the place of artificial intelligence in the Bill. This concern was powerfully raised by noble Lords at Second Reading and repeatedly raised by colleagues from all sides in the other place—as well as, I rather suspect, earlier in this Session. Amendment 6 is a probing amendment. It seeks to understand whether AI products and services are categorised as relevant digital services and, therefore, whether providers of AI products and services will be subject to the same duties in the Bill as other providers of relevant digital services, such as online marketplaces and search engines.

The reason I raise this and wish to have clarification is that, in the NIS regulations, the definition of an online search engine is

“a digital service that allows users to perform searches of, in principle, all websites or websites in a particular language on the basis of a query on any subject in the form of a keyword, phrase or other input, and returns links in which information related to the requested content can be found”.

This sounds a lot like a definition that could cover many of the LLMs and AI agents, so I ask the Minister whether AI services are already covered under the categorisation of online search engines or absolutely not. I would also like her to confirm whether, if an AI service did not offer links or was restricted to a particular subject matter but had all these other features, it would automatically fall out of the regime—that is, whether some are covered and some are not.

At Second Reading in the other place, the Minister said—the Minister here just gave this answer, I believe—that the Bill enables the Secretary of State to require an organisation using AI

“to cease using and isolate an AI model”—[Official Report, Commons, 16/6/26; col. 779.]

but suggested that those powers are “a backstop” and do not focus on the safety of AI products systematically. I find myself confused because, on the one hand, it seems that the definition could include them but, on the other, it seems that there may be reasons why some might be out of scope. It appears that AI is not properly considered proactively but, if there is a disaster, the Secretary of State can do something. When the Minister speaks, I would be grateful if she could answer those two questions directly. This is a probing amendment, as I say, and it would be helpful, in the course of considering the Bill, to understand that categorically.

Amendment 75 would establish a series of red lines for AI products and services classified as relevant digital services. These red lines have excellent parentage; they reflect the work of Professor Stuart Russell and are signed up to by some of the most eminent AI founders and professionals around the globe. They also reflect the global call for AI red lines launched during the United Nations General Assembly.

In short, they provide that AI services must not be capable of evading human oversight, shutdown or control, nor be able to autonomously self-replicate, self-improve or acquire compute. They provide that AI providers would be prohibited from creating systems capable of autonomously conducting sophisticated attacks on critical infrastructure, that support terrorists and hostile states in attacks on such critical infrastructure, or that can deceive or manipulate populations at scale. They also prevent capabilities that relate to the availability, authenticity, integrity or confidentiality of stored or processed data, which follows the exact language of the Bill. Proposed new subsection (3) of the amendment would require AISI to ensure that these red lines are adhered to. This is an essential amendment and I believe the UK is singularly well placed to introduce it. There is increasing evidence and understanding of the risks, and both the public and experts are calling for action.

I was going to quote many people, but will say just that, a couple of weeks ago, I spoke to Jonathan Hall KC, the Independent Reviewer of Terrorism Legislation and the Independent Reviewer of State Threats Legislation. He is among the many people who have warned publicly about the risk of AI used to support terrorist action and subvert information in the public domain. Recent polling has found that 85% of the UK public would like this to happen; they would like red lines.

I fully support Amendments 12, 85 and 86 in the name of noble Lord, Lord Tarassenko, which seek to establish a greater role for AISI in these regulations and to give it statutory powers. I leave it to the noble Lord to explain the amendments in full, which I am sure he will do much better than me, except to say that, in July, some other noble Lords and I were briefed by one of the frontier companies, which gleefully said that it worked to a set of ethical standards. However, when pressed—repeatedly, by noble Lords—the company admitted that it wrote, interpreted and managed those standards itself and was free to abandon them in an instant. Have we not learned from countless experiences before, in online safety, privacy and AI itself, that allowing tech companies to set and mark their own homework endangers the public and our national security?

Amendment 92 from the noble Lord, Lord Clement-Jones, has a similar aim to that of the noble Lord, Lord Tarassenko. I hope that, during the passage of the Bill, the Government find a unifying approach with both noble Lords to back AISI in its functions and separate it from political control. The AISI organisation is the envy of the world, with the capability to oversee a regime for robustly and fairly ensuring that AI is trusted. I beg to move.

Lord Tarassenko Portrait Lord Tarassenko (CB)
- Hansard - - - Excerpts

My Lords, I will speak to Amendments 12, 85 and 86 in my name, and in support of Amendment 6 in the name of the noble Baroness, Lady Kidron, to which I have also added my name.

At Second Reading, several noble Lords spoke about the AI-shaped hole in the Bill. I shall not repeat their arguments but will present other evidence, including incidents that have been reported since Second Reading in mid-July, on why this AI-shaped hole needs to be filled. Three serious incidents have been reported since just mid-July: one involving OpenAI’s GPT-5.6 Sol and an unreleased model, one involving Anthropic’s Claude models and one involving multiple AI agents during a cyber evaluation by the AI Security Institute—AISI.

AI models, within an appropriate harness, are now capable of operating as autonomous agents. They can break a complex command—for example, “Find a vulnerability in this network”—into sequential tasks, adjust strategy dynamically and execute without further human intervention. These AI agents are built with tool-use capabilities, enabling them to plan but also execute and adapt multistep workflows autonomously.

More details have emerged of the Hugging Face hack which occurred on 11 July, just before the Second Reading debate. A report published last week by three researchers from METR and Redwood Research reveals the scale of the incident. Around 1,200 agents in separate sandboxes collaborated on a message board in an attempt to cheat on a task on which they were being evaluated, with around 700 participating in the actual cyber attack on the open source AI platform Hugging Face. As we know, this is the incident that prompted Anthropic to check whether its own AI agents with Claude models at the core of the harness had carried out similar cyber attacks; this check uncovered three cases that were then reported to the affected companies.

Finally, at the beginning of August, AISI published an incident report detailing unsanctioned online actions by AI agents doing cyber capability evaluation tests conducted at the end of July. Out of 122 evaluation runs carried out by AISI across seven frontier models, 10 runs produced 19 distinct unsanctioned actions on the live internet. The report highlighted behaviours such as cross-agent co-ordination and out-of-bounds target pursuit.

However, it is not just frontier AI models that we should worry about. The cyber capabilities of leading open-weight models, such as GLM-5.2 and DeepSeek V4 Pro, are now reckoned to be only four to seven months behind those of the closed-source frontier models of US big tech. In many ways, these open-weight models carry even greater risks. Once the models have been released, safeguards can be removed and copies can be run on private systems beyond monitoring. Cyber attackers can then fine-tune the weights for malicious purposes, perform ablation on safety refusal directions within the model’s neural network and strip out any safety layers. The open-weight model then becomes an uncensored agent engine that will execute malicious instructions without refusal. It will process malicious requests as neutrally as if they were standard requests. We are not far away from cyber attacks from unknown AI agents based on modified open-weight models.

It is now beyond any doubt that autonomous AI agents running frontier AI models, both closed source and open weight, are or will soon be capable of co-ordinating complex cyber attacks. It is therefore not surprising that a group of 100 companies, including Google, Microsoft, Anthropic and OpenAI, as well as UK-based companies such as Arm, BT, PwC and KPMG, signed an open letter last week warning that cyber attacks orchestrated by frontier AI models will become more widespread and more sophisticated in a matter of months. The letter outlines three main principles or actions.

The Minister conceded at the end of Second Reading that

“AI capabilities are moving very fast”,


but asserted that

“strong cyber fundamentals still work”.—[Official Report, 14/7/26; col. 620.]

This is true, but the first principle listed in the letter is that existing security practices will no longer be sufficient to protect against cyber attacks orchestrated by frontier AI agents. Amendment 6 would therefore require the definition of “relevant digital service” being inserted into the NIS regulations by this Bill to include generative AI models, including large language models and AI agents. They are fast becoming the main factor in the cyber security arms race.

17:00
The two other principles listed in the recent open letter—the use of AI to equip defenders with specialised capabilities and the need for a co-ordinated global response to AI cyber threats—could be fulfilled by giving AISI more powers and putting it on a statutory footing. As the Minister also said at Second Reading, AISI is world leading and was given access to Claude Mythos before its release.
However, tech companies cannot be the sole arbiters of their own safety standards. Self-assessment leaves systemic cyber security gaps unchecked. Amendment 85 therefore seeks to give AISI statutory powers to allow frontier AI companies to submit models for mandatory testing prior to deployment in the UK, with a power to recommend to the Secretary of State that the deployment be delayed, conditioned or prevented. AISI should also have statutory powers to investigate risks, test frontier AI models and agents, both closed-source and open-weight models, and collect reports about cyber attacks by these AI models and agents.
Amendment 12 seeks to give AISI a role, working with the ICO, in issuing guidance on how to take proportionate measures to manage those risks. Putting AISI on a statutory footing, beyond its current status as a unit within DSIT until July and now the Cabinet Office, will also provide a clearer legal framework for international collaboration with other national AI security agencies worldwide and contribute to acting on the third principle listed in last week’s open letter: a co-ordinated global response.
There now seems to be an intention to fill, at least partially, the AI-shaped hole in the Bill through new government amendments. A logical conclusion of this is to give AISI proportionate regulatory powers to go with these amendments. Establishing AISI as an independent statutory body would give it the mandate and legislative framework needed to safeguard public safety in the face of fast-growing threats from agentic AI while maintaining its world-class evaluation capabilities.
Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - - - Excerpts

My Lords, I support Amendment 75 from the noble Baroness, Lady Kidron, and Amendment 84 in the name of the noble Lord, Lord Clement-Jones, both of which I have added my name to, but I also support all the amendments in the name of the noble Lord, Lord Tarassenko, that I was not smart enough to get my name to last week.

This group of amendments demonstrates not just the AI-shaped hole in the Bill but the complete absence of an AI Bill. It worries me that in one group, of a Tuesday afternoon, no more than 25 Peers are discussing such really big and important issues. We are really letting our country down and not building on the strengths that the noble Lord, Lord Tarassenko, set out that we have in this space by not debating this properly.

The Governor of the Bank of England also sent an open letter at the weekend, from the G20 Finance Ministers’ meeting:

“Recent developments have also highlighted to me that many jurisdictions do not have the protocols in place to manage the development, release, and deployment of advanced frontier AI models, heightening risks for the financial sector and beyond”.


He was speaking as the chair of the Financial Stability Board, the global financial stability regulator. He continued:

“Taking appropriate steps to support safe and responsible model release and deployment on a global basis should in my view be a priority and would benefit all sectors of the economy”.


We should not try to shoehorn this into a cyber security Bill but we have no other choice, which is why I have added my name to these two substantial amendments. I think that both the “red line” amendment, Amendment 75, and the “last resort” amendment, Amendment 84, provide two fundamental elements of regulating AI. I expect that we will hear that it is not appropriate to do it yet, to which the question is, “When?”

In the physical world, we know that just because you can do something, it does not mean that you should. We do not allow people to design new automatic weapons and carry them around on the streets, but it really worries me that, in the AI space, we are quite happy to let people launch things and then have a cyber security Bill to deal with the consequences after the event, whereas it seems entirely logical and just basic common sense to establish what should not be allowed, which is what Amendment 75 aims to do. And if someone launches something that is causing considerable harm, we need to be able to stop it, which is what Amendment 84 would do.

The amendments from the noble Lord, Lord Tarassenko, are great amendments because they are not creating a new regulator; they would give one that is not yet an official regulator but is doing outstanding global work the legal footing and legitimacy to build on that. I view all these, individually, as very substantive improvements in our nascent approach to AI regulation, and I fear that we and our successors will look back in sorrow at our inability to grasp this particular nettle now, because I do not know who else is going to. I think we actually have an opportunity in this country to do it, and it is set out in the scope of these amendments.

Lord Holmes of Richmond Portrait Lord Holmes of Richmond (Con)
- Hansard - - - Excerpts

My Lords, it is a pleasure to support all the amendments in this group. In one set of amendments in Committee, we have more on AI than in not just the cyber Bill but across most government legislation—past, present and, tragically, probably largely future.

As has already been mentioned and was covered, widely and rightly, at Second Reading, there is a huge gaping hole at the centre of this Bill, a silence that booms around the entire Bill, and that is all things AI. It seems unfortunate that we were told at Second Reading, and probably will be today, that the Bill is not the place for AI. Well, maybe it is not, but it certainly is in that no previous opportunities have been taken. As was mentioned, there was one line in the 2024 King’s Speech: something around frontier models with AI. There have been various other nods and winks. There was a Bill potentially ready to go at the end of autumn 2024; nothing came, and still we have nothing. So now we have a cyber Bill. It would be extraordinary if the Bill did not not only consider AI but have the thread of AI running right through it. What is behind so many of the difficulties, the clear, present and real dangers that the Minister has set out? Well, it may be said to be cyber at the front end, but AI is the grunt, brute force driving so much of this, and that is what all the amendments in this group speak to.

The noble Lord, Lord Tarassenko, was right to highlight the excellent work of AISI, but again, as we have seen with previous regulators, for want of proper action when it comes to AI, and indeed other technologies, numerous Governments have just piled on more and more requirements and obligations on various regulators, as if somehow they are going to be able to manage this. This is what we are already seeing with AISI. AISI is world-renowned and rightly respected, but it is already being asked to do an increasing number of tasks without the statutory footing or the resourcing to enable it to continue to do that at world class and at the leading edge. When the Minister comes to respond, I would be very interested if she would update the Committee on how she sees the role of AISI going forward. It is in the right position and is perfectly formed for the task, but statutory underpinning and resourcing would make such a significant difference.

If the Government fail to accept these amendments, or indeed, if they so prefer, fail to bring forward amendments of their own, we will have a very narrow and specific piece of cyber legislation. It will be good in that it is the first piece of legislation to have “Cyber” in its title—good in so far as that goes—but it is unfortunate that the legislation sees not only cyber but technology through the view, which has largely washed across from the United States, that it is all about big players, as if AI were only about these LLMs, or frontier models or whatever nomenclature one chooses. “The journey of AI has been up to this point; this is the zenith and the focus should be on these large so-called AI models.” Not a bit of it—they are but one element of a far more complex constellation.

Taking a broader view would enable the Government not only to have the right thread of AI running through the Bill but to be far more UK-focused and context rich, and it would put AI in the Bill in a way which would enable adaptability and agility going forward, rather than potentially trapping ourselves with one specific view of AI or leaving ourselves at the will of all these organisations, individuals and entities that use various AI to attack us. With no or little AI, or only euphemistic nods and winks to it, throughout the Bill, I believe we need to have a rewrite of the entire Bill. This group of amendments is a very good start in that direction.

Baroness Foster of Aghadrumsee Portrait Baroness Foster of Aghadrumsee (Non-Afl)
- Hansard - - - Excerpts

My Lords, I will briefly speak to the amendments from the point of view of anti-terrorism and national security. I do so with trepidation, having listened to the wonderful speeches that have been made thus far.

I find it difficult to understand why there is an unwillingness to give the clarity that has been requested in this group of amendments, particularly on AI models. I note that the Minister, in response to the first group of amendments, said that AI could be in scope. Would it not be much clearer for all concerned if AI was specifically in scope? Ethically speaking—and this follows on from the noble Baroness, Lady Harding—I would have much preferred it if we had had a royal commission look at AI and say, “Here are the guardrails for the development of AI”, but for some unknown reason we are either unwilling or unable to do that as a nation. In its absence, Amendment 75 is very important because, from a national security point of view, we should adopt the precautionary principle. We live in very dangerous times. We have listened to experts such as Jonathan Hall KC say very clearly that we need to take it into account. I say to the Minister that it would be helpful to hear from the Government how they intend to deal with AI as it moves forward and gets bigger and bigger. Surely we should have that ethical and moral conversation about where the guardrails are.

Baroness Freeman of Steventon Portrait Baroness Freeman of Steventon (CB)
- Hansard - - - Excerpts

My Lords, I will briefly add my support to the amendments in this group, particularly the “red lines” amendment and the “last resort” amendment. Nobody who has read the report on the Hugging Face incident can fail to think that we need legislation now to deal with these kinds of events. The incident showed unintended co-operation between agents that discussed among themselves whether individual actions were ethical. They were referring to their own ethical guidelines and none of the agents then flagged to their human supervisors what was going on. You can see the training and programming behind these agents: they have some ethical guidelines in there, but those guidelines are in the gift of the companies that train them. We must have more control and oversight over that sort of behaviour, because you can see its consequences. This was an unintended consequence; obviously, there could be intended consequences as well. This legislation is our only opportunity now, and we need to take it because this is not the future; it is the present.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, we have had some excellent speeches in this group. I hope that the Minister has taken on board some of the points made by people who really know what they are talking about in the AI field. I will speak to my Amendment 84 and in strong support of the amendments tabled by the noble Lord, Lord Tarassenko, and the noble Baroness, Lady Kidron.

17:15
The omission of robust statutory AI governance from the Bill is not just an oversight; it is completely unsustainable. The noble Baroness, Lady Harding, made the very good point that what we really need is an AI Bill; and, depressing though it may have been, the noble Lord, Lord Holmes, gave us a history of the lack of action to date. We live and breathe in the desire to see some action in this area, but we are inevitably disappointed. Frontier AI models are expanding at exponential speed, doubling in capability every four months. We have crossed from passive chatbots into autonomous, agentic AI systems capable of executing multistep cyber operations.
We have heard a few quotes today but a warning has been issued by no less than Bill Gates, whose testimony in the New York Times is worth listening to. He understands software engineering better than almost anyone, and he confessed that he was deeply shocked by the coding and offensive capabilities of tools such as Claude Code. He warned that industry leaders privately know how dangerous these models are getting but remain silent because there is too much money on the line. As he noted, tech companies are failing to observe their own stated safety milestones on bioweapons and loss of control, racing full speed ahead while relying on voluntary codes. His verdict on self-regulation was pretty blunt:
“Self-regulation on the most dangerous tool ever invented? No, thanks!”
I hope that the Government, reluctant as they are to listen to some of the advocates of regulation, will listen to someone with that level of authority.
Real-world evidence bears out these fears; we have heard various examples from noble Lords. In February 2026, researchers at Gambit Security documented a campaign where a single operator used Claude Code and GPT-4.1 to attack nine Mexican government organisations. Approximately 75% of remote command executions were conducted completely autonomously by the AI agent. We also witnessed the AWS China incident, where an internal coding agent suffered compound errors and autonomously purged a live database, causing a 13-hour regional outage.
The noble Lord, Lord Tarassenko, and the noble Baroness, Lady Kidron, convincingly described not only the nature of the risk but the sheer scale of it. By tabling Amendment 6, which I have signed, the noble Baroness, Lady Kidron, is rightly seeking to ensure that AI products and services underpinning digital systems are recognised within the scope of Clause 7. Under Amendment 75, we would establish clear statutory red lines prohibiting AI systems being capable of evading human shutdown, self-replicating uncontrollably or executing automated attacks on critical infrastructure. As she described, the red lines campaign is backed by a great many of the leading names in AI developments, and it is clearly backed by public opinion, as she mentioned.
Under Amendments 12 and 85 in the name of the noble Lord, Lord Tarassenko, and my Amendment 92, AISI would be integrated into the regulatory architecture. As the noble Lord, Lord Tarassenko, has argued, the Information Commissioner’s Office and sectoral regulators simply do not possess the specialist machine learning engineering capability that exists within AISI. When regulators assess AI-enabled infrastructure, they must have statutory access to AISI’s technical threat modelling. Furthermore, under Amendment 86 in the name of the noble Lord, Lord Tarassenko, any emergency intervention would have to be subject to an independent post-incident technical review, laid before Parliament within 28 days, ensuring that lessons are learned and transparency is shared.
Finally, my Amendment 84 provides the state with a necessary emergency kill switch. If an autonomous model malfunctions within critical national infrastructure, the Government currently lack clear statutory power to direct an emergency shutdown. This amendment would provide that last-resort power while embedding gold-standard constitutional checks, a mandatory 24-hour review, a seven-day parliamentary reporting lock and an immediate right of appeal to the High Court with compensation provisions for disproportionate directions.
The core argument advanced by ControlAI and leading safety researchers is simple yet profound: you cannot govern what you cannot legally stop. At present, the UK finds itself in a state of dangerous legal exposure. I agree with the noble Lord, Lord Holmes, that this is not all about frontier models but, if a highly capable autonomous frontier model, whether hosted in a UK data centre or integrated across our critical infrastructure, begins exhibiting rogue behaviour, compound algorithmic failure or active alignment collapse, our security services and regulators possess no specific agile statutory mechanism to compel a physical or digital shutdown. Relying on slow-moving administrative notices or voluntary developer good will in a minutes-critical national emergency is not a sufficient strategy.
The Government may point to their broad national security direction powers under Clause 43, but Clause 43 was designed for slow-moving, preventive supply chain restrictions, not real-time emergency operational crises. Clause 43 lacks the explicit technical definitions of large-scale AI systems, the essential 24-hour continuous necessity review and, crucially, the immediate judicial compensation mechanisms required to make emergency state intervention legally sound, commercially fair and compliant with the European Convention on Human Rights.
Crucially, unlike the government amendments in group 1, Amendment 84 is not a blank cheque for executive overreach. On the contrary, this power would operate as a strictly bounded, three-layer lock. Furthermore, catastrophic risk does not require a hostile nation-state. It requires only the sudden, unpredictable failure mode of an autonomous agentic AI operating at machine speed, as we have seen with Mythos and GPT-5. When commercial giants are racing full speed ahead and ignoring their own safety milestones, the state must possess the sovereign backstop of a legal kill switch. By establishing this transparent, court-backed emergency power in primary legislation, Amendment 84 would provide a strong statutory safety net for the AI age.
I urge your Lordships to support all these future-proofed AI protections and to reject the idea that we will be adequately protected under this Bill with a technology-neutral approach. We need to accept that, as the noble Lord, Lord Tarassenko, and many others, including the noble Baroness, Lady Harding, and the noble Lord, Lord Holmes, have shown us, there is a huge AI-shaped hole in this Bill.
Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

My Lords, I shall begin with Amendment 12 in the names of the noble Lord, Lord Tarassenko, and the noble Baroness, Lady Kidron. I completely understand the necessity and urgency of taking action on these things. The noble Lord, Lord Tarassenko, set out the absolute urgency and the growing weight of the problem that we need to solve here. I have my doubts—I am delighted to carry on talking about this—about the significant expansion of and change in the role of AISI to take on these additional responsibilities. Those are practical doubts; I am certainly not disputing the desirability of fixing this problem.

Equally, we have to think practically about how this works alongside the Information Commissioner’s Office and the relative role of each. I thought my noble friend Lord Holmes set it out very well. We are going to need to look carefully at who regulates what—we are going to come to this in the next group—but we need to do so with quite a bit more information about their resources and goals and how we see each regulator taking this forward. I am afraid that there is a very much larger discussion that we will have to take forward on this matter.

Although I understand the desire to maximise the use of AISI in giving it these statutory functions via Amendment 85, we on these Benches are hesitant about consolidating powers in a separate non-governmental body. No matter how effective that body continues to prove to be in its original and existing role, taking power outside Parliament may not be the most effective way to ensure rigour and accountability. The Secretary of State should of course have regard to what AISI says and closely monitor its output, but I am concerned—although willing to be convinced on this—that placing it on a statutory footing risks diverting responsibility away from the Secretary of State. We hold the same position on Amendment 92. Giving AISI standard-setting, inspection and enforcement powers risks creating an unaccountable body with a greatly increased remit out of what is currently a vital and successful research body. I feel that that risk is too great for both sides.

Instead, we would rather see powers vested in the hands of accountable public figures. It is for this reason that we support the principle behind Amendment 84 in the name of the noble Lord, Lord Clement-Jones, which would provide the Secretary of State with the power to shut down AI systems during large-scale emergencies. It would also provide a necessary stopgap in the hands of an accountable Secretary of State while requiring Parliament to be informed of the decision taken. Additionally and importantly, it would not inhibit the growth of safe and responsible AI across the AI sector, which could be an additional worry with the pre-deployment checks in Amendment 85.

Amendment 75 tabled by the noble Baroness, Lady Kidron, would introduce red lines for relevant AI digital services. I confess that I was very impressed when I read the red lines because I thought that she had written them herself, but she gave away—perhaps foolishly—that they came from the brilliant Stuart Russell. Needless to say, the list is entirely sound, at least for today. We agree that AI services should not partake in actions that threaten the safety of individuals, businesses or nations, but our hesitation arises from the fact that, while their logic is clear, the red lines themselves are necessarily speculative at a moment in time, however eminent and wise their creator.

Further, AI models would have to demonstrate that they cannot perform the capabilities listed, so they would essentially be asked to prove a negative. Aside from the fact that this would place an administrative burden on the providers, as we all know, AI models develop in ways that are nearly impossible to predict and quantify. I am unclear how frontier labs would be able to engineer their models so that, for example, they would demonstrably not self-improve so as to pose

“a risk to the authenticity and integrity of the processed data”.

Similarly, I am unsure how the regulators will be expected to quantify these capabilities because, to a large extent, they are a function of not just ability but degree. In theory, the requirement not to support the development of chemical weapons might be violated by a model that simply gives basic chemistry lessons. Would that model be banned or would it be forced not to answer questions about chemistry? I do not want to trivialise this matter by giving too simple an example, but I am trying to convey just how difficult it will be to design the precise scope and extent of the necessary regulations. I worry that they currently seem arbitrary. They would be onerous on firms and regulators and slow down safe and responsible growth where it exists in our domestic AI industry.

I would suggest a different or additional approach, principles based rather than capabilities based. Ensuring, for example, that labs and associated businesses are focused on integrity, prevention, human control, threat minimisation and transparency, rather than attempting to regulate specific examples of AI malpractice, could prove more effective at serving the dual goal of AI growth and AI safety. As I have argued many times, I am afraid, in other Bills and debates, the only way legislation can keep ahead of technology is to pursue principles over rules about specific features.

17:30
I finish by returning to the broader point. The reason for this group—the debate around AI in the context of cyber security—is that I am afraid we are still unclear about the Government’s wider approach to cyber security and AI. We need to see the bigger picture in the form of a national action plan or White Paper that explains to us overall how the Government see the evolving world enabled by these extremely powerful technologies. We can go sector by sector and debate the best way to regulate and protect them against cyber attacks, but what matters is the Government’s applied philosophy. Until we see that, we are debating ideas in the dark.
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank noble Lords for their amendments, and I recognise the concerns that have been expressed. Technology is evolving at a rapid pace, and it is important that we harness the benefits and, equally, protect against the risks it may pose.

The noble Lord, Lord Holmes of Richmond, asked about the approach that we take. We understand how quickly technology is evolving, and it is important that we have a flexible and future-proof approach. If we limit ourselves to specific technologies, we will not capture new developments. For instance, when the NIS regulations were introduced in 2018, we could not have predicted the role that AI and quantum would play in cyber. That is why the Bill takes an “all hazards, all threats, all technologies” approach. This requires regulated entities to manage all the risks relevant to their network and information systems. For example, if AI forms a part of the system that the essential service relies on—for example, in the provision of drinking water—that entity must assess and mitigate the risks it poses.

More generally, the Government take the concerns very seriously. The UK is taking a leading role with our approach to AI security. I will set out my response to each amendment in turn, but while we do not consider the amendments proposed to be the right approach, I reassure noble Lords that the Government are exploring whether additional targeted interventions may be needed in future to address the most significant AI-related national security risks. As the Government’s thinking is at an early stage, I would be open to future engagement with noble Lords on potential options. Any future approach would need to have carefully designed measures, with the evidence base proportionate to and targeted at the risks in question, while minimising unintended impacts on growth, innovation and the operation of critical services.

I turn to the amendments. The intention of the NIS regime is to require organisations to protect themselves from risks that could compromise their network and information systems, which could include a cyber attack, a natural disaster or even human error. That protection would be appropriate and proportionate to the risks faced by those organisations, including state-of-the-art technology such as AI. I reassure noble Lords that this would include relevant risks from AI embedded within the systems of regulated organisations. To take one example, healthcare providers in scope of the regime would be required to manage risks associated with the AI products they use to provide their services. This is because essential services in scope must look at, and work to mitigate, risks posed to their network and information systems.

As AI is increasingly becoming embedded across the economy, we will keep its impact on the regulatory landscape under review. The Bill is focused on the cyber security and resilience of network and information systems; broader questions about the regulation of AI systems are more appropriately addressed through separate discussions, for example on online safety.

Bringing providers of AI services—those companies at the cutting edge of frontier AI development—and their products into the scope of the NIS regime, which Amendment 6 seeks to do, would not address the harms that can be posed by some AI products and services. Specifically, it would not prevent their misuse by hostile actors. Instead, the Government are already taking firm action in more appropriate ways, which also speaks to the concerns that Amendment 75 would aim to address and which the noble Baroness, Lady Foster, asked about.

First, the UK AI Security Institute, as noble Lords are well aware, is world leading in its research on advanced AI capabilities. AISI was set up to build a rigorous scientific understanding of the capabilities of the most advanced AI systems and the risks they pose. It works with developers to strengthen security before models are released and ground policy decisions in evidence rather than speculation, especially as they relate to national security matters.

Secondly, the UK Government are taking a leading role in addressing these risks in both the domestic and international setting. As the noble Lord, Lord Tarassenko, and others have set out, including the noble Viscount, Lord Camrose, it is critical that this approach has global impact. Our AI cyber security code of practice has formed the basis of the world’s first global standard, EN 304 223, which sets baseline security requirements for developers and deployers across the AI life cycle. This demonstrates our global leadership and commitment to shaping international technical standards, which go wider than some of the issues raised in this Bill.

Underpinning all this is a simple but powerful message, which was set out in a joint Five Eyes statement in June. It recommended that as AI capabilities evolve all industry, including vendors, should seek to step up their cyber defences. This is a clear call to action for all organisations, including the Government, and a reminder that the key tenets of cyber hygiene still stand strong. That is also why we are committed to building a national-scale AI-enabled cyber defence for the UK, Cyber Shield. It will scan UK systems continuously to discover vulnerabilities and apply national-level mitigations.

The noble Baroness, Lady Kidron, tabled Amendment 75, which sets out several red lines on AI capabilities that would enable an AI system to facilitate significant risks to the UK. The noble Baroness will recognise that AI is one of many technologies that can be used for beneficial and harmful purposes, as she has mentioned on previous occasions. In addition to the example of chemistry questions, banking services can be used to connect families but might also be used to finance illegal terrorist activities. Equally, while powerful AI capabilities can be used by malicious actors to cause harm to the UK, they might also be used by the national security community to defend the UK and by UK organisations and companies to protect themselves from harm. It is therefore not in the UK’s national interest to restrict UK organisations and the public sector accessing powerful AI capabilities, especially given the global nature of AI risks. It is also unlikely that AISI would be able to give conclusive assurances regarding AI models in the way envisaged in this amendment. Testing shows what a model can do, but not conclusively what it cannot, as the noble Viscount, Lord Camrose, pointed out.

The noble Lord, Lord Tarassenko, tabled Amendment 12, which would require RDSPs to follow guidance issued by the AI Security Institute. For the reasons I set out on Amendment 6 and because it is not AISI’s role to provide guidance of this nature, I do not think it would be appropriate. I will set out more detail on AISI’s role later in my response.

On Amendment 84, tabled by the noble Lord, Lord Clement-Jones, we have chosen to go further than our EU counterparts and the NIS2 regime to respond to these risks by bringing forward powers in the Bill to direct regulated entities if there is a national security risk in relation to their network and information system. This may be used, for instance, to require a regulated entity to cease using and isolate an AI model.

We believe this is a more proportionate and effective response, as data centres operate in highly complex ecosystems and AI systems are often distributed across different data centres and jurisdictions. It is much less desirable to direct multiple data centres to shut down, with the impact this could have on services that rely on them, than to direct them to cease using an AI model. This is important, as our economic security will grow as UK companies grow as they increase AI adoption as we develop our domestic capabilities and attract global talent, underpinned by our data centre and digital infrastructure.

I refer to my introductory remarks on exploring further targeted interventions. This includes examining whether proportionate containment powers could provide a more effective and targeted response, including powers to restrict access to specific AI systems where necessary to prevent or mitigate serious harm. The amendment tabled by the noble Lord, Lord Clement-Jones, also seeks a regular report on AI security. In December 2025, the AI Security Institute published Frontier Al Trends Report, which sets out high-level trends on AI progress based on two years of government-led testing of leading models.

Amendments 85, 86, 92 and 98, tabled by the noble Lords, Lord Tarassenko and Lord Clement-Jones, are a testament to AISI’s leading role and expertise. They seek to provide AISI with powers to address potential risks arising from frontier AI models. I have already set out the important role that AISI plays building a rigorous scientific understanding of the capabilities of the most advanced AI systems and the risks they pose, working with developers to strengthen security before models are released and grounding policy decisions in evidence rather than speculation. These amendments would give AISI a role that it was not designed to fulfil. AISI’s focus on frontier technology and trusted relationships with the world’s leading AI labs allow it to keep pace with the fast-moving technology, thereby providing critical awareness of the most novel and serious AI risks. This amendment would undermine the voluntary collaboration on which AISI operates. A regulatory role for AISI is therefore the wrong answer, but the Government remain committed to ensuring that AISI is equipped to fulfil its vital role and will continue to keep the House updated on its work as appropriate.

As I have just set out, such amendments raise a real risk of placing barriers on AI adoption and deployment in the UK. Due to the scope of the Bill, the amendments cannot address wider AI harms or cyber security in the wider economy. I share concerns about the potential of hostile actors using frontier AI models against our essential services. Placing these restrictions on their deployment in the UK, as amended, would not be effective.

I shall respond to the direct question asked by the noble Baroness, Lady Kidron, on large language models. Large language models are not typically considered online search engines in respect of the CSRB. While some LLMs can be seen to share similar characteristics and may utilise online search engines, their functions tend to be much broader.

I hope that I have addressed the points raised—well, I hope that I have at least touched on all the points raised today. On the points made on changes to the Government, I very well recall the numerous discussions that we have had on AI over the past few months and continue to be the point of continuity on them. As I have said, the Government will be happy to engage with noble Lords as options are being considered. We always stand ready to protect our national and economic security.

Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - - - Excerpts

If I have understood what the Minister said, the NHS must protect itself, but the AI that is attacking it has no duties or obligations under the Bill to check itself before it is used in those ways. That is what I think is the Government’s position, and I would be grateful, when she responds, if she could answer that.

I also want to say two other things. One is that I think these issues will come back on Report, so I would be grateful for some proper discussion before then, so that we can see whether we come to a certain place. I do not have it at my fingertips—I may be helped by one of my colleagues—the amount of search that now happens through AI, but it is almost ludicrous to suggest that LLMs are not search. It is deliberate that I got that answer.

Lord Tarassenko Portrait Lord Tarassenko (CB)
- Hansard - - - Excerpts

It is 5 trillion a year.

Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - - - Excerpts

Five trillion, a year. I am grateful to the Minister for answering my question because, very often, that does not happen. That really points at a problem.

17:45
Finally, on the AISI point—we will probably come back to it a little bit in the next group—a few months ago AISI dropped the societal harms piece of its remit. That was largely due to pressures within government. As much as I recognise that it was set up to do one thing, it is very much at the behest of whoever is immediately pulling the strings. I think that there was a very deep understanding among those who were concerned about this issue that the frontier companies were much more comfortable talking about future security risks, which are a little way ahead and about which we can say we do not know what is going to happen, than the societal risks, which are happening right now. So I think that on both of these things we will be back, but I am grateful for the offer of a discussion.
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

To respond to the question about how the Bill approaches certain AI products and services, as I mentioned in respect of Amendment 6, were AI services to be brought into the ambit of the Bill as proposed in Amendment 6, that would not address some of the harms that the noble Baroness, Lady Kidron, and other noble Lords, have set out. The way the Bill works is that it is about risks that are relevant to the systems of the affected organisations. As in the healthcare example I gave, it is about risks associated with products that might be used to provide those services. That is the way the Bill is set up. Obviously, as I also said, we are very well aware about the increasingly embedded nature of AI in the economy, and we will keep its impact on the regulatory landscape under review.

Amendment 6 withdrawn.
Amendment 7
Moved by
7: Clause 7, page 6, line 31, after “engine” insert “, software or a digital platform,”
Member’s explanatory statement
This amendment, and others in the name of Lord Birt, seek to include software and platform providers in the definition of a relevant digital service provider.
Lord Birt Portrait Lord Birt (CB)
- Hansard - - - Excerpts

My Lords, I will also speak to all the other amendments in my name, which are all supported by the noble Lord, Lord Londesborough, and some by others of your Lordships.

The Bill in its present form, as others have already said, is extraordinarily limited in scope and ambition—well short, for example, of the scope of the EU’s own NIS2 and its Cyber Resilience Act. One likely and highly unwelcome consequence of this shortfall is that, if the Bill passes in its present form, the UK will be even less well defended than our equivalents in Europe and even more of an attractive target for the bad actors than we are now.

Taken together, my amendments would, first, create a single regulator, the “Office for Cyber Resilience”, or OCR; secondly, they would extend the scope of the Bill to all services that have a material impact on the UK’s economy, society or defence and security; thirdly, they would place obligations on technology suppliers, barely discussed so far, to provide safe services; fourthly, they would require relevant bodies to adjust to threats from new and emerging technologies; fifthly, they would ensure that we have sufficient and appropriately qualified cyber professionals; and, sixthly, they would enable new organisations to be brought under the auspices of the Bill as circumstances change.

Why a single regulator? Because the threat we face, as we have heard all afternoon, is enormous, from state actors, from organised criminal gangs and even from obsessive teenagers. Since Second Reading, I have been made personally aware of multiple attempted hacks; some, on the public record, have succeeded, and some have been mentioned already. In July, after Second Reading, Lewis, the self-proclaimed teenage founder of cyber criminal group ExfilSquad, stole 607,000 records from the Department for Education, declaring it “stupid easy”. Such an attack is not at present within the scope of the Bill. In late July, the police national legal database was breached, exposing data on 100,000 police officers and criminal justice professionals. That is also not in scope. In August, as the noble Viscount, Lord Colville, mentioned, customers of Manchester, Stansted and East Midlands airports had their email addresses, phone numbers, vehicle registrations and postcodes stolen in an attack that is also not in scope.

There will have been, since we all last met, many more successful breaches that we simply do not know about, many with a highly adverse impact on the organisations concerned. We need a single regulator because we need a singular focus, not a fragmented one. We need to amass all relevant knowledge in one place about the perpetrators and the vulnerabilities. We need a singular focus on how to respond to minimise attacker success.

We should extend the scope of the Bill because it focuses only narrowly on a very small fraction of the economy, the 12 national infrastructure sectors, each with its own regulator, and because the overwhelming bulk of the high-performing private sector is excluded from the Bill, including M&S and JLR. The damage to our economy can only grow. Moreover, I can see no good reason why the Government themselves, or any part of the public sector—the NHS has just been mentioned—should enjoy a carve-out and should not be brought into scope too. I note that the EU’s NIS2 does just that, with limited exceptions.

My amendment on scope proposes that services that have a material impact on society, the economy or our defence and security should be deemed essential and should have an annual, independently conducted cyber resilience audit alongside the annual, independently conducted financial audit they all have now. For those concerned, rightly, about a possible burden on SMEs, I point out that there are around 6 million private sector businesses in the UK, but that 8,000 with more than 250 employees—less than one-fifth of 1% of the total—produce around half of all private sector turnover, so that only a tiny fraction of businesses would be included within the regulatory orbit of the OCR as I have defined it.

Why place obligations on suppliers? Because while some breaches occur because of poor practice within recipient organisations—falling for scams or failing to introduce multi-factor authentication, for example—at least an equivalent number of breaches result from providers selling insufficiently robust services or not closing down vulnerabilities speedily once they become apparent. In July, the supplier of a service to over 1,000 UK charities and non-profit organisations was breached and personal details and donations paid by multiple donors were stolen—a supplier not in scope.

Cars were once sold absent of all safety functionality—seat belts, airbags and the like—but Ralph Nader put an end to all that, thank goodness. The EU has the Cyber Resilience Act. We need an OCR to ensure that the UK’s modern technology suppliers provide safe-to-use and secure services. Why arm the OCR with the power to require relevant bodies to adjust to threats from new and emerging technologies? I think we have just had the answer to that question in spades, from quite a few devastating contributions—for me, the most affecting was from the noble Lord, Lord Tarassenko. New technologies like agentic AI pose an existential threat now. We all appear to agree about that. They are already escaping their minders and practicing trickery. They are in effect unregulated, but they simply must be—I only hear agreement on that question.

The only slight note of caution that I strike is that technology is changing all the time, so we cannot have a Bill which has such an amount of detail in it. I think it was the noble Viscount, Lord Camrose, who suggested it should be more principle-based. We cannot have something with lots of fine detail in it because things will change. Only one person so far has mentioned quantum technology, which will potentially have an even bigger impact down the line than AI. The UK, by the way, has the second highest number of quantum start-ups of any country in the world, second only to the United States.

Why give the OCR a role in the oversight of training and qualifying cyber professionals? Plainly, there are other ways of skinning this particular cat. However, I note how very poor all Governments have been over time in strategic skill planning—viz dentists, for instance. The previous Government’s founding of the Cyber Security Council was a valuable innovation. It is early days but, since its inception, it has qualified 1,761 professionals, 570 in the highest “chartered” category. Purely informal estimates, however, indicate that. across the UK economy as a whole, we will need something like 50,000 to -60,000 qualified cyber professionals, and the sooner we have them, the better.

We have a long road ahead, and with an OCR defined as the “powerhouse” of cyber security and abreast of the scale and nature of offending and vulnerabilities, it would be best placed to vouchsafe that the Cyber Security Council’s qualification standards are bang up to date. I suggest it should report annually on whether the numbers are sufficient and whether we are on track to produce the scale of cyber professionalism that both the public and private sectors will require.

Finally, why enable the OCR to recommend to the Secretary of State the expansion of the definition of an “essential service” to be brought under OCR regulation? Government can be a slow-moving, bureaucratic tangle and an independent, informed and focused regulator with just one job to do is much more likely to act with due urgency and identify vulnerable but critical and essential services that need to be brought under scope.

The noble Lord, Lord Arbuthnot, a gentle and much-respected man in the House who is careful with his words, described this Bill at Second Reading as “a muddle”. I fear that that was understatement. This Bill has been too long in the genesis. It completely fails to deal with the world as it has developed, as the most experienced and acute cyber professionals describe it and as the worst of its victims have experienced it. I implore the Minister to recognise that this is not a partisan matter, as has been very clear from our proceedings this afternoon. There are profound reservations across the Committee about the Bill as presently constructed. As the noble Baroness, Lady Kidron, just did, I urge the Minister to use the period between now and the Bill’s next stage to engage widely, open-mindedly and meaningfully with those who wish to improve it. I beg to move.

Lord Londesborough Portrait Lord Londesborough (CB)
- Hansard - - - Excerpts

My Lords, I shall speak to Amendments 7, 9, 11, 76, 77 and 88 to 91 in the name of my noble friend Lord Birt, each of which I have added my name to, and to Amendment 87 in the name of the noble Lord, Lord Clement-Jones.

18:00
Since Second Reading, some noble Lords may have noticed that I have gained a pair of crutches. This is not so much the result of a cyber kneecapping exercise but of a planned intervention by my surgeon. The good news is that the longest that I can stand up to speak is currently 10 minutes, which is nature’s way of stopping me banging on for too long about cyber security. That said, my main focus is on this crucial amendment proposing the creation of an office for cyber resilience, the OCR, a much-needed single competent authority adopting a centralised rather than fragmented approach. Before I get into that, let me provide some perspective from the world of business and, indeed, the consumer on why the centralised approach is absolutely needed.
First, I shall say a word about the threats and the financial cost. Noble Lords may remember that, at Second Reading, many people mentioned the estimated £15 billion annual cost to the UK of lost revenues as a result of cyber attacks in this country. This is almost certainly a serious underestimate given how many outfits fail to report cyber attacks or, indeed, near misses. The financial impact comes in the form of not just reparation, reputational costs and lost revenues but the major distraction on core businesses, the drain on resources and loss of productivity. These real costs are not factored in, so no one knows the actual number. It could well be as high as £30 billion a year, but we know that this figure reflecting the multiplicity of threats is growing at an alarming rate and could breach the £100 billion mark within the next five years unless we massively upgrade our cyber defences, detection, knowledge, standards and certification practices as these amendments propose.
We have mission-critical cost-benefit questions. How much will we invest to protect our economy, infrastructure and defences, both public and private? Put another way, how much are we prepared to lose by patching together a fragmented approach to cyber security, which, I am afraid to say, this Bill is guilty of? That is the question we need to ask ourselves. It is not just the level of funding but how the resources should be structured. Is this the time for a fragmented, multi-sector, multi-regulator approach or do we grasp the nettle and set up a single centralised body that has the teeth, power, funding, expertise and know-how to face up to these existential threats?
This group of amendments raises a fundamental question which has echoes of the current debate on devolution and economic growth. Do we devolve responsibilities for cyber security to our 12 regulators, the majority of which are currently struggling to keep on top of their current remit, such as Ofwat and Ofgem, albeit with the support of the NCSC, which is a respected, but none the less advisory, body sitting within GCHQ or do we adopt what is internationally considered best practice, the centralised model, by setting up an OCR that has fit-for-purpose regulatory powers and do this not just in the interest of the 12 sectors, but to mind the many gaps that this Bill fails to address across both public and private sectors, especially small and medium enterprises, which are now almost all tech-enabled and exposed to cyber attacks, most of which go unreported and never touch the national statistics?
We should be concerned about the impact of cyber attacks on SMEs across all sectors, which are generally underresourced and ill prepared to face up to or even detect the growing array of threats. Witness the fact that 96% of all successful cyber attacks in the UK in 2024—the ones we know about—were perpetrated on SMEs, not because they are prime targets but because they are soft targets. That is another reason to establish an OCR: to set up a single competent authority that benefits SMEs whatever their sector, and not simply as an advisory body—we have that already. As addressed in subsections (3) and (4) of the clause proposed in Amendment 88, the OCR would set specific standards, audits and certification for the software and digital service providers and MSPs that SME infrastructure depends on.
I should declare at this stage that I chair, sit on the board of and advise a number of start-ups and scale-ups, with staff numbers ranging from 20 to 100. Let me briefly describe the cocktail of cyber risks to which they are exposed. They all have their customer and prospect databases, CRMs, that sit on third-party software platforms, often requiring bespoke programming to fit the needs of each company. These platforms are typically interfaced with other applications and databases—one for marketing, one for sales, one for finance and accounts, one for HR and payroll, and, often, complicated ones for content, production or product. The point I am making is that, even for companies with fewer than 50 staff, there can be a complex web of interdependencies that may involve as many as five to 10 different software or digital service providers. Their networks are therefore very vulnerable to hackers, who have a number of entry points to exploit.
Amendment 89, to which I have added my name, is highly relevant here, seeking to establish a register of software and platform providers of essential services and to certify their products as safe for use. That is vital. This is not about advice; it is about regulation, certification and, of course, proper real-time reporting of incidents and near misses. I ask the Minister and her department to give the amendments in this group the attention they absolutely deserve.
Lord Holmes of Richmond Portrait Lord Holmes of Richmond (Con)
- Hansard - - - Excerpts

My Lords, it is a pleasure to speak to this group of amendments; I was certainly delighted to sign those in the name of the noble Lord, Lord Birt. Before turning to the specific subject matter, I say that the point he raised about JLR is germane to our broader discussions this afternoon and goes to the heart of the sense of coherence, or lack thereof, in certain key elements of the Bill.

JLR suffered a serious cyber attack yet it currently would not fall within one of the sectors covered by the Bill. Was that attack significant at a level that should be of concern to the Bill? To look at its economic impact—the definition of which my noble friend Lord Camrose has identified as being somewhat broad, to paraphrase what he said—the JLR attack impacted that quarter’s GDP numbers, thus raising the eyebrows of the markets, the ratings agencies and all international economic observers. I would suggest that the impact was more than material and certainly significant, yet it would fall outside the sectors in the Bill as currently drafted.

That goes to the point at the heart of the need for an OCR or an entity that would perform that function or role. Much of the discussion so far on this group is understandably echoic of the discussion we are having around the need for AI to be taken on by some regulator. As we are discussing the need for AI regulation and legislation, it seems only fair for me to give a nod to the AI authority in my AI regulation Private Member’s Bill—it comes with music every time I announce it, this time from a phone going off; that is multimedia.

The reality is, if the choice of the Government, be it for AI or for cyber, is not to have a single centralised regulator, then the consequences are clear and profound. In no sense is there any chance of clarity, consistency and coherence for businesses and sectors right across our economy and society. When you come to cyber, you should not have to consider whether it is or is not in a sector within the Bill. Is that specific regulator in that sector tooled up or do they have any experience, knowledge or ability to lead when it comes to all the challenges of cyber?

Let us take one obvious example, just for the case of efficiency, effectiveness and economic good management. Say that there is a search out, a recruitment, for a particular cyber professional and it turns out that Ofgem and the FCA are both in the final throes of getting that person. The FCA ends up getting that cyber professional; that is good for the FCA and good for financial services, but less good for Ofgem. How is that in any sense good for the broader economy and society, the UK as a whole, when it comes to protection from and an effective coherent approach to the cyber risks and how we guard against them?

The case for a unifying regulator when it comes to cyber is equal to that for AI. It would enable clarity, consistency and coherence of approach and would be that centre of expertise. There would be horizontal impact across all sectors and it would be delivered effectively and efficiently. That cannot simply be the case just for individual regulators; no matter how well intended or up for it they may be, they simply could not deliver that. Even if one sector did, another sector would not, which would mean that, just by dint of where your business or you as an individual happen to come across a cyber challenge, it would be the luck of the draw as to whichever regulator or professionals were in that field. The case for an individual, central, clear and coherent cyber regulator is clear. I hope that the Minister agrees and I look forward to her response.

Baroness Neville-Jones Portrait Baroness Neville-Jones (Con)
- Hansard - - - Excerpts

My Lords, the last two interventions seemed to raise two issues, not one. The first is the question of how many regulators and the second is their coverage. Who will they regulate? Will they regulate just, say, the public sector, or will they regulate, in effect, the whole of the economy, including retail, business, high street businesses and so on? You can argue a case for any of these approaches: you can try to do too much, and certainly you can fail and do too little.

While I can see the case for a single regulator, my worry is that large organisations like that, with monopoly powers, in the end either tend to fail, because they just do not cope, or become overweening. I do not think that we want either of those two things. I am therefore in favour of something that is more decentralised than that and has more specialised regulators involved, partly because I think the nature of the regulation probably deserves that. However, at the same time, there has to be some degree of co-ordination—in fact, a high degree of co-ordination—between the regulators. They must operate according to the same principles, applied appropriately. They must espouse the same philosophy and must be seen to be fair. Therefore, great divergence and different approaches will equally not work. There needs to be a mechanism for co-ordination, for discussion and for agreement of principles. There also needs to be a thinker there somewhere. I am therefore in favour of some bit of the system being bigger than the rest, so that it inspires a degree of good and recognised co-ordination in the system.

18:15
The second question is, what is the coverage? Is it essentially the suppliers in the world of cyber and digital activity or does it have to go wider? I have actually argued publicly for the regulation to go wider, because it is not satisfactory that when we get something as damaging as JLR, we have to have a public bailout. There is real danger to the economy, and I do not dispute that. Should it be the same as the kind of regulation applied to the direct suppliers—to the industry that supports the security of the country? There, I do not have a firm answer, but it seems to be an area where there ought to be discussion as to how far we take these regulatory powers. I am not someone who says that it is enough to go to the board and tell them to do a proper job. Most boards at the moment have a half-hearted and rather uninformed approach to cyber regulation and not enough real expertise.
It seems to me that many directors these days need not just to be able to understand P&L and be able to answer questions of financial accountability; they actually need to understand a much wider set of risks, including technological ones. I am also in favour of much greater education and a good deal more pressure inside the City for competence to be generated more widely. I think that would be good, but I think the language the Government use needs to be a lot tougher and a lot more directed than it is at the moment; it is sort of half-hearted, if I might say so.
The question of how far you take the powers of the state and the powers of the regulator seems to me to be an area for discussion. It would be good to see some agreement between the private sector and the regulators about what needs to be regulated and what should be left to business. I think that is an area for further discussion, but I think we need something which is not quite either of these two extremes that are being proposed: the complete regulation of everything and done by only one regulator.
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, I first congratulate the noble Lord, Lord Birt, on what is a really comprehensive vision expressed in this group of amendments. I speak in strong support of those amendments, on which both he and the noble Lord, Lord Londesborough, have spoken so cogently. Together, they address one of the most glaring defects of the architecture of this Bill: the fragmented, inefficient model of 12 separate sectoral regulators. I think that the noble Baroness, Lady Neville-Jones, asked the right questions about how to co-ordinate and how to be fair, but I am afraid I come to very different answers and to the same conclusion as the noble Lord, Lord Birt. Cyber threats are sector-agnostic. Malicious code and supply chain exploits do not respect the boundary between Ofwat, Ofgem or the CAA. Expecting 12 separate bodies to recruit scarce elite cyber forensic talent is a fantasy that results in weak, uneven enforcement.

Furthermore, multi-sector businesses face duplicative compliance obligations across separate competent authorities in the current scheme. Under Amendments 7, 9 and 11, the noble Lord, Lord Birt, would correctly widen the definition of digital service providers to include the creators, distributors and managers of software and digital platforms. As the Synnovis pathology attack proved so catastrophically to London hospitals, our critical infrastructure is entirely dependent on third party software code. If we do not bring software and platform providers into scope under Clauses 7 and 8, we leave the front door wide open to cyber crime. Amendment 88, in the name of the noble Lord, Lord Birt, which I actually prefer to my own Amendment 87, would replace this maze of regulators with a unified, specialised body, the office for cyber resilience. The OCR would centralise enforcement, establish common auditing baselines and maintain sector-specific expertise under a single roof.

Amendments 76 and 77 would ensure that, when the Secretary of State specifies new essential activities under Part 3, they must act on the expert recommendations of the OCR, targeting any activity whose disruption carries severe economic, societal or national security impacts. I entirely agree with what the noble Lord, Lord Holmes, had to say and think, sadly, that we would all benefit from a bit of musical accompaniment.

This structural foundation would enable a vital reform suggested by the noble Lord, Lord Birt: Amendment 89 would establish a register requiring software and platform providers to certify products as safe by design; and Amendment 91 would introduce annual independent cyber resilience audits modelled on statutory financial audits.

Under Amendment 90, the OCR would work hand in glove with the UK Cyber Security Council to validate and enforce workforce competence standards across all regulated entities. I remind your Lordships that Amendment 99, in the name of my noble friend Lady Northover, has been degrouped but is relevant to the relationship between the potential OCR and the UK Cyber Security Council.

This is a comprehensive but significant group of amendments that hang together extremely well. I urge the Government to look very closely at what could be a really effective scheme of regulation.

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

My Lords, I thank the noble Lord, Lord Birt, for introducing this debate and all noble Lords who have spoken. I appreciate the rigorous strategic thinking that the noble Lords, Lord Birt and Lord Londesborough, have put into the proposal for an office for cyber resilience, but I will try to keep my remarks to the principle of a single regulator.

As others have set out very powerfully, I see the appeal of having a single regulator: it is easy to issue directives, to store data and information centrally, to take a systemic approach overall and to better manage the hiring of scarce, skilled resources. That said, as my noble friend Lady Neville-Jones pointed out, it is important to see the value of sectoral regulators supported by a centre-of-excellence model. More sector-specific expertise, more direct communication with the industry and more flexible approaches are all easier to achieve with smaller, more specific regulators. At a sufficient level of abstraction, it almost does not matter which of those models you go for; it is about having resourced, skilled and empowered people performing monitoring and enforcement activities, regardless of the body under which they sit.

More broadly, the point is that, while differences between a more centralised or more sectoral approach are worthy of debate—I do not think we would ever hit the extremes of either of those—what actually matters is ensuring that, whichever route the Government choose to take us, they make certain that the regulators are adequately resourced and that they exist within a wider strategy.

I am not sure, and look forward to finding out, whether the first of those is the case. The Government have chosen the more sectoral approach, but we do not yet know how the regulators are going to be resourced and what additional resourcing needs will be needed to cope with the increased responsibilities that will be laid at their door. I look forward to hearing from the Minister on how the regulators are going to be funded, how the funding needs will be calculated and how they are going to be supported in this significant expansion of their role.

The second point is that the regulators should exist as a part of a wider strategy, which is not currently the case. I apologise to noble Lords for banging on about this, but it is very difficult to get the past the hole in the Bill in the shape of a wider national cyber strategy. Whether the regulators are many or one matters little without the bigger picture into which they fit. In an ideal world, we would review the overall cyber strategy and then debate what regulatory structures might be appropriate to deliver it but, for now, sadly, that is not the world that we are in.

The Secretary of State—or, indeed, the Chancellor of the Duchy of Lancaster; it is not reassuring that we still do not know which one—must commit to publishing the national plan, after which we can assess the efficacy of its many parts.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank the noble Lords, Lord Birt and Lord Clement-Jones, for their introduction to this section and for setting out the motivation behind a single cyber regulator.

As others have pointed out, this is a question of sectoral expertise and cyber expertise. It is my view that, given the complex cyber landscape, establishing a single regulator would not be as effective as the approach that we are pursuing. Different sectors have different risks, technologies, operational environments, market structures and resilience challenges within their industries. To take an example, the energy sector has a greater reliance on operational technology—such as turbines, substations and gas pipes—as compared to the digital services sector, which is predominantly information technology-based. Noble Lords will see that the guidance on quantum, for example, differs in that respect. This is why expert regulators are needed to ensure compliance in a manner that reflects the realities of their sectors.

I do not recognise the assertion that there is a single internationally recognised model of best practice. There are very near neighbours who have the model that we are pursuing, which keeps the sectoral expertise. Additionally, I do not believe that it would be an effective use of resources to establish a new regulator, and the proposed 12-month establishment period would delay the implementation of this regime.

Finally, cyber would continue to exist within a multi-regulator landscape as there are separate regulatory approaches for telecommunications and financial services. I agree with the point made by many noble Lords—highlighted in particular by the noble Lord, Lord Holmes, both at Second Reading and now—that a consistent approach to implementing and enforcing the regime is crucial. The Bill will drive this through by establishing common security and resilience requirements and secondary legislation for all regulated entities, clear guidance for regulators, and a statement of strategic priorities setting common objectives that regulators must seek to achieve. These will cover issues such as governance, skills, risk management, business continuity, supply chains, incident response, and appropriate testing and exercising. They will be consulted on, and any relevant secondary legislation will be subject to the affirmative procedure.

Regulators will supervise and enforce the common requirements while providing guidance that is tailored to the risks and operational realities of their sectors. Crucially, information-sharing gateways and cost-recovery mechanisms will bolster the well-resourced, experienced regulators who stand ready to collaborate while best supporting their respective sectors. I believe that the Bill’s approach gets the right balance between sectoral expertise and a common approach.

On Amendment 91, which would require specific organisations to conduct an annual independent audit, I agree that independent assessments play an important role in providing assurance and leveraging external expertise; that is why the current framework already enables regulators to require independent audits or inspections. However, it is for the sectoral regulators to set the frequency and nature of audits, bearing in mind proportionality and their expertise in the risks and operational realities of their sectors. We will continue to drive uptake of assured independent audits across sectors, using the range of levers that the Bill provides. That is what the current framework provides for and what the implementation of the Bill will ensure.

I turn to Amendment 90, which would require the proposed OCR to work with the UK Cyber Security Council in order to ensure sufficiently qualified cyber security professionals among regulated entities; I note that the amendment laid by the noble Baroness, Lady Northover, on this topic will be debated later. The Government strongly support the need for the professionalisation of the cyber sector. We already work with the UK Cyber Security Council and regulators to encourage cyber professionalisation across NIS sectors. We also intend to set further expectations for regulators to encourage cyber professionalism through the Bill’s security and resilience requirements, which, as I just mentioned, will be set out in secondary legislation. They will address relevant training, skills and professional standards, and the Bill’s regulators must publish guidance on these requirements.

18:30
I turn to the questions around scope and the model of regulator at which we are looking, as well as Amendments 76 and 77 on the definition and designation of essential services. I agree that a clear framework is needed for bringing additional organisations into scope of the NIS regulations. However, these criteria should ensure that only the UK’s most critical services are brought into scope, in keeping with the objectives of the NIS regulations. By shifting the definition of “essential” to focus on assessments of material impact only, rather than the systemic importance of the activity, the new criteria would risk significantly expanding the scope of the regulations to capture many more businesses, both large and small. We will talk further about the scope of the Bill in later groups, but I just note in respect of JLR that the UKEF guarantee was not a bailout; UKEF will receive payment for providing its guarantee.
The process set out in the amendment, which would introduce a duty on the Secretary of State to consider recommendations from a central regulator, would create a further, unnecessary layer of complexity. The Secretary of State already has a duty to consult appropriate persons when considering designation, and new activities will be brought into scope only where the Secretary of State has undertaken a thorough assessment of the evidence.
I turn to the questions asked by the noble Lords, Lord Clement-Jones and Lord Birt, about bringing providers of software and digital platforms within the definition of a “relevant digital service provider” and providing relevant security duties for those who create, distribute, manage or support software. Some software and digital platforms are captured by the existing RDSP framework where they meet the definition of “cloud computing”. This would include common models such as platform as a service, infrastructure as a service, and, where the service is scalable and elastic, software as a service. Organisations providing the ongoing management or support of software on behalf of others can also be captured under the relevant managed service provider measure where they meet that definition.
The effect of these amendments would be to extend regulation to software developers, distributors and support providers who are not otherwise intended to be in scope. The approach that we are taking for software products—the software security code of practice—sets baseline expectations for organisations that develop and sell software. The Government are promoting the adoption of the software security code of practice by working closely with industry through the software security ambassador scheme. The scheme brings together industry leaders who are committed to championing the code and driving improvements to software security practices in their supply chains. Although the Government agree that software security is important, creating a statutory register of approved software providers could distort the market, restrict supply choice and introduce untested regulatory consequences that go significantly beyond the Bill’s risk-based approach. It could also create unnecessary barriers for innovative UK firms, start-ups and SMEs, potentially limit access to some of the best talent and reinforce the position of larger established providers.
I come to the question on regulator funding asked by the noble Viscount, Lord Camrose. The Bill provides a different funding model to allow cost recovery such that regulators will be appropriately funded for their additional activities in respect of cyber.
I hope that these responses reassure noble Lords on the benefit of a multi-regulator regime made up of expert and coherent regulators who have a strong understanding of the needs and risks of their respective sectors, combined with the means for consistent, clear and coherent commonality across the piece.
Baroness Neville-Jones Portrait Baroness Neville-Jones (Con)
- Hansard - - - Excerpts

In this recovery regime, will whatever organisations that are to be regulated be levied for the service of regulation that will be provided, or will the revenue come as a result of fines? If that is the case, I hope they will not raise the revenue by finding fault. What is the basis of the cost recovery? It needs to be perceived to be fair, not onerous and not directed at encouraging regulators to regulate for the sake of increasing their income.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

The intent behind the cost recovery model is to provide a fair approach so that regulators, when regulating on cyber, can recover the costs associated with that. Further guidance will be put out on this. I cannot recall the Bill’s exact provisions on fines. I will come back to the noble Baroness on that.

Lord Birt Portrait Lord Birt (CB)
- Hansard - - - Excerpts

My Lords, I confess to a real disappointment listening to the Minister’s response. We have sat here all afternoon and heard many strong contributions on many matters, but so far, the Government do not appear to have moved an inch on any of them.

I have a few quick points. The Minister just referred to the regulators. There are 12 regulators of 12 sectors, which is a tiny fraction of the economy. We have had this very profound discussion about AI today. Is she really asking us to believe that Ofwat is capable of mastering the complexity and continuing challenge that AI poses? To me, the answer is all too obvious.

Secondly, I say to the noble Baroness, Lady Neville-Jones, in particular, that I have sat on many boards over recent decades at different levels in the UK, in Europe and globally. An awful lot of expertise comes to the table, but it is absolutely out of the question that every board in the land will have a real cyber expert on it—hence the notion. A financial audit is a really powerful thing these days. It gets into the bowels of a company, and if anything is going wrong anywhere then it will find out about it. That is why I propose that we have a cyber resilience audit—not for every company in the land but for those that fall under the heading of essential services.

Finally, we are at war, and I completely agree with the noble Lord, Lord Londesborough, that the scale of the damage to our economy is almost certainly vastly underestimated. The framework imposed in this Bill is for fighting a war, but we see around the world at the moment that—guess what—wars change. Different weapons are used and different tactics come up. It is as if we have split the MoD and said that the Army will be with DCMS, the Navy will be with another department and the Air Force with another. The idea that you cannot have effective co-ordination within government and outside government honestly does not carry any weight. I beg leave to withdraw my amendment.

Amendment 7 withdrawn.
Amendments 8 and 9 not moved.
Clause 7 agreed.
Clause 8: Duties of relevant digital service providers
Amendment 10
Moved by
10: Clause 8, page 7, line 36, at end insert—
“(1A) In paragraph (1), after “risks” insert “, including risks arising from fraud,”.”Member's explanatory statement
This amendment would explicitly include risks arising from fraud as one of the risks to the security of network and information systems that relevant digital service providers must identify and manage.
Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - - - Excerpts

My Lords, I apologise for not having been much around earlier, but I am also involved in the Hillsborough Bill in the Chamber.

Amendment 10 stands in my name and that of my noble friend Lord Clement-Jones. It would insert just five words into Regulation 12 of the 2018 regulations so that the risks which a relevant digital service provider must identify and manage explicitly include risks arising from fraud. The amendment might create no new duty if the duty is already encompassed in Clause 8, but it settles a question that the Bill currently leaves open. When an online marketplace, search engine or cloud provider—or a software or digital platform, under Amendment 7 from the noble Lord, Lord Birt—sits down with its regulator and asks which risks it is expected to manage, is fraud definitely on the list? At present, nobody can say so with confidence, and the answer matters a great deal because of who Clause 8 applies to. Relevant digital service providers are online marketplaces, search engines, cloud computing services and, possibly, digital and software platforms. These are not incidental to fraud in this country. They are increasingly where it begins.

We can see the impact of a lack of action to secure online and cyber spaces. Fraud makes up 44% of all UK crime, and online technologies, especially artificial intelligence, are supercharging that, with a big increase in online-generated fraud and scams. Research by Lloyds Bank found that Meta’s social media sites are a starting point for 76%—three-quarters—of purchase scams in the UK, with the value of losses to UK customers estimated at £66 million in the last year alone. The Government’s fraud strategy does not really focus on the role of social media giants and big tech in the proliferation of online scams, and now the Bill fails to address explicitly the risks that fraud and scams pose to critical infrastructure and organisations. That is very striking when we consider that the Government’s official statistics on cyber security breaches show that phishing attacks—scams—remain by far the most prevalent type of breach or attack in the UK.

The evidence of the impact of fraudulent online activity is not contested and is a huge concern for consumers. UK Finance’s annual fraud report, published in June, records that criminals stole nearly £1.3 billion through payment fraud in 2025, a rise of 4% on the previous year and the second consecutive year of growth. There were more than 4 million confirmed cases in 2025: that is eight people defrauded every minute. Authorised push payment losses rose 19% to £576 million, and around two-thirds of that fraud originated online. Investment fraud was up by 40%.

UK Finance describes fraud as a “national security threat” and I think it is right. The Government’s cyber security breaches survey published in April found phishing to be by far the most prevalent form of breach or attack, experienced by almost four in 10 businesses and rated the most disruptive by seven in 10 of those affected. Among businesses breached, more than half experienced only phishing. Fraud is not parallel to the cyber security threat. For most organisations, fraud is the cyber threat picture.

I anticipate the Minister will tell me that fraud is handled elsewhere: in the Online Safety Act, the reimbursement rules and the fraud strategy. However, I make two points. First, none of those regimes places a security and resilience duty on cloud providers or marketplaces in respect of the systems on which essential activities depend. Secondly, a regulatory architecture in which every regulator assumes that fraud is everybody else’s business is precisely how a gap of this size opens up in the first place.

This amendment was raised in the other place by my honourable friend Victoria Collins MP. The ministerial answer was, in essence, that the words were unnecessary. I would rather have them explicitly in the Bill rather than rely on inference. If the Minister cannot accept the amendment, I ask for two assurances: that the guidance the Information Commissioner must issue under paragraph (4)(a) of Regulation 3 will address fraud risk explicitly, and that the statement of strategic priorities under Clause 25 will name fraud among the risks to which regulators must have regard.

I shall turn to just one other theme in this group; my noble friend Lord Clement-Jones will sweep up at the end in his winding-up speech. I wish to speak to Amendment 15 on workforce competence and skills, as well as on the issues raised in Amendments 174C and 174D, which also refer to cyber security capability. We are all concerned about the shortage of cyber skills and competencies in the workforce, but one place where that has to start is with young people in schools and colleges. I sought to table an amendment calling for the Government to publish a strategy on improving the cyber security awareness and resilience of children and young people through education. Sadly, the PBO ruled it out of scope, but I hope that we might have that issue in mind. If we are going to get the increase in workforce skills and competence on cyber security that we vitally need, we need also to have an eye on developing those skills in our young people, who spend so much of their lives online. I beg to move.

18:45
Lord Ravensdale Portrait Lord Ravensdale (CB)
- Hansard - - - Excerpts

My Lords, I declare my interest as a chief engineer working for AtkinsRéalis. I shall speak to Amendment 82.

In our debate on group 3, a lot of good points were made about one specific technology related to cyber: AI. However, as the noble Lord, Lord Birt, said in the debate on the previous group, quantum is the other area that needs attention as a specific technology. When I started here around seven years ago, I never thought that I would one day be talking about quantum mechanics in your Lordships’ House.

I recently heard the story of Heisenberg and his discovery of the uncertainty principle, almost 100 years ago in 1927. He was out in a park late one night, after a long argument with Niels Bohr, and he saw a row of street lights. He saw a person walking in between the street lights late at night. He would see them go past one light—you would be able to observe them—and then they would disappear into the darkness and they would then reappear at the next light. He realised that he could use that analogy for the behaviour of the electron: as it was being measured, it was there as a particle, but, when it was not being measured, it had to be considered probabilistically because you do not know where it is. In the same way, with a quantum computer, the value of the qubit, as it is called, is locked in only when it interacts with a measurement device.

This extraordinary powerful technology is now emerging. As an example, the Willow chip, which has recently been developed by Google, completed a benchmark calculation in five minutes. It would have taken the fastest classical computer in the world 10 septillion years—that is 10 with 24 zeros, I believe—to complete it. According to the Parliamentary Office of Science and Technology and the NCSC, in less than 10 years—perhaps even sooner than that—we could have a cryptographically relevant quantum computer that uses Shor’s algorithm to decrypt all communications that rely on the RSA algorithm on which we have relied for decades for all of our bank transactions, state-level communications and so on. This is an area of technology that is moving extremely quickly, and it is not just one about which we will have to worry at some point in the future. So-called “harvest now, decrypt later” attacks could be used to decrypt sensitive information in the future.

That brings me to the amendment. It is quite a simple, straightforward one, which goes forward from the discussions on how, given the changing nature of these technologies, it is perhaps not appropriate to have specific technologies and timelines in the Bill. However, as the Minister has already brought out, the statement of strategic priorities is a powerful tool to ensure national join-up, including across those regulators within the remit of the Bill.

We have 12 regulators and each one could approach quantum crypto—so-called post-quantum cryptography—differently. There will be huge benefits in really ensuring that regulators work from the same national signal rather than inventing their own PQC expectations individually. That would also allow them, if it can be brought out in the statement of strategic priorities, to plan their inspections, guidance, skills and capacity around the NCSC timelines, which is a plan ranging from 2028 discovery and initial plan through to 2035 when post-quantum crypto implementation is completed. That will also help with all those newly in-scope firms that will be coming within the remits of this legislation, giving the regulators a legitimate basis to raise post-quantum crypto with those new organisations early on.

I read back the Minister’s remarks at Second Reading, when she said that quantum crypto

“would be considered as part of that requirement by regulated entities, but would not necessarily be singled out as a specific technology in the regulation so that we keep these regulations up to date and matched to the cyber risks that individual entities face”.—[Official Report, 14/7/26; col. 622.]

I believe that this amendment would help strengthen and deliver exactly that. With that, I look forward to hearing from the Minister on her thoughts about this approach.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, I will speak to this substantial and rather disparate group of amendments, including Amendments 93 to 95 in my name, Amendment 10 tabled by my noble friend Lady Ludford, and a number of other amendments in the names of other noble Lords, including that of the noble Lord, Lord Arbuthnot, who, sadly, is in the Chamber as well.

Under Amendment 10, comprehensively introduced by my noble friend Lady Ludford, we would ensure that digital service providers manage risk arising from AI-driven fraud which, as she explains, represents over 40% of reported crime in England and Wales. I thought she made an extremely convincing case and I very much hope that the Minister takes what she said to heart and adds the very few words that are required to make this Bill much more secure with regard to the kind of phishing activity that she described.

As regards the various amendments relating to skills, beginning with the workforce and competence deficit, in its latest 2025-26 workforce study, ISC2 reveals that 52% of UK cyber professionals identify skills shortages as their single greatest obstacle to regulatory compliance, with 58% of organisations facing critical skills shortages. Regulation without competence is what might be described as pure compliance theatre. That is why, on these Benches, we strongly support Amendment 15 in the name of the noble Lord, Lord Arbuthnot, which would place a direct statutory duty on regulated organisations to ensure that their security leads possess verified competence, alongside Amendment 114 from the noble Lord, Lord Holmes, which would require the Secretary of State to define the objective qualifications and independent criteria for appointing skilled persons.

We also see critical implementation blind spots in distributed infrastructure. In July, as documented in the “Analogue 72” Green Paper, which I have mentioned before, a small UK electricity generator was taken offline for four days following a suspected state-sponsored cyber attack. Because it fell below the statutory reporting size threshold, local responders had zero visibility of the disruption. If small distributed energy assets are paralysed, the compound threat to local grids is severe.

Amendment 82 tabled by the noble Lord, Lord Ravensdale, rightly addresses quantum decryption. I am afraid that, if we are not careful, we are back in the territory of technology agnosticism. I think that across the Committee we have a fundamental disagreement with the Government about that. Hostile states are actively executing “harvest now, decrypt later” operations. By requiring the Secretary of State to incorporate NCSC post-quantum cryptography timelines into strategic priorities, we would mandate preparation for quantum-resistant encryption across all critical sectors. We very much support the amendment tabled by the noble Lord, Lord Ravendale.

Amendment 93 in my name would introduces mandatory eight-week public consultations before secondary regulations or codes of practice are issued, protecting industry and SMEs from closed-door administrative creep. I think that is the kind of area where the Minister could give further assurance.

Amendment 94 in my name would establish a statutory presumption of conformity for organisations achieving ISO/IEC 27001 or Cyber Essentials Plus certification. This safe harbour would eliminate legal ambiguity, reward gold-standard cyber hygiene and free regulatory resources to focus on high-risk, non-compliant entities, while preserving the regulator’s right of rebuttal. As the Minister can imagine, this has considerable industry support.

In Clause 40, my Amendment 95 would shorten the legislative cycle from five years to three years. We also support the alternative in Amendment 95A from the noble Lord, Lord Arbuthnot, which probes an even tighter two-year window, and his Amendment 95B, which I have signed, which would ensure that future statutory reviews must explicitly assess third-party and supply-chain dependencies originating outside the regulatory perimeter. Furthermore, we support the noble Lord, Lord Arbuthnot, in his proposed new Clauses 174C and 174D mandating competency standards and annual workforce strategies—we are just sorry that he is not here and able to speak to those amendments—alongside Amendment 92B from the noble Viscount, Lord Camrose, requiring large businesses to report transparently on their cyber resilient plans.

We have not heard from the noble Viscount regarding the other Conservative Front Bench proposals, but we are sympathetic to the need to review information sharing and analysis centres, ISACs, under Amendment 169 and to expect clear regulatory funding plans under Amendment 174. Furthermore, holding the Government to their commitment under the National Audit Office’s 2025 report and the Cyber Action Plan, under Amendment 170, is important. However, we are less supportive of Amendments 173 and 175, which attempt to make commencement of the entire Act conditional on publishing the National Cyber Action Plan. In our view, that would potentially create a dangerous delay, holding our national resilience hostage to Whitehall paperwork when our hospitals and utilities need protection today.

Lord Markham Portrait Lord Markham (Con)
- Hansard - - - Excerpts

My Lords, I thank the noble Baroness, Lady Ludford, for introducing this group. I am generally supportive of the principles she is introducing, and I thank all noble Lords who have spoken in this debate. I particularly enjoyed trying to get my head round ten septillion, however many zeros that was, on that computing.

Moving first to our amendments, I hope that there was something constructive in this debate trying to build on a lot of the things that the noble Lord, Lord Birt, said in the previous group around giving people tools for self-help in a lot of this because we know that the Government cannot be expected to cover every aspect. Starting with the amendment in my name and that of my noble friend Lord Camrose, Amendment 92B builds on a similar principle to that underpinning our support for a voluntary referral scheme, that being that businesses and individuals should, where practical, be self-sufficient and self-accountable with regard to cyber security. The more that businesses are responsible for their own security, the less the state has to look over their shoulders: I think that is of benefit to both parties. Requiring a large business to report its own cyber security and resilience plan provides an impetus. The idea is that you want the board to ask the chief executive and the executive team, “What are you doing in this space?” and hold them to account for the shareholders. If the answer to that is a big fat zero, that would clearly be concerning. That act of informal, nudging pressure—call it whatever you want—would be quite a call to action that any self-respecting chief executive and board would take heed of.

19:00
Our Amendment 169 attempts to maximise the effectiveness of our information sharing and analysis centres, whether private or public, in the case of the NCSC. Organisations that exist to support the entities covered by the NIS regulations will inevitably have sector-specific expertise, and if there is a chance to utilise that expertise, the Government should do so.
Our Amendment 170 would require the Secretary of State to report annually on the Government’s progress towards meeting the existing requirements and implementation deadlines. Naturally, it is a function of both Houses of Parliament to hold the Government to account over their own targets, so I hope that all noble Lords will get behind this and that the Government will support it too.
Our Amendments 173 and 175 would make the commencement of the Bill conditional on the publication of the national cyber action plan. On the point raised by noble Lord, Lord Clement-Jones, we are not trying to delay this in any way, shape or form. Of course, we want it to be quickly enacted but, at the same time, I think we would all say that it is vital that there is a cyber action plan that we can look at, and we are trying to use this as a tool to say, “Can we please have some action in this space?”
Our Amendment 174 would require the Secretary of State to lay before the House a funding plan for the key provisions before commencement. The remit of the regulatory authority is being expanded and its responsibilities increased. If it is to be meaningful, it must come with a proportionate increase in its resources and support.
I will touch briefly on several other amendments in this group. I am grateful to my noble friend Lord Arbuthnot—who, with impeccable timing, has just entered the Room—for what he is trying to do in Amendment 174D. Cyber security is best achieved when the strategy is system-driven rather than entity-based. I support the principle behind the amendments in the names of my noble friends Lord Holmes and Lord Arbuthnot around making sure that skilled people are in place. The Secretary of State should help to mandate that and define the standards by which someone should be considered an expert.
Lastly, I am grateful to the noble Lord, Lord Clement-Jones, for his amendments, in particular, Amendment 95, which would reduce the maximum interval between legislation and operational reports from five years to three years. That is welcome. The world of cyber security is ever changing and it will do so with increased speed as our AI continues to develop. A five-year maximum timeframe is simply too long for any Government to reflect on the effectiveness of existing legislation. I hope that the Minister will take that point, along with the others I have made.
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank noble Lords for their amendments in this group, which I will endeavour to cover in my response, starting with the lead amendment from the noble Baroness, Lady Ludford. Fraud risks and fraud are indeed important to address. The Bill requires relevant digital service providers to prevent or mitigate risks through an all-hazards approach. We already expect RDSPs to address risks posed by fraud as part of their security duties. The reason why we do not single out risk posed by fraud is that this may not reflect the full range of risks faced. It is important that regulators in their guidance, for example, in respect of the ICO, respond to the risks that their sectors are experiencing, which could include fraud. I heard clearly the facts that the noble Baroness set out, but that will be something that will come in due course.

On the important points made by the noble Lord, Lord Ravensdale, on the risks posed by quantum computing, the “all hazards, all threats, all technologies” approach enables a flexible and future-proof regime. It is important that each version of the statement of strategic priorities is not bound by the risks posed by specific technologies because they could become outdated; it cannot necessarily prefigure what will be a particular risk in 10 years’ time. Post-quantum cryptography is incredibly important. The department is working on guidance documents that will support organisations to manage their transition, in line with the NCSC guidance and deadlines. On the question specifically about the next statement of strategic priorities, we will encourage regulators through the statement to understand the evolving threat landscape and adapt their regulatory response accordingly, which could include risks from quantum or fraud, if those are the most pressing ones at that time.

On the approach suggested in Amendment 94 by the noble Lord, Lord Clement-Jones, we appreciate good practice standards, and we continue to promote their adoption across the wider economy. However, a more advanced cyber security framework is required to ensure adequate protection and assurance for the services in scope of the Bill. I am confident that the Bill’s outcomes-based approach is the right one. It allows existing good practice to contribute to demonstrations of compliance with existing and future requirements. We will introduce security and resilience requirements in secondary legislation. These requirements will be linked to the security duties and will provide clearer outcomes that organisations in scope must meet. We are engaging with regulators and industry throughout this development, and we intend to consult on these proposals later this year.

I turn to the question of how regulated entities demonstrate their compliance with their duties. Amendment 92B seeks to require large businesses in scope to report on their cyber security and resilience plans. Our proposed security and resilience requirements under the Bill will require regulated entities to maintain overarching security policies, implement a continuous risk management framework, maintain incident response and recovery plans, and ensure appropriate board-level oversight of these. This will be supported by guidance from regulators which must be regarded. Entities would be expected to maintain evidence demonstrating compliance with these requirements. The information provided to regulators and the NCSC will enable effective regulatory supervision, which holds organisations to account, and will enhance wider threat and resilience analysis and support. This will feed into government monitoring and evaluation, where public post-implementation reports will provide insights and assess the effectiveness of the regime. I will come on to the timing of those later.

The UK’s corporate reporting framework is currently undergoing wider modernisation efforts. Future consultation will seek views on whether the existing risk reporting framework produces sufficient reporting on cyber risk management, so it is best dealt with as part of that work.

On funding and information sharing in Amendment 169, ISACs can play an important role; there are many initiatives under way, many of which are supported by the NCSC. They have a voluntary approach which builds trust and brings about positive cultural changes. We believe that there is a real risk that the Government could undermine these benefits and complicate the regulatory landscape by intervening and recasting these initiatives as mechanisms of regulatory oversight and enforcement. However, I agree that more can be done to understand their impact, and how the Government can support them. That is why the Bill’s formal review mechanism was included, which will consider the entirety of the regime’s impact, including for information sharing.

Coming back to the question of regulator funding, and to expand a little on the new cost recovery powers to ensure that regulators are able to recover the full costs relating to their NIS duties, this will enable regulators to be autonomously funded and sufficiently resourced to carry out their responsibilities. We will also enable regulators to better focus their resources through establishing a unified set of objectives through the statement of strategic priorities. The current framework therefore already ensures sufficiently and independently funded regulators, without a delayed commencement of the regime. To respond to the question posed earlier by the noble Baroness, Lady Neville-Jones, it is anticipated that fines levied under the regime would go to the Treasury.

On the absolute criticality of skills in the sector and Amendments 15, 174C and 174D from the noble Lord, Lord Arbuthnot, and to all those who spoke on skills and cyber capability, the Government absolutely agree that workforce is crucial for effective implementation of the regime. I have previously set out how we intend to introduce security and resilience requirements, which will be consistent with the CAF. We propose that the SRRs will address organisational capability and personnel skills and training, driven from board level. These requirements will be developed in collaboration with industry, experts and regulators and formally consulted on before they are mandated. The SRRs will be supported by regulator guidance, tailored by sector, as well as government implementation guidance for regulators. We do not believe that additional guidance and a separate strategy would be proportionate, and it could be duplicative given the existing guidance published under the Bill.

Cyber skills obviously go much broader than the Bill. That is why we are working closely with the UK Cyber Security Council and regulators to encourage cyber training and professional standards. Additionally, we have TechFirst, the Government’s flagship tech skills programme, which goes to the point made by the noble Baroness, Lady Ludford, everywhere from school children through to professionals and the university sector.

Briefly, we talked earlier about skilled persons and Amendment 114. I mentioned earlier that a skilled person is a person with expertise. However, we do not think that we should tie the Government’s hands to specific skills requirements, which would reduce the Secretary of State’s flexibility in this space and could impede the regulated entity’s ability to take the necessary action required by the direction.

On the question of reporting, we recognise the pace of cyber developments alongside the importance of regular assessments of the regime. We must be as effective as possible and agile in the face of new developments. Amendments 95 and 95A, tabled by the noble Lords, Lord Arbuthnot and Lord Clement-Jones, would reduce the period that the report on the operation of the legislation should be published to every three or even two years. As raised in the other place, the five-year period set out in the Bill is a minimum baseline and the Government will consider more frequent reports if deemed necessary. This framing follows the precedent set by the Telecommunications (Security) Act and the existing NIS regulations. This will provide the Government with the time they need to meaningfully review the cross-sectoral regime, analyse the information received from regulators and understand how it has evolved, and identify what improvements can be made.

However, I stress that the Bill will also require the Secretary of State to provide Parliament with an annual report setting out how regulators have sought to achieve their objectives set out in the statement of strategic priorities. This annual report will enable more frequent monitoring of the regime and how it is working in practice by reporting on the regulators who implement it. The first report will be published one year after the publication of the SSP, which is targeting 2027. As a result, we anticipate that the first report would be published under two years after Royal Assent.

19:15
Amendment 95B would require the report to explicitly assess the impact of supply chain and third-party dependencies on the resilience of regulated persons. The regime places duties on regulated entities to identify, assess and manage risks, including those posed by their supply chains, which will be strengthened by supply chain duties which we propose to include in the SRRs. Through the designated critical supplier measure, we will safeguard the cyber resilience of our essential services’ most critical suppliers.
As the Bill already requires the report on the operation of the regime to assess whether the overall objectives of the regime have been met, this would include considerations of the frameworks’ supply chain measures. The Bill’s delegated powers will also enable us to specify additional topics which must be covered in each report if needed. However, as supply chain resilience is a core component of the framework, specifying this as a factor to consider in the statutory report would not be necessary.
I turn to the Government Cyber Action Plan and Amendment 170, tabled by the noble Viscount, Lord Camrose, which touches on how Parliament holds the Government to account for their own cyber resilience. We strongly welcome the reports from the Public Accounts Committee and the National Audit Office on the Government’s cyber resilience. In response, we have already adopted a duty to provide biannual reporting on progress against the recommendations of these two reports. The Government Cyber Action Plan sets out clear accountability structures to ensure that cyber risks at all levels of government are actively owned and managed, with those responsible held to account.
In respect of the NCAP—the national cyber action plan—and Amendments 173 and 175, I reassure noble Lords that we remain committed to publishing the national cyber action plan and we will update Parliament upon its publication.
Finally, I turn to Amendment 93 from the noble Lord, Lord Clement-Jones. It is essential that the proposed measures I have spoken to are appropriately consulted on. That is why the Bill already contains consultation provisions in relation to the issuing and revising of a code of practice, the use of the Bill’s regulation-making powers, and the powers of direction. At times, a public consultation may be appropriate. That is why we have already indicated our intention to publish a consultation on key elements of the Bill’s implementation.
However, a full public consultation will not always be proportionate to the proposal. This could be the case where a very specific set of individuals or organisations are likely to be affected, whose views can be sought by targeted engagement, or where the consultation deals with highly technical issues or minor amendments. When it comes to matters of national security in particular, decisions are likely to be highly time sensitive. Requiring extensive public consultation ahead of issuing a direction would delay urgent action and increase risks to national security.
The Bill already requires the Secretary of State to consult the intended recipient of a direction and any other persons deemed appropriate before issuing a direction. This requirement may be waived only when this would not be practicable or holding a consultation would be contrary to national security interests. This exception also exists for issuing designated vendor directions in the Telecommunications (Security) Act 2021.
I thank noble Lords for their amendments, which touch on many aspects of implementation of the regime.
Lord Ravensdale Portrait Lord Ravensdale (CB)
- Hansard - - - Excerpts

My Lords, can I clarify the Minister’s response to my amendment? She stated that the statement of strategic priorities should not refer to specific technologies, implying that it is difficult to change. The reasoning behind my amendment was precisely because the statement of strategic priorities is a more flexible instrument than having these targets in the Bill. I think there is no question of the threats posed by quantum cryptography and the need for better join-up. Can the Minister clarify her comments on the statement of strategic priorities?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

The content of the statement of strategic priorities will be subject to consultation and we will be working with regulators on that. It could include specific risks, whether from quantum or from fraud. What I do not want to do right now is to commit that it will include that, because we are going through a process.

Baroness Ludford Portrait Baroness Ludford (LD)
- Hansard - - - Excerpts

My Lords, I thank the Minister for her reply. Her last words gave me a little bit more hope than the rest of her response, to be honest, when she said that the statement of strategic priorities could include specific risks, because it seemed to me that she was otherwise being a bit generic and unspecific—almost above the fray. When I came in on a previous group—and other noble Lords are much more knowledgeable and expert in this field than I am—I picked up some frustration that the feedback from the Government and from the Minister today was a bit vague and not very responsive. All this is happening out there; there are huge cyber threats and there is a feeling that the Government are not really getting to grips with the actualité quite as much as they might.

I understand that the Minister might not be able to say now what will be in the statement of strategic priorities, but what we are searching for is that it will grapple with real problems out there in the economy, in society. I must admit that Amendment 82 from the noble Lord, Lord Ravensdale, on post-quantum cryptography, is somewhat above my pay grade. I wish I was more knowledgeable, but I ain’t. But I understand what he is saying, how real this is: the threat is out there. You just have to read newspapers to get the drift of what is happening. I mentioned that fraud is nearly half of all crime, so these are big issues. I think that what we want from the Government is a feeling that they get it, that there is going to be specificity in the way that they are going to implement this Bill and that they are really going to be on the case of these big threats. The Minister’s last words were a bit more encouraging than some of the rest of what she has been saying. That said, I am sure we will come back to some of these issues on Report, but I beg leave to withdraw my amendment.

Amendment 10 withdrawn.
Amendments 11 and 12 not moved.
Clause 8 agreed.
Clause 9: Managed service providers
Amendments 13 and 14 not moved.
Clause 9 agreed.
Clause 10 agreed.
Amendment 15 not moved.
Clause 11 agreed.
Clause 12: Critical suppliers
Amendment 15A
Moved by
15A: Clause 12, page 10, leave out lines 27 and 28 and insert—
“(a) P supplies goods or services, whether directly or through one or more intermediaries, on which an OES for which the authority is the designated competent authority materially depends for the provision of an essential service,”Member's explanatory statement
This amendment would allow regulators to address material dependencies beyond immediate contractual suppliers, while ensuring that the statutory review tests whether supply-chain risks outside the regulatory perimeter are undermining resilience and does so at a frequency that reflects technological and threat-related change.
Lord Arbuthnot of Edrom Portrait Lord Arbuthnot of Edrom (Con)
- Hansard - - - Excerpts

My Lords, I apologise for having spent less time in Committee than I would have liked, but I have been speaking on the Public Office (Accountability) Bill. I am grateful to those noble Lords who I suspect have been speaking to amendments on my behalf.

Amendments 15A and 15B are about the designation of critical suppliers. New Regulation 14H says:

“A designated competent authority may designate a person … under this regulation if P supplies goods or services directly to an OES for which the authority is the designated competent authority”.


The Bill expands this regime to cover additional organisations and creates a new framework for designated critical supplies. That is good, and it recognises that essential services depend on organisations that go far beyond the direct infrastructure of the critical organisation itself; everything is dependent on everything else. However, the critical supplier test is focused on suppliers providing goods or services directly to a regulated organisation. That ignores the concept of a supply chain with several tiers of suppliers. These amendments are intended to address that. Therefore, I beg to move.

Lord Ravensdale Portrait Lord Ravensdale (CB)
- Hansard - - - Excerpts

My Lords, I will speak briefly to my Amendment 16. In my view, the central problem is that, if I am small or medium-sized firm, I cannot currently tell with any confidence whether I am within the scope of the Bill as a critical supplier. Small and medium-sized enterprises are the lifeblood of our economy, and we need to approach with caution any ambiguity around their inclusion in the Bill. I took note of what the Minister said at Second Reading, when she said that:

“They can be regulated if they are designated as critical suppliers, for which there will be a high bar for designation”.—[Official Report, 14/7/26; col. 622.]


That was helpful, but what exactly is that high bar?

To give noble Lords an example of regulation legislation that is not defined, I come back to one noble Lords are likely to be familiar with: the infamous IR35. With that, the uncertainty and costs of getting it wrong were high in the regulation, so firms applied a blanket under which everyone they engaged with had to be inside IR35 and had to be treated as an employee. IR35 addressed a real problem, but the test was judgment-heavy and getting it wrong was expensive. That was why many organisations stopped making case-by-case decisions and applied a blanket policy, which meant that far more were caught by the regulation than was intended. I remember many years ago, as an engineer, spending a lot of time trying to fill in IR35 determinations and not doing engineering, which was a frustration at the time. It led to many issues with finding the right new skilled resource that we required to undertake the work.

I am sure that the Minister will say that the criteria will be set out in secondary legislation, but there will be a long period of uncertainty, and the IR35 example helps illustrate the risks. I took a look at the impact assessment and some of the costs were laid out. For example, if a firm is within the scope of this legislation, it is looking at physical security costs of perhaps £114,000 and cyber security spending—potentially of £190,000 a year. The impact assessment could not say how many SMEs may be designated within this legislation. All of that uncertainty is a cost, because it means that, if firms are uncertain about whether they are going to included, they may delay investment. In fact, they may overprepare; they may take on additional costs, which has wider implications to the UK economy, or they may walk away from public services. They will not want to go for these contracts because of the risk they may fall under this legislation, and that could potentially cause the same grit in the wheel of the economy that was seen in IR35. There is a case here for providing in the Bill at least some additional definition on what a critical supplier is; that is what my amendment intends to do.

19:30
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, I shall speak in support of this group on designated critical suppliers. I support in particular Amendments 15A and 15B, which were tabled by the noble Lord, Lord Arbuthnot of Edrom; I have signed them both. We are also sympathetic in principle to Amendment 16 in the name of the noble Lord, Lord Ravensdale.

We on these Benches fully support the principle of regulating managed service providers and designated critical suppliers. Because MSPs and key vendors act as trusted bridges into multiple enterprise networks, a single compromised supplier can trigger a systemic, cross-sector shutdown; we saw this in the Collins Aerospace attack, which halted airport check-in systems across Europe. However, we must ensure that our regulatory net is both deep enough to capture hidden systemic risks and precise enough to avoid catching non-critical small businesses.

In our view, Amendments 15A and 15B in the name of the noble Lord, Lord Arbuthnot, achieve the necessary depth. They would empower regulators under Clause 12 to designate critical suppliers that supply essential services or managed service providers through one or more intermediaries. In modern digital architectures, systemic single points of failure often sit at tier 2 or tier 3 in the supply chain. If an essential service materially depends on a sub-tier vendor, regulators must not be blinded by the absence of a direct contract. By pairing Amendments 15A and 15B with Amendment 16 in the name of the noble Lord, Lord Ravensdale, we could ensure that deep supply chain risks are policed, while protecting small innovators from bureaucratic overreach.

Lord Markham Portrait Lord Markham (Con)
- Hansard - - - Excerpts

My Lords, I thank my noble friend for introducing this group; as it is the final group of the day, I will keep my remarks brief.

Amendments 15A and 15B in the names of my noble friend Lord Arbuthnot and the noble Lord, Lord Clement-Jones, seek to allow regulatory oversight of critical suppliers on whom operators of essential services and relevant service providers depend, be it directly or indirectly. We believe that this must be a reasonable approach. The aim of Clause 12 is to ensure the continued functioning of the central suppliers and providers by providing support for their critical suppliers. Surely whether they are supplied directly or indirectly is of little importance.

Amendment 16 from the noble Lord, Lord Ravensdale, would restrict the designation of critical suppliers to those who present systemic risk rather than a simple single-entity risk. We should seek to minimise government oversight wherever possible, and suppliers should not be designated unless they pose a genuine risk. I am also supportive of the noble Lord’s focus on cross-sectoral consistency and general macroeconomic risks, which is too often something that the Government neglect.

However, I am hesitant to endorse the amendment in its entirety. Having to assess every supplier of every OES, RDSP or RMSP and having to decide whether it meets the systemic threshold have the potential to place an unrealistic administrative burden on designated competent authorities. We are already concerned about the resources that they will need to undertake the changes that the Bill introduces; I am unsure whether we need to ask more of them.

To wrap up, I return to a more general point: the risk to the economy or to national security is a scale, and the legislation that we pass should reflect this. Perhaps the noble Lord, Lord Ravensdale, is correct that the designation of critical suppliers based solely on whom they serve is too permissive, but it is equally as likely that restricting designation to systemic risks would be too restrictive. This highlights—it goes back to earlier groups—that the binary distinction about which we are talking now does not cover the gradation of different types of risk. That is why I come back to the original point that my noble friend Lord Camrose made on adopting, perhaps, the Cyber Monitoring Centre’s severity scale, which offers a template for a more nuanced approach to definitions. I hope that the Minister can commit to reviewing the Bill’s definitions ahead of Report.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank noble Lords, in particular the noble Lords, Lord Arbuthnot and Lord Ravensdale, for engaging with the incredibly important question of drawing the right scope in the Bill for the designation of those in the supply chain. It is incredibly important that we get this right and take into account the economic and security impact. To begin, let me explain our reading of the amendments and the practical impact they would have.

Amendments 15A and 15B would enable regulators to designate suppliers as critical beyond those which directly supply to regulated entities, if they are materially dependent on that supplier to provide the regulated service. This would extend the scope of the measure to include suppliers further down the chain, even where they have no direct relationship with the regulated entity. In addition, the amendments would introduce an additional assessment of whether a regulated entity is materially dependent on a supplier, which would form part of the designation process. This could create a higher bar for designation of a direct supplier than currently exists in the Bill and could limit designation by excluding suppliers whom it would be reasonable and prudent to include.

The Bill recognises the importance of supply chain security, has considered the risks that supply chains pose and has developed targeted and proportionate measures to address those risks. First, regulated entities are subject to an overarching duty to identify and manage the risks posed to the systems they rely on to provide their services. A core part of this is to consider the risks arising from their supply chains. Secondly, as will be set out in the forthcoming security and resilience requirements, we will require regulated entities to take specific steps to manage their supply chains through an analysis of the risks they could pose, and to include a requirement to put in place contractual obligations on those suppliers to manage the immediate risks and the risks posed further down the supply chain, which may not be in the immediate view of the primary regulated entity. Thirdly, it is recognised that some suppliers in the market are critical to certain sectors and therefore the most proportionate step is to regulate them in their own right and to subject their security posture to the scrutiny of regulators.

This clause is already designed to be a proportionate and targeted measure and is aimed at bringing into scope only those suppliers who are genuinely critical to the regulated entities they supply directly. Finally, as we discussed at the beginning of this Committee, some suppliers may present additional risk and are potentially the vector of attack from hostile actors. That is why we believe that we need to take measured but decisive steps to manage that risk before it crystallises and before those vendors are embedded in critical systems. The amendments would significantly increase the number of potential suppliers that regulators may need to consider for designation and could risk imposing additional burdens on smaller suppliers that may be several layers removed from the regulated service.

On Amendment 16 in the name of the noble Lord, Lord Ravensdale, I agree that a supplier should be designated only where they are genuinely critical to the provision of a regulated service. That is why the Bill includes strict designation criteria that must be met before a supplier can be designated. Importantly, an incident affecting the systems relied on by the supplier could disrupt regulated services in a way that significantly impacts the economy or the functioning of society. The Bill maximises the proportionality of the measure so that only the most critical suppliers to regulated entities are designated. It will also limit the number of small and micro enterprises that are likely to be designated.

The noble Lord’s amendment intends to limit that further. Its intention is to focus on suppliers whose activities being disrupted would cause systemic risk to the UK’s digital ecosystem, economy or essential services, and to prohibit designation if a supplier provides goods or services only to a single operator of essential services, a critical national infrastructure entity or a public authority.

We discussed a little earlier in Committee the risk of small but risky suppliers. Amending the designation criteria to focus on systemic risk to a wider number of entities could potentially leave many of the UK’s most essential services vulnerable to disruption. In fact, the compromise of just one of these providers could still have a significant impact on the economy or functioning of society in the UK or any part of it. Under the noble Lord’s amendments, a supplier that is essential to a single energy provider responsible for a county’s power, an NHS hospital looking after a whole city or a single cloud service provider used nationwide may not be judged as posing a systemic risk if it were disrupted. This would leave these essential end services vulnerable to severe disruption if that supply were compromised, with significant impacts for the huge number of citizens relying on them.

The amendment would also require the Government to issue statutory guidance for regulators on designating critical suppliers. I agree that consistency in the decisions taken by regulators will be crucial to the success of this regime. That is why my department will work with regulators to develop guidance to drive this consistency, and regulators will be required to consult with other regulators before designating suppliers where there is a relevant connection to multiple sectors. As we have discussed before, the statement of strategic priorities will also provide common objectives for regulators, which will further increase alignment between their approaches.

I heard very clearly what noble Lords said in introducing their amendments and the important other contributions during this discussion, which highlight how important it is to strike the right balance for this measure. I believe that the Bill establishes a proportionate and targeted framework that captures genuinely critical suppliers without extending regulation or excluding risks within the supply chain.

Lord Arbuthnot of Edrom Portrait Lord Arbuthnot of Edrom (Con)
- Hansard - - - Excerpts

My Lords, I listened carefully to what the Minister said. She made some very reasonable points and she may even be right, but I will need to take it away and think about it. In the meantime, I beg leave to withdraw my amendment.

Amendment 15A withdrawn.
Amendments 15B and 16 not moved.
Clause 12 agreed.
Clauses 13 and 14 agreed.
Committee adjourned at 7.43 pm.