AI: Human Extinction

Lord Clement-Jones Excerpts
Tuesday 15th September 2026

(5 days, 13 hours ago)

Lords Chamber
Read Full debate Read Hansard Text Watch Debate Read Debate Ministerial Extracts
Baroness Twycross Portrait Baroness Twycross (Lab)
- View Speech - Hansard - - - Excerpts

My noble friend raises a number of interesting points. It is true that we need to address this internationally. AI clearly crosses national borders. It is not like previous forms of new technology. We need to find the way forward in getting the balance right. We have been using our opportunity to lead internationally in having those conversations across borders as one of the leaders in AI safety.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - -

My Lords, I declare an interest as a consultant to DLA Piper on AI regulation and policy. Just two weeks ago, the Government resisted a proposal from Members right across this House to introduce an AI kill switch into cyber legislation on the grounds that the Government were “technology agnostic”. How agnostic does the Minister feel today?

Baroness Twycross Portrait Baroness Twycross (Lab)
- View Speech - Hansard - - - Excerpts

I presume that the noble Lord is referring to the amendment tabled to the Cyber Security and Resilience (Network and information Systems) Bill. One of the things that we have done is introduce the Bill and the guidance to work through that. I know that my noble friend Lady Lloyd will be happy to talk further with the noble Lord about this. One of the issues with a kill switch is that it would be impossible for Britain simply to turn AI off. Another issue is the extent of people’s concerns about whether a kill switch could or would work, but I know my noble friend Lady Lloyd would be delighted to speak further to the noble Lord.

Moved by
92C: Clause 37, page 62, line 24, leave out subsection (7)
Member’s explanatory statement
This probing amendment would remove the power for the Secretary of State to amend this Act by regulations so as to change the consultation and parliamentary scrutiny requirements applying to a code of practice. It responds to the recommendation of the Delegated Powers and Regulatory Reform Committee in its 7th Report.
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, I think that we are in the final furlong. In moving my Amendment 92C, I will also speak to the closely aligned Amendment 95C under my name. These amendments raise a profound and non-negotiable constitutional principle. They respond directly to the almost always authoritative recommendations of the Delegated Powers and Regulatory Reform Committee in its seventh report of this Session and are strongly supported by the principles laid down by the Select Committee on the Constitution in its third report. Together, these amendments seek to delete two deeply objectionable provisions that represent a classic example of secondary legislation creep—provisions where the Executive are seeking a blank cheque to unilaterally rewrite the rules.

Amendment 92C targets Clause 37 and seeks to leave out subsection (7). Under the Bill as drafted, Clause 37(7) grants the Secretary of State the unilateral power to make regulations to amend the Act to change and potentially dilute the consultation and parliamentary scrutiny requirements that apply to a code of practice. This is a Henry VIII power of quite an extensive kind. In the Government’s original delegated powers memorandum of November 2025, the department, as it then was, argued that this power was necessary to allow flexibility in case a 40-day parliamentary scrutiny period became, in its words, “unfeasible” or

“a detriment to the quality of … a code”.

But as the Delegated Powers Committee correctly noted in its seventh report, the rules governing how Parliament scrutinises the Executive must be set by Parliament in primary legislation; they should not be subject to the administrative convenience of a Minister. Allowing a Minister to use secondary legislation to alter or weaken the very procedural safeguards that this House has debated is not constitutionally correct. The committee’s recommendation is clear and unambiguous: subsection (7) must be removed.

That brings me to Amendment 95C, which seeks to leave out Clause 40(5). Clause 40 requires the Secretary of State to lay a report before Parliament on the operation of this cyber security legislation. However, subsection (5) grants the Secretary of State the power to amend this primary legislation via regulations to change the matters to be covered in those same reports. Again, in their original November 2025 memorandum, the Government defended this by claiming that they needed flexibility to ensure that reports could be expanded over time as technology matures.

With the greatest respect, that argument is entirely spurious. If the Government merely wish to report on more things, they are already fully entitled to include voluntary supplementary chapters in their reports. But by granting themselves a statutory power to amend the legal requirements of Clause 40, they are taking the power to delete or dilute the core mandatory reporting obligations that Parliament has put in the Bill. They would, in effect, be legally empowered to write their own report cards, deciding behind closed doors what they must disclose to Parliament and what they can quietly omit, including critical scrutiny over how they have used the vast delegated powers under Clause 29(1).

The Delegated Powers Committee was again clear. This power is inappropriate, lacks coherent justification and should be deleted from the Bill. The Select Committee on the Constitution too, in its third report, expressed serious anxieties about the overall design of the legislation. It warned that this is a framework Bill that relies far too heavily on secondary regulations to establish the actual perimeters of national cyber resilience.

When a Bill already delegates such sweeping unprecedented powers to the Executive, amplified by the amendments to introduce a parallel high-risk vendor framework, laid on 24 August and discussed on the first day of this Committee, it is doubly important that the statutory channels of parliamentary oversight remain supreme. We cannot allow the Government to use secondary regulations to dismantle the guardrails that keep them accountable. I urge the Minister to accept these common-sense, committee-backed corrections and agree to delete Clause 37(7) and Clause 40(5) before Report. I beg to move.

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

My Lords, I thank the noble Lord, Lord Clement-Jones, for opening the final day of Committee. For a Bill of such importance, I am surprised at the speed of our progress. However, if quantity has been low, quality has more than compensated.

I agree with the noble Lord that this Committee deserves rather more justification from the Government as to the need for the powers they are granting themselves. The Delegated Powers and Regulatory Reform Committee described the Clause 37(7) power as “unusual” and “novel”, capable of watering down requirements for consultation as it is not constrained by set criteria. The Government’s justification thus far for this power is that it allows them to

“prioritise the content of the code of practice, rather than arbitrary requirements”.

It sounds to me rather as if the Government’s position is that they see any set requirements for consultations and codes of practice as arbitrary. If that is the case—I would appreciate clarification from the Minister—I have to agree with the committee’s description that the position is “quite extraordinary”.

By the way, I noted this morning that the Chancellor of the Duchy of Lancaster has demanded an end to the culture of consultation. I fear that that will be quite a wrench for the former DSIT and its functions, it having launched four new consultations on a single day in July without having responded to the more than 11,000 responses to the AI and copyright consultation. We are already unclear about the machinery of government for that former department. Can the Minister tell us whether its existing and planned consultations will continue or whether today’s announcement represents a fundamental change of approach?

It is not clear why the power conferred by Clause 40(5) has to be sufficiently broad to allow the Government to water down the contents of reports on network and information systems. Could it not be amended, as the committee has recommended, so that the power cannot be used to reduce the requirements to report? It is not unreasonable to question whether the Government really need these extensive powers. Your Lordships’ Committee deserves at least more justification than the Government describing set criteria as arbitrary. I appreciate the need for flexible and adaptive approaches to legislating for fast-moving technologies, but that must come with accountability and I am not sure that we have the balance right at this point. I look forward to the Minister’s response.

Baroness Ramsey of Wall Heath Portrait Baroness in Waiting/Government Whip (Baroness Ramsey of Wall Heath) (Lab)
- Hansard - - - Excerpts

I thank the noble Lord for his Amendments 92C and 95C, and note that these amendments were recommended by the Delegated Powers and Regulatory Reform Committee in its report of 17 July. Some noble Lords may be aware that, until very recently, I was the chair of that committee. I am wondering how best to describe myself: am I gamekeeper turned poacher or poacher turned gamekeeper? I had better let noble Lords decide at the end of my responses.

These delegated powers were included to prevent a scenario where procedure takes priority over the best possible products, whether that be a code of practice or a report on the legislation. The delegated powers will not allow Ministers to bypass Parliament. They are about ensuring that government can respond quickly and effectively to new threats and new technologies that could undermine our national security. The law has always been slower than innovation, and it is unlikely to catch up unless we change our approach. Ministers must provide clear justification and carry out assessments before regulations are laid before Parliament.

On the code of practice, we anticipate that any code will be updated from time to time to remain effective, in line with the latest recommended good practice, evolving threat information and emerging technologies. Any revisions and reissues of a code of practice must first be consulted on with relevant stakeholders before they are effective.

On consultations, it might be above my pay grade to comment so soon after the Chancellor of the Duchy of Lancaster has commented, but I am sure that my noble friend the Minister will have a further response to that at some point, possibly in writing.

I assure noble Lords that the Government are carefully considering the committee’s recommendations and the views of noble Lords today, and will reflect accordingly ahead of Report. My noble friend the Minister will respond formally to the Delegated Powers and Regulatory Reform Committee in the usual manner ahead of Report.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

I thank the Minister for her response, which was the reverse of the usual ministerial response—the sting was not in the tail but at the beginning. The end was much more conciliatory, given that she said the Government will consider taking on board the DPRRC’s recommendations before Report. I very much hope they do. At this stage in Committee, of course, nothing gets decided, but I assure the Minister that, if this continues, and the Government do not respond in some shape or form to both those pretty solid recommendations from the committee, we will bring this back on Report.

When I say that the sting was in the beginning of the response, I mean that it was a bit surprising, given that the Minister has been the chair of the committee and knows the seriousness with which we all take its recommendations. A huge amount of work goes into the detail, and she knows how much store we place on the recommendations. I hope that she will use all her influence to make sure that the Government introduce before Report something along the lines of what I have produced. In the meantime, I beg leave to withdraw Amendment 92C.

--- Later in debate ---
Baroness Northover Portrait Baroness Northover (LD)
- Hansard - - - Excerpts

My Lords, all the amendments that I have put down to the Bill are derived from evidence we received on the National Resilience Select Committee. I am sorry that I was not here last week to address those that came up then, and I am very grateful to my noble friend Lord Clement-Jones for presenting them for me.

Several members of the Select Committee, including me, were in Finland last week looking at its preparedness for attack. Finland has faced the threat from its long border with Russia throughout the history of its country, and its preparedness on a whole-of-society basis is extremely impressive. Although we do not have a long border with Russia to focus our minds, we know that cyber attacks can immediately undermine our whole society and economy. One of the things we heard on our Select Committee is that not only are many companies unprepared for cyber attacks but that there is a shortage of skills in this area.

This amendment is seeking to move things forward. The proposed new clause would

“give the UK Cyber Security Council statutory functions to validate qualifications, to monitor the supply of and demand for cyber security professionals in the areas covered by the Bill, and to audit whether regulated organisations employ certified professionals—a ‘competence mandate’ for the regime”.

I have received some useful information from the sector, which welcomes my attempt to try to ensure that we have sufficient cyber professionals and that there is a mechanism by which they are certified. There are analogies with the certification of medical professionals, for example. Their certification is conducted independently, and I recognise the importance of that. What I am arguing for here is the principle and not necessarily the route suggested by my amendment. How this is best done can be further discussed between Committee and Report.

The National Cyber Security Centre reported that nationally significant cyber incidents have more than doubled in a year. According to its survey, only 7% of UK businesses have formally reviewed the potential cyber security risk presented by their wider supply chain. Evidence to our Select Committee suggests that skills shortages are a key challenge here, especially for SMEs and those in the public sector. It is clear that cyber education, training and apprenticeships, and so on, must accompany these reforms.

The Bill places greater responsibility on organisations to identify and manage cyber risk. However, beyond those technological solutions, these obligations will require skilled professionals to carry them out. The Bill refers to the appointment of a “skilled person” in the context of a national security directive but does not delve into what constitutes a skilled person. I realise that this will change over time, but there should be ways of addressing this.

Neither does the Bill acknowledge the role of skilled persons in delivering its wider objectives. Those in the field have called on the Government to amend the Bill to require organisations to access a cyber security workforce that is qualified to recognise professional standards. We know that this skills shortage exists, weakening our national resilience. One report showed that 87% of organisations experienced at least one consequence due to skills need, so it is becoming strategically important to address this. The Government should use the Bill as an opportunity to professionalise the sector by committing to a cyber security workforce and skills strategy, and mandating that regulators and regulated entities use suitably skilled people for the purposes of compliance with the regulation.

Recognised professional qualifications and certifications anchored in international standards should be required so that we and the regulators are reassured that the work is being carried out to a certain standard. The UK Cyber Security Council was granted royal chartered status to establish a self-regulating, politically independent professional body, structured on proven models of other professional bodies such as the GMC. The UK needs to transition from a fragmented patchwork of varying certifications to a unified national standard of professional competence and ethical conduct.

Therefore, the Bill should recognise the council as the authority for setting and maintaining these standards. Given that the Bill aims to enhance the security and resilience of the UK and the critical sectors that underpin our economy, that needs to be assisted by a suitably skilled workforce to implement it. Of course we need to take further action to make sure that we train people, but this amendment is designed to help move this forward by ensuring that those in this area are sufficiently skilled. I beg to move.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, I was hoping that there would be other contributors—there will be a double-banking on this amendment.

I support Amendment 99, tabled by my noble friend. Throughout our deliberations on this Bill, the Government have placed enormous emphasis on imposing tough, outcomes-based statutory duties on operators and suppliers across our critical infrastructure, but we must confront an uncomfortable truth: we can pass the most sophisticated cyber security regulations in the world but, if our economy lacks the trained, qualified human beings required to design, implement and maintain those defences, those regulations remain completely meaningless. Without a professional workforce capability, this Bill merely codifies what ISC2 has rightly termed “compliance theatre”—an expensive box-ticking exercise that produces mountains of paperwork without making our national networks one bit safer.

Look at the scale of the crisis facing our domestic cyber workforce. In its landmark 2025-26 cyber security workforce study, ISC2 revealed that 52% of UK cyber security professionals identify severe skills shortages as their single greatest barrier to complying with cyber regulations. Further, 58% of organisations reported a critical or significant skills deficit, with an astonishing 87% suffering direct operational consequences from missed system patches and delayed vulnerability remediation to active security oversights. Across the civilian economy, the UK currently faces an 88% shortage of certified cyber practitioners. In an environment of such extreme scarcity, how on earth do the Government expect regulated water utilities, transport operators and medium-sized managed service providers to fulfil the heavy duties created by this Bill?

Amendment 99, from my noble friend, would provide a structural solution to this workforce crisis by placing the UK Cyber Security Council on a formal statutory footing. Crucially, as she explained, this connects directly to the definition of a skilled person under Clause 43. If the Government are serious about raising our national resilience floor, they must recognise that human competence is just as vital as technological hardware. By embedding the UK Cyber Security Council’s competence mandate in primary legislation, Amendment 99 would ensure that our cyber laws are backed by the skilled workforce needed to defend us.

I strongly urge the Minister to accept this amendment. By professionalising our cyber workforce, we would elevate this Bill from more than a compliance exercise to a genuine national capability.

Lord Vaizey of Didcot Portrait Lord Vaizey of Didcot (Con)
- Hansard - - - Excerpts

My Lords, I intervene in support of the amendment in the name of the noble Baroness, Lady Northover. I do not want the Liberal Democrats to be on their own, so I hear the call from the noble Lord, Lord Clement-Jones. It brings me back to the coalition days, when I and the noble Baroness, Lady Northover, were once Ministers in the same department—so my support is heartfelt.

I support the substance of the amendment. As the noble Baroness, Lady Northover, says, it may not necessarily be the right amendment but the spirit behind it is absolutely one that the Government should recognise. I was a bit concerned when the noble Baroness was outlining the intention behind the amendment whether it could perhaps be seen as a burden on business, particularly when we talk about small businesses and the need to audit their cyber preparedness. However, to recall my contribution at Second Reading, I said at the time that, although we tend to debate cyber in the Chamber and other places as a great threat that we need to address, it is also a fantastic economic opportunity. I should declare that I am an adviser to a company called Digital Futures, which trains software developers. We do not train them in cyber but obviously the need to build up a skilled workforce in cyber is absolutely essential.

The noble Baroness, Lady Northover, referred to the patchwork of qualifications that exist in this area. It seems to me that the Government have a clear opportunity and a clear role to guide us through the maze and to put the National Cyber Security Centre on a statutory footing to give it the ultimate role in deciding the appropriate qualifications in cyber and to begin a sustained campaign to show young people, people returning to the workforce or people who are considering a new career that there is a route through to recognised, well set out cyber qualifications that will contribute to the national economy and our cyber resilience. I therefore wholeheartedly back this amendment.

--- Later in debate ---
Lord Birt Portrait Lord Birt (CB)
- Hansard - - - Excerpts

I think we all share the sympathy that the noble Baroness, Lady Northover, has identified SMEs need. There are 5.7 million SMEs in the UK and many of them—indeed, most of them—will purchase what are relatively complex platforms. The noble Lord, Lord Londesborough, is extremely experienced in the SME sector; I have less experience than him, but I do have some. Hardly any of them will be able to employ anybody who is able to understand either the complexity of the platform that they have purchased or the highly dynamic threats to that platform that exist. There are many ways in which we need to raise our game and to help.

I personally think that, at least in the short term, the most important thing, which we have not discussed enough so far, is to require providers to supply safe products and, moreover, when they become vulnerable—which happens all the time, often unexpectedly—to patch those products for their customers immediately. The providers have a level of sophistication that the customers do not, and we have insufficiently focused on that in our discussion so far.

The second thing to mention—this is not really part of the Bill—is that the Government’s Cyber Essentials programme is very sound. The Minister quoted a figure the other day, which I forget, but only a trivial number of businesses have signed up and taken the pledge. This needs much more publicity and much more dynamism from within government to raise the understanding of the level of threat that SMEs face.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, I too support Amendment 100, in the name of my noble friend Lady Northover, and will add my support to the very useful speeches from the noble Lords, Lord Vaizey, Lord Birt and Lord Londesborough. I entirely agree with the noble Lord, Lord Vaizey, about the need to inject a sense of urgency into this. The noble Lords, Lord Birt and Lord Londesborough, asked some very fair questions, which went back to some of the debate we had on a single regulator and product liability, all of which are relevant to the kinds of duties that SMEs are under.

I welcome what the Minister had to say about the Government’s consciousness of the needs of SMEs, but this amendment would provide a blueprint for a much better form of support for SMEs. They account for 99% of all private sector businesses but, as the NCC Group and industry experts have repeatedly warned, they represent what might be described as the soft underbelly of our national supply chains. They are the prime targets for cyber criminals seeking a backdoor into critical infrastructure.

It is completely unrealistic to expect a 60-person small supplier to bear the same heavy compliance overheads as a multinational utility. A single ransomware attack can permanently destroy a small firm. Hostile state actors and ransomware syndicates are no longer focusing exclusively on attacking the fortified perimeters of FTSE 100 utilities or government departments; instead, they deliberately target smaller, resource-poor suppliers and niche contractors embedded in tier 2 or tier 3 of critical supply chains, using them as an easy, undefended backdoor into our critical national infrastructure.

Under the expanded critical supplier provisions in Clause 12 and the managed services duties in Clause 9, thousands of medium-sized businesses and specialised tech vendors will now be pulled directly into the statutory NIS regime, facing severe regulatory requirements under threat of multi-million pound penalties. However, as the Government’s own impact assessments acknowledge, there is a staggering what might be called resource asymmetry across UK businesses. A 50-person specialised component manufacturer or regional logistics provider does not have a dedicated chief information security officer or possess a 24/7 security operations centre and cannot afford to hire elite forensic incident response teams on £500-an-hour retainers. When a sophisticated ransomware attack hits a small business, it is frequently an existential event that forces insolvency.

During Committee stage in the Commons, when my honourable friend Freddie van Mierlo MP brought forward this proposal, the Minister in the Commons rejected it on the grounds that the Government already provide voluntary advice online. A downloadable PDF checklist on GOV.UK is not an incident response service. When a small critical supplier is locked out of its servers by a Russian ransomware gang at 2 o’clock on a Sunday morning, a generic website checklist is completely useless. It does not need advice to check its passwords; it needs an active, human, technical first responder to help it contain the malware, isolate compromised systems and safely recover its data.

Amendment 100 would bridge this capability gap by mandating a dedicated national support service modelled directly, as my noble friend explained, on the proven and globally respected Australian Cyber Security Centre’s framework. In Australia, the federal Government provide small and medium-sized businesses with free direct phone-in emergency technical support, active breach triage and hands-on recovery assistance. It has achieved extraordinary success in hardening Australia—

--- Later in debate ---
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

To continue, if the state is going to impose heavy, legally binding supply chain security duties on small businesses, backed by turnover-based fines, the state has a moral and strategic obligation to provide the operational tools needed to meet those standards. By establishing a free, Australian-style digital safety net under Amendment 100, we would turn the Bill from a purely punitive compliance exercise into a genuine co-operative national partnership for cyber resilience, and I urge the Minister to accept this vital common-sense amendment.

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

My Lords, I thank the noble Baroness, Lady Northover, for her amendment and, needless to say, I support the intention behind it. It is clearly right that, having placed several new duties on businesses and their vendors, the Government consider how to ensure that they are able to carry them out. This is particularly the case for SMEs, which are often far less resilient, less well-resourced and more vulnerable to cyber attacks than their larger counterparts. But, when thinking through this idea, I was trying to come up with some sort of framework to estimate the costs of such a provision, and I just could not arrive at a satisfactory estimate, except that they would be very considerable, particularly given the urgency, complexity and difficulty of incident response.

As I think the noble Lord, Lord Clement-Jones, and others mentioned, providing advice on a government website is cheap and useful, but providing urgent incident response is far from cheap. That begs the question: would it be funded by the companies benefiting from this directly or the taxpayer? I am not sure that either is wholly satisfactory. The actual costs of running such a programme will depend largely on how it would operate and the terms of service it would offer. I am very grateful to the noble Baroness, Lady Northover, for pointing to the Australian example; I confess that I was unaware of it before and would be interested to know what service it provides and to what level. It is incredibly hard to estimate how it will operate and what terms of service it will offer. The rate of cyber attacks is non-linear, the scale, nature and complexity of each attack will vary significantly and the number of staff needed or resources available for a response at any one time would necessarily be volatile and unpredictable.

--- Later in debate ---
Moved by
148A: After Clause 52, insert the following new Clause—
“Appeals against decisions under section 50(1) A person may appeal to the Upper Tribunal against—(a) a confirmation decision given to the person under section 50;(b) a decision under section 50 to require the person to pay a penalty;(c) the amount of a penalty which the person is required to pay under section 50.(2) An appeal under this section must be brought before the end of the period of 28 days beginning with the day on which notice of the decision appealed against was given to the person, or within such longer period as the Upper Tribunal may allow.(3) The Upper Tribunal must determine an appeal under this section on the merits and by reference to the matters before it, and not by applying the principles that would be applied by a court on an application for judicial review.(4) On an appeal under this section the Upper Tribunal may—(a) confirm, vary or cancel the decision appealed against,(b) substitute for that decision any decision that the Secretary of State could have made, or(c) remit the matter to the Secretary of State with such directions as the Upper Tribunal considers appropriate.(5) Where an appeal is brought under subsection (1)(b) or (c), the requirement to pay the penalty is suspended until the appeal is determined, withdrawn or abandoned.(6) Tribunal Procedure Rules must make provision, for the purposes of proceedings under this section, about—(a) securing that information is not disclosed where disclosure would be contrary to the interests of national security,(b) the holding of proceedings, or of parts of proceedings, in the absence of a party or a party’s legal representative, and(c) the appointment of a person to represent the interests of a party in proceedings, or parts of proceedings, from which that party and that party’s legal representative are excluded.(7) Nothing in this section affects any right to apply for judicial review.”Member’s explanatory statement
This new clause would provide a right of appeal to the Upper Tribunal, on the merits, against a confirmation decision or a financial penalty imposed under section 50, with provision for the protection of national security material. It implements the recommendation of the Constitution Committee in its 3rd Report.
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, Amendment 148A stands in my name on the Marshalled List. This amendment would address a profound, structural and deeply disturbing gap in the judicial oversight and democratic accountability of the Bill. It represents a direct implementation of the authoritative recommendation of the Select Committee on the Constitution, in its third report of this Session.

Under Clause 50, the Secretary of State, acting as the direct enforcement authority for national security directions, is empowered to issue a unilateral confirmation decision that potentially imposes hugely significant financial penalties on non-compliant organisations. Under Clause 49, these penalties can reach a peak of up to £17 million or 10% of global turnover for commercial undertakings. Even for non-undertakings—such as our cash-strapped NHS trusts, local government authorities, or educational bodies—the penalty can be a crushing £17 million, with daily ongoing fines of up to £100,000 per day. Yet, under the Bill as currently drafted, the Government expect us to accept that the only avenue of legal recourse for an affected organisation to challenge these business-destroying fines is judicial review in the High Court.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I resume with Amendments 174A and 174B, which were introduced by the noble Lord, Lord Markham. They would require the Secretary of State to create a register of “foreign powers” that pose a threat to UK cyber security, to review this register and to lay the report in Parliament. This is intended to inform the use of the powers granted under Part 4 of the Bill. The noble Lord is right that hostile foreign actors pose a clear risk to our essential services. National security is the first responsibility of any Government, which is why we are addressing these risks actively, including through the Bill.

The Bill will grant the Secretary of State important new powers to issue national security directions to regulated entities or regulators, where their compromise poses a national security risk. We will seek to strengthen the Government’s national security toolkit further, to protect our supply chains from hostile actors. That is why we put forward a package of amendments to introduce new powers that would enable the UK to address vendor-related cyber risks by hostile actors in our critical infrastructure supply chains. I look forward to engaging noble Lords further on this essential package ahead of Report.

Any decision to use the powers in the Bill will be informed by expert national security advice, including from GCHQ. The direction powers provide a strategic case-by-case basis to safeguarding our national security, irrespective of the specific actor. As a result, a country-specific approach lacks the nuance required to assess and respond comprehensively to all relevant risks. We also need to proceed responsibly in how we categorise and present these risks in the public sphere.

That is not to say that we shirk transparency about these kinds of risk. The Government are already able to communicate with Parliament and the public about such cyber risks where it is appropriate to do so. As the noble Lord, Lord Markham, set out, the NCSC annual report highlights risks posed by foreign actors; we work with the NCSC to mitigate these risks.

I note that noble Lords have confronted this question before, notably during the passage of the Telecommunications (Security) Act, where there was cross-party support for vendors to be assessed on a case-by-case basis, rather than by designating nations themselves as hostile actors. I hope that, in that vein, noble Lords are reassured that the Government have the tools to act strategically, acting on the right intelligence where hostile states seek to do us harm.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

I thank the Minister for her response and the noble Lords, Lord Vaizey and Lord Markham, for their contributions. I cannot help feeling that the approach to this by the noble Lord, Lord Vaizey, is coloured by his history as a Minister. I can understand that because I saw the frustration within Ofcom over the type of judicial review. It was a particular type of judicial review: it was not a full merits-based appeal, but it allowed merits to be considered as part of the judicial review process. Subsequently, that was changed, which has probably calmed the way in which appeals are carried on.

However, in this particular case, although he said that he was not sighted as to the secrecy aspects of this, it was quite interesting to hear what the noble Lord, Lord Markham, had to say. He started by saying that he supported the amendment, then—rather coloured, I think, by the response of the noble Lord, Lord Vaizey—he did a bit of a U-turn halfway through what was a speech originally written in support. I am sure that he knows in his heart that this is the right one.

Really, the argument in this case is expediency versus justice. I think that choosing expediency, especially in the light of what the Constitution Committee had to say, would be extremely inadvisable. I was encouraged by the fact that the Minister is producing a memorandum in response to the Constitution Committee; we all wait with bated breath for when that arrives. In the meantime, I beg leave to withdraw my amendment.

Amendment 148A withdrawn.
--- Later in debate ---
Moved by
164: After Clause 58, insert the following new Clause—
“Computer Misuse Act 1990: statutory defence for cyber security activities(1) The Secretary of State must, within 12 months of the day on which this Act is passed, carry out and publish a review of whether the introduction of a statutory defence under section 1 of the Computer Misuse Act 1990 (unauthorised access to computer material) for persons carrying on legitimate cyber security activities is necessary or desirable to improve the security and resilience of network and information systems used or relied on in connection with the carrying on of essential activities.(2) The review under subsection (1) must consider, in particular—(a) the position of cyber security researchers, vulnerability testers and threat-intelligence practitioners acting in good faith,(b) the conditions and safeguards (including as to authorisation, proportionality and reporting) that any such defence should contain, and(c) the approaches taken in other jurisdictions.(3) On concluding the review, the Secretary of State must lay before Parliament a report which sets out—(a) the findings and conclusions of the review, and(b) whether the Secretary of State intends to bring forward proposals for such a statutory defence, and, if so, the intended timetable for doing so.”Member’s explanatory statement
This new clause seeks to place a statutory duty on the Secretary of State to review, within 12 months, whether a statutory defence under section 1 of the Computer Misuse Act 1990 for good-faith cyber security researchers and vulnerability testing is needed to improve the UK’s cyber resilience, and to report to Parliament.
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, Amendment 164 is in my name and, I am delighted to say, that of the noble Lord, Lord Arbuthnot of Edrom. Sadly, he is tied up next door with matters of national security—I hope that I am not giving away any secrets—and is unable to speak to this amendment, but I value the support that he has given as a long-standing campaigner for changes to the Computer Misuse Act.

This amendment addresses a long-standing, globally recognised and increasingly dangerous absurdity in our criminal law: the fact that our primary cyber crime statute, the Computer Misuse Act 1990, criminalises the very cyber security professionals who are actively working to defend our country. The Computer Misuse Act is now 36 years old. It was drafted in 1990—an era before the world wide web had entered public consciousness, when less than 0.5% of the British public had ever sent an email and when the entire concept of proactive, ethical vulnerability research was completely unimagined. Because the Act was drafted at such a primitive stage of the digital revolution, it contains a blanket, indiscriminate prohibition on all unauthorised access to computer material. In its current form, it draws no legal distinction whatever between a malicious hacker, backed by a hostile foreign state and seeking to sabotage our critical national infrastructure, and an ethical, good-faith cyber security researcher—a “white hat” hacker, if you like—seeking to discover and responsibly disclose vulnerabilities before criminals can exploit them.

The real-world consequence of this statutory blind spot is that British cyber defenders are forced to operate with one hand tied behind their backs. Consider the day-to-day operational reality: if an ethical researcher in the UK scans an internet-facing network, identifies a critical zero-day vulnerability that leaves an NHS hospital dataset or a municipal water control system exposed, and takes the basic technical steps necessary to verify the flaw, they have technically committed a criminal offence under Section 1 of the 1990 Act. They face prosecution and imprisonment, even if their actions were undertaken entirely in good faith, strictly in the public interest and followed by immediate responsible disclosure to the National Cyber Security Centre or the affected operator.

I and others have received overwhelmingly passionate representations from the CyberUp campaign, representing what might be described as the elite of our domestic cyber security industry. Alongside the Criminal Law Reform Now Network and the NCC group, its evidence is stark. It says that the chilling effect of the Computer Misuse Act is actively undermining our national cyber resilience. Leading UK cyber security companies are routinely forced to prohibit their researchers conducting proactive threat intelligence gathering and vulnerability research on UK-based infrastructure because the legal risks are unacceptable. When British researchers identify an active cyber threat originating abroad, they are legally constrained from investigating the command and control servers if doing so involves touching a remote system without explicit owner authorisation.

Meanwhile, our international competitors have moved ahead. The United States updated its Department of Justice charging policies explicitly to protect good-faith security research. Countries such as Portugal, France and Australia have established clear and legal safe harbours for ethical cyber defenders. As a direct result, British cyber talent and commercial investment are migrating overseas to jurisdictions where proactive defence is recognised as a public good, rather than a criminal act.

During the Bill’s passage in the other place and during our Second Reading debate, the Government’s response was to agree with the principle of reform while arguing that this Bill is not the appropriate vehicle. Ministers pointed to an ongoing Home Office review and suggested that reform must wait for a hypothetical future security Bill. We have been waiting for the outcome of that Home Office review for more than five years; it was kicked into the long grass of Whitehall interdepartmental delays while our critical network remained under siege.

There is potentially a contradiction at the heart of the Government’s strategy on this issue. On one hand, Ministers are using this Bill to impose sweeping new legal duties and heavy, turnover-based penalties on operators to secure their networks; on the other hand, the Government continue to criminalise the very security professionals and ethical researchers whom these operators must hire to test and harden their systems.

Amendment 164 would resolve this contradiction cleanly, decisively and safely. It seeks to insert a direct substantive statutory defence into Sections 1 and 3 of the CMA. An individual charged under the Act would have a complete legal defence if they can prove that their conduct was reasonable for the detection or prevention of crime, or that they were carrying on legitimate cyber security activities, specifically defined in the Bill as vulnerability research, penetration testing, threat intelligence-gathering or a responsible disclosure necessary to safeguard system security.

Crucially, this amendment would not create a free-for-all or a loophole for malicious actors. It would empower the Secretary of State to approve a statutory code of practice, setting out the precise standards, rules of engagement and reporting protocols that constitute legitimate, good-faith cyber security activity. Anyone who acts outside those clear standards remains fully subject to criminal prosecution. Let us also consider the significant economic dividend of this reform. Independent economic modelling from the CyberUp Campaign demonstrates that introducing a statutory defence for legitimate cyber security activities would add 9,500 high-skilled, high-wage jobs and generate £2.5 billion in additional revenue for the UK economy.

We cannot build a resilient nation by preserving laws written for the floppy disk era. In an age of automated AI exploits and state-sponsored ransomware, we must unchain our cyber defenders. We have been here before, and the Government’s arguments for delay have run completely out of road. During our debates and correspondence on the then Crime and Policing Bill and, previously, the then Data (Use and Access) Bill, the Government repeatedly acknowledged the strength of our case. The noble Lord, Lord Katz, stood at the Dispatch Box and conceded that the Computer Misuse Act is dangerously outdated and that the Home Office were actively preparing a statutory defence under Section 1 to protect ethical cyber security researchers. Indeed, in correspondence following those debates, Ministers confirmed that engagement with industry and system owners was well advanced, but their stock excuse for resisting our amendments was always the same: “This is the wrong legislative vehicle. Wait for the upcoming cyber security legislation”. Well, here we are—this is the cyber security and resilience Bill. If primary cyber legislation cannot fix the statute that actively criminalises our front-line cyber defenders, what on earth can?

When the Government updated law enforcement powers under the Crime and Policing Act to seize domains and IP addresses, Ministers were quick to assure us that police powers are tightly bound by the Police and Criminal Evidence Act 1984 and statutory exemptions under Section 10 of the CMA. Yet independent security researchers, who discover over half of all critical system vulnerabilities before hostile state actors can weaponise them, enjoy zero statutory protections. They are left entirely at the whim of prosecutorial discretion and the threat of catastrophic legal action. The review of the noble Lord, Lord Vallance, recommended this defence three years ago. The CyberUp Campaign and techUK have drafted the ethical safeguards. In correspondence, Ministers have told us that they agree in principle. It is time to honour those commitments and put a direct statutory defence in this Bill. I urge the Minister to support this vital amendment. I beg to move.

Lord Vaizey of Didcot Portrait Lord Vaizey of Didcot (Con)
- Hansard - - - Excerpts

My Lords, I strongly support the amendment from the noble Lord, Lord Clement-Jones, whether technically or in spirit. He is right to point out how outdated the Computer Misuse Act is and that its blanket prohibition on undertaking cyber security activities without any public interest defence is ridiculous.

The noble Lord’s amendment goes to the heart of the frustrations that have been expressed in debates on this Bill, particularly at Second Reading; sadly, I was not able to attend Committee last week, but I imagine they were reiterated again. This is an incremental and technical Bill that clears up some important anomalies. Time and time again, noble Lords have raised the point that it is missing the bigger picture. Now that we live in a digital age when absolutely everything depends on digital infrastructure, it seems to be absolutely extraordinary that we are not taking a much bigger view on updating our legislation, institutions, resources and skill base, to make this core infrastructure fit for purpose. It seems extraordinary to me that the Computer Misuse Act has not been touched for 36 years. It is well out of date. It may well be that there are other elements of it that have to be looked at.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I am grateful to the noble Lord for raising this topic through his amendment, and I recognise the strength of feeling on reforming the Computer Misuse Act. I agree that the UK should have the right legislative framework to allow us to tackle the threats posed by cyber criminals.

The Home Office has already carefully reviewed the Computer Misuse Act and proposes to introduce a defence to Section 1 for accredited cyber security researchers when carrying out certain cyber security activity that would currently be unlawful under Section 1 of the CMA. The Home Office has worked closely with the NCSC, law enforcement and the cyber security industry to refine these proposals. The noble Lord, Lord Clement-Jones, was briefed by Home Office officials on these proposals in February, and I hope this is able to demonstrate meaningful progress that the Government are making on this issue. The Home Office recognises that legislating in this area is a priority and will do so as parliamentary time allows. As noble Lords here are all aware, the King’s Speech in May included a commitment to a national security Bill, with measures to update the Computer Misuse Act, and work is ongoing to bring forward this legislation.

The review proposed by this particular amendment would be undesirable because it would be limited to the scope of the NIS regulations. This would be too narrow for the scope of the Computer Misuse Act; it is also unlikely to provide the Government with new information on how the Act should be reformed. I am sure that the noble Lord and others in this Room will be active in the passage of this legislation once introduced. I have read his correspondence with the Home Office, including the activities that the noble Viscount, Lord Camrose, referenced, and his expertise across all these areas will be hugely welcomed once it is introduced.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

I thank the Minister for that response. The noble Lord, Lord Vaizey, said that we know what the Minister will say: that it will be in a future piece of legislation. To that extent, we are pleased that at least we have a commitment to it, but this has been going on for an awfully long time. We tabled amendments during the passage of the Crime and Policing Act and the Data (Use and Access) Act. There has been plenty of time for the Home Office, or any other department to address this—DSIT could have taken this by the scruff of the neck—because it is such an egregious aspect of the current legislation.

I am pleased to hear that the Minister has read the correspondence. I hope she did not fall asleep while doing so; it is pretty interminable. She may well find that we come back to this on Report because, as she said at the beginning, feelings are running high about it. It is almost a demonstration of how not to run a Government. If you cannot get to grips with something as straightforward and important as this and just make a decision about it, that speaks volumes.

I thank noble Lords who have spoken today and demonstrated support across the board. On a light-hearted note, I say to the noble Lord, Lord Tarassenko, that of course Claude said that; it is trained on my speeches. As the noble Baroness, Lady Harding, said, this is self-evidently sensible. The trouble is, it is self-evident to us, but we despair sometimes, and the perfect must not be the enemy of the good. As the noble Baroness, Lady Neville-Jones, said, the objective is to put researchers in a safe position.

Finally, the noble Lord, Lord Vaizey, exhorted me to make sure that we have a date and a timeline. When will the national security Bill come forward? We saw it in the King’s Speech but I have had no contact from anybody in the Home Office about what they might insert in the Bill. I do not know whether anybody in this Committee has had notice of when a Bill might come forward. I think the Minister recognises the sheer impatience that most of us feel in this field, and I very much hope that, between Committee and Report, we can get some more clarity in this area for the benefit of all those researchers. In the meantime, I beg leave to withdraw the amendment.

Amendment 164 withdrawn.
--- Later in debate ---
The amendment proposes a requirement for the Secretary of State to consult on achieving the minimisation of identifiable data, while looking at deletion and at what needs to be kept. It is seen as constructive. Again, if there are other suggestions, I am happy to talk about the best ways of going about this, but I very much hope that all noble Lords will see that it is a sensible and pragmatic approach to try to deal with a problem. It would remove a lot of the juicy targets—for want of better words—from a potential attack vector in the first place. I beg to move.
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, despite the fact that this is the last group, it is a really important area and this amendment rightly reflects that. We strongly support Amendment 174E. It would introduce a fundamentally elegant and highly necessary cyber security principle that the Bill has otherwise completely ignored: that of data minimisation and the proactive reduction of what is called our national data attack surface.

The most sophisticated cyber defence system in the world cannot protect data that has already been stolen. Conversely, the most ruthless ransomware gang or hostile state-sponsored actor cannot compromise data that was never collected or which has already been securely deleted. In the realm of digital defence, we must move past the narrow defensive mindset of simply building thicker walls around our databases. We must begin to ask a more fundamental strategic question: why are we keeping these massive, un-anonymised and highly vulnerable data honeypots in the first place?

The empirical evidence from our public sector is deeply alarming. We have received detailed and coruscating briefings from the Centre for Long-Term Resilience and our technical authorities. The National Audit Office’s January 2025 report on government cyber resilience revealed that approximately 28% of government technology is legacy software, leaving our public bodies highly vulnerable to attack.

Consider the catastrophic ransomware attack on the British Library in October 2023. When the library refused to pay a ransom of 20 bitcoins, the Rhysida ransomware group released 600 gigabytes of stolen customer and staff data on to the dark web. The library’s own subsequent post-mortem was clear: its reliance on legacy applications and older network designs substantially and unnecessarily increased the volume of sensitive customer data sitting on the network. This was data hoarding, plain and simple, and the price was paid by the British citizens whose personal details are now permanently compromised.

Consider the hack by ExfilSquad, when normal teenagers living with their parents managed to breach a public database, leaking the sensitive personal details of 100,000 police officers and staff on the dark web, alongside data from the Ministry of Defence and the Department for Education. How did they do it? They did not deploy supercomputers or advanced zero-day exploits, they simply exploited a basic, misconfigured Power Pages database. The hackers’ own boast on the dark web was chilling. They said the data was accessible without any authentication whatever.

Why are these databases so large? Because our public bodies routinely collect and indefinitely retain vast, sprawling, unanonymised datasets, from birth certificates and benefit records to housing benefits and electoral roles, without any systematic statutory drive to minimise or anonymise them. That is why the Association of British Insurers and the NCSC both advise that data encryption and data minimisation are critical to reducing the leverage that a threat actor has in ransomware attacks. By rendering exfiltrated data unreadable through encryption—or better yet, non-existent through deletion—we take away the hackers’ ammunition.

While the Bill focuses heavily on the administrative paper exercise of incident reporting, it remains completely silent on the contents of the databases themselves. Amendment 174E would provide a strategic corrective. It would legally oblige the Secretary of State to open a public consultation within one month of the Bill’s passing to evaluate the cyber-resilience benefits of minimising data collection and increasing data anonymisation across our public bodies. By forcing our public sector to lead by example, this amendment could begin the vital work of shifting the UK towards a genuine resilience-by-design model. It would reduce our vulnerability, harden our national defences and protect the digital lives of our citizens. I urge the Minister to accept this vital safeguard.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank the noble Lord, Lord Markham, for raising this important issue again. Good data hygiene and security is essential to ensuring that public bodies are resilient to cyber attacks. Through the Bill, we are better protecting data, to make our essential services safer and more secure for all those who rely on them. This includes through security and resilience requirements, which will form part of the duties placed on regulated entities and which I have mentioned at previous sittings of this Committee. In our consultation later this year, we will propose that these requirements cover data security. 

Let me emphasise that where personal data is concerned, all public bodies must already comply with the data protection principles in the UK GDPR. This includes requirements to keep personal data secure, process only the minimum amount needed to deliver their objectives, periodically review whether this data is relevant and adequate for the public body’s purposes and not to retain this data for longer than is necessary. The Information Commission regulates the data protection legislation independently of the Government. It has a range of powers at its disposal to investigate alleged breaches and require public bodies to address non-compliant practices.

Significant obligations exist under the UK GDPR. In addition, our upcoming consultation will examine measures to strengthen data security within the security and resilience regulations. A separate consultation, as proposed by the noble Lord, would not be a good route through, but it would be a good idea for us to meet and think about the most appropriate route for advice on data security in the context of the SRRs. I suggest that we focus our discussion on the SRRs in the intervening period.

As this is the last time I will speak in Committee, I want to reflect on some of the points made by noble Lords. Obviously, productivity and growing the UK economy are big themes for all of us. It is true that we have progressed through Committee faster than perhaps people anticipated, but I have heard very clearly the points that have been made very succinctly, both on fundamental structural issues—to which, as I have said, I think the approach in the Bill is right, I am just logging the fact that I have absolutely heard the motivation for that, around consistency and so on—and indeed on some of the more technical points that noble Lords have made about some of the details of the Bill, some of which I have already undertaken to come back on.

I thank the Committee for its scrutiny and noble Lords for the experience they have brought to the Committee from their practical walks of life.

Baroness Neville-Jones Portrait Baroness Neville-Jones (Con)
- Hansard - - - Excerpts

My Lords, in moving Amendment 17, I will also speak to Amendment 28, which is closely related. Amendment 17 is in part a probing amendment about what constitutes an incident and the circumstances in which reporting is obligatory. It does not affect the amendment that I think the Government will move immediately afterwards.

As drafted, Clause 15 gives the very strong impression that an incident “capable of having” an adverse effect on security must be reported. If this is the case, it constitutes a much wider definition of what should be reported than if it were described as an incident “likely to have” an adverse effect. I think it is a widely held view—it is certainly the case in the industry and a point with which I agree—that “likely to have” would be far too wide a definition and would lead to extensive overreporting and an undue and unnecessary burden on regulators. Looking at the drafting, I asked myself what was the point of the “capable of having” definition in Clause 15.

I shall put forward a hypothesis. It would be very helpful if the Minister could confirm that it is a correct understanding of the existing draft, and that it does not mean that all incidents capable of having an adverse effect on security will need to be reported. Is it right to say that the definition in Clause 15 of what constitutes an “incident” applies across the whole of the regulations, and therefore feeds into security as well as reporting duties? That is to say, firms have a preventive duty to defend against what could be and what could happen, as well as what is likely to happen. That is a preventive duty. Can the Minister confirm that the phrase “capable of having” means that firms should have adequate preventive policies, but it is not—this is where the point comes in—the trigger for an incident to be reported, because in each case this requires it to have affected or be affecting the system?

I am making a distinction between “capable of having”, which applies to a duty to pursue preventive policies, and the trigger of the duty to report, which lies not in the phrase “capable of having” but in “likely to have”. Then there are examples of what I am saying in the regulations, and I can cite them: Regulation 11(3)(a), on page 21 at line 35; Regulation 12A(2)(a), on page 26; and Regulation 14E(2)(a), on page 29 at line 27. If the Minister can confirm that, within existing structures, what I have said is correct—there are no circumstances in which “capable of having” would be the reporting trigger—that would be a very helpful clarification. I will listen closely to the Minister’s reply on this point.

There is a “however”: there is a snag when it comes to the introduction of data centres, and that is the object of my Amendment 28. Data centres sit outside the existing structures that I have just talked about but, as yet in the drafting, there are no reporting trigger regulations for them. It is intended that the data centres should be, in future, big players in the system, so it matters that there is a gap in our information about the circumstances in which they would have a duty to report. It is an odd anomaly. New Regulation 11A(3)—on page 23, from lines 13 and 14 onwards—makes reportable

“an incident which could have had … a significant”

effect, whether or not it had any impact at all or anything was affected. As there is no list of factors for judging what constitutes a significant attack in the Bill, it makes it quite difficult to interpret.

For the operators of essential digital services and managed service providers, such factors are set out expressly in the new regulations in the Bill. However, they are absent for data centres. Why is this the case? What is the rationale for what appears an anomaly? It means that, when reporting an incident, a data centre has to do so when any of the following have had, or were likely to have,

“a significant impact on the operation or security of the network and information systems relied on to provide the data centre service … a significant impact on the continuity of the data centre service … or … any other impact, in the United Kingdom or any part of it, which is significant”.

These are very wide definitions of liability to report, and the discrepancy between them and those applying to other operators seems neither sensible from a security point of view nor fair for different business circumstances, as there will be all sorts of different businesses using data centres.

Although I hope that this will not be the case, I fear that the Government may say that the thresholds and factors for all categories of business will be set out in secondary legislation and subject to consultation. I ask the Minister to think hard about the adequacy of that reply. We are talking here about a penalty-backed duty, which is the core element of the Bill; it is not some minor point. It would seem a poor legislative approach in a foundational Bill for a new regime to fail to define the factors leading to a penalty for a significant segment of providers, when there are indicators in the Bill for other categories of provider. Those other players have different, less demanding and more sensible terms for a trigger for reporting. If data centre regulations need to be different from those for the other players that I have mentioned and the rest of the market, can the Minister explain why? It is the kind of complexity that will give the sectoral approach to regulation a controversial reputation, because it immediately raises the issue of making different rules for people who are apparently, in practice, in the same category. I hope that is not the case and that the issue can be resolved by remedying the drafting.

To sum up, in addition to my request for a clear statement from the Minister about the trigger for a duty to report in existing structures being related to the likelihood of an adverse effect on security and not on capability, I hope she will also take seriously the need to level the playing field for data centres on this issue and remedy what seems an important defect in the drafting of the Bill. I beg to move.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, I will speak to this core group of amendments on incident reporting, in particular to Amendment 165, standing in my name, while addressing the other amendments in this group. First, Amendment 17, which was very cogently set out by the noble Baroness, Lady Neville-Jones, addresses what has emerged as one of the most contentious technical faultlines, in our view, across Part 2 of this Bill: the statutory threshold that triggers mandatory incident reporting to the designated competent authority, the NCSC. As the Bill is drafted, Clause 15 fundamentally widens the reporting net by redefining a reportable incident to include any event that is merely “capable of having” an adverse effect on the security of network and information systems, as the noble Baroness described.

While one can readily understand the cyber security community’s desire for complete visibility, in practice, the phrase “capable of having” is an operational disaster. In the daily reality of enterprise networking, thousands of automated port scans, routine phishing lures and perimeter firewall probes occur every hour. Almost every single one of these low-level events is technically capable of having an adverse effect, if multiple defensive layers were to fail simultaneously. By forcing businesses to notify regulators under threat of £17 million penalties whenever an event is merely “capable” of causing harm, the Government will unleash an administrative tsunami of defensive reporting.

Rather than enhancing national security, this compliance overload will drown NCSC analysts in background noise, making it far harder to detect sophisticated state-sponsored attacks. Amendment 17, in our view, would resolve this by replacing “capable of having” with the objective standard of “likely to have”. This would restore the established probability threshold used across UK regulatory frameworks, ensuring that mandatory notifications are reserved strictly for genuine material threats where there is a real likelihood of operational compromise.

This issue is compounded by the Government’s own drafting amendments, specifically Amendments 19, 36 and 44, which replicate the ultra-broad definition of compromise throughout parts 2 and 3. By removing “users” from Clause 15 and redefining data compromise to cover any event affecting data stored or processed on a system, the Government are dramatically expanding the notification net to include technical data anomalies that cause zero destruction or loss to actual customers. Combining this sweeping definition of data compromise with the low “capable of having” trigger will hugely affect responsible operators. It will force critical suppliers and small digital providers to spend their limited resources filling in compliance paperwork, rather than actively defending their infrastructure.

We risk creating a reporting system that captures everything and understands nothing. We must have objective reporting thresholds. By accepting the noble Baroness’s Amendment 17, restoring the “likely to have” test, we would ensure that mandatory reporting delivers high-quality actionable threat intelligence, rather than an unmanageable flood of routine notifications.

Under the new reporting regime, hundreds of incidents will be notified to regulators and the NCSC, but at present the Bill lacks any mechanism to ensure that aggregate intelligence is shared with Parliament or industry. Under Amendment 165 in my name, I propose that the Government lay an annual anonymised report before Parliament, detailing incident volumes, sector breakdowns and principal attack vectors. This would provide software developers and CNI operators with the situational awareness needed to harden defences.

--- Later in debate ---
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

May I interrupt the Minister before she moves on to the next set of amendments? I do not intend to ambush her as regards her amendments this time around, but I seek an assurance, given that there seems to be quite a philosophical difference between her amendments today and those put forward by the noble Baroness, Lady Neville-Jones. There is considerable industry concern about the disproportionality involved. I seek an assurance from the Minister that, between Committee and Report, she will actively consult on the impact of this part of the Bill—Clause 15—and not just when it is in black-letter form. There is quite a lot of concern from many industry voices. It is incumbent on the Government to listen to those voices on the impact of this reporting structure and these duties before they go ahead in a way that many of us believe will not be helpful for the running of these businesses.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

We have already undertaken some consultation and I am happy to commit to contact affected businesses and business organisations and have further conversations between now and Report. Perhaps if I progress a little more, I may be able to answer some of the questions that may have given rise to some of this but, equally, there are different rationales for some different thresholds in the Bill, which, again, I am just about to come on to. I will set out the rationale for those because I think that they are well motivated and are linked to the risk profile that we see in the country and the connectedness of certain regulated entities in the country.

I turn to the amendments tabled by the noble Baroness, Lady Neville-Jones, and her questions to me on the link between the definitions and whether they apply beyond incident reporting. They apply to the security duties within the Bill, which means that regulated entities have a duty to prevent or minimise the impact of incidents. The amendments from the noble Baroness would limit this and reduce their security and resilience. We think that not every incident should be reportable but that organisations need to take appropriate and proportionate steps to mitigate the risks before, during and after a broader set of incidents.

On the second part of the noble Baroness’s amendments and her second question, the Government have recognised that the reporting threshold for data centres is broader than that for other regulated entities under the Bill. This reflects the distinctive role and risk profile of data centres. They are the physical infrastructure underpinning digital services across the economy and the public sector. Unlike the virtual cloud layer, for instance, they combine cyber, physical, personal and operational technology risks. This is particularly important in collocation facilities where infrastructure belonging to numerous customers is concentrated in one location. Then they need physical access to the premises and information about facilities or operational systems. A single incident could therefore exploit both physical and digital vulnerabilities, potentially affecting the confidentiality, integrity or availability of services belonging to multiple customers and sectors. The consequences may also extend beyond the facility’s immediate geographic location, because the hosted service can support users and central services elsewhere. That is the rationale for having this threshold applying to data centres.

To come on to the questions raised, including by the noble Lord, Lord Clement-Jones, on the use of the phrase “capable of”, and the points made in the amendment from the noble Baroness, Lady Neville-Jones, replacing “could have had” or “capable of having” with “likely to have” would exclude some incidents because their eventual impact was uncertain or successfully contained. It would also constrain the security duties, as I mentioned. In reference to the incident reporting definitions introduced by Clause 15, the subsequent detail sets out how the notification of incidents applies in each regulated sector, except for data centres. That is how the definition is made for regulated sectors other than data centres.

There are a lot of safeguards in the Bill to ensure that reporting remains proportionate. It is intended to capture significant near misses, not routine scanning, unsuccessful low-level attacks or ordinary operational events, and clear guidance will ensure that the industry understands this threshold. As the noble Baroness, Lady Neville-Jones, pointed out, we will set this out in secondary legislation and that will allow the consultation to take place that the noble Lord, Lord Clement-Jones, emphasised is so important—we agree with that. We have undertaken extensive engagement to date and will continue to do so.

--- Later in debate ---
Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - - - Excerpts

My Lords, I rise to introduce a large number of amendments, for which I apologise: Amendments 18 to 23, 25 to 31, 33 to 39, 41 to 47 and 49 and 50.

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - - - Excerpts

Full house. Fear not—it is not as complex as it seems. These amendments, which I have introduced, and I am grateful for the support of the noble Baroness, Lady Kidron, and my noble friend Lord Holmes of Richmond, seek to strengthen the staged reporting requirements of the four different groups of entities, so each change must be repeated four times. Because of the way in which the Bill is drafted, I was unable to introduce the change just once; I had to put in each micro phrase, hence so many amendments. The aim is to strengthen the staged reporting requirements for operators of essential services, data centres, relevant digital service providers and relevant managed service providers, so everything is multiplied by four.

The Bill, as it stands, requires only an initial report within 24 hours and a full notification within 72 hours of an incident. My amendments would add two further stages: an intermediate report which is capped at 14 days after the incident has first been notified, or sooner if the relevant regulator requires, and a final report within one month. In all four cases, the reports must be given without undue delay, so that regulated entities cannot use the timeframes as an excuse to delay until the end of the time period.

These amendments are in line with the EU’s NIS2 directive. The reason why I have introduced them, as I said at Second Reading, is that I have lived this. I absolutely understand what the fog feels like. In the first moment when you have been attacked, you do not understand what has happened: you do not know who is attacking you, you do not know what they could have stolen, you do not know where they have gone, but you do know that it is serious. That is your first report. You start to understand, 72 hours later, quite how awful it could be. That is your second report, where you start to get real data, because your teams have worked all night, usually all around the world, to try to work out where the malign actors have gone. But it is really only after a couple of weeks that you have a proper sense of what has happened.

I recognise that my experience is, obviously, 10 years old, but quite recently I had a long conversation with some of the leaders at Marks & Spencer. The thing that scared me most was that it seemed so similar to my experience 10 years ago and that this basic process is likely to be the same. So we need the requirement to properly update whatever you learn two weeks on, and then a month later the fog starts to clear and you have a proper sense of the real scale of the problem.

The reason why we need to put this in legislation is that, throughout that entire period, all the incentives for you, as a corporate leader, are not to say anything. This is the biggest corporate taboo. Your board will be encouraging you not to tell everyone, the public will be telling you not to tell everyone and there is a real risk, unless you are forced to, that you just make it easier for the blackmailers to do their work. My personal experience was of being blackmailed during this process. Obviously, at the time, there were none of these regulations. I can tell your Lordships that there were so many voices saying, “Why don’t you just shut up? You don’t know what’s going on yet. Keep quiet”. Yet if, in the fog, you share this information with regulators and with law enforcement agencies, that is how the law can prevail. It is how regulators can work out what is happening and how they can warn others who might be affected. It is how the law enforcement agencies can do their work to try to find the bad guys.

This really matters if we want the rule of law to exist in the digital world, because the incentives, even for entirely well-meaning and upstanding leaders of corporations—and government departments, dare I say—are to keep quiet. We need to put these reporting requirements in the Bill. All the amendments would do is bring our own legislation in line with the NIS2 framework. To be honest, many of these companies and these incidents are likely to need to be reported in Europe at the same time as they are in the UK. As my noble friend Lady Neville-Jones said, there is a real primacy on keeping things simple. The more we can mirror and have exactly the same reporting requirements, the easier it will be when you are in that terrifying moment when you realise that you have a serious incident. I beg to move.

--- Later in debate ---
Lord Arbuthnot of Edrom Portrait Lord Arbuthnot of Edrom (Con)
- Hansard - - - Excerpts

My Lords, good can come out of bad events. The experience, as well as the speech, of my noble friend Lady Harding is one such good aspect. If it combines with bringing us into line with European practice, which so many businesses already have to follow, so much the better. I hope the Minister will be as sympathetic as she possibly can to my noble friend’s amendments.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, I very strongly support this set of amendments on the staged notification of incidents. This is a significant group of amendments from the noble Baroness, Lady Harding, and so well supported by the noble Baroness, Lady Kidron, and the noble Lord, Lord Holmes; he has illustrated this extremely well. As has been described, the noble Baroness, Lady Harding, has a great deal of experience. She brings an invaluable perspective to this Committee, having led a major telecommunications provider through one of the most high-profile corporate cyber breaches in British history. She speaks from real experience and understands very clearly what happens inside an organisation in the immediate aftermath of a severe attack. We should listen extremely carefully to what she has to say.

In those critical opening hours, incident response teams and forensic engineers are working under an intense fog of war, so to speak, actively fighting to contain the malware, to isolate compromised servers and to protect customer data. We cannot expect an organisation to produce an exhaustive, multivariable forensic post-mortem within the first few hours of a fast-moving operational crisis. Yet, as Clause 15 currently stands, the reporting pipeline that follows the initial notification is left thin and unstructured. The noble Baroness’s amendments fix this with three-stage architecture, which is mirrored clause by clause across each category of regulated entity: operators of essential services, data centres, relevant digital service providers and relevant managed service providers.

I will not add much more, as noble Lords have already spoken extremely eloquently. Cyber incidents do not likely conclude on the day a final report falls due. Where an incident is still live at the point that the final report is owed, the entity must instead give a progress report on the information known to date, followed by the final report within one month of the incident ceasing. That seems to me to be a very sensible and realistic accommodation of how live incidents unfold.

Finally, I turn to the amendments tabled by the noble Lord, Lord Ashcombe, although I do not see him here in Committee. They would extend the deadline for the full notification from 72 hours to 30 days. I understand the underlying concerns, as 72 hours can be an unforgiving window in which to complete a full investigation and analysis. However, it is the amendments from the noble Baroness, Lady Harding, that deliver what we need. Intermediate reporting exists precisely so that the authorities are not left in the dark for weeks at a time. Taken together, the noble Baroness’s amendments replace a single blunt deadline with a structured, predictable reporting line, which gives business clarity on exactly what is required and when, while ensuring that the NCSC and our competent authorities receive high-quality, structured intelligence, rather than a single, rushed snapshot. As she said, this is the kind of staged discipline that the EU’s NIS2 directive already reflects and which this Bill should emulate.

Lord Markham Portrait Lord Markham (Con)
- Hansard - - - Excerpts

As per the points made by other noble Lords, this is a prime example of when you realise how valuable it is to have in this House and, in particular, in this Committee people who have lived experience. Because of that, this is a well thought out set of proposals; I thank my noble friend Lady Harding for bringing them before us, and I thank my noble friend Lord Holmes and the noble Baroness, Lady Kidron, for supporting them.

These amendments mirror a lot of what I saw from the other side when I was the Health Minister and we had the problems with Synnovis and testing. That is where I am coming from: you realise that you need some real teeth because, even though you have public bodies such as the NHS, which you think would listen to the Minister on certain requirements, that that does not always follow. The point made by my noble friend Lady Harding about everyone telling you to keep quiet applies to state organisations just as much as it does to private companies. Having teeth is an important part of all this and of making things happen.

The staged approach has been mentioned. In your first 72 hours, it is all about wanting just to get the information out there. One of my questions—I will come on to the rest in a minute—is: what are we doing on our side with that information? We must make sure that it is being used valuably and used to alert others. Only later on, around the 30-day mark, do you get into the “lessons learned” stage. So staged reporting would be a very sensible and well thought out approach.

That brings me on to another point; I would be grateful if the Minister could address it. If we are requiring businesses to provide such information to the Government very quickly, what will they get back? The strong justification for rapid incident reporting is surely that the NCSC can aggregate the intelligence, identify common attack vectors and vulnerabilities, and rapidly warn other organisations before they, too, are attacked. Obviously, that is the difference between regulatory reporting and genuine national cyber defence. I would be grateful if the Minister could explain the planning and what will happen operationally when one of these early notifications is received. How quickly will the information be assessed? How quickly will actionable intelligence be disseminated to other potentially vulnerable organisations? What obligations will there be on the Government and the regulators to ensure that the information provided by one organisation improves the resilience of everyone else?

Of course, there is a wider point here. Throughout our consideration of the Bill, we need to guard against measuring success by the number of organisations regulated or the number of reports submitted. Rather, the real test is whether fewer attacks succeed, whether we identify attacks faster, whether organisations can recover more quickly and whether intelligence from one attack prevents the next one. That is the outcomes we want this regime to achieve.

I hope that the Minister will look seriously at the principles behind these amendments, and in particular at whether we can achieve a reporting structure that gives the Government the information they genuinely need quickly while allowing organisations to concentrate their scarce cyber expertise on the thing that matters most: defeating the attack.

--- Later in debate ---
I am not entirely sure whether the amendments in the name of the noble Lord, Lord Ashcombe, were spoken to, but, as a precautionary measure, I resist the suggestion to extend the timeframe for submitting the full incident notification. His amendments would require the full notification to be submitted within 30 days of a regulated entity becoming aware of an incident, rather than the current deadline of 72 hours. This change would mean that regulated entities would provide no information to their regulators following the initial notification issued within 24 hours, which could create a worrying gap between the regulator’s and the NCSC’s awareness of the incident. Maintaining the rhythm set out in the Bill would mitigate that risk.
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, before the noble Baroness, Lady Harding, stands up, I heard what the Minister had to say about consulting across sectors. I was reminded that, at Second Reading, I mentioned the fact that the law firm with which I am associated, DLA Piper, was subjected to a NotPetya ransomware attack back in 2017. What the Minister said is completely at odds with not only what the noble Baroness, Lady Harding, said, but the experience that we had in the way that we needed to understand how these events unfold. It would be really helpful to know from the Minister, or for her to publish, the sectors where the Government have had those discussions and which parts of industry have agreed that this is an appropriate form of incident reporting.

What we are trying to do, throughout the Bill, is to ground it in what is practical. At the moment, despite the fact that we are letting through some government amendments, it seems that we are heading in the wrong direction with this clause. It is going to be disproportionate in the way that it impacts on business and is not even going to be fit for purpose, despite the disproportionality. It is just not going to work.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I think we all agree that we want a proportionate and clear regime. The noble Lord supports further incident reporting here—additional stages of incident reporting. In our impact assessment, we clearly set out the implications of that in its cost to business and so on. We will come on shortly to discuss potentially broadening the scope of incidents that would be reported. We have not been able to quantify that potential impact, as a sort of counterfactual, because we are only just discussing that.

--- Later in debate ---
Lord Holmes of Richmond Portrait Lord Holmes of Richmond (Con)
- Hansard - - - Excerpts

My Lords, I support all these amendments. They bring the customer perspective well into focus, which the Bill is currently chronically insufficient on, in my view. As the noble Baroness, Lady Harding, identified, if these amendments do not quite get to the precision of it, how will the Government bring something forward that will do the trick perfectly? This is a critically significant element which is currently not within the Bill. On an allied point, which has already been nodded to, I ask the Minister, since the Bill’s drafting seems to like “likely to”, and, in earlier additions “capable of”, why would there not be coherence through the Bill as to the type of legal construction that is being used throughout? Surely, that would not only be beneficial and more precise, but it would give greater clarity to all those who have to engage with the issues therein.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, I, too, support these customer notification amendments tabled by the noble Baroness, Lady Harding of Winscombe. As I have said, the noble Baroness brings vital lived experience, in more ways than I thought, from the front line of corporate crisis response. When a major cyber breach occurs, vague statutory requirements to notify customers

“as soon as reasonably practicable”

lead to corporate delay. Amendment 58 would replace this with a strict statutory 24-hour notification clock, while Amendment 65 would establish explicit harm triggers and require providers to provide actionable remediation advice to affected customers. Look at what Amendments 60 and 65, in particular, would achieve across Clause 16.

Under Amendment 65, notification would be explicitly triggered whenever an incident causes or threatens severe operational disruption, substantial financial loss or material harm to downstream users. Furthermore, Amendment 71 would place a positive duty on the provider to advise customers on immediate remediation steps that they can take. In the cyber realm, time is the attacker’s greatest ally. If a hospital, bank or small supplier is informed within 24 hours that their cloud or managed service provider has been breached and given technical instructions on how to isolate their systems, they can prevent contagion before it paralyses their operations. We must ensure that customer notification is prompt and meaningful, empowering downstream businesses to isolate compromised systems before contagion spreads, so we very strongly support these amendments.

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

My Lords, I, too, thank my noble friend Lady Harding of Winscombe for tabling this important set of amendments, which we welcome, and for clarifying the refinements of the grouping process, which had slightly eluded me up to that point. As with the previous group, this would amend four key areas of, on this occasion, customer reporting. It would tighten the timing to notify customers; widen the incidents expected to be reported by removing the adverse impact criterion; add extra reporting triggers; and add an “advice on remedies” duty.

Of course, businesses should be supported in the case of cyber attacks and our priority must be preventing, containing and controlling such incidents, but this cannot come at the expense of the customers that businesses serve and depend on. Customers deserve to know when a firm they depend on is targeted, even if such an attack does not necessarily directly adversely affect them. They deserve to be informed promptly and they deserve to be informed of potential remedies.

It is worth saying that there is a welcome side effect to doing so, based on the premise that behaviours are the best guard against cyber attack. Constantly being aware that cyber attacks are going on will improve behaviours. As was said earlier, the goal is not to create panic but, on a continuum between insouciance and panic, we must imbue a point closer to concern more widely in the population to keep people aware that we are constantly at risk of being hacked. On these Benches we feel these are wise, pragmatic and helpful changes. I certainly hope the Minister agrees.

--- Later in debate ---
Lord Holmes of Richmond Portrait Lord Holmes of Richmond (Con)
- Hansard - - - Excerpts

My Lords, I support this amendment, particularly in terms of its probing nature and what work can potentially be done between Committee and Report in this respect. It is really about the question of mandation. There should not be any question of a voluntary requirement. This is something that is not about the individual organisation, business or entity. It goes broader than that. It is about the community, the greater good and the country. The fact of a near miss says nothing about the severity of intent and the intel that can thus be gleaned to benefit at that point across the sector, the community, the country and beyond. Mandation has to be the standard for this provision.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, I cannot possibly compete with the Shakespearean seven stages—as opposed to ages—of the noble Baroness, Lady Kidron. We support Amendment 72 in its entirety. Voluntary reporting is the bit of the amendment that we particularly like. Our national security services and sectoral competent authorities desperately need early upstream visibility of emerging threat patterns before a full-blown systemic crisis unfolds. In the cyber domain, the precursors to the catastrophic attack—the subtle network probes, the exploratory reconnaissance and near misses—often appear weeks before a critical system is actually breached.

At present, the Bill creates a bit of an all-or-nothing trap. If any entity experiences a sophisticated near miss that fails to cross the statutory threshold of an active disruptive breach, it has a powerful legal incentive to keep quiet. It fears that, if it approaches a regulator voluntarily, it will expose itself to regulatory scrutiny, compliance investigations and potential enforcement action. In our view, including a dedicated statutory framework into the NIS regulations specifically for the voluntary notification of near misses, sub-threshold anomalies and early-stage cyber threats would be a significant beneficial addition to the Bill. In effect, it would establish a safe harbour for intelligence sharing.

As the recent “Analogue 72” green paper powerfully argued, we must move away from a culture of fear and silence in this area and we must encourage continuous proactive information flows between our critical infrastructure operators and the NCSC. We strongly support this amendment.

Lord Reay Portrait Lord Reay (Con)
- Hansard - - - Excerpts

My Lords, I thank my noble friend Lady Harding of Winscombe for her amendment, to which the noble Baroness, Lady Kidron, has added her name. We believe that this is a straightforward amendment. If we are to tackle cyber attacks seriously and to create a generally resilient cyber system, we should not simply stop at the reporting of incidents that happen. A key way of ensuring that we build not just a responsive but a preventive cyber system is by knowing what potential risks exist and who is attempting to commit cyber attacks, even if they have not done so yet. This is a reasoned amendment that places a requirement only on those already considered regulated persons, with the opportunity for others not regulated to report voluntarily. I hope that the Minister will agree.

--- Later in debate ---
Baroness Berger Portrait Baroness Berger (Lab)
- Hansard - - - Excerpts

My Lords, I will speak quickly. I was just checking my records, particularly on Amendment 167. It was just under a year ago that I completed the FT board director programme, which was specifically around cyber risk for boards. In a room of around 50 people, we had a tabletop exercise on a real-life scenario about what one should do in the event of a very serious cyber crisis and cyber risk. I was struck by a number of things. In the room were people with vast waves of expertise and experience, none of whom was a technology expert. All said that no other members of their board had attended training like this. They were there because, having completed a board director programme, it piqued their interest, as it did mine, it was freely on offer and they decided to attend.

Having gone through that session, we covered things such as the regulatory experience, issues around how to challenge management in the event of one of these incidents, how you need to test organisational resilience, how you need to look at the risks involved, and how to respond decisively and to have the expertise and understanding to do so. It was very clear to me, even during that half-day exercise, that that training was not sufficient for me as a board director and member to be able to fulfil that role.

Having gone through that experience, I think for many reasons that this amendment is so important to ensure that boards across this country—be they private boards, FTSE boards or boards of regulated companies—can do their jobs effectively. In this world, which is extending—I echo the points made about AI—it is even more imperative that we have this amendment to ensure that boards are able to fulfil their roles effectively.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, this has been a really useful debate, particularly because it has distilled all the considerable board experience—and, indeed, board training experience—around this Committee. I very much hope that the Minister listened to it with interest.

Amendment 74 in the name of the noble Baroness, Lady Morgan, moved by the noble Baroness, Lady Kidron, would align the UK with the EU’s NIS2 framework. It would introduce personal civil liability for senior executives who deliberately or carelessly neglect cyber duties. My noble friend Lady Ludford’s Amendment 167 would mandate board-level oversight and technical training. In our view, to build national resilience, cyber security must become a fiduciary director’s personal responsibility. As the noble Baroness, my noble friend and the noble Lord, Lord Arbuthnot, have said, this change is long overdue and would be additional to other existing sectors. We need to learn from experience in the way mentioned by the noble Baroness, Lady Harding; I very much hope that we will do so in the course of the Bill.

Together, these two amendments target arguably the single greatest cultural—the noble Baroness, Lady Kidron, rightly emphasised “culture”—and behavioural failure in UK cyber security today: the persistent treatment of cyber security by company boards as a delegated technical IT issue rather than a core personal and fiduciary leadership responsibility. The Government’s approach to corporate cyber governance has been almost entirely passive to date, I am afraid. Ministers have relied on voluntary guidance, such as the Cyber Governance Code of Practice, hoping that boards would voluntarily prioritise digital resilience.

The proof of this policy failure is undeniable. My noble friend quoted the Cyber Security Breaches Survey, which showed that board-level ownership of cyber risk has declined over the past three years. Of course, if boards neglect cyber security, that carries massive public costs, as seen in the recent major supply chain disruptions where, although company directors face strict personal legal liabilities under company law for signing off on financial accounts, they are permitted to treat systemic cyber vulnerabilities—vulnerabilities that can wipe hundreds of millions of pounds from the economy and paralyse critical national supply chains—with complete personal legal impunity.

My noble friend also reminded us of the catastrophic real-world cost of this boardroom neglect in the automotive sector, where a supply chain breach at Jaguar Land Rover cost an estimated £500 million, halted production lines for four months and forced the Government to step in with a £1.5 billion loan guarantee. We have seen the same in retail, also mentioned by my noble friend: the cyber attack on Marks & Spencer cost £300 million and contributed to a 99% collapse in pre-tax profits.

Amendment 74 would provide the direct legislative teeth that the Bill is missing by introducing personal civil liability for senior executives. It would amend the NIS regulations to establish that, where a regulated entity fails to comply with core risk management duties, and that failure was committed with the consent, connivance or deliberate or careless neglect of a senior executive, the regulator may impose a personal civil penalty.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank the noble Baronesses who introduced their amendments, including the noble Baroness, Lady Kidron, who did so on behalf of the noble Baroness, Lady Morgan, for raising the incredibly important topic of board accountability and senior management oversight. It is absolutely right that organisations, especially those delivering our essential services, are held properly accountable for their activities. That is why the Bill creates a more meaningful enforcement regime in terms of the maximum fines that can be levied—up to £17 million or 4% of turnover, whichever is higher—alongside a simpler process for taking that forward.

I also agree with the points made by the noble Baronesses, Lady Ludford and Lady Neville-Jones, and by my noble friend Lady Berger, on the extent of this being within the regulatory perimeter as well as the non-regulatory perimeter. Boards upskilling themselves and taking training seriously is absolutely imperative. That is why we have our Cyber Governance Code of Practice, which is at the heart of our approach to board and executive accountability. I personally feel that I am an extremely active proponent of this. For those who feel that we are not doing enough, I request their support in continuing to highlight that important code of practice in their own organisations, and on all the numerous boards they sit on, to make sure that we are governing cyber risk appropriately—and that many of the board directors they sit alongside are aware of it.

That is obviously not the limit of the approach that we are taking. We are going to introduce new security and resilience requirements in our secondary legislation. Our proposals will include a dedicated requirement on board-level governance, which will be consistent with the NCSC’s cyber assessment framework. It will cover issues such as organisational capability, senior responsibility, accountability for security and resilience, and effective risk escalation. In that way, we will connect the clarity on what is expected of boards with accountability through the enforcement regime.

I will touch on the point alluded to by the noble Lord, Lord Clement-Jones, on the EU’s regime. Individual liability for board-level members is not mandatory under NIS2. Different EU member states have taken different approaches to implementing the directive in this respect, so there is not a single model of implementation that the EU is following.

To conclude, I would also concur with the point that the noble Viscount, Lord Camrose, made on the importance of attracting those with cyber expertise to take on board-level roles and be able to contribute as part of the board accountable to shareholders in that way. We do not want to introduce anything that might disincentivise either senior executives with cyber expertise or those at board level from taking these very important roles.

I believe that, together with the enforcement regime and the security and resilience requirements, those two things will cement the importance of board and executive accountability firmly into the regime, in the way that noble Lords have highlighted today. That is the right approach.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, can I just check something before the noble Baroness, Lady Kidron, rises? The Minister has uttered some very warm words about the responsibilities of directors, but am I right in thinking that in nothing of what she said is there any intent for the Bill to create a legal liability that compels directors in the way that these two amendments do, or any form of personal financial fiduciary duty on a director? What she is arguing for, despite the warm words, is, essentially, a voluntary scheme.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

We will consult on the security and resilience requirements that will come out of the Bill. They will contain a requirement on board governance and those expectations will be set out as a result of the Bill. The regulators and others enforcing the Bill will take that into account in their enforcement regime.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

I am sorry to press, but the Minister is saying that these are expectations. Will she write to us? There is a huge lack of clarity in the middle of those warm words. We take encouragement from the fact that the Government want to see boards take responsibility, but where are the teeth?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

Obviously, we have not yet gone out to consultation on the security and resilience requirements; we will do that after the Bill passes. I can certainly update on the process, the expectation and how that links with the enforcement duties in further detail.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

The Minister is also going to have to point out the power under which the Government are going to act to actually fix that liability, or make sure that the guidance, or whatever it is, is complied with, because we are talking about the power and the duties in primary legislation. It is all very well for the Government to say, “We’re going to produce guidance”, but unless there is something in the Bill that permits that and makes sure that the Government can make it stick, we are all going to feel dissatisfied.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I am happy to write to explain how the security and resilience requirements fit into the structure of the Bill and the consultation and scrutiny that they will undergo.

--- Later in debate ---
Lord Russell of Liverpool Portrait Lord Russell of Liverpool (CB)
- Hansard - - - Excerpts

My Lords, just quickly, I will back up the noble Baroness, Lady Ludford, on Amendment 168. I, like many other noble Lords, have been involved with a variety of charities that were impacted by the cyber security breach at Beacon CRM, which has about 1,500 charities that store an enormous amount of personal data. I looked at its website, and perhaps this will emphasise to the Minister the problem that we face. This is what this website, which had a major security breach in the past, says about its security:

“The secure choice for security-conscious charities. Beacon has all of the security certifications and features that you should expect from your CRM, and we’re adding more all the time”.


It says that it is ISO 27001:2022 certified and Cyber Essentials Plus certified and that

“Cyber Essentials Plus is the highest level of certification in the UK government’s Cyber Essentials scheme, and includes a technical audit of the Beacon team’s endpoint devices”.

It says that it has “World-class infrastructure” and that it is “A UK-based system”. If I was a potential customer of Beacon reading all that, I would feel a very false sense of security about the level of knowledge and defence that its systems have. That is clearly not the case. There is a clear, major mismatch between the degree of confidence that organisations such as Beacon have in their own cyber security and the reality of how feeble and weak they actually are. Before this happens again and again, it would be helpful to look at this more closely and see whether we need to do more.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, the noble Lord, Lord Birt, was right to remind us that we perhaps need something rather more generic and comprehensive when we are assessing whether a particular sector should be brought into the Bill, but that does not mean that we should not use this group of amendments to illustrate that the Bill at the moment is not nearly comprehensive enough in the way it is structured and the sectors that it contains.

The Bill remains stubbornly wedded to what we might call the traditional 2018 five utilities model: water, energy, transport, health and core telecoms. But we have moved on from that world. Today, systemic digital risk does not respect what might be called 20th century arbitrary utility boundaries for critical national infrastructure. An adversary seeking to disrupt our society or blackmail the UK does not need to compromise a power station; it can strike our democratic institutions, food distribution networks, university research labs, orbital satellites or software supply chains.

Amendment 79, tabled by my noble friend Lady Ludford, designates services supporting registered political parties as essential activities. Hostile state actors, from Russian GRU units to Chinese state-sponsored espionage networks, are actively targeting our political parties. As my honourable friend and my noble friend have argued strongly, political parties are a vital part of our constitutional machinery, yet they operate on shoestring budgets with high staff turnovers, heavily reliant on consumer-grade IT and voluntary workers, while holding vast tranches of confidential voter files, donor databases and what we might call strategic policy intelligence. If a hostile power exfiltrates or manipulates a major political party’s systems, the threat is not just a commercial data breach but the subversion of our electoral integrity and democratic sovereignty. To leave our political parties outside statutory NCSC cyber standards is an indefensible democratic blind spot that Amendment 79 would decisively rectify.

Amendment 80, tabled by my noble friend Lady Northover, who sadly cannot be present, addresses the fact that the Bill remains frozen in that 2018 world. It will bring critical manufacturing, industrial food production and large-scale food distribution networks under statutory cyber resilience duties. Our contemporary manufacturing and retail logistics networks are no longer purely mechanical operations; they are vast, hyper-automated cyber-physical systems. They run on automated warehouse robotics, internet-connected telemetry and algorithmic just-in-time delivery pipelines.

Consider the manufacturing of critical transport equipment. When Jaguar Land Rover suffered a catastrophic supply chain cyber breach, the damage was not confined to a single company balance sheet. Production lines were frozen for four months, hundreds of component manufacturers were dragged to the brink of collapse and the economic fallout cost between £1.6 billion and £2.1 billion, making it the costliest cyber attack in British history and forcing the state to step in with loan guarantees. In an economy that depends to a large extent on vehicle transport and haulage equipment, leaving critical automotive and transport manufacturing outside statutory NIS protections is an invitation to systemic economic blackmail.

Even more acute is the vulnerability of our food supply. Modern food processing and supermarket distribution operate with less than 48 hours of inventory buffer. When Marks & Spencer was hit by a major ransomware incident, it cost £300 million to remediate and wiped 99% from its statutory pre-tax profits. As I said earlier, if a hostile state or sophisticated ransomware syndicate executes a co-ordinated attack against the central routeing software of two major distribution operators, supermarket shelves across our cities would begin emptying within two days.

Amendment 80 provides a clear, proportionate statutory safeguard. It includes an explicit turnover threshold of £12 million, ensuring that local bakeries, independent farmers and small shops face zero regulatory burden. It targets solely the industrial food processors and large-scale distributors whose distribution would threaten the daily functioning of society. In doing so, it aligns the UK with the EU’s NIS2 directive, which has already brought food production, processing and critical manufacturing under statutory cyber obligations. Our European neighbours recognise that you cannot have national resilience if your food supply can be halted by a single malicious click, so why are this Government leaving Britain’s food supply chain completely exposed?

That brings me to Amendment 81, also in the name of my noble friend Lady Northover, which designates the space and satellite sector as an essential activity under Part 3. The omission of the space sector from primary cyber security legislation in 2026 is nothing short of extraordinary. The space sector is formally identified in the Government’s own industrial strategy as a core national growth driver. Yet the Bill treats orbital infrastructure as if it were entirely invisible. Our entire critical national infrastructure, from financial transaction timestamps across the City of London and automated container port logistics, to emergency blue-light dispatch, cellular networks and high-voltage grid synchronisation, relies absolutely on satellite positioning, navigation and timing—PNT.

Ground-truth economic studies demonstrate that a five-day blackout of satellite positioning systems would inflict a staggering £5.2 billion direct loss on the UK economy. Furthermore, the UK possesses world-leading capability in earth observation and small satellite manufacturing, with sovereign launch facilities advancing at SaxaVord. But satellites, ground uplink stations and space telemetry are dual-use systems. As the House of Lords special inquiry committee on space, which I sat on, has heard throughout its evidence sessions, satellite communications and orbital command links are under relentless, daily cyber probing, jamming and spoofing by hostile state adversaries. An exploit deployed against the satellite operator’s ground command software can sever communications, blind environmental monitoring or hijack commercial orbital satellites.

Amendment 81 would rectify this strategic blind spot. It would place a statutory requirement on the Secretary of State, within six months, to make regulations bringing the space sector into scope as an essential activity. It specifically covers the operation of space objects and launch facilities, satellite communications, earth observation and critical PNT services, while requiring the Government to designate an appropriate regulatory authority such as the CAA or Ofcom to supervise compliance.

Before moving on to my own amendments, I welcome Amendment 81A, moved by the noble Baroness, Lady Berger, covering the education sector. Our world-class universities are the engines of the UK science and technology prowess, holding billions of pounds of cutting-edge IP, defence research and quantum computing prototypes. They are under relentless cyber espionage assault from foreign adversaries, while centralised bodies such as UCAS and qualification boards, as the noble Baroness said, hold sensitive data on millions of young people. Bringing education into scope under Part 3 is an urgent national security necessity.

I have tabled new amendments—Amendments 81B, 81C and 81D—which address the single most gaping, indefensible and dangerous structural failure of the Bill: the complete and absolute exclusion of central government, public authorities, local councils and our core democratic electoral infrastructure from the scope of our national cyber security perimeters. How can we claim to be building a genuinely cyber resilient nation when the public administration itself is left out entirely in the cold? I wish I had more time to expand on those three amendments, but I will content myself with hoping that the Minister will have considered those amendments and will come back with a positive response. Of course, we strongly look forward to an answer to my noble friend Lord Russell of Liverpool’s questions on Amendment 168.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

My Lords, I thank noble Lords for raising so many aspects of the scope of the Bill. I recognise the sentiment among noble Lords today about the importance of expanding its scope. Our approach has been to target regulatory requirements on a select number of essential services, while using non-regulatory but effective measures to improve the cyber security and resilience of the wider economy.

As I set out at Second Reading, I have asked my officials to work across government to consider what additional services would merit being brought into scope of the regime in future. This will allow us to make a holistic and considered approach. To ensure our assessment is appropriately prioritised, I would first like to focus on the CNI sectors not already covered by the NIS regime.

I share the intent behind the objective from the noble Viscount, Lord Camrose—which the noble Lord, Lord Markham, spoke to—that the process to expand the scope of the regime should be rigorous and evidence based. As set out in the Bill, for something to be defined as a new essential activity under its powers, the Secretary of State must be satisfied that the activity is essential to the economy or the day-to-day functioning of society in all or part of the UK. This is reserved for the most vital activities in our nation. To the point raised by the noble Lord, Lord Birt, I believe that that is a clear test. In reaching a decision, the relevant departments would need to carry out a risk assessment and any economic assessments, and consider whether inclusion is proportionate. This is part of normal policy development. After that, proposals would be subject to consultations and the affirmative procedure.

The noble Viscount proposed in his amendment that assessment for inclusion be carried out on an entity-by-entity basis, which obviously differs from the sectoral approach we have taken thus far. Setting out the detail that would need to be published according to the amendment could lead to a release of information about individual companies that could pose commercial or national security risks, due to their criticality. I think that the sectoral approach is better. As others have said today, looking at a systemic approach to the sectors is the right way to look at what is in the statutory approach.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

I am sorry to interrupt the Minister, but clarification along the way would be very helpful. She has asked her officials to see what other sectors should be brought in and has given an indication of the kind of test, but we are dealing with a bit more fog here. Is she promising us something in primary legislation or will it appear in secondary legislation? Will it just be something that government policy will cover, and we will have no say on the kinds of sectors that should be included?

For instance, the Minister is the Space Minister. Do we have an indication that space, or any of the key activities within space, will be included? Do we have any white smoke from the department as to whether that sector will be included? Will we hear by Report what sectors might be included? It is all a bit vague, and that does not give us a great deal of assurance.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I was referring to the process by which sectors can be brought into scope of the Bill, as set out in it and using the powers in the Bill. That would follow the process I just mentioned, which would be subject to consultation and the affirmative procedure. That is the process that I am referring to.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

But the powers are further down the track; they are under secondary legislation. I am assuming the Minister is promising that the Secretary of State will set out the criteria by which a new sector is brought in. Is that right? Do we have any indication, apart from what the Minister has said today in response to the noble Lord, Lord Markham, as to what those criteria will be?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I have highlighted a few of those criteria regarding the extent to which the activity is essential to the economy or the day-to-day functioning of society in all or part of the UK. Obviously, we already have the list of critical national infrastructure. We need to go through a whole process, as others have mentioned. We would need to make our assessment and then consult with industry on that, so there is a process to go through here. That process of consultation and talking to industry, or any affected sector, is absolutely critical. I am absolutely happy to update noble Lords and engage further ahead of Report on this.

In terms of the report referenced in Amendment 92A, I do not think we would need a statutory obligation to bring this report back, as set out. I mentioned the focus on entities rather than sectors, and it is better to look at the sectoral approach.

--- Later in debate ---
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, if the Minister could commit to adding that to the conversations we are bound to have to have between now and Report—

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I am not only committing; I am offering, so I am happy to have the noble Lord confirm that that would be good. I am absolutely offering that as part of the engagement ahead of Report.

I have heard the numerous areas that have been raised for inclusion in the Bill. We should look in a methodical and sensible way at these and at the implications—as we have previously discussed—for the obligations that will placed on any entities that come within the scope of the Bill, such as incident reporting, board accountability and so on, so that we do this in a very sensible manner. That is why this is the right approach to take.

--- Later in debate ---
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, at the risk of irritating the Minister even further, it is great to hear of some of this activity, but that is not the same as bringing it under the terms of the Bill.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

It is not the same. I wish to stress that the importance of strengthening cyber resilience can happen outside of legislation being put in place. There are many efforts that can go on to improve cyber resilience.

Moving on to the amendment of the noble Baroness, Lady Ludford, and her question about the scope, as well as the questions of the noble Lord, Lord Russell of Liverpool, about CRMs and so on, I do not know the specifics of this CRM. I am very happy to write after hearing of the attributes that were enumerated for its characteristics. Businesses that offer software as a service are in scope of the NIS regulations as cloud computing services, under the RDSP definition, if they meet the definitions in the Bill. In the case of the particular company that was mentioned, I do not know whether that would meet any definitions in the Bill.

Data protection legislation is obviously in place already, and processors are meant to have the systems in place for regularly testing, assessing and evaluating the effectiveness of their measures for ensuring the security of that processing. That legislation is already in place.

Moving on to the public sector, I will respond to the questions from the noble Lords, Lord Birt and Lord Clement-Jones. The Government are already taking equivalent steps to secure their own essential activities through the Government Cyber Action Plan, published in January this year. That plan applies to government departments, arm’s-length bodies and wider public sector organisations. It sets out clear expectations, targets and milestones at all levels to transform cyber security and resilience in the public sector. The outcomes of the plan are aligned with those of the Bill; there will be a consistent approach to strengthening cyber resilience across the public sector. Government departments are accountable for setting expectations and overseeing resilience across the sectors and organisations within their purview, while individual organisations remain responsible for managing their own cyber security and resilience.

This brings me on to Amendment 81A—

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

Let me work backwards here. The noble Baroness makes a very good point: the services delivered at local level often mirror those at central government level. At the moment, we are consulting on the question of the best value duty to give additional prominence. One of the issues with mapping these requirements into local government is that many different services are indeed provided. We may need to come back to that in more detail.

The government cyber unit now resides within DCMS. The team has transferred over and is up and running; I have spoken to them many times recently. The unit is very active in progressing the government cyber action plan as per the timetable and the target plan.

On the question about the approach to looking at other sectors to bring in, that is why I mentioned at Second Reading that I had already asked my officials to work across government to consider what additional services would merit being brought in. I mentioned earlier today that focusing on CNI services not already covered by the NIS regime would be the right place to start.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, will the Minister show some greater enthusiasm for her own regulatory scheme? I hope that the criteria that she adopts within the department as to whether certain sectors are going to be brought in will be about not only the criticality of the services but the need for transparency on the incidents themselves. We have had this whole debate about notification being beneficial so that organisations such as the NCSC actually know what is going on, that we the public know what is going on and the level of threat, and that our intelligence services are fully apprised.

The noble Baroness, Lady Neville-Jones, was entirely right on critical sectors, such as space. If there is no duty of notification on, say, a satellite manufacturer or something, we will all be in the dark. The Government rightly introduced this Bill to introduce greater transparency and duties on some very important sectors. We simply want to make sure that we capture all the important sectors and that they are all subject to the duty. This shying away from the Government’s own framework seems completely contrary.

--- Later in debate ---
Baroness Berger Portrait Baroness Berger (Lab)
- Hansard - - - Excerpts

My Lords, I support the principles behind these amendments. A point was raised by the noble Baroness, Lady Ludford, and I wish to make the point in a different way. Many reasons have been shared during this debate, which I share. The noble Baroness, Lady Ludford, referred to the questions asked by Chi Onwurah MP in the other place. It is interesting because I submitted a very similar Question just before the end of the summer in July. I asked:

“what proportion of the computing and cloud services used by government departments are provided by suppliers that are … headquartered outside the UK, or … subject to the jurisdiction of a government outside the UK”.

I asked that specifically in the wake of recent events and the debate we had in July.

The Answer came back on Tuesday. I accept that the Question asked by Chi Onwurah MP was specifically about AWS, but I was asking about all services hosted outside the UK. The Answer was:

“This information is not held centrally. Individual government departments are responsible for managing their own commercial arrangements for computing and cloud services and would need to confirm the proportion of services provided by suppliers headquartered outside the UK”.


The Government do not know how much they are collectively relying on other countries for our key government digital infrastructure. Our Government’s critical systems, public services and citizens’ data are increasingly reliant on foreign-hosted clouds and data centres. While the Answer refers to “commercial arrangements”, I think it is about much more than that. This is a question of our national security and resilience. I believe we urgently need a digital sovereignty strategy to ensure that we know the answers to these questions, that we can act on them and that we can prevent any future challenges happening to ensure that we are as resilient as we should be.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, I will speak to this very strategic group of amendments. I use that word again because the noble Baroness, Lady Kidron, made it quite clear from the outset that that is exactly what we lack: a clear national strategy. I pay tribute to her tenacity in tabling Amendment 83, following what I thought was an extremely useful debate on the last day before we went into recess. That is still very much top of mind at the moment, as the Minister can see from the contributions today. If we had another debate today, I do not think we would feel any greater assurance than we did on the day of that debate.

I also thank my noble friend Lady Ludford for having tabled Amendment 166, which is along very much the same lines. We have at the moment, particularly in the public sector—I thought the noble Baroness, Lady Berger, put this extremely well—near total and escalating digital dependence on foreign technology monopolies and foreign jurisdictions. It is quite prevalent in Whitehall. There is a kind of ignorance about the geopolitical reality that so much of what might be described as the digital stack is owned, operated and controlled from abroad. I will come on to our procurement policies shortly.

Amendment 83 defines the pillars of true digital sovereignty. It would tackle extreme market concentration. As we have heard, three American technology giants— Amazon, Google and Microsoft—control a staggering 73% of the cloud computing and enterprise hosting supporting our UK financial sector and public services. If an AWS region or Microsoft Azure network suffers a systemic failure, three-quarters of the City of London and vast swathes of government administration are instantly paralysed. Concentrating our critical national infrastructure into a handful of corporate choke points is the very antithesis of national resilience.

Secondly, it directly confronts foreign extraterritorial legal exposure. Because our critical public data is predominantly hosted on foreign cloud architectures, that data remains legally exposed to foreign statutory instruments, most notably the US CLOUD Act, and is subject to sudden unilateral geopolitical shifts. As my noble friend Lady Ludford said, we saw a chilling preview of this vulnerability only recently when the US Administration temporarily cut off European and UK financial institutions from accessing Anthropic’s AI model, Claude Mythos. Whatever the rights and wrongs of Mythos and its capabilities—we have a pretty good idea of what the wrongs were from what the AI Security Institute had to say—suppose that we had adopted this powerful model in a cyber defensive role; if an ally can pull the plug on front-line cyber security tools overnight, we do not possess true digital sovereignty. If a foreign ally can pull the plug on critical cutting-edge technology at a moment’s notice, we do not have true national resilience but a dangerous dependency.

My noble friend Lady Ludford’s Amendment 166 would force the Government to publish a formal digital sovereignty strategy within 12 months, assessing foreign reliance and reforming public procurement to prioritise secure home-grown UK technology. In fact, both amendments would tackle a glaring failure of current government procurement. The UK possesses world-leading academic institutions and an exceptional cyber security start-up ecosystem. But we suffer from a chronic scale-up failure. Time and again, major public contracts, such as the recent NHS and defence platforms, are automatically handed to dominant foreign tech giants such as Palantir, rather than nurturing and scaling home-grown British technology.

Proposed subsection (2)(c) of Amendment 83 and my noble friend Lady Ludford’s Amendment 166 would provide the solution. They would legally require the Government to use public procurement as a strategic lever to prioritise secure, interoperable and sovereign UK-developed technologies. That is how we build long-term sovereign capacity on our own soil, create high-wage tech jobs and prevent our best innovations being swallowed up by our international competitors.

In an era of contested supply chains, autonomous AI warfare and geopolitical instability, a nation that cannot secure its own digital foundation cannot truly govern itself. I very much hope that the Government will take heed of these amendments, even if they do not take them on board in this Bill. The former Secretary of State for DSIT is on the record as being very much in favour of digital sovereignty, and I hope that that carries through into the current Government.

Lord Reay Portrait Lord Reay (Con)
- Hansard - - - Excerpts

My Lords, I thank all noble Lords who have added their names to the amendments and who have spoken in this debate. Both amendments in this group are underpinned by the same principle that national security and national technological capabilities deserve a unified plan—not one that targets some sectors and entities and not others, but a holistic plan that brings together all sectors and industries into a single framework. His Majesty’s Opposition therefore support the intention behind the amendments.

However, at risk of repetition, the Government could avoid the need for these propositions. They could do away with your Lordships’ worries if they would commit, as mentioned by my noble friend Lord Camrose, to publishing a national cyber action plan within a set timeframe, and commit to including national digital sovereignty as part of that plan. In light of Tuesday’s debate on AI, we request a review and update of the previous Government’s AI White Paper to ensure that AI regulation and cyber regulation are aligned. They need to operate in lockstep, and this Bill is an appropriate place to do it. It is evident that national sovereignty and a reduced reliance on foreign technology is vital to ensuring national wholesale cyber security. I commend these amendments in their aims to achieve that, and I look forward to the Minister’s reply.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank noble Lords for continuing the debate with which we ended the previous session: the very important topic of the technological and digital sovereignty of the UK. That is very important to this Government and we are taking action on it. It possibly has not been focused on enough in past years but, across many areas, that is what we are doing.

We are clear that we need a coherent approach and a clear direction. We obviously need to take into account that technologies and markets evolve, and the core of that approach was set out in the modern industrial strategy and the Digital and Technologies Sector Plan. That set out the direction of travel, and the Government will continue to consider how our priorities are best articulated.

Our objective, as I articulated at the end of July, is not complete independence but strategic resilience through a combination of domestic capability, diversified international partnership and targeted management of critical dependencies. This allows us to access the best of global markets while capitalising on our domestic capabilities. That is why we already have in place a range of regulatory and non-regulatory frameworks that enable us to embed those objectives through existing industrial, technological and resilience strategies. I will talk to some of those now.

For essential services in scope of the network and information systems regime, such as drinking water, health and energy, all entities are required to manage and mitigate the risks posed to their systems that deliver essential services. This includes the risks set out in the amendment of the noble Baroness, Lady Ludford.

On market concentration, which the noble Baroness, Lady Kidron, and the noble Lord, Lord Clement-Jones, referred to, the CMA is acting. It concluded an investigation into the cloud services market in July last year, highlighting competition issues arising from market concentration. It has since announced packages of actions to improve competition in cloud services. This work has directly informed our thinking, as we develop a more strategic approach to how the public sector procures cloud services.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, I point out to the Minister that not all is rosy in that particular cloud services garden. The CMA failed to designate those major US hyperscalers as having strategic market status, which, for many of us, was a rather extraordinary outcome.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

It has announced a series of measures, including actions from Microsoft and Amazon, to support greater choice for UK businesses and the public sector.

On my noble friend Lady Berger’s question, it is true that cloud spend is distributed across departments and managed through a range of departmental contracts and commercial arrangements. We have established a cross-government cloud consumption dashboard to improve the visibility of cloud usage across the public sector, and we are working with both suppliers and departments to further improve the quality and completeness of our cloud infrastructure spend data to provide a joined-up view today and for the future. That is something that the Government are acting on.

Baroness Lloyd of Effra Portrait The Parliamentary Under-Secretary of State, Department for Business, Innovation, Science and Trade and Department for Digital, Culture, Media and Sport (Baroness Lloyd of Effra) (Lab)
- Hansard - - - Excerpts

My Lords, I will also speak to the other amendments in my name in this group. I thank noble Lords for their constructive engagement on this topic over the Summer Recess. I particularly thank the noble Viscount, Lord Camrose, and his colleagues for sending their questions in advance. I will seek to address those in my opening remarks.

This package of amendments introduces new powers that will enable the UK to address vendor-related cyber risks in our critical infrastructure. The principal new clause introduces a new direction power. It enables the Secretary of State to direct entities in scope of the power where they are using, or may potentially use, vendor-supplied goods, services or facilities in connection with their network and information systems that could create national security risks.

It is becoming increasingly clear that there are axes of cyber risks that the Government need to address. These risks arise from goods or services supplied by another company being harnessed as tools for sabotage, surveillance or espionage. But they also exist where goods or services constitute critical points of failure due to their defective design or vulnerabilities. Noble Lords would have had some sense of these risks from debates during this Bill—in particular, discussions about remote access in embedded products such as cellular modules and the scope for hostile interference and control.

GCHQ has also raised escalating concerns about supply-chain vulnerabilities in the wider geopolitical context. The director of GCHQ explicitly called out those risks in her annual lecture in May this year when discussing the challenges posed by a relationship with China and the threats posed by Russian cyber operations. That is why we have tabled Amendment 102 to tackle decisively these risks and protect our national security. Our intention is to limit the use of this power to operators of essential services in the first instance, although we will review the case for bringing other entities into scope in the future.

Supplementary amendments contain the mechanisms needed to operationalise the power. They enable the Secretary of State to set statutory timeframes for decision-making, to specify and update which entities are in scope of the vendor-related direction power and to introduce mandatory procurement screening should this ever be considered necessary to protect national security. They also introduce a power to bring more entities into scope of the existing direction power in Clause 43.

The powers to bring entities into scope of this framework are rightly restricted. To be brought into scope, the Secretary of State or Chancellor of the Duchy of Lancaster must be satisfied that the entity is essential to the economy or the day-to-day functioning of society in all or part of the UK. This is consistent with the Bill’s definition of essential activity in Clause 24. Either Minister can exercise the power. It has been drafted like this to accommodate machinery of government changes.

The decision to introduce the amendments has not been taken lightly. The Bill already includes important national security powers to direct regulated entities whose systems have been compromised, or which are at risk of being compromised, by hostile actors. This new power allows the Government to act before vendors become embedded in supply chains and before taking action becomes costly and disruptive. It will give operators greater confidence in their procurement planning and avoid the need for costly interventions down the line.

Crucially, we are not proposing to introduce these powers in isolation. They will be part of a broader framework which will also include procurement guidance for operators and a voluntary referral route into government where operators have identified potentially risky procurements. The voluntary self-referral route will enable the Government to assist operators with vendor-related concerns, provide them with guidance on how to proceed and, where necessary, inform decisions about the issuing of a direction.

We intend to consult on the implementation of the framework in due course. This will include the criteria for referral and how the mechanism will work in practice. In the event that this Government ever determined a mandatory referral scheme was necessary, we would intend to consult on the definition of a “qualifying transaction” before laying the necessary secondary legislation. However, I emphasise that it is not our current intention to set up a mandatory scheme.

Ultimately, we expect this wider framework will minimise the need for formal interventions using the new powers. However, it is crucial that the power is in place as a backstop to guarantee the Government’s ability to protect the UK’s national security. I beg to move.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, I assume that there are no Back-Bench contributions at this point, so I will speak on behalf of the Liberal Democrats to this very significant group of amendments tabled by the Minister as recently as 24 August. I thank her for her introduction today and for her brief meeting shortly after their tabling.

At the outset, from these Benches we express our strong concern about the timing and the sheer scale of the Government’s package of new amendments. To drop 65 amendments of this nature on the eve of Committee, which will completely reshape the architecture of this Bill, after its passage through the Commons, is a major challenge to effective parliamentary scrutiny. The Minister’s letter, also dated 24 August, came alongside these 65 new amendments, so we have had very little time to consider them. As far as I can see, a full Ministerial Statement did not accompany them; we had to rely on the coverage of Computer Weekly to understand the Government’s motives.

The Government have quietly established a major parallel high-risk vendor regime. Under Amendments 102 and 103, the Secretary of State—and now, crucially, under Amendment 101, the Chancellor of the Duchy of Lancaster—are granted unilateral powers to issue vendor-related directions. They can legally order an organisation to prohibit, restrict, remove, disable or modify any software, hardware or digital facility supplied by a designated high-risk vendor. Furthermore, under Amendment 105 they are given the power to establish a mandatory referral scheme, legally forcing companies to submit technology procurement contracts to the Cabinet Office for security clearance before signing.

Let us look closely at the operational mechanism in Amendment 103, which ISC2 has rightly highlighted. The proposed new clause mandates that a company appoints a “skilled person” to oversee compliance and, under subsection (5) of the proposed new clause, permits the Secretary of State to rely on a list of persons published by GCHQ. I ask the Minister: what is this list? Is it public or classified? What objective criteria will govern inclusion? How will conflicts of interest be avoided, and how will independent professional competence be assured? To create statutory compliance roles backed by secret lists is entirely unacceptable.

Under Amendment 108, the Secretary of State can make regulations bringing any specific company into the scope of the Clause 43 directions without bringing them into the NIS regulations as a whole. Under Amendment 127, the Government will insert an emergency “made affirmative” procedure allowing regulations and vendor bans to take effect immediately without prior parliamentary debate. Furthermore, under Amendment 148 the Secretary of State can prohibit a company disclosing that they have received a direction or are in consultation, backed by civil penalties of up to £10 million or £50,000 per day.

There is also a second critical implication—the backdoor regulation of advanced artificial intelligence systems. At Second Reading, the Minister assured the House that advanced AI systems and LLMs were out of scope. These amendments appear to reverse that position. Under Amendment 108, any entity providing essential goods or services can be specified. As our critical infrastructure increasingly integrates agentic AI models, such as GPT-5 or Anthropic’s Mythos, these developers become points of supply chain risk concentration. It seems that, under Amendment 102, the Government can designate AI developers as high-risk vendors and mandate pre-procurement vetting. Is that the case and, if so, why not say so?

The Government will no doubt resist the transparent, legally bounded emergency shutdown power proposed by Amendment 84, with its High Court backstops and seven-day parliamentary reporting, yet here the Government demand sweeping, secretive executive powers to ban software, veto procurement and gag businesses with zero judicial checks. These Benches cannot give these 65 government amendments a free pass. I remind the Minister that, in Grand Committee, unanimity is required for amendments to carry. We insist that the Government come back on Report with strict guardrails and clear limits on executive market intervention without parliamentary consent before these new powers can be exercised.

Quite apart from that, both the Constitution Committee and the Delegated Powers and Regulatory Reform Committee had something to say about the existing powers in the Bill, but neither committee has had a chance to look at these amendments. I am sure that they will have comments to make in due course.

Lord Holmes of Richmond Portrait Lord Holmes of Richmond (Con)
- Hansard - - - Excerpts

My Lords, I apologise for not speaking before the Liberal Front Bench, but the great news for everybody in Grand Committee is that I am not the Conservative Front Bench. That is good to know. I declare my relevant technology interests as adviser to the Crown Estate and to Simmons & Simmons LLP.

I have just a few questions for the Minister, most of which revolve around what was known when the Bill was in the Commons and what has become known since it was in your Lordships’ House at Second Reading that have required this raft of amendments to come forward over August. The Minister, in her opening, described defective by design; this is an interesting principle, which could have broad applicability, but, as the noble Lord, Lord Clement-Jones, said, we were clearly told at Second Reading that AI and all therein were not in the scope of this Bill. Does this raft of government amendments change that fundamentally? Is it a nod or hint to it? Is this a large, fundamental change in the Government’s policy approach to large language models and enhanced AI, as covered by this raft of proposed amendments?

Is the Minister’s view that changes to the machinery of government will not be complete and clear by the time the Bill completes its passage through your Lordships’ House, hence the need for the reference to the Secretary of State or the Chancellor of the Duchy of Lancaster? Is there a broader issue on that point, worth the Committee considering, on how the shuffling of departmental deckchairs ahead of the Summer Recess is going down? How long will this take to be settled? Could the Minister update the Grand Committee on what is happening with clarity on where every last element of science, innovation and technology policy now rests? Do they all have a clear, identified home and ministerial responsibility?

In later groups we will come on to talk about AI and the deafening silence on AI—until this raft of amendments. Perhaps the Minister would like to comment, in responding, on whether the Government have had a significant change of direction on these technologies, as illustrated by these amendments, or whether they have not. Thus, what will the Government’s response be when these issues are discussed in later groups, compared to the response that they gave at Second Reading?

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I will need to write to the noble Lord on that specific question of how GCHQ’s powers are executed in respect of operational decisions such as this. I am aware that in other areas they are within Secretary of State responsibility, whether they are exercised by a Secretary of State, advised by GCHQ or whether, as the noble Lord suggests, they are actually undertaken by GCHQ.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, I thank the Minister for her gracious, intended withdrawal of Amendment 1, and I am sure we will have a much better debate on Report as a result, particularly once we have had a chance to read her remarks on both interventions today. However, I hope she will agree with me, especially in terms of what she said about being technology agnostic through the Bill, that we will have a much better debate as we come to talk about specific AI issues as a result of not having already incorporated those in the Bill. So, all the way around we will have a much better debate about the proper shape of the Bill as a result of those amendments being withdrawn.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

With that, I believe now is the time where I beg to leave to withdraw Amendment 1.

--- Later in debate ---
Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - - - Excerpts

My Lords, I support Amendments 3, 8 and 13 in the name of the noble Baroness, Lady Kidron, to which I have added my name. I will not repeat too much all her comments on our learning from the Online Safety Act that small does not mean low risk. However, it should not be a surprise that those of us who championed that amendment to the then Online Safety Bill have again put our names to it. We have learned the hard way that, in online safety, risk can come from the smallest providers.

I have learned it personally. I retired from TalkTalk 10 years ago and I remember, what must have been 11 years ago—I promise this is not a cyber attack story—a mapping exercise across all the telcos, mobile and fixed, looking at our even then incredibly complex data centre networks across Europe. I am sure this has all changed and is much more complex, but I remember discovering, as a result of that exercise, that all of us were routing traffic through the same small data centre in central Europe and none of us was aware that we were doing so. These networks are expanding so fast and data centres and managed service providers are growing so fast that it is impossible for people to retain perfect knowledge 100% of the time, so a small provider really can be a node that brings down the whole network. It is not just in child safety that we have learned that small can mean very risky; it is also the case in the world of physical digital infrastructure, which we have known for some time in telecoms. That is why these amendments are so important.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, these amendments confront us immediately with some of the Bill’s most fundamental potential structural weaknesses—the danger of a static, arbitrary and pre-digital scope. The Government appear to have conceded this point already by tabling those infamous 65 high-risk vendor amendments in the previous group. Let us look first at Amendment 3 in the name of the noble Baroness, Lady Kidron, which I would have signed if there had been room.

As drafted, the Bill brings data centres into scope, relying entirely on rigid physical megawatt thresholds—specifically a rated IT load of 1 megawatt, or 10 megawatts for enterprise facilities. In the modern cloud ecosystem, physical power load is a crude and unreliable proxy for risk. A highly dense, interconnected facility drawing under 1 megawatt can host the critical patient records of multiple NHS trusts, emergency dispatch telemetry or core local government routing directories. If that facility is compromised, the societal and economic devastation will be catastrophic, regardless of how much electricity it pulls from the grid—the noble Baroness drew the parallels with NHS data centres.

Amendment 3 would provide the essential statutory fix. It would empower Ofcom to apply a risk-based designation that looks beyond physical power to evaluate the customer base, data sensitivity and critical interconnectivity. I listened with considerable interest and sympathy to what the noble Baronesses, Lady Kidron and Lady Harding, had to say about parallels with the Online Safety Act, which is engraved on our hearts.

--- Later in debate ---
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, we have had some excellent speeches in this group. I hope that the Minister has taken on board some of the points made by people who really know what they are talking about in the AI field. I will speak to my Amendment 84 and in strong support of the amendments tabled by the noble Lord, Lord Tarassenko, and the noble Baroness, Lady Kidron.

--- Later in debate ---
The question of how far you take the powers of the state and the powers of the regulator seems to me to be an area for discussion. It would be good to see some agreement between the private sector and the regulators about what needs to be regulated and what should be left to business. I think that is an area for further discussion, but I think we need something which is not quite either of these two extremes that are being proposed: the complete regulation of everything and done by only one regulator.
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, I first congratulate the noble Lord, Lord Birt, on what is a really comprehensive vision expressed in this group of amendments. I speak in strong support of those amendments, on which both he and the noble Lord, Lord Londesborough, have spoken so cogently. Together, they address one of the most glaring defects of the architecture of this Bill: the fragmented, inefficient model of 12 separate sectoral regulators. I think that the noble Baroness, Lady Neville-Jones, asked the right questions about how to co-ordinate and how to be fair, but I am afraid I come to very different answers and to the same conclusion as the noble Lord, Lord Birt. Cyber threats are sector-agnostic. Malicious code and supply chain exploits do not respect the boundary between Ofwat, Ofgem or the CAA. Expecting 12 separate bodies to recruit scarce elite cyber forensic talent is a fantasy that results in weak, uneven enforcement.

Furthermore, multi-sector businesses face duplicative compliance obligations across separate competent authorities in the current scheme. Under Amendments 7, 9 and 11, the noble Lord, Lord Birt, would correctly widen the definition of digital service providers to include the creators, distributors and managers of software and digital platforms. As the Synnovis pathology attack proved so catastrophically to London hospitals, our critical infrastructure is entirely dependent on third party software code. If we do not bring software and platform providers into scope under Clauses 7 and 8, we leave the front door wide open to cyber crime. Amendment 88, in the name of the noble Lord, Lord Birt, which I actually prefer to my own Amendment 87, would replace this maze of regulators with a unified, specialised body, the office for cyber resilience. The OCR would centralise enforcement, establish common auditing baselines and maintain sector-specific expertise under a single roof.

Amendments 76 and 77 would ensure that, when the Secretary of State specifies new essential activities under Part 3, they must act on the expert recommendations of the OCR, targeting any activity whose disruption carries severe economic, societal or national security impacts. I entirely agree with what the noble Lord, Lord Holmes, had to say and think, sadly, that we would all benefit from a bit of musical accompaniment.

This structural foundation would enable a vital reform suggested by the noble Lord, Lord Birt: Amendment 89 would establish a register requiring software and platform providers to certify products as safe by design; and Amendment 91 would introduce annual independent cyber resilience audits modelled on statutory financial audits.

Under Amendment 90, the OCR would work hand in glove with the UK Cyber Security Council to validate and enforce workforce competence standards across all regulated entities. I remind your Lordships that Amendment 99, in the name of my noble friend Lady Northover, has been degrouped but is relevant to the relationship between the potential OCR and the UK Cyber Security Council.

This is a comprehensive but significant group of amendments that hang together extremely well. I urge the Government to look very closely at what could be a really effective scheme of regulation.

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

My Lords, I thank the noble Lord, Lord Birt, for introducing this debate and all noble Lords who have spoken. I appreciate the rigorous strategic thinking that the noble Lords, Lord Birt and Lord Londesborough, have put into the proposal for an office for cyber resilience, but I will try to keep my remarks to the principle of a single regulator.

As others have set out very powerfully, I see the appeal of having a single regulator: it is easy to issue directives, to store data and information centrally, to take a systemic approach overall and to better manage the hiring of scarce, skilled resources. That said, as my noble friend Lady Neville-Jones pointed out, it is important to see the value of sectoral regulators supported by a centre-of-excellence model. More sector-specific expertise, more direct communication with the industry and more flexible approaches are all easier to achieve with smaller, more specific regulators. At a sufficient level of abstraction, it almost does not matter which of those models you go for; it is about having resourced, skilled and empowered people performing monitoring and enforcement activities, regardless of the body under which they sit.

More broadly, the point is that, while differences between a more centralised or more sectoral approach are worthy of debate—I do not think we would ever hit the extremes of either of those—what actually matters is ensuring that, whichever route the Government choose to take us, they make certain that the regulators are adequately resourced and that they exist within a wider strategy.

I am not sure, and look forward to finding out, whether the first of those is the case. The Government have chosen the more sectoral approach, but we do not yet know how the regulators are going to be resourced and what additional resourcing needs will be needed to cope with the increased responsibilities that will be laid at their door. I look forward to hearing from the Minister on how the regulators are going to be funded, how the funding needs will be calculated and how they are going to be supported in this significant expansion of their role.

The second point is that the regulators should exist as a part of a wider strategy, which is not currently the case. I apologise to noble Lords for banging on about this, but it is very difficult to get the past the hole in the Bill in the shape of a wider national cyber strategy. Whether the regulators are many or one matters little without the bigger picture into which they fit. In an ideal world, we would review the overall cyber strategy and then debate what regulatory structures might be appropriate to deliver it but, for now, sadly, that is not the world that we are in.

The Secretary of State—or, indeed, the Chancellor of the Duchy of Lancaster; it is not reassuring that we still do not know which one—must commit to publishing the national plan, after which we can assess the efficacy of its many parts.

--- Later in debate ---
Lord Ravensdale Portrait Lord Ravensdale (CB)
- Hansard - - - Excerpts

My Lords, I declare my interest as a chief engineer working for AtkinsRéalis. I shall speak to Amendment 82.

In our debate on group 3, a lot of good points were made about one specific technology related to cyber: AI. However, as the noble Lord, Lord Birt, said in the debate on the previous group, quantum is the other area that needs attention as a specific technology. When I started here around seven years ago, I never thought that I would one day be talking about quantum mechanics in your Lordships’ House.

I recently heard the story of Heisenberg and his discovery of the uncertainty principle, almost 100 years ago in 1927. He was out in a park late one night, after a long argument with Niels Bohr, and he saw a row of street lights. He saw a person walking in between the street lights late at night. He would see them go past one light—you would be able to observe them—and then they would disappear into the darkness and they would then reappear at the next light. He realised that he could use that analogy for the behaviour of the electron: as it was being measured, it was there as a particle, but, when it was not being measured, it had to be considered probabilistically because you do not know where it is. In the same way, with a quantum computer, the value of the qubit, as it is called, is locked in only when it interacts with a measurement device.

This extraordinary powerful technology is now emerging. As an example, the Willow chip, which has recently been developed by Google, completed a benchmark calculation in five minutes. It would have taken the fastest classical computer in the world 10 septillion years—that is 10 with 24 zeros, I believe—to complete it. According to the Parliamentary Office of Science and Technology and the NCSC, in less than 10 years—perhaps even sooner than that—we could have a cryptographically relevant quantum computer that uses Shor’s algorithm to decrypt all communications that rely on the RSA algorithm on which we have relied for decades for all of our bank transactions, state-level communications and so on. This is an area of technology that is moving extremely quickly, and it is not just one about which we will have to worry at some point in the future. So-called “harvest now, decrypt later” attacks could be used to decrypt sensitive information in the future.

That brings me to the amendment. It is quite a simple, straightforward one, which goes forward from the discussions on how, given the changing nature of these technologies, it is perhaps not appropriate to have specific technologies and timelines in the Bill. However, as the Minister has already brought out, the statement of strategic priorities is a powerful tool to ensure national join-up, including across those regulators within the remit of the Bill.

We have 12 regulators and each one could approach quantum crypto—so-called post-quantum cryptography—differently. There will be huge benefits in really ensuring that regulators work from the same national signal rather than inventing their own PQC expectations individually. That would also allow them, if it can be brought out in the statement of strategic priorities, to plan their inspections, guidance, skills and capacity around the NCSC timelines, which is a plan ranging from 2028 discovery and initial plan through to 2035 when post-quantum crypto implementation is completed. That will also help with all those newly in-scope firms that will be coming within the remits of this legislation, giving the regulators a legitimate basis to raise post-quantum crypto with those new organisations early on.

I read back the Minister’s remarks at Second Reading, when she said that quantum crypto

“would be considered as part of that requirement by regulated entities, but would not necessarily be singled out as a specific technology in the regulation so that we keep these regulations up to date and matched to the cyber risks that individual entities face”.—[Official Report, 14/7/26; col. 622.]

I believe that this amendment would help strengthen and deliver exactly that. With that, I look forward to hearing from the Minister on her thoughts about this approach.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, I will speak to this substantial and rather disparate group of amendments, including Amendments 93 to 95 in my name, Amendment 10 tabled by my noble friend Lady Ludford, and a number of other amendments in the names of other noble Lords, including that of the noble Lord, Lord Arbuthnot, who, sadly, is in the Chamber as well.

Under Amendment 10, comprehensively introduced by my noble friend Lady Ludford, we would ensure that digital service providers manage risk arising from AI-driven fraud which, as she explains, represents over 40% of reported crime in England and Wales. I thought she made an extremely convincing case and I very much hope that the Minister takes what she said to heart and adds the very few words that are required to make this Bill much more secure with regard to the kind of phishing activity that she described.

As regards the various amendments relating to skills, beginning with the workforce and competence deficit, in its latest 2025-26 workforce study, ISC2 reveals that 52% of UK cyber professionals identify skills shortages as their single greatest obstacle to regulatory compliance, with 58% of organisations facing critical skills shortages. Regulation without competence is what might be described as pure compliance theatre. That is why, on these Benches, we strongly support Amendment 15 in the name of the noble Lord, Lord Arbuthnot, which would place a direct statutory duty on regulated organisations to ensure that their security leads possess verified competence, alongside Amendment 114 from the noble Lord, Lord Holmes, which would require the Secretary of State to define the objective qualifications and independent criteria for appointing skilled persons.

We also see critical implementation blind spots in distributed infrastructure. In July, as documented in the “Analogue 72” Green Paper, which I have mentioned before, a small UK electricity generator was taken offline for four days following a suspected state-sponsored cyber attack. Because it fell below the statutory reporting size threshold, local responders had zero visibility of the disruption. If small distributed energy assets are paralysed, the compound threat to local grids is severe.

Amendment 82 tabled by the noble Lord, Lord Ravensdale, rightly addresses quantum decryption. I am afraid that, if we are not careful, we are back in the territory of technology agnosticism. I think that across the Committee we have a fundamental disagreement with the Government about that. Hostile states are actively executing “harvest now, decrypt later” operations. By requiring the Secretary of State to incorporate NCSC post-quantum cryptography timelines into strategic priorities, we would mandate preparation for quantum-resistant encryption across all critical sectors. We very much support the amendment tabled by the noble Lord, Lord Ravendale.

Amendment 93 in my name would introduces mandatory eight-week public consultations before secondary regulations or codes of practice are issued, protecting industry and SMEs from closed-door administrative creep. I think that is the kind of area where the Minister could give further assurance.

Amendment 94 in my name would establish a statutory presumption of conformity for organisations achieving ISO/IEC 27001 or Cyber Essentials Plus certification. This safe harbour would eliminate legal ambiguity, reward gold-standard cyber hygiene and free regulatory resources to focus on high-risk, non-compliant entities, while preserving the regulator’s right of rebuttal. As the Minister can imagine, this has considerable industry support.

In Clause 40, my Amendment 95 would shorten the legislative cycle from five years to three years. We also support the alternative in Amendment 95A from the noble Lord, Lord Arbuthnot, which probes an even tighter two-year window, and his Amendment 95B, which I have signed, which would ensure that future statutory reviews must explicitly assess third-party and supply-chain dependencies originating outside the regulatory perimeter. Furthermore, we support the noble Lord, Lord Arbuthnot, in his proposed new Clauses 174C and 174D mandating competency standards and annual workforce strategies—we are just sorry that he is not here and able to speak to those amendments—alongside Amendment 92B from the noble Viscount, Lord Camrose, requiring large businesses to report transparently on their cyber resilient plans.

We have not heard from the noble Viscount regarding the other Conservative Front Bench proposals, but we are sympathetic to the need to review information sharing and analysis centres, ISACs, under Amendment 169 and to expect clear regulatory funding plans under Amendment 174. Furthermore, holding the Government to their commitment under the National Audit Office’s 2025 report and the Cyber Action Plan, under Amendment 170, is important. However, we are less supportive of Amendments 173 and 175, which attempt to make commencement of the entire Act conditional on publishing the National Cyber Action Plan. In our view, that would potentially create a dangerous delay, holding our national resilience hostage to Whitehall paperwork when our hospitals and utilities need protection today.

Lord Markham Portrait Lord Markham (Con)
- Hansard - - - Excerpts

My Lords, I thank the noble Baroness, Lady Ludford, for introducing this group. I am generally supportive of the principles she is introducing, and I thank all noble Lords who have spoken in this debate. I particularly enjoyed trying to get my head round ten septillion, however many zeros that was, on that computing.

Moving first to our amendments, I hope that there was something constructive in this debate trying to build on a lot of the things that the noble Lord, Lord Birt, said in the previous group around giving people tools for self-help in a lot of this because we know that the Government cannot be expected to cover every aspect. Starting with the amendment in my name and that of my noble friend Lord Camrose, Amendment 92B builds on a similar principle to that underpinning our support for a voluntary referral scheme, that being that businesses and individuals should, where practical, be self-sufficient and self-accountable with regard to cyber security. The more that businesses are responsible for their own security, the less the state has to look over their shoulders: I think that is of benefit to both parties. Requiring a large business to report its own cyber security and resilience plan provides an impetus. The idea is that you want the board to ask the chief executive and the executive team, “What are you doing in this space?” and hold them to account for the shareholders. If the answer to that is a big fat zero, that would clearly be concerning. That act of informal, nudging pressure—call it whatever you want—would be quite a call to action that any self-respecting chief executive and board would take heed of.

--- Later in debate ---
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, I shall speak in support of this group on designated critical suppliers. I support in particular Amendments 15A and 15B, which were tabled by the noble Lord, Lord Arbuthnot of Edrom; I have signed them both. We are also sympathetic in principle to Amendment 16 in the name of the noble Lord, Lord Ravensdale.

We on these Benches fully support the principle of regulating managed service providers and designated critical suppliers. Because MSPs and key vendors act as trusted bridges into multiple enterprise networks, a single compromised supplier can trigger a systemic, cross-sector shutdown; we saw this in the Collins Aerospace attack, which halted airport check-in systems across Europe. However, we must ensure that our regulatory net is both deep enough to capture hidden systemic risks and precise enough to avoid catching non-critical small businesses.

In our view, Amendments 15A and 15B in the name of the noble Lord, Lord Arbuthnot, achieve the necessary depth. They would empower regulators under Clause 12 to designate critical suppliers that supply essential services or managed service providers through one or more intermediaries. In modern digital architectures, systemic single points of failure often sit at tier 2 or tier 3 in the supply chain. If an essential service materially depends on a sub-tier vendor, regulators must not be blinded by the absence of a direct contract. By pairing Amendments 15A and 15B with Amendment 16 in the name of the noble Lord, Lord Ravensdale, we could ensure that deep supply chain risks are policed, while protecting small innovators from bureaucratic overreach.

Lord Markham Portrait Lord Markham (Con)
- Hansard - - - Excerpts

My Lords, I thank my noble friend for introducing this group; as it is the final group of the day, I will keep my remarks brief.

Amendments 15A and 15B in the names of my noble friend Lord Arbuthnot and the noble Lord, Lord Clement-Jones, seek to allow regulatory oversight of critical suppliers on whom operators of essential services and relevant service providers depend, be it directly or indirectly. We believe that this must be a reasonable approach. The aim of Clause 12 is to ensure the continued functioning of the central suppliers and providers by providing support for their critical suppliers. Surely whether they are supplied directly or indirectly is of little importance.

Amendment 16 from the noble Lord, Lord Ravensdale, would restrict the designation of critical suppliers to those who present systemic risk rather than a simple single-entity risk. We should seek to minimise government oversight wherever possible, and suppliers should not be designated unless they pose a genuine risk. I am also supportive of the noble Lord’s focus on cross-sectoral consistency and general macroeconomic risks, which is too often something that the Government neglect.

However, I am hesitant to endorse the amendment in its entirety. Having to assess every supplier of every OES, RDSP or RMSP and having to decide whether it meets the systemic threshold have the potential to place an unrealistic administrative burden on designated competent authorities. We are already concerned about the resources that they will need to undertake the changes that the Bill introduces; I am unsure whether we need to ask more of them.

To wrap up, I return to a more general point: the risk to the economy or to national security is a scale, and the legislation that we pass should reflect this. Perhaps the noble Lord, Lord Ravensdale, is correct that the designation of critical suppliers based solely on whom they serve is too permissive, but it is equally as likely that restricting designation to systemic risks would be too restrictive. This highlights—it goes back to earlier groups—that the binary distinction about which we are talking now does not cover the gradation of different types of risk. That is why I come back to the original point that my noble friend Lord Camrose made on adopting, perhaps, the Cyber Monitoring Centre’s severity scale, which offers a template for a more nuanced approach to definitions. I hope that the Minister can commit to reviewing the Bill’s definitions ahead of Report.

UK Streaming and Cinema Sector

Lord Clement-Jones Excerpts
Monday 2nd March 2026

(6 months, 2 weeks ago)

Lords Chamber
Read Full debate Read Hansard Text Watch Debate Read Debate Ministerial Extracts
Baroness Twycross Portrait Baroness Twycross (Lab)
- View Speech - Hansard - - - Excerpts

I have heard that loud and clear, and I will convey the sentiment of the House back to colleagues in DCMS.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - -

My Lords, I declare an interest as chair of the Authors’ Licensing and Collecting Society. The Minister said that she cannot at this stage rule out certain aspects of what might be contained in the paper due from the Secretary of State this March, but can she rule in the importance of making sure that AI developers must license UK content for the training and grounding of their models?

Baroness Twycross Portrait Baroness Twycross (Lab)
- View Speech - Hansard - - - Excerpts

Our priority is to ensure that the UK is ready for AI-related risks while supporting responsible innovation and long-term growth. We are considering all potential options to deliver on the UK’s ambition. It would be a very foolish and brave Minister to pre-empt a report that has yet to be published, but I look forward to future debates on this matter.

Enterprise Act 2002 (Mergers Involving Newspaper Enterprises and Foreign Powers) Regulations 2025

Lord Clement-Jones Excerpts
Tuesday 22nd July 2025

(1 year, 1 month ago)

Lords Chamber
Read Full debate Read Hansard Text Watch Debate Read Debate Ministerial Extracts
As someone who believes passionately in the future of our free press, I know which side I am on and that is why I will be voting against the amendment in the name of the noble Lord, Lord Fox. I would urge all others who want to secure a sustainable, optimistic future for our media to do the same.
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - -

My Lords, I strongly support my noble friend Lord Fox’s fatal amendment. When this House welcomed a complete ban on foreign government ownership at the Third Reading of the Digital Markets, Competition and Consumers Bill last March, the then Government proposed a 5% exemption for passive sovereign wealth fund investment. The noble Baroness, Lady Stowell, and the noble Lords, Lord Forsyth, Lord Robertson and Lord Anderson, deserve huge credit for securing this change, alongside the then Minister, the noble Lord, Lord Parkinson.

Yet in a remarkable about-face, this Labour Government propose allowing foreign state-owned investors to hold up to 15% stakes, tripling the previously proposed threshold. As we have heard, 15% is not trivial. Even a 15% stake can provide extraordinary leverage, board representation, veto powers over key decisions and a very real influence over editorial policy.

The Competition and Markets Authority guidance on mergers’ jurisdiction and procedure makes it clear that there is no exhaustive list of relevant factors. Even one board seat may suffice, depending on circumstances. The regulations currently allow multiple foreign states each to acquire a 15% stake. Nothing would stop a consortium of foreign regimes stacking up a controlling interest in a British newspaper. The Government acknowledged this flaw in their letter of 21 July, admitting, as we have again heard, that this will need correcting in the autumn. But why proceed with these regulations when the Government admit that they are fundamentally flawed? The 15% threshold contrasts starkly with international best practice. Australia sets just 5% for media companies.

There has been some argument today, notably from the noble Lord, Lord Black, that our struggling newspaper industry needs foreign investment. Even the Minister talked about existential threats. But if conventional investors are reluctant, as the noble Lords, Lord Fox and Lord Forsyth, say, foreign state investors clearly seek a different return: influence. Should we mortgage editorial independence when the price is erosion of public trust?

The consultation process was deeply problematic, with only four responses, primarily from newspaper groups seeking foreign investors. This hardly justifies tripling the threshold. The Government claim they can intervene if passive investors become active, but how does one monitor passivity and detect influence? As the Secondary Legislation Scrutiny Committee noted, it is an impossible task to determine nuanced changes indicating influence. In matters of press freedom, we must err on the side of caution.

I see that the noble Lord, Lord Black of Brentwood, came out in yesterday’s Telegraph, and today, with all guns blazing. His attack on the Liberal Democrat position fundamentally mischaracterised what the Press Recognition Panel actually does. The PRP is not a statutory media regulator that controls editorial content. It is an independent body that recognises voluntary press regulators, such as Impress, while IPSO deliberately chooses not to seek recognition to avoid meeting proper independent standards. This system protects press freedom by ensuring that regulatory bodies themselves meet robust standards for independence and effectiveness.

The characterisation of this amendment by the noble Lord, Lord Black, as “onerous statutory controls” is the same misleading tactic used by media proprietors to avoid genuine accountability while maintaining maximum commercial freedom. The position of these Benches is entirely consistent: genuine press freedom requires protection from all forms of external influence, whether political interference, proprietorial control or foreign state investment. Our support for Leveson-compliant independent regulation and opposition to foreign state media investment both serve the same principle: to ensure editorial independence from external pressures.

The stakes could not be higher. As the noble Lord, Lord Black, has mentioned, this legislation is clearly drafted to facilitate deals such as the potential takeover of the Telegraph by RedBird Capital, whose Chinese connections are subject to concern. A 5% cap strikes the right balance, allowing for genuine commercial investment while preventing the accumulation of influence that will strangle press freedom. The British public deserve to know—

Lord Knight of Weymouth Portrait Lord Knight of Weymouth (Lab)
- Hansard - - - Excerpts

As ever, the noble Lord has made a good case. He made his point—as did the noble Lord, Lord Forsyth—around what a percentage stake might mean if the returns are not going to be great. What difference is there between 5% and 15% in respect of the argument he is making about influence? If someone wants to invest 5%, surely they are doing it on the same basis as 15%.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

Perhaps the noble Lord has never been on the board of a public limited company. There is a huge difference between a 5% and a 15% ownership stake.

Lord Knight of Weymouth Portrait Lord Knight of Weymouth (Lab)
- Hansard - - - Excerpts

There is a difference, but the argument the noble Lord is making is that people are seeking to get influence rather than a financial return. If you are taking 5%, you are doing so for a financial return. Why would investors not also be looking for a financial return on 15% in just the same way?

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

If a company has a series of 5% ownership stakes it will have a plurality of shareholders and therefore a mix of influence, but if you own a 15% stake you have a much higher share in the company and are probably entitled to a single board member.

Lord Forsyth of Drumlean Portrait Lord Forsyth of Drumlean (Con)
- View Speech - Hansard - - - Excerpts

Is it not that there is a difference between 5% being held by a foreign government and 5% being held by a national wealth fund or something of that kind?

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

I entirely agree with the noble Lord. I do not understand why the noble Lord, Lord Knight, is raising what seems to be a pretty obvious issue.

The British public deserve to know that their morning newspaper delivers journalism guided by British values and editorial independence, not the preferences of foreign powers.

Briefly on this House’s conventions: the guidance issued in the 2006 report from the Joint Committee on Conventions—which was mentioned by noble friend Lord Fox—is still current, despite the 2015 Strathclyde review. It concluded:

“On the basis of the evidence, we conclude that the House of Lords should not regularly reject Statutory Instruments, but that in exceptional circumstances it may be appropriate for it to do so. This is consistent with past practice, and represents a convention recognised by the opposition parties”.


Subsequently in March 2007, with strong support from the then Archbishop of Canterbury I succeeded with a fatal amendment that prevented a super- casino being located in east Manchester. Since then, in January 2013, the noble Lord, Lord Bach, succeeded in defeating a legal aid order. I welcome what the noble Baroness, Lady Stowell, had to say about the existence of the convention.

Those were exceptional circumstances and so too are today’s. The ownership of our press is a matter of great public policy importance, and we are fully entitled to defeat these regulations. I urge noble Lords to support my noble friend Lord Fox’s fatal amendment. Let us send a clear message that the integrity of the British press is not negotiable: 5% is sufficient, but 15% is a doorway to influence that, once opened, may prove impossible to close. I commend the amendment to the House.

We on these Benches also oppose the draft Enterprise Act 2002 (Amendment of Section 58 Considerations) Order 2025 and the draft Enterprise Act 2002 (Definition of Newspaper) Order 2025, which have been tabled for approval today. These orders propose extending the ambit of the Enterprise Act to encompass digital media and broadening the definition of “news media” to explicitly include online news, websites and broadcasting. If we were at one on the question of media ownership then this would be a welcome extension. However, expansion at this time, while fundamental concerns regarding foreign ownership of traditional newspapers remain unresolved—or, indeed, are potentially being dangerously broadened—is illogical and dangerous, and we will not support these draft orders.

Online Safety Bill

Lord Clement-Jones Excerpts
Lord Parkinson of Whitley Bay Portrait The Parliamentary Under-Secretary of State, Department for Culture, Media and Sport (Lord Parkinson of Whitley Bay) (Con)
- Hansard - - - Excerpts

My Lords, I beg to move Motion A and, with the leave of the House, I shall also speak to Motions B to H.

I am pleased to say that the amendments made in your Lordships’ House to strengthen the Bill’s provisions were accepted in another place. His Majesty’s Government presented a number of amendments in lieu of changes proposed by noble Lords, which are before your Lordships today.

I am grateful to my noble friend Lady Morgan of Cotes for her continued engagement on the issue of small but high-risk platforms. The Government were happy to accept her proposed changes to the rules for determining the conditions that establish which services will be designated as category 1 or 2B services. In making the regulations, the Secretary of State will now have the discretion to decide whether to set a threshold based on either the number of users or the functionalities offered, or on both factors. Previously, the threshold had to be based on a combination of both.

It remains the expectation that services will be designated as category 1 services only where it is appropriate to do so, to ensure that the regime remains proportionate. We do not, for example, expect to apply these duties to large companies with very limited functionalities. This change, however, provides greater flexibility to bring smaller services with particular functionalities into scope of category 1 duties, should it be necessary to do so. As a result of this amendment, we have also made a small change to Clause 98—the emerging services list—to ensure that it makes operational sense. Before my noble friend’s amendment, a service would be placed on the emerging services list if it met the functionality condition and 75% of the user number threshold. Under the clause as amended, a service could be designated as category 1 without meeting both a functionality and a user condition. Without this change, Ofcom would, in such an instance, be required to list only services which meet the 75% condition.

We have heard from both Houses about the importance of ensuring that technology platforms are held to account for the impact of their design choices on children’s safety. We agree and the amendments we proposed in another place make it absolutely clear that providers must assess the impact of their design choices on the risk of harm to children, and that they deliver robust protections for children on all areas of their service. I thank in particular the noble Baroness, Lady Kidron, the noble Lords, Lord Stevenson of Balmacara and Lord Clement-Jones, my noble friend Lady Harding of Winscombe and the right reverend Prelate the Bishop of Oxford for their hard work to find an acceptable way forward. I also thank Sir Jeremy Wright MP for his helpful contributions to this endeavour.

Noble Lords will remember that an amendment from the noble Baroness, Lady Merron, sought to require the Secretary of State to review certain offences relating to animals and, depending on the outcome of that review, to list these as priority offences. To accelerate protections in this important area, the Government have tabled an amendment in lieu listing Section 4(1) of the Animal Welfare Act 2006 as a priority offence. This will mean that users can be protected from animal torture material more swiftly. Officials at the Department for Environment, Food and Rural Affairs have worked closely with the RSPCA and are confident that the Section 4 offence, unnecessary suffering of an animal, will capture a broad swathe of illegal activity. Adding this offence to Schedule 7 will also mean that linked inchoate offences, such as encouraging or assisting this behaviour, are captured by the illegal content duties. I am grateful to the noble Baroness for raising this matter, for her discussions on them with my noble friend Lord Camrose and for her support for the amendment we are making in lieu.

To ensure the speedy implementation of the Bill’s regime, we have added Clauses 116 to 118, which relate to the disclosure of information by Ofcom, and Clauses 170 and 171, which relate to super-complaints, to the provisions to be commenced immediately on Royal Assent. These changes will allow Ofcom and the Government to hold the necessary consultations as quickly as possible after Royal Assent. As noble Lords know, the intention of the Bill is to make the UK the safest place in the world to be online, particularly for children. I firmly believe that the Bill before your Lordships today will do that, strengthened by the changes made in this House and by the collaborative approach that has been shown, not just in all quarters of this Chamber but between both Houses of Parliament. I beg to move.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - -

My Lords, I thank the Minister very warmly for his introduction today. I shall speak in support of Motions A to H inclusive. Yes, I am very glad that we have agreement at this final milestone of the Bill before Royal Assent. I pay tribute to the Minister and his colleagues, to the Secretary of State, to the noble Baronesses, Lady Morgan, Lady Kidron and Lady Merron, who have brought us to this point with their persistence over issues such as functionalities, categorisation and animal cruelty.

This is not the time for rehearsing any reservations about the Bill. The Bill must succeed and implementation must take place swiftly. So, with many thanks to the very many, both inside and outside this House, who have worked so hard on the Bill for such a long period, we on these Benches wish the Bill every possible success. He is in his place, so I can say that it is over to the noble Lord, Lord Grade, and his colleagues at Ofcom, in whom we all have a great deal of confidence.

Online Safety Bill

Lord Clement-Jones Excerpts
Baroness Morgan of Cotes Portrait Baroness Morgan of Cotes (Con)
- View Speech - Hansard - - - Excerpts

My Lords, I welcome Amendments 5 and 6, as well as the amendments that reflect the work done and comments made in earlier stages of this debate by the noble Baroness, Lady Kennedy. Of course, we are not quite there yet with this Bill, but we are well on the way as this is the Bill’s last formal stage in this Chamber before it goes back to the House of Commons.

Amendments 5 and 6 relate to the categorisation of platforms. I do not want to steal my noble friend’s thunder, but I echo the comments made about the engagement both from my noble friend the Minister and from the Secretary of State. I am delighted that the indications I have received are that they will accept the amendment to Schedule 11, which this House voted on just before the Recess; that is a significant and extremely welcome change.

When commentators outside talk about the work of a revising Chamber, I hope that this Bill will be used as a model for cross-party, non-partisan engagement in how we make a Bill as good as it possibly can be—particularly when it is as ground-breaking and novel as this one is. My noble friend the Minister said in a letter to all of us that this Bill had been strengthened in this Chamber, and I think that is absolutely right.

I also want to echo thanks to the Bill team, some of whom I was working with four years ago when we were talking about this Bill. They have stuck with the Bill through thick and thin. Also, I thank noble Lords across the House for their support for the amendments but also all of those outside this House who have committed such time, effort, support and expertise to making sure this Bill is as good as possible. I wish it well with its final stages. I think we all look forward to both Royal Assent and also the next big challenge, which is implementation.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - -

My Lords, I thank the Minister for his introduction today and also for his letter which set out the reasons and the very welcome amendments that he has tabled today. First, I must congratulate the noble Baroness, Lady Stowell, for her persistence in pushing amendments of this kind to Clause 45, which will considerably increase the transparency of the Secretary of State’s directions if they are to take place. They are extremely welcome as amendments to Clause 45.

Of course, there is always a “but”—by the way, I am delighted that the Minister took the advice of the House and clearly spent his summer reading through the Bill in great deal, or we would not have seen these amendments, I am sure—but I am just sorry that he did not take the opportunity also to address Clause 176 in terms of the threshold for powers to direct Ofcom in special circumstances, and of course the rather burdensome powers in relation to the Secretary of State’s guidance on Ofcom’s exercise of its functions under the Bill as a whole. No doubt we will see how that works out in practice and whether they are going to be used on a frequent basis.

My noble friend Lord Allan—and I must congratulate both him and the noble Lord, Lord Knight, for their addressing this very important issue—has set out five assurances that he is seeking from the Minister. I very much hope that the Minister can give those today, if possible.

Congratulations are also due to the noble Baroness, Lady Kennedy, for finding a real loophole in the offence, which has now been amended. We are all delighted to see that the point has been well taken.

Finally, on the point raised by the noble Lord, Lord Rooker, clearly it is up to the Minister to respond to the points made by the committee. All of us would have preferred to see a comprehensive scheme in the primary legislation, but we are where we are. We wanted to see action on apps; they have some circumscribing within the terms of the Bill. The terms of the Bill—as we have discussed—particularly with the taking out of “legal but harmful”, do not give a huge amount of leeway, so this is not perhaps as skeleton a provision as one might otherwise have thought. Those are my reflections on what the committee has said.

Lord Knight of Weymouth Portrait Lord Knight of Weymouth (Lab)
- View Speech - Hansard - - - Excerpts

My Lords, I do not know how everyone has spent their summer, but this feels a bit like we have been working on a mammoth jigsaw puzzle and we are now putting in the final pieces. At times, through the course of this Bill, it has felt like doing a puzzle in the metaverse, where we have been trying to control an unreliable avatar that is actually assembling the jigsaw—but that would be an unfair description of the Minister. He has done really well in reflecting on what we have said, influencing his ministerial colleagues in a masterclass of managing upwards, and coming up with reasonable resolutions to previously intractable issues.

We are trusting that some of the outcome of that work will be attended to in the Commons, as the noble Baroness, Lady Morgan, has said, particularly the issues that she raised on risk, that the noble Baroness, Lady Kidron, raised on children’s safety by design, and that my noble friend Lady Merron raised on animal cruelty. We are delighted at where we think these issues have got to.

For today, I am pleased that the concerns of the noble Baroness, Lady Stowell, on Secretary of State powers, which we supported, have been addressed. I also associate myself with her comments on parliamentary scrutiny of the work of the regulator. Equally, we are delighted that the Minister has answered the concerns of my noble friend Lady Kennedy and that he has secured the legislative consent orders which he informed us of at the outset today. We would be grateful if the Minister could write to us answering the points of my noble friend Lord Rooker, which were well made by him and by the Delegated Powers Committee.

I am especially pleased to see that the issues which we raised at Report on remote access have been addressed. I feel smug, as I had to press quite hard for the Minister to leave the door open to come back at this stage on this. I am delighted that he is now walking through the door. Like the noble Lord, Lord Allan, I have just a few things that I would like clarification on—the proportional use of the powers, Ofcom taking into account user privacy, especially regarding live user data, and that the duration of the powers be time- limited.

Finally, I thank parliamentarians on all sides for an exemplary team effort. With so much seemingly falling apart around us, it is encouraging that, when we have common purpose, we can achieve a lot, as we have with this Bill.

--- Later in debate ---
Finally, I thank my noble friends Lady Gillian Merron and Lord Jim Knight, who have supported me throughout this period despite having significant responsibilities in other areas, have taken the strain when needed without complaint, and have indeed won improvements to the Bill that I perhaps would not even have thought of, let alone obtained. It has been a real team effort, a joy and a pleasure, and a most enjoyable experience.
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - -

My Lords, I am probably going to echo quite a lot of what the noble Lord, Lord Stevenson, had to say, and I also pay tribute to him. This is an absolutely crucial piece of cross-party-supported legislation that many said was impossible. I believe that it is a landmark, and we should all take huge encouragement from seeing it pass through this House.

We started with the Green Paper, as the noble Lord, Lord Stevenson, said, back in 2017. Many of us have been living with this issue since then, and I hope that therefore the House will not mind if I make a few more extended remarks than usual on the Motion that the Bill do now pass. I will not disappoint the noble Lord, Lord Stevenson, because I will quote from the original Joint Committee report. As we said in the introduction to our Joint Committee report back in 2021:

“The Online Safety Bill is a key step forward for democratic societies to bring accountability and responsibility to the internet”.


We said that the most important thing was to

“hold online services responsible for the risks created by their design and operation”.

Our children and many others will be safer online as a result.

Across the House, this has been a huge joint venture. We made some very good progress, with the Minister and the Secretary of State demonstrating considerable flexibility. I thank them sincerely for that. We have tightened the Bill up, particularly regarding harms and risks, while, I believe, ensuring that we protect freedom of expression. Many Members of this House, including former Members of the Joint Committee, can take some pride in what has been achieved during the passage of the Bill through the House. I will add my thanks to some of them individually shortly.

The Minister mentioned a relatively short list; he was actually rather modest in mentioning some of the concessions that have been given while the Bill has passed through the House. For instance, the tightening up of the age-assurance measures and the adding of a schedule of age-assurance principles are really important additions to the Bill.

Risk assessment of user empowerment tools is very important, and I believe that the provisions about app stores and future regulation are an important aspect of the Bill. The freedom of expression definition has been inserted into the Bill. We have had new offences, such as facilitating self-harm and intimate image abuse, added during the passage of the Bill. I am delighted to say that, as the noble Lord, Lord Stevenson, said, we expect to hear further concessions in the Commons on both the functionality issue raised by the noble Baroness, Lady Kidron, and the category 1 aspects raised by the noble Baroness, Lady Morgan.

We very much welcome the amendments that have been tabled today, including the remote-viewing clarification. We wait to hear what the Government’s position will be—I am sure that discussions are ongoing since the House voted to include a provision to review whether animal cruelty offences online should be brought into scope, and I am delighted to see the noble Baroness, Lady Hayman, here—and whether they will preserve the amendment and perhaps also include wildlife-trafficking offences in order to ensure that we avoid ping-pong on that last issue.

We on these Benches have never been minded to spoil the ship for a halfpenny-worth of tar, but that is not to say that there are not areas where we would have liked to have seen a bit more progress. I do not think the Minister will be surprised to hear me say that there are one or two such areas, such as: risk assessment, where we believe that the terms of service should be subject to a mandatory risk assessment; the threshold of evidence required for illegality; the prosecution threshold as regards the encouragement of non-fatal self-harm; the intent requirement for cyber flashing; and verification status and visibility, and whether Ofcom can actually introduce requirements.

I heard what the Minister had to say about AI-generated pornography but, like the NSPCC, I am not convinced that we have adequately covered the features provided as part of a service in the metasphere with which users interact. Bots in the metaverse are demonstrating an extraordinary level of autonomy that could potentially be harmful and, it seems, may not be covered by the Bill. Time will tell, and we will see whether that is the case.

Then of course there is the lack of legislative teeth for the review of research access and no requirement for guidance afterwards. I very much hope that will happen, despite there being no obligation at the end of the day.

I have mentioned Clauses 176 and 177. We wait to see how those will pan out. Then of course there is the issue on which these Benches have spoken virtually alone: the question of news publisher definition and exemption.

I very much welcome the last piece of assurance that the Minister gave in terms of Ofcom’s powers under Clause 122. Even as late as last night we heard news reports and current affairs programmes discussing the issue, and I genuinely believe that what the Minister said will be reassuring. Certainly I took comfort from what he had to say, and I thank him for agreeing to say it at a pretty late stage in the proceedings.

I think we all recognise that in many ways the Bill is just the beginning. There will be much further work to be done. We need to come back on misinformation when the committee set up under Clause 153 has reported. I hope that in particular it will look at issues such as provenance solutions such as those provided by the Content Authenticity Initiative. Fundamental changes will be needed to our electoral law in order to combat misinformation in the course of our elections, because we have had several Select Committees say that, and I believe the misinformation advisory committee will come to the same conclusion.

It is also clear that Parliament itself needs to decide how best to scrutinise the Bill in both its operation and its effectiveness. As we in the Joint Committee sought to suggest, there could be a Joint Committee of both Houses to carry on that scrutiny work, but I very much hope that will not be the case. I hope the SIT Select Committee in the Commons will pick up the cudgel and that the committee of the noble Baroness, Lady Stowell, the Communications and Digital Select Committee, will do likewise in the House of Lords.

Online Safety Bill

Lord Clement-Jones Excerpts
Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- View Speech - Hansard - - - Excerpts

My Lords, I promise I will be brief. I, too, welcome what the Minister has said and the amendments that the Government have proposed. This is the full package which we have been seeking in a number of areas, so I am very pleased to see it. My noble friend Lady Newlove and the noble Baroness, Lady Kidron, are not in their places, but I know I speak for both of them in wanting to register that, although the thoughtful and slow-and-steady approach has some benefits, there also some real costs to it. The UK Safer Internet Centre estimates that there will be some 340,000 individuals in the UK who will have no recourse for action if the platforms complaints mechanism does not work for them in the next two years. That is quite a large number of people, so I have one very simple question for the Minister: if I have exhausted the complaints procedure with an existing platform in the next two years, where do I go? I cannot go to Ofcom. My noble friend Lord Grade was very clear in front of the committee I sit on that it is not Ofcom’s job. Where do I go if I have a complaint that I cannot get resolved in the next two years?

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - -

My Lords, I declare an interest as chair of Trust Alliance Group, which operates the energy and communications ombudsman schemes, so I have a particular interest in the operation of these ADR schemes. I thank the Minister for the flexibility that he has shown in the provision about the report by Ofcom and in having backstop powers for the Secretary of State to introduce such a scheme.

Of course, I understand that the noble Baroness, Lady Newlove, and the UK Safer Internet Centre are very disappointed that this is not going to come into effect immediately, but there are advantages in not setting out the scheme at this very early point before we know what some of the issues arising are. I believe that Ofcom will definitely want to institute such a scheme, but it may be that, in the initial stages, working out the exact architecture is going to be necessary. Of course, I would have preferred to have a mandated scheme, in the sense that the report will look not at the “whether” but the “how”, but I believe that at the end of the day it will absolutely obvious that there needs to be such an ADR scheme in order to provide the kind of redress the noble Baroness, Lady Harding, was talking about.

I also agree with noble Baroness, Lady Morgan, that the kinds of complaints that this would cover should include fraudulent adverts. I very much hope that the Minister will be able to answer the questions that both noble Baronesses asked. As my noble friend said, will he reassure us that the department and Ofcom will not take their foot off the pedal, whatever the Bill may say?

Lord Parkinson of Whitley Bay Portrait Lord Parkinson of Whitley Bay (Con)
- View Speech - Hansard - - - Excerpts

I am grateful to noble Lords for their warm support and for heeding the advice of the noble Lord, Lord Stevenson, on brevity. We must finish our Report today. The noble Lord, Lord Allan, is right to mention my noble friend Lady Newlove, who I have spoken to about this issue, as well as the noble Lord, Lord Russell of Liverpool, who has raised some questions here.

Alongside the strong duties on services to offer content reporting and complaints procedures, our amendments will ensure that the effectiveness of these provisions can be reviewed after they have had sufficient time to bed in. The noble Lord, Lord Allan, asked about timing in more detail. Ofcom must publish the report within the two-year period beginning on the day on which the provision comes into force. That will allow time for the regime to bed in before the report takes place, ensuring that its conclusions are informed by how the procedures work in practice. If necessary, our amendments will allow the Secretary of State to impose via regulations a duty on the providers of category 1 services to arrange for and engage in an impartial, out-of-court alternative dispute resolution procedure, providing the further strengthening which I outlined in opening.

I can reassure my noble friend Lady Morgan of Cotes that reporting mechanisms to facilitate providers’ removal of fraudulent advertisements are exactly the kinds of issues that Ofcom’s codes of practice will cover, subject to consultation and due process. As companies have duties to remove fraudulent advertising once they are alerted to it, we expect platforms will need the necessary systems and processes in place to enable users to report fraudulent adverts so that providers can remove them.

My noble friend Lady Harding asked the question which was posed a lot in Committee about where one goes if all avenues are exhausted. We have added further avenues for people to seek redress if they do not get it but, as I said in Committee, the changes that we are bringing in through this Bill will mark a significant change for people. Rather than focusing on the even-further-diminished possibility of their not having their complaints adequately addressed through the additional amendments we are bringing today, I hope she will see that the provisions in the Bill and in these amendments as bringing in the change we all want to see to improve users’ safety online.

--- Later in debate ---
Lord Allan of Hallam Portrait Lord Allan of Hallam (LD)
- View Speech - Hansard - - - Excerpts

My Lords, I am pleased to follow the noble Baroness, Lady Morgan of Coates, and her amendment, which tries to help parliamentary counsel draft better regulations later on. I am really struggling to see why the Government want to resist something that will make their life easier if they are going to do what we want them to do, which is to catch those high-risk services—as the noble Baroness, Lady Finlay, set out—but also, as we have discussed in Committee and on Report, exclude the low-risk services that have been named, such as Wikipedia and OpenStreetMap.

I asked the Minister on Report how that might happen, and he confirmed that such services are not automatically exempt from the user-to-user services regulations, but he also confirmed that they might be under the subsequent regulations drafted under Schedule 11. That is precisely why we are coming back to this today; we want to make sure that they can be exempt under the regulations drafted under Schedule 11. The test should be: would that be easier under the amended version proposed by the noble Baroness, Lady Morgan, or under the original version? I think it would be easier under the amended version. If the political intent is there to exclude the kind of services that I have talked about—the low-risk services—and I think it should be, because Ofcom should not be wasting time, in effect, supervising services that do not present a risk and, not just that, creating a supervisory model that may end up driving those services out of the UK market because they cannot legally say that they will make the kind of commitments Ofcom would expect them to make, having two different thresholds, size and functionality, gives the draftspeople the widest possible choice. By saying “or”, we are not saying they cannot set a condition that is “and” or excludes “and”, but “and” does exclude “or”, if I can put it that way. They can come back with a schedule that says, “You must be of this size and have this kind of functionality”, or they could say “this functionality on its own”—to the point made by the two noble Baronesses about some sites. They might say, “Look, there is functionality which is always so high-risk that we do not care what size you are; if you’ve got this functionality, you’re always going to be in”. Again, the rules as drafted at the moment would not allow them to do that; they would have to say, “You need to have this functionality and be of this size. Oh, whoops, by saying that you have to be of this size, we’ve now accidentally caught somebody else who we did not intend to catch”.

I look forward to the Minister’s response, but it seems entirely sensible that we have the widest possible choice. When we come to consider this categorisation under Schedule 11 later on, the draftspeople should be able to say either “You must be this size and have this functionality” or “If you’ve got this functionality, you’re always in” or “If you’re of this size, you’re always in”, and have the widest possible menu of choices. That will achieve the twin objectives which I think everyone who has taken part in the debate wants: the inclusion of high-risk services, no matter their size, and the exclusion of low-risk services, no matter their size—if they are genuinely low risk. That is particularly in respect of the services we have discussed and which the noble Lord, Lord Moylan, has been a very strong advocate for. In trying to do good, we should not end up inadvertently shutting down important information services that people in this country rely on. Frankly, people would not understand it if we said, “In the name of online safety, we’ve now made it so that you cannot access an online encyclopaedia or a map”.

It is going to be much harder for the draftspeople to draft categorisation under Schedule 11, as it is currently worded, that has the effect of being able to exclude low-risk services. The risk of their inadvertently including them and causing that problem is that much higher. The noble Baroness is giving us a way out and I hope the Minister will stand up and grab the lifeline. I suspect he will not.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - -

My Lords, I welcome the Minister’s Amendment 238A, which I think was in response to the DPRRC report. The sentiment around the House is absolutely clear about the noble Baroness’s Amendment 245. Indeed, she made the case conclusively for the risk basis of categorisation. She highlighted Zoe’s experience and I struggle to understand why the Secretary of State is resisting the argument. She knocked down the nine pins of legal uncertainty, and how it was broader than children and illegal by reference to Clause 12. The noble Baroness, Lady Finlay, added to the knocking down of those nine pins.

Smaller social media platforms will, on the current basis of the Bill, fall outside category 1. The Royal College of Psychiatrists made it pretty clear that the smaller platforms might be less well moderated and more permissive of dangerous content. It is particularly concerned about the sharing of information about methods of suicide or dangerous eating disorder content. Those are very good examples that it has put forward.

I return to the scrutiny committee again. It said that

“a more nuanced approach, based not just on size and high-level functionality, but factors such as risk, reach, user base, safety performance, and business model”

should be adopted. It seems that many small, high-harm services will be excluded unless we go forward on the basis set out by the noble Baroness, Lady Morgan. The kind of breadcrumbing we have talked about during the passage of the Bill and, on the other hand, sites such as Wikipedia, as mentioned by noble friend, will be swept into the net despite being low risk.

I have read the letter from the Secretary of State which the noble Baroness, Lady Morgan, kindly circulated. I cannot see any argument in it why Amendment 245 should not proceed. If the noble Baroness decides to test the opinion of the House, on these Benches we will support her.

Lord Knight of Weymouth Portrait Lord Knight of Weymouth (Lab)
- View Speech - Hansard - - - Excerpts

My Lords, I have good news and bad news for the Minister. The good news is that we have no problem with his amendments. The bad news, for him, is that we strongly support Amendment 245 from the noble Baroness, Lady Morgan of Coates, which, as others have said, we think is a no-brainer.

The beauty of the simple amendment has been demonstrated; it just changes the single word “and” to “or”. It is of course right to give Ofcom leeway—or flexibility, as the noble Baroness, Lady Finlay, described it—in the categorisation and to bring providers into the safety regime. What the noble Baroness, Lady Morgan, said about the smaller platforms, the breadcrumbing relating to the Jake Davison case and the functionality around bombarding Zoe Lyalle with those emails told the story that we needed to hear.

As it stands, the Bill requires Ofcom to always be mindful of size. We need to be more nuanced. From listening to the noble Lord, Lord Allan of Hallam—with his, as ever, more detailed analysis of how things work in practice—my concern is that in the end, if it is all about size, Ofcom will end up having to have a much larger number in scope on the categorisation of size in order to cover all the platforms that it is worried about. If we could give flexibility around size or functionality, that would make the job considerably easier.

We on this side think categorisation should happen with a proportionate, risk-based approach. We think the flexibility should be there, the Minister is reasonable—come on, what’s not to like?

--- Later in debate ---
Lord Stevenson of Balmacara Portrait Lord Stevenson of Balmacara (Lab)
- Hansard - - - Excerpts

My Lords, this amendment would require the Secretary of State, when seeking to exercise certain powers in the Bill, to provide the relevant Select Committees of both Houses with draft regulations and impact assessments, among other things. I should admit up front that this is a blatant attempt to secure an Online Safety Bill version of what I have called the “Grimstone rule”, established in the international trade Bill a few years ago. Saving his blushes, if the ideas enshrined in the amendment are acceptable to the Government, I hope that the earlier precedent of the “Grimstone rule” would ensure that any arrangements agreed under this amendment would be known in future as the “Parkinson rule”. Flattery will get you many things.

The Bill places a specific consultation requirement on the Government for the fee regime, which we were just talking about, categorisation thresholds, regulations about reports to the NCA, statements of strategic priorities, regulations for super-complaints, and a review of the Act after three years—so a wide range of issues need to be put out for consultation. My context here, which is all-important, is a growing feeling that Parliament’s resources are not being deployed to the full in scrutinising and reviewing the work of the Executive on the one hand and feeding knowledge and experience into future policy on the other. There is continuing concern about the effectiveness of the secondary legislation approval procedures, which this amendment would bear on.

Noble Lords have only to read the reports of the Select Committees of both Houses to realise what a fantastic resource they represent. One has only to have served on a Select Committee to realise what potential also exists there. In an area of rapid technical and policy development, such as the digital world, the need to be more aware of future trends and potential problems is absolutely crucial.

The pre-legislative scrutiny committee report is often quoted here, and it drew attention to this issue as well, recommending

“a Joint Committee of both Houses to oversee digital regulation with five primary functions: scrutinising digital regulators and overseeing the regulatory landscape … scrutinising the Secretary of State’s work into digital regulation; reviewing the codes of practice laid by Ofcom under any legislation relevant to digital regulation … considering any relevant new developments such as the creation of new technologies and the publication of independent research … and helping to generate solutions to ongoing issues in digital regulation”—

a pretty full quiver of issues to be looked at.

I hope that when he responds to this debate, the Minister will agree that ongoing parliamentary scrutiny would be helpful in providing reassurances that the implementation of the regime under the Bill is going as intended, and that the Government would also welcome a system under which Parliament, perhaps through the Select Committees, can contribute to the ways suggested by the Joint Committee. I say “perhaps”, because I accept that it is not appropriate for primary legislation to dictate how, or in what form, Parliament might offer advice in the manner that I have suggested; hence the suggestion embedded in the amendment—which I will not be pressing to a Division—which I call the “Parkinson rule”. Under this, the Minister would agree at the Dispatch Box a series of commitments which will provide an opportunity for enhanced cross-party scrutiny of the online safety regime and an opportunity to survey and report on future developments of interest.

The establishment of the new Department for Science, Innovation and Technology and its Select Committee means that there is a new dedicated Select Committee in the Commons. The Lords Communications and Digital Committee will continue, I hope, to play a vital role in the scrutiny of the digital world, as it has with the online safety regime to date. While it would be for the respective committees to decide their priorities, I hope the Government would encourage the committees in both Houses to respond to their required consultation processes and to look closely at the draft codes of practice, the uses of regulation-making powers and the powers of direction contained in the Bill ahead of the formal processes in both Houses. Of course, it could be a specialist committee if that is what the Houses decide, but there is an existing arrangement under which this “Parkinson rule” could be embedded. I have discussed the amendment with the Minister and with the Bill team. I look forward to hearing their response to the ideas behind the amendment. I beg to move the “Parkinson rule”.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - -

I support the amendment of the noble Lord, Lord Stevenson. Here is an opportunity for the Minister to build a legislative monument. I hope he will take it. The reason I associate myself with it is because the noble Lord, Lord Stevenson—who has been sparing in his quoting of the Joint Committee’s report, compared with mine—referred to it and it all made very good sense.

The amendment stumbles only in the opinion of the Government, it seems, on the basis that parliamentary committees need to be decided on by Parliament, rather than the Executive. But this is a very fine distinction, in my view, given that the Government, in a sense, control the legislature and therefore could will the means to do this, even if it was not by legislation. A nod from the Minister would ensure that this would indeed take place. It is very much needed. It was the Communications and Digital Committee, I think, that introduced the idea that we picked up in the Joint Committee, so it has a very good provenance.

Lord Hope of Craighead Portrait Lord Hope of Craighead (CB)
- View Speech - Hansard - - - Excerpts

My Lords, I offer my support to the amendment. I spent some time arguing in the retained EU law Bill for increased parliamentary scrutiny. My various amendments did not succeed but at the end of the day—on the final day of ping-pong—the Minister, the noble Lord, Lord Callanan, gave certain assurances based on what is in Schedule 5 to that Act, as it now is, involving scrutiny through committees. So the basic scheme which my noble kinsman has proposed is one which has a certain amount of precedent—although it is not an exact precedent; what might have been the “Callanan rule” is still open to reconstruction as the “Parkinson rule”. I support the amendment in principle.

--- Later in debate ---
Baroness Stowell of Beeston Portrait Baroness Stowell of Beeston (Con)
- View Speech - Hansard - - - Excerpts

My Lords, I added my name to some amendments on this issue in Committee. I have not done so on Report, not least because I have been so occupied with other things and have not had the time to focus on this. However, I remain concerned about this part of the Bill. I am sympathetic to my noble friend Lord Moylan’s Amendment 255, but listening to this debate and studying all the amendments in this group, I am a little confused and so have some simple questions.

First, I heard my noble friend the Minister say that the Government have no intention to require the platforms to carry out general monitoring, but is that now specific in any of the amendments that he has tabled? Regarding the amendments which would bring further safeguards around the oversight of Ofcom’s use of this power, like my noble friend Lady Harding, I have always been concerned that the oversight approach should be in line with that for the Investigatory Powers Act and could never understand why it was not in the original version of the Bill. Like her, I am pleased that the Government have tabled some amendments, but I am not yet convinced that they go far enough.

That leads me to the amendments that have been tabled by the noble Lords, Lord Stevenson and Lord Clement-Jones, and particularly that in the name of the noble Lord, Lord Allan of Hallam. As his noble friend Lord Clement-Jones has added his name to it, perhaps he could answer my question when he gets up. Would the safeguards that are outlined there—the introduction of the Information Commissioner—meet the concerns of the big tech companies? Do we know whether it would meet their needs and therefore lead them not to feel it necessary to withdraw their services from the UK? I am keen to understand that.

There is another thing that might be of benefit for anyone listening to this debate who is not steeped in the detail of this Bill, and I look to any of those winding up to answer it—including my noble friend the Minister. Is this an end to end-to-end encryption? Is that what is happening in this Bill? Or is this about ensuring that what is already permissible in terms of the authorities being able to use their powers to go after suspected criminals is somehow codified in this Bill to make sure it has proper safeguards around it? That is still not clear. It would be very helpful to get that clarity from my noble friend, or others.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - -

My Lords, it is a pleasure to follow the noble Baroness, Lady Stowell. My noble friend has spoken very cogently to Amendment 258ZA, and I say in answer to the question posed by the noble Baroness that I do not think this is designed to make big tech companies content. What it is designed to do is bring this out into the open and make it contestable; to see whether or not privacy is being invaded in these circumstances. To that extent it airs the issues and goes quite a long way towards allaying the concerns of those 80 organisations that we have heard from.

I am not going to repeat all the arguments of my noble friend, but many noble Lords, not least on the opposite Benches, have taken us through some of the potential security and privacy concerns which were also raised by my noble friends, and other reasons for us on these Benches putting forward these amendments. We recognise those concerns and indeed we recognise concerns on both sides. We have all received briefs from the NSPCC and the IWF, but I do not believe that essentially what is being proposed here in our amendments, or indeed by the amendments put forward by the noble Lord, Lord Stevenson, are designed in any way to prevent Ofcom doing its duty in relation to child sexual abuse and exploitation material in private messaging. We believe that review by the ICO to ensure that there is no invasion of privacy is a very useful mechanism.

We have all tried to find solutions and the Minister has put forward his stab at this with the skilled persons report. The trouble is, that does not go far enough, as the noble Baroness, Lady Stowell, said. Effectively, Ofcom can choose the skilled person and what the skilled person is asked to advise on. It is not necessarily comprehensive and that is essentially the major flaw.

As regards the amendments put forward by the noble Lord, Lord Stevenson, it is interesting that the Equality and Human Rights Commission itself said:

“We are concerned by the extent and seriousness of CSEA content being shared online. But these proposed measures may be a disproportionate infringement on millions of individuals’ right to privacy where those individuals are not suspected of any wrongdoing”.


It goes on to say:

“We recommend that Ofcom should be required to apply to an independent judicial commissioner—as is the case for mass surveillance under the Investigatory Powers Act”.


I am sure that is the reason why the noble Lord, Lord Stevenson, put forward his amendments; if he put them to a vote, we would follow and support. Otherwise, we will put our own amendments to the House.

Lord Stevenson of Balmacara Portrait Lord Stevenson of Balmacara (Lab)
- View Speech - Hansard - - - Excerpts

My Lords, this has been—since we first got sight of the Bill and right the way through—one of the most difficult issues to try to find balance and a solution. I know that people have ridiculed my attempt to try and get people to speak less in earlier amendments. Actually, in part it was so we could have a longer debate here—so the noble Lord, Lord Moylan, should not be so cross with me, and I hope that we can continue to be friends, as we are outside the Chamber, on all points, not just this one.

Talk is not getting us to a solution on this, unfortunately. I say to the Minister: I wonder whether there is a case here for pausing a little bit longer on this, because I still do not think we have got to the bottom of where the balance lies. I want to explain why I say that, because, in a way, I follow the noble Baroness, Lady Stowell, in worrying that there are some deeper questions here that we have not quite got the answers to. Nothing in the current amendments gets us to quite the right place.

I started by thinking that, if only because Ofcom was being seen to be placed in a position of both being a part of the regulatory process, but also having the rights to interpose itself into where this issue about encryption came up, Ofcom needed the safety of an external judicial review along the lines of the current RIPA system. That has led us to my Amendments 256, 257 and 259, which try to distil that sensibility into a workable frame for the Bill and these issues. I will not push it to a vote. It is there because I wanted to have in the discussion a proper look at what the RIPA proposal would look like in practice.

--- Later in debate ---
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - -

My Lords, I think the upshot of this brief debate is that the noble Lord, Lord Knight —how he was tracked down in a Pret A Manger, I have no idea; he is normally too fast-moving for that—in his usual constructive and creative way is asking the Government to constructively engage to find a solution, which he discussed in that Pret A Manger, involving a national helpline, the NSPCC and the Children’s Commissioner, for the very reasons that he and my noble friend Lord Allan have put forward. In no way would this be some of kind of quango, in the words of the noble Baroness, Lady Fox.

This is really important stuff. It could be quite a game-changer in the way that the NSPCC and the Children’s Commissioner collaborate on tackling the issues around social media, the impact of the new rights under the Bill and so on. I very much hope that the Government will be able to engage positively on this and help to bring the parties together to, in a sense, deliver something which is not in the Bill but could be of huge importance.

Lord Parkinson of Whitley Bay Portrait Lord Parkinson of Whitley Bay (Con)
- View Speech - Hansard - - - Excerpts

My Lords, first, I reassure noble Lords that the Government are fully committed to making sure that the interests of children are both represented and protected. We believe, however, that this is already achieved through the provisions in the Bill.

Rather than creating a single advocacy body to research harms to children and advocate on their behalf, as the noble Lord’s amendment suggests, the Bill achieves the same effect through a combination of Ofcom’s research functions, the consultation requirements and the super-complaints provisions. Ofcom will be fully resourced with the capacity and technological ability to assess and understand emerging harms and will be required to research children’s experiences online on an ongoing basis.

For the first time, there will be a statutory body in place charged with protecting children from harm online. As well as its enforcement functions, Ofcom’s research will ensure that the framework remains up to date and that Ofcom itself has the latest, in-depth information to aid its decision-making. This will ensure that new harms are not just identified in retrospect when children are already affected by them and complaints are made; instead, the regulator will be looking out for new issues and working proactively to understand concerns as they develop.

Children’s perspectives will play a central role in the development of the framework, as Ofcom will build on its strong track record of qualitative research to ensure that children are directly engaged. For example, Ofcom’s ongoing programme, Children’s Media Lives, involves engaging closely with children and tracking their views and experiences year on year.

Alongside its own research functions, super-complaints will ensure that eligible bodies can make complaints on systemic issues, keeping the regulator up to date with issues as they emerge. This means that if Ofcom does not identify a systemic issue affecting children for any reason, it can be raised and then dealt with appropriately. Ofcom will be required to respond to the super-complaint, ensuring that its subsequent decisions are understood and can be scrutinised. Complaints by users will also play a vital role in Ofcom’s horizon scanning and information gathering, providing a key means by which new issues can be raised.

The extensive requirements for Ofcom to consult on codes of practice and guidance will further ensure that it consistently engages with groups focused on the interests of children as the codes and guidance are developed and revised. Children’s interests are embedded in the implementation and delivery of this framework.

The Children’s Commissioner will play a key and ongoing role. She will be consulted on codes of practice and any further changes to those codes. The Government are confident that she will use her statutory duties and powers effectively to understand children’s experiences of the digital world. Her primary function as Children’s Commissioner for England is promoting and protecting the rights of children in England and to promote and protect the rights of children across the United Kingdom where those rights are or may be affected by reserved matters. As the codes of practice and the wider Bill relate to a reserved area of law—namely, internet services—the Children’s Commissioner for England will be able to represent the interests of children from England, Scotland, Wales and Northern Ireland when she is consulted on the preparation of codes of practice. That will ensure that children’s voices are represented right across the UK. The Children’s Commissioner for England and her office also regularly speak to the other commissioners about ongoing work on devolved and reserved matters. Whether she does that in branches of Pret A Manger, I do not know, but she certainly works with her counterparts across the UK.

I am very happy to take back the idea that the noble Lord has raised and discuss it with the commissioner. There are many means by which she can carry out her duties, so I am very happy to take that forward. I cannot necessarily commit to putting it in legislation, but I shall certainly commit to discussing it with her. On the proposals in the noble Lord’s amendment, we are concerned that a separate child user advocacy body would duplicate the functions that she already has, so I hope with that commitment he will be happy to withdraw.

--- Later in debate ---
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - -

My Lords, I can be very brief. My noble friend Lady Benjamin and the noble Baronesses, Lady Harding, Lady Morgan and Lady Fraser, have all very eloquently described why these amendments in this group are needed.

It is ironic that we are still having this debate right at the end of Report. It has been a running theme throughout the passage of the Bill, both in Committee and on Report, and of course it ran right through our Joint Committee work. It is the whole question of safety by design, harm from functionalities and, as the noble Baroness, Lady Morgan, said, understanding the operation of the algorithm. And there is still the question: does the Bill adequately cover what we are trying to achieve?

As the noble Baroness, Lady Harding, said, Clause 1 now does set out the requirement for safety by design. So, in the spirit of amity, I suggested to the Minister that he might run a check on the Bill during his free time over the next few weeks to make sure that it really does cover it. But, in a sense, there is a serious point here. Before Third Reading there is a real opportunity to run a slide rule over the Bill to see whether the present wording really is fit for purpose. So many of us around this House who have lived and breathed this Bill do not believe that it yet is. The exhortation by the ethereal presences of the noble Baronesses, Lady Kidron and Lady Harding, to keep pressing to make sure that the Bill is future-proofed and contains the right ingredients is absolutely right.

I very much hope that once again the Minister will go through the hoops and explain whether this Bill really captures functionality and design and not just content, and whether it adequately covers the points set out in the purpose of the Bill which is now there.

Baroness Merron Portrait Baroness Merron (Lab)
- View Speech - Hansard - - - Excerpts

My Lords, as we have heard, the noble Baroness, Lady Harding, made a very clear case in support of these amendments, tabled in the name of the noble Baroness, Lady Kidron, and supported by noble Lords from across the House. The noble Baroness, Lady Morgan, gave wise counsel to the Minister, as did the noble Lord, Lord Clement-Jones, that it is worth stepping back and seeing where we are in order to ensure that the Bill is in the right place. I urge the Minister to find the time and the energy that I know he has—he certainly has the energy and I am sure he will match it with the time—to speak to noble Lords over the coming Recess to agree a way to incorporate systems and functionality into the Bill, for all the reasons we have heard.

On Monday, my noble friend Lord Knight spoke of the need for a review about loot boxes and video games. When we checked Hansard, we saw the Minister had promised that such a review would be offered in the coming months. In an unusual turn of events, the Minister exceeded the timescale. We did not have to hear the words “shortly”, “in the summer” or “spring” or anything like that, because it was announced the very next day that the department would keep legislative options under review.

I make that point simply to thank the Minister for the immediate response to my noble friend Lord Knight. But, if we are to have such a review, does this not point very much to the fact that functionality and systems should be included in the Bill? The Minister has a very nice hook to hang this on and I hope that he will do so.

Online Safety Bill

Lord Clement-Jones Excerpts
Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- View Speech - Hansard - - - Excerpts

My Lords, I will speak briefly on a couple of amendments and pick up from where the noble Lord, Lord Allan, just finished on Amendment 186A. I associate myself with all the comments that the noble Baroness, Lady Kidron, made on her Amendment 191A. As ever, she introduced the amendment so brilliantly that there is no need for me to add anything other than my wholehearted support.

I will briefly reference Amendment 253 from the noble Lord, Lord Clement-Jones. Both his amendment and my noble friend Lord Moylan’s point to one of the challenges about regulating the digital world, which is that it touches everything. We oscillate between wanting to compartmentalise the digital and recognising that it is interconnected to everything. That is the same challenge faced by every organisation that is trying to digitise: do you ring-fence or recognise that it touches everything? I am very supportive of the principles behind Amendment 253 precisely because, in the end, it does touch everything. It is hugely important that, even though this Bill and others still to come are creating an extraordinarily powerful single regulator in the form of Ofcom, we also recognise the interconnectivity of the regulatory landscape. The amendment is very well placed, and I hope my noble friend the Minister looks favourably on it and its heritage from the pre-legislative scrutiny committee.

I will briefly add my thoughts on Amendment 186A in this miscellaneous group. It feels very much as if we are having a Committee debate on this amendment, and I thank my noble friend Lord Moylan for introducing it. He raises a hugely important point, and I am incredibly sympathetic to the logic he set out.

In this area the digital world operates differently from the physical world, and we do not have the right balance at all between the powers of the big companies and consumer rights. I am completely with my noble friend in the spirit in which he introduced the amendment but, together with the noble Lord, Lord Allan, I think it would be better tackled in the Digital Markets, Competition and Consumers Bill, precisely because it is much broader than online safety. This fundamentally touches the issue of consumer rights in the digital world and I am worried that, if we are not careful, we will do something with the very best intentions that actually makes things slightly worse.

I worry that the terms and conditions of user-to-user services are incomprehensible to consumers today. Enshrining it as a contract in law might, in some cases, make it worse. Today, when user-to-user services have used our data for something, they are keen to tell us that we agreed to it because it was in their terms of service. My noble friend opens up a really important issue to which we should give proper attention when the Digital Markets, Competition and Consumers Bill arrives in the House. It is genuinely not too late to address that, as it is working its way through the Commons now. I thank my noble friend for introducing the amendment, because we should all have thought of the issue earlier, but it is much broader than online safety.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - -

My Lords, even by previous standards, this is the most miscellaneous of miscellaneous groups. We have ranged very broadly. I will speak first to Amendment 191A from the noble Baroness, Lady Kidron, which was so well spoken to by her and by the noble Baroness, Lady Harding. It is common sense, and my noble friend Lord Allan, as ever, put his finger on it: it is not as if coroners are going to come across this every day of the week; they need this kind of guidance. The Minister has introduced his amendments on this, and we need to reduce those to an understandable code for coroners and bereaved parents. I defy anybody, apart from about three Members of this House, to describe in any detail how the information notices will interlock and operate. I could probably name those Members off the top of my head. That demonstrates why we need such a code of practice. It speaks for itself.

I am hugely sympathetic to Amendment 275A in the name of the noble Baroness, Lady Finlay, who asked a series of important questions. The Minister said at col. 1773 that he would follow up with further information on the responsibility of private providers for their content. This is a real, live issue. The noble Baroness, Lady Kidron, put it right: we hope fervently that the Bill covers the issue. I do not know how many debates about future-proofing we have had on the Bill but each time, including in that last debate, we have not quite been reassured enough that we are covering the metaverse and provider content in the way we should be. I hope that this time the Minister can give us definitive chapter and verse that will help to settle the horses, so to speak, because that is exactly what the very good amendment in the name of the noble Baroness, Lady Finlay, was about.

--- Later in debate ---
Lord Parkinson of Whitley Bay Portrait Lord Parkinson of Whitley Bay (Con)
- Hansard - - - Excerpts

We are keen to ensure that coroners have access to the information and expertise that they need, while respecting the independence of the judicial process to decide what they do not know and would like to know more about and the role of the Chief Coroner there. It is a point that I have discussed a lot with the noble Baroness and with my noble friend Lady Newlove in her former role as Victims’ Commissioner. I am very happy to continue doing so because it is important that there is access to that.

The noble Lord, Lord Stevenson, spoke to the amendments tabled by the noble Baroness, Lady Merron, about supposedly gendered language in relation to Clauses 141 and 157. As I made clear in Committee, I appreciate the intention—as does Lady Deben—of making clear that a person of either sex can perform the role of chairman, just as they can perform the role of ombudsman. We have discussed in Committee the semantic point there. The Government have used “chairman” here to be consistent with terminology in the Office of Communications Act 2002. I appreciate that this predates the Written Ministerial Statement which the noble Lord cited, but that itself made clear that the Government at the time recognised that in practice, parliamentary counsel would need to adopt a flexible approach to this change—for example, in at least some of the cases where existing legislation originally drafted in the former style is being amended.

The noble Lord may be aware of a further Written Ministerial Statement, made on 23 May last year, following our debates on gendered language on another Bill, when the then Lord President of the Council and Leader of the House of Commons said that the Office of the Parliamentary Counsel would update its drafting guidance in light of that. That guidance is still forthcoming. However, importantly, the term here will have no bearing on Ofcom’s decision-making on who would chair the advisory committees. It must establish that this could indeed be a person of either sex.

Amendment 253 seeks to enable co-operation, particularly via information-sharing, between Ofcom and other regulators within the UK. I reassure noble Lords that Section 393 of the Communications Act 2003 already includes provisions for sharing information between Ofcom and other regulators in the UK.

As has been noted, Ofcom already co-operates effectively with other domestic regulators. That has been strengthened by the establishment of the Digital Regulation Co-operation Forum. By promoting greater coherence, the forum helps to resolve potential tensions, offering clarity for people and the industry. It ensures collaborative work across areas of common interest to address complex problems. Its outputs have already delivered real and wide-ranging impacts, including landmark policy statements clarifying the interactions between digital regulatory regimes, research into cross-cutting issues, and horizon-scanning activities on new regulatory challenges. We will continue to assess how best to support collaboration between digital regulators and to ensure that their approaches are joined up. We therefore do not think that Amendment 253 is necessary.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, the Minister has not stated that there is a duty to collaborate. Is he saying that that is, in fact, the case in practice?

Lord Parkinson of Whitley Bay Portrait Lord Parkinson of Whitley Bay (Con)
- Hansard - - - Excerpts

Yes, there is a duty, and the law should be followed. I am not sure whether the noble Lord is suggesting that it is not—

--- Later in debate ---
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

Is there a duty to collaborate between regulators?

Lord Parkinson of Whitley Bay Portrait Lord Parkinson of Whitley Bay (Con)
- Hansard - - - Excerpts

I am not sure that I follow the noble Lord’s question, but perhaps—

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, the Minister is saying that, in practice, there is a kind of collaboration between regulators and that there is a power under the Communications Act, but is he saying that there is any kind of duty on regulators to collaborate?

Lord Parkinson of Whitley Bay Portrait Lord Parkinson of Whitley Bay (Con)
- Hansard - - - Excerpts

If I may, I will write to the noble Lord setting that out; he has lost me with his question. We believe, as I think he said, that the forum has added to the collaboration in this important area.

The noble Baroness, Lady Finlay, raised important questions about avatars and virtual characters. The Bill broadly defines “content” as

“anything communicated by means of an internet service”,

meaning that it already captures the various ways through which users may encounter content. In the metaverse, this could therefore include things such as avatars or characters created by users. As part of the user-to-user services’ risk assessments, providers will be required to consider more than the risk in relation to user-generated content, including aspects such as how the design and operation of their services, including functionality and how the service is used, might increase the risk of harm to children and the presence of illegal content. A user-to-user service will need to consider any feature which enables interaction of any description between users of the service when carrying out its risk assessments.

The Bill is focused on user-to-user and search services, as there is significant evidence to support the case for regulation based on the risk of harm to users and the current lack of regulatory and other accountability in this area. Hosting, sharing and the discovery of user-generated content and activity give rise to a range of online harms, which is why we have focused on those services. The Bill does not regulate content published by user-to-user service providers themselves; instead, providers are already liable for the content that they publish on their services themselves, and the criminal law is the most appropriate mechanism for dealing with services which publish illegal provider content.

The noble Baroness’s Amendment 275A seeks to require Ofcom to produce a wide-ranging report of behaviour facilitated by emerging technologies. As we discussed in Committee, the Government of course agree that Ofcom needs continually to assess future risks and the capacity of emerging technologies to cause harm. That is why the Bill already contains provisions which allow it to carry out broad horizon scanning, such as its extensive powers to gather information, to commission skilled persons’ reports and to require providers to produce transparency reports. Ofcom has already indicated that it plans to research emerging technologies, and the Bill will require it to update its risk assessments, risk profiles and codes of practice with the outcomes of this research where relevant.

As we touched on in Committee, Clause 56 requires regular reviews by Ofcom into the incidence of content that is harmful to children, and whether there should be changes to regulations setting out the kinds of content that are harmful to children. In addition, Clause 143 mandates that Ofcom should investigate users’ experience of regulated services, which are likely to cover user interactions in virtual spaces, such as the metaverse and those involving content generated by artificial intelligence.

--- Later in debate ---
Lord Parkinson of Whitley Bay Portrait Lord Parkinson of Whitley Bay (Con)
- Hansard - - - Excerpts

I am happy to provide further detail in writing and to reiterate the points I have made as it is rather technical. Content that is published by providers of user-to-user services themselves is not regulated by the Bill because providers are liable for the content they publish on the services themselves. Of course, that does not apply to pornography, which we know poses a particular risk to children online and is regulated through Part 5 of the Bill. I will set out in writing, I hope more clearly, for the noble Baroness what is in scope to reassure her about the way the Bill addresses the harms that she has rightly raised.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

Will the Minister copy other Members in?

--- Later in debate ---
Lord Moylan Portrait Lord Moylan (Con)
- View Speech - Hansard - - - Excerpts

My Lords, it is valuable to be able to speak immediately after my noble friend Lady Harding of Winscombe, because it gives me an opportunity to address some remarks she made last Wednesday when we were considering the Bill on Report. She suggested that there was a fundamental disagreement between us about our view of how serious online safety is—the suggestion being that somehow I did not think it was terribly important. I take this opportunity to rebut that and to add to it by saying that other things are also important. One of those things is privacy. We have not discussed privacy in relation to the Bill quite as much as we have freedom of expression, but it is tremendously important too.

Government Amendment 247A represents the most astonishing level of intrusion. In fact, I find it very hard to see how the Government think they can get away with saying that it is compatible with the provisions of the European Convention on Human Rights, which we incorporated into law some 20 years ago, thus creating a whole law of privacy that is now vindicated in the courts. It is not enough just to go around saying that it is “proportionate and necessary” as a mantra; it has to be true.

This provision says that an agency has the right to go into a private business with no warrant, and with no let or hindrance, and is able to look at its processes, data and equipment at will. I know of no other business that can be subjected to that without a warrant or some legal process in advance pertinent to that instance, that case or that business.

My noble friend Lord Bethell said that the internet has been abused by people who carry out evil things; he mentioned terrorism, for example, and he could have mentioned others. However, take mobile telephones and Royal Mail—these are also abused by people conducting terrorism, but we do not allow those communications to be intruded into without some sort of warrant or process. It does not seem to me that the fact that the systems can be abused is sufficient to justify what is being proposed.

My noble friend the Minister says that this can happen only offline. Frankly, I did not understand what he meant by that. In fact, I was going to say that I disagreed with him, but I am moving to the point of saying that I think it is almost meaningless to say that it is going to happen offline. He might be able to explain that. He also said that Ofcom will not see individual traffic. However, neither the point about being offline nor the point about not seeing individual traffic is on the face of the Bill.

When we ask ourselves what the purpose of this astonishing power is—this was referred to obliquely to some extent by the noble Baroness, Lady Fox of Buckley—we can find it in Clause 91(1), to which proposed new subsection (2A) is being added or squeezed in subordinate to it. Clause 91(1) talks about

“any information that they”—

that is, Ofcom—

“require for the purpose of exercising, or deciding whether to exercise, any of their online safety functions”.

The power could be used entirely as a fishing expedition. It could be entirely for the purpose of educating Ofcom as to what it should be doing. There is nothing here to say that it can have these powers of intrusion only if it suspects that there is criminality, a breach of the codes of conduct or any other offence. It is a fishing expedition, entirely for the purpose of

“exercising, or deciding whether to exercise”.

Those are the intrusions imposed upon companies. In some ways, I am less concerned about the companies than I am about what I am going to come to next: the intrusion on the privacy of individuals and users. If we sat back and listened to ourselves and what we are saying, could we explain to ordinary people—we are going to come to this when we discuss end-to-end encryption—what exactly can happen?

Two very significant breaches of the protections in place for privacy on the internet arise from what is proposed. First, if you allow someone into a system and into equipment, especially from outside, you increase the risk and the possibility that a further, probably more hostile party that is sufficiently well-equipped with resources—we know state actors with evil intent which are so equipped—can get in through that or similar holes. The privacy of the system itself would be structurally weakened as a result of doing this. Secondly, if Ofcom is able to see what is going on, the system becomes leaky in the direction of Ofcom. It can come into possession of information, some of which could be of an individual character. My noble friend says that it will not be allowed to release any data and that all sorts of protections are in place. We know that, and I fully accept the honesty and integrity of Ofcom as an institution and of its staff. However, we also know that things get leaked and escape. As a result of this provision, very large holes are being built into the protections of privacy that exist, yet there has been no reference at all to privacy in the remarks made so far by my noble friend.

I finish by saying that we are racing ahead and not thinking. Good Lord, my modest amendment in the last group to bring a well-established piece of legislation—the Consumer Rights Act—to bear upon this Bill was challenged on the grounds that there had not been an impact assessment. Where is the impact assessment for this? Where is even the smell test for this in relation to explaining it to the public? If my noble friend is able to expatiate at the end on the implications for privacy and attempt to give us some assurance, that would be some consolation. I doubt that he is going to give way and do the right thing and withdraw this amendment.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - -

My Lords, the debate so far has been—in the words of the noble Baroness, Lady Fox—a Committee debate. That is partly because this set of amendments from the Government has come quite late. If they had been tabled in Committee, I think we would have had a more expansive debate on this issue and could have knocked it about a bit and come back to it on Report. The timing is regrettable in all of this.

That said, the Government have tabled some extremely important amendments, particularly Amendments 196 and 198, which deal with things such as algorithms and functionalities. I very much welcome those important amendments, as I know the noble Baroness, Lady Kidron, did.

I also very much support Amendments 270 and 272 in the name of the noble Baroness, Lady Fraser. I hope the Minister, having been pre-primed, has all the answers to them. It is astonishing that, after all these years, we are so unattuned to the issues of the devolved Administrations and that we are still not in the mindset on things such as research. We are not sufficiently granular, as has been explained—let alone all the other questions that the noble Lord, Lord Stevenson, asked. I hope the Minister can unpack some of that as well.

I want to express some gratitude, too, because the Minister and his officials took the trouble to give us a briefing about remote access issues, alongside Ofcom. Ofcom also sent through its note on algorithmic assessment powers, so an effort has been made to explain some of these powers. Indeed, I can see the practical importance, as explained to us. It is partly the lateness, however, that sets off what my noble friend Lord Allan called “trigger words” and concerns about the remote access provisions. Indeed, I think we have a living and breathing demonstration of the impact of triggers on the noble Lord, Lord Moylan, because these are indeed issues that concern those outside the House to quite a large degree.

--- Later in debate ---
Lord Parkinson of Whitley Bay Portrait Lord Parkinson of Whitley Bay (Con)
- Hansard - - - Excerpts

Yes, and we can point to the current actions of Ofcom to show that it is indeed doing this already, even without that legislative stick.

I turn to the amendments in the name of my noble friend Lord Bethell and the noble Lord, Lord Clement-Jones, on researchers’ access to data. Amendment 237ZA would confer on the Secretary of State a power to make provisions about access to information by researchers. As my noble friend knows, we are sympathetic to the importance of this issue, which is why we have tabled our own amendments in relation to it. However, as my noble friend also knows, in such a complex and sensitive area that we think it is premature to endow the Secretary of State with such broad powers to introduce a new framework. As we touched on in Committee, this is a complex and still nascent area, which is why it is different from the other areas to which the noble Lord, Lord Clement-Jones, pointed in his contribution.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

The noble Baroness, Lady Harding, made the point that in other areas where the Minister has agreed to reviews or reports, there are backstop powers; for instance, on app stores. Of course, that was a negotiated settlement, so to speak, but why can the Minister not accede to that in the case of access for researchers, as he has with app stores? Indeed, there is one other example that escapes me, which the Minister has also agreed to.

Lord Parkinson of Whitley Bay Portrait Lord Parkinson of Whitley Bay (Con)
- Hansard - - - Excerpts

We touched on the complexity of defining who and what is a researcher and making sure that we do not give rise to bad actors exploiting that. This is a complex area, as we touched on in Committee. As I say, the evidence base here is nascent. It is important first to focus on developing our understanding of the issues to ensure that any power or legislation is fit to address those challenges. Ofcom’s report will not only highlight how platforms can share data with researchers safely but will provide the evidence base for considering any future policy approaches, which we have committed to doing but which I think the noble Lord will agree are worthy of further debate and reflection in Parliament.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

The benefit of having a period of time between the last day of Report on Wednesday and Third Reading is that that gives the Minister, the Bill team and parliamentary counsel the time to reflect on the kind of power that could be devised. The wording could be devised, and I would have thought that six weeks would be quite adequate for that, perhaps in a general way. After all, this is not a power that is immediately going to be used; it is a general power that could be brought into effect by regulation. Surely it is not beyond the wit to devise something suitable.

Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - - - Excerpts

Before the Minister stands up, I also wondered—

--- Later in debate ---
Baroness Kidron Portrait Baroness Kidron (CB)
- View Speech - Hansard - - - Excerpts

My Lords, I will speak to the government Amendments 274B and 274C. I truly welcome a more detailed approach to Ofcom’s duties in relation to media literacy. However, as is my theme today, I raise two frustrations. First, having spent weeks telling us that it is impossible to include harms that go beyond content and opposing amendments on that point, the Government’s media literacy strategy includes a duty to help users to understand the harmful ways in which regulated services may be used. This is in addition to understanding the nature and impact of harmful content. It appears to suggest that it is the users who are guilty of misuse of products and services rather than putting any emphasis on the design or processes that determine how a service is most often used.

I believe that all of us, including children, are participants in creating an online culture and that educating and empowering users of services is essential. However, it should not be a substitute for designing a service that is safe by design and default. To make my point absolutely clear, I recount the findings of researchers who undertook workshops in 28 countries with more than 1,000 children. The researchers were at first surprised to find that, whether in Kigali, São Paulo or Berlin, to an overwhelming extent children identified the same problems online—harmful content, addiction, privacy, lack of privacy and so on. The children’s circumstances were so vastly different—country and town, Africa and the global north et cetera—but when the researchers did further analysis, they realised that the reason why they had such similar experiences was because they were using the same products. The products were more determining of the outcome than anything to do with religion, education, status, age, the family or even the country. The only other factor that loomed large, which I admit that the Government have recognised, was gender. Those were the two most crucial findings. It is an abdication of adult responsibility to place the onus on children to keep themselves safe. The amendment and the Bill, as I keep mentioning, should focus on the role of design, not on how a child uses it.

My second point, which is of a similar nature, is that I am very concerned that a lot of digital literacy—for adults as well as children, but my particular concern is in schools—is provided by the tech companies themselves. Therefore, once again their responsibility, their role in the system and process of what children might find from reward loops, algorithms and so on, is very low down on the agenda. Is it possible at this late stage to consider that Ofcom might have a responsibility to consider the system design as part of its literacy review?

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - -

My Lords, this has been a very interesting short debate. Like other noble Lords, I am very pleased that the Government have proposed the new clauses in Amendments 274B and 274C. The noble Baroness, Lady Bull, described absolutely the importance of media literacy, particularly for disabled people and for the vulnerable. This is really important for them. It is important also not to fall into the trap described by the noble Baroness, Lady Kidron, of saying, “You are a child or a vulnerable person. You must acquire media literacy—it’s your obligation; it’s not the obligation of the platforms to design their services appropriately”. I take that point, but it does not mean that media literacy is not extraordinarily important.

However, sadly, I do not believe that the breadth of the Government’s new media literacy amendments is as wide as the original draft Bill. If you look back at the draft Bill, that was a completely new and upgraded set of duties right across the board, replacing Section 11 of the Communications Act and, in a sense, fit for the modern age. The Government have made a media literacy duty which is much narrower. It relates only to regulated services. This is not optimum. We need something broader which puts a bigger and broader duty for the future on to Ofcom.

It is also deficient in two respects. The noble Lord, Lord Knight, will speak to his amendments, but it struck me immediately when looking at that proposed new clause that we were missing all the debate about functionalities and so on that the noble Baroness, Lady Kidron, debated the other day, regarding design, and that we must ensure that media literacy encompasses understanding the underlying functionalities and systems of the platforms that we are talking about.

I know that your Lordships will be very excited to hear that I am going to refer again to the Joint Committee. I know that the Minister has read us from cover to cover, but at paragraph 381 on the draft Bill we said, and it is still evergreen:

“If the Government wishes to improve the UK’s media literacy to reduce online harms, there must be provisions in the Bill to ensure media literacy initiatives are of a high standard. The Bill should empower Ofcom to set minimum standards for media literacy initiatives that both guide providers and ensure the information they are disseminating aligns with the goal of reducing online harm”.


I had a very close look at the clause. I could not see that Ofcom is entitled to set minimum standards. The media literacy provisions sadly are deficient in that respect.

Lord McNally Portrait Lord McNally (LD)
- View Speech - Hansard - - - Excerpts

I am not surprised that my noble friend refers to his experience on the Joint Committee. He will not be surprised that I am about to refer to my experience on the Puttnam committee in 2003, which recommended media literacy as a priority for Ofcom. The sad fact is that media literacy was put on the back burner by Ofcom for almost 20 years. While I listen to this House, I think that my noble friend is quite right to accuse the Government, hard as the Minister has tried, of a paucity of ambition and—more than that—of letting us slip into the same mistake made by Ofcom after 2003 and allowing this to be a narrow, marginal issue. The noble Baroness, Lady Kidron, has reminded us time and again that unless we educate those who are using these technologies, these abuses will proliferate.

Therefore, with what my noble friend is advocating and what we will keep an eye on as the Bill is implemented—and I now literally speak over the Minister’s head, to the Member behind—Ofcom must take media literacy seriously and be a driving force in its implementation, for the very reasons that the noble Baroness, Lady Fox, referred to. We do not want everybody protected by regulations and powers—we want people protected by their own knowledge of what they are dealing with. This is where there is a gap between what has been pressed on the Government and what they are offering.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - -

My Lords, I thank my noble friend very much for that intervention.

Lord Harlech Portrait Lord Harlech (Con)
- Hansard - - - Excerpts

My Lords, I remind the House that, as we are on Report, interventions on current speakers should be for direct questions or points of elucidation.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

I am sure my noble friend with 30 years’ experience stands duly corrected. He has reminded us that we have 20 years’ experience of something being on the statute book without really cranking up the powers and duties that are on it or giving Ofcom appropriate resources in the media literacy area. If that was about offline—the original 2003 duty—we know that it is even more important online to have these media literacy duties in place. I very much hope that the Minister can give us, in a sense, a token of earnest—that it is not just about putting these duties on the statute book but about giving Ofcom the resources to follow this up. Of course, it is also relevant to other regulators, which was partly the reason for having a duty of co-operation. Perhaps he will also, at the same time, describe how regulators such as Ofsted will have a role in media literacy.

I shall briefly talk about Amendment 269AA to Clause 141, which is the clause in the Bill setting up the advisory committee on misinformation and disinformation. I heard very clearly what the noble Baroness, Lady Fox, had to say, and I absolutely agree—there is no silver bullet in all this. Establishing provenance is but one way in which to get greater transparency and authentication and exercise judgment; it is not the complete answer, but it is one way of getting to grips more with some of the information coming through online. She may have seen that this is an “and” rather than an “or”, which is why the amendment is phrased as it is.

Of course, it is really important that there are initiatives. The one that I want to mention today about provenance is the Content Authenticity Initiative, which I mentioned in Committee. We need to use the power of such initiatives; it is a global coalition working to increase transparency in digital content through open industry standards, and it was founded four years ago and has more than 1,500 members, with some major companies such as Adobe, Microsoft, NVIDIA, Arm, Intel—I could go on. I very much hope that Ofcom will engage with the Content Authenticity Initiative, whatever the content of the Bill. In a sense, I am raising the issue for the Minister to give us assurances that this is within the scope of what the committee will be doing—that it is not just a question of doing what is in the Bill, and this will be included in the scope of the advisory committee’s work.

Thea AI has been an industry-led initiative that has developed content credentials which encode important metadata into pieces of content. Those pieces of information reside indefinitely in the content, wherever it is used, published or stored, and, as a result, viewers are able to make more informed decisions about whether or not to trust the content. The advisory committee really should consider the role of provenance tools such as content credentials to enable users to have the relevant information to decide what is real and what is disinformation or misinformation online. That would entirely fit the strategy of this Bill to empower adult users.

--- Later in debate ---
Having listened to this helpful debate, I remain confident that the provisions we are proposing will tackle the challenges that noble Lords have raised.
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - -

I do not believe that the Minister has dealt with the minimum standards issue.

Lord Parkinson of Whitley Bay Portrait Lord Parkinson of Whitley Bay (Con)
- Hansard - - - Excerpts

I do not think that the noble Lord was listening to that point, but I did.

--- Later in debate ---
Moved by
219: Clause 158, leave out Clause 158
Member’s explanatory statement
This amendment would remove Clause 158 (Directions in special circumstances) from the Bill and is intended to further probe the Secretary of State’s power in this area.
Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

My Lords, Clause 158 is one of the more mysterious clauses in the Bill and it would greatly benefit from a clear elucidation by the Minister of how it is intended to work to reduce harm. I thank him for having sent me an email this afternoon as we started on the Bill, for which I am grateful; I had only a short time to consider it but I very much hope that he will put its content on the record.

My amendment is designed to ask how the Minister envisages using the power to direct if, say, there is a new contagious disease or riots, and social media is a major factor in the spread of the problem. I am trying to erect some kind of hypothetical situation through which the Minister can say how the power will be used. Is the intention, for example, to set Ofcom the objective of preventing the spread of information on regulated services injurious to public health or safety on a particular network for six months? The direction then forces the regulator and the social media companies to confront the issue and perhaps publicly shame an individual company into using their tools to slow the spread of disinformation. The direction might give Ofcom powers to gather sufficient information from the company to make directions to the company to tackle the problem.

If that is envisaged, which of Ofcom’s media literacy powers does the Minister envisage being used? Might it be Section 11(1)(e) of the Communications Act 2003, which talks about encouraging

“the development and use of technologies and systems for regulating access to such material, and for facilitating control over what material is received, that are both effective and easy to use”.

By this means, Ofcom might encourage a social media company to regulate access to and control over the material that is a threat.

Perhaps the Minister could set out clearly how he intends all this to work, because on a straight reading of Clause 158, we on these Benches have considerable concerns. The threshold for direction is low—merely having

“reasonable grounds for believing that circumstances exist”—

and there is no sense here of the emergency that the then Minister, Mr Philp, cited in the Commons Public Bill Committee on 26 May 2022, nor even of the exceptional circumstances in Amendment 138 to Clause 39, which the Minister tabled recently. The Minister is not compelled by the clause to consult experts in public health, safety or national security. The Minister can set any objectives for Ofcom, it seems. There is no time limit for the effect of the direction and it seems that the direction can be repeatedly extended with no limit. If the Minister directs because they believe there is a threat to national security, we will have the curious situation of a public process being initiated for reasons the Minister is not obliged to explain.

Against this background, there does not seem to be a case for breaching the international convention of the Government not directing a media regulator. Independence of media regulators is the norm in developed democracies, and the UK has signed many international statements in this vein. As recently as April 2022, the Council of Europe stated:

“Media and communication governance should be independent and impartial to avoid undue influence on policymaking or”


the discriminatory and

“preferential treatment of powerful groups”,

including those with significant political or economic power. The Secretary of State, by contrast, has no powers over Ofcom regarding the content of broadcast regulation and has limited powers to direct over radio spectrum and wireless, but not content. Ofcom’s independence in day-to-day decision-making is paramount to preserving freedom of expression. There are insufficient safeguards in this clause, which is why I argue that it should not stand part of the Bill.

I will be brief about Clause 159 because, by and large, we went through it in our debate on a previous group. Now that we can see the final shape of the Bill, it really does behove us to stand back and see where the balance has settled on Ofcom’s independence and whether this clause needs to stand part of the Bill. The Secretary of State has extensive powers under various other provisions in the Bill. The Minister has tabled welcome amendments to Clause 39, which have been incorporated into the Bill, but Clause 155 still allows the Secretary of State to issue a “statement of strategic priorities”, including specific outcomes, every five years.

Clause 159 is in addition to this comprehensive list, but the approach in the clause is incredibly broad. We have discussed this, and the noble Lord, Lord Moylan, has tabled an amendment that would require parliamentary scrutiny. The Secretary of State can issue guidance to Ofcom on more or less anything encompassed by the exercise of its functions under this Act, with no consultation of the public or Parliament prior to making such guidance. The time limit for producing strategic guidance is three years rather than five. Even if it is merely “have regard” guidance, it represents an unwelcome intervention in Ofcom going about its business. If the Minister responds that the guidance is merely “to have regard”, I will ask him to consider this: why have it all, then, when there are so many other opportunities for the Government to intervene? For the regulated companies, it represents a regulatory hazard of interference in independent regulation and a lack of stability. As the noble Lord, Lord Bethell, said in Committee, a clear benefit of regulatory independence is that it reduces lobbying of the Minister by powerful corporate interests.

Now that we can see it in context, I very much hope that the Minister will agree that Clause 159 is a set of guidance too many that compromises Ofcom’s independence and should not stand part of the Bill.

Lord Allan of Hallam Portrait Lord Allan of Hallam (LD)
- View Speech - Hansard - - - Excerpts

My Lords, I will add to my noble friend’s call for us to consider whether Clause 158 should be struck from the Bill as an unnecessary power for the Secretary of State to take. We have discussed powers for the Secretary of State throughout the Bill, with some helpful improvements led by the noble Baroness, Lady Stowell. This one jars in particular because it is about media literacy; some of the other powers related to whether the Secretary of State could intervene on the codes of practice that Ofcom would issue. The core question is whether we trust Ofcom’s discretion in delivering media literacy and whether we need the Secretary of State to have any kind of power to intervene.

I single out media literacy because the clue is in the name: literacy is a generic skill that you acquire about dealing with the online world; it is not about any specific text. Literacy is a broader set of skills, yet Clause 158 has a suggestion that, in response to specific forms of content or a specific crisis happening in the world, the Secretary of State would want to takesb this power to direct the media literacy efforts. To take something specific and immediate to direct something that is generic and long-term jars and seems inappropriate.

I have a series of questions for the Minister to elucidate why this power should exist at all. It would be helpful to have an example of what kind of “public statement notice”—to use the language in the clause—the Government might want to issue that Ofcom would not come up with on its own. Part of the argument we have been presented with is that, somehow, the Government might have additional information, but it seems quite a stretch that they could come up with that. In an area such as national security, my experience has been that companies often have a better idea of what is going on than anybody in government.

Thousands of people out there in the industry are familiar with APT 28 and APT 29 which, as I am sure all noble Lords know, are better known by their names Fancy Bear and Cozy Bear. These are agents of the Russian state that put out misinformation. There is nothing that UK agencies or the Secretary of State might know about them that is not already widely known. I remember talking about the famous troll factory run by Prigozhin, the Internet Research Agency, with people in government in the context of Russian interference—they would say “Who?” and have to go off and find out. In dealing with threats such as that between the people in the companies and Ofcom, you certainly want a media literacy campaign which tells you about these troll agencies and how they operate and gives warnings to the public, but I struggle to see why you need the Secretary of State to intervene as opposed to allowing Ofcom’s experts to work with company experts and come up with a strategy to deal with those kinds of threat.

The other example cited of an area where the Secretary of State might want to intervene is public health and safety. It would be helpful to be specific; had they had it, how would the Government have used this power during the pandemic in 2020 and 2021? Does the Minister have examples of what they were frustrated about and would have done with these powers that Ofcom would not do anyway in working with the companies directly? I do not see that they would have had secret information which would have meant that they had to intervene rather than trusting Ofcom and the companies to do it.

Perhaps there has been an interdepartmental workshop between DHSC, DCMS and others to cook up this provision. I assume that Clause 158 did not come from nowhere. Someone must have thought, “We need these powers in Clause 158 because we were missing them previously”. Are there specific examples of media literacy campaigns that could not be run, where people in government were frustrated and therefore wanted a power to offer it in future? It would be really helpful to hear about them so that we can understand exactly how the Clause 158 powers will be used before we allow this additional power on to the statute book.

In the view of most people in this Chamber, the Bill as a whole quite rightly grants the Government and Ofcom, the independent regulator, a wide range of powers. Here we are looking specifically at where the Government will, in a sense, overrule the independent regulator by giving it orders to do something it had not thought of doing itself. It is incumbent on the Government to flesh that out with some concrete examples so that we can understand why they need this power. At the moment, as noble Lords may be able to tell, these Benches are not convinced that they do.

--- Later in debate ---
Lord Parkinson of Whitley Bay Portrait Lord Parkinson of Whitley Bay (Con)
- Hansard - - - Excerpts

I am happy to make it clear, as I did on the last group, that the power allows Ofcom not to require platforms to remove content, only to set out what they are doing in response to misinformation and disinformation—to require platforms to make a public statement about what they are doing to tackle it. In relation to regulating news providers, we have brought the further amendments forward to ensure that those subject to sanctions cannot avail themselves of the special provisions in the Bill. Of course, the Secretary of State will be mindful of the law when issuing directions in the exceptional circumstances that these clauses set out.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - -

While the Minister is describing that, can he explain exactly which media literacy power would be invoked by the kind of example I gave when I was introducing the amendment and in the circumstances he has talked about? Would he like to refer to the Communications Act?

Lord Parkinson of Whitley Bay Portrait Lord Parkinson of Whitley Bay (Con)
- Hansard - - - Excerpts

It depends on the circumstances. I do not want to give one example for fear of being unnecessarily restrictive. In relation to the health misinformation and disinformation we saw during the pandemic, an example would be the suggestions of injecting oneself with bleach; that sort of unregulated and unhelpful advice is what we have in mind. I will write to the noble Lord, if he wants, to see what provisions of the Communications Act we would want invoked in those circumstances.

In relation to Clause 159, which is dealt with by Amendment 222, it is worth setting out that the Secretary of State guidance and the statement of strategic priorities have distinct purposes and associated requirements. The purpose of the statement of strategic priorities is to enable the Secretary of State to specifically set out priorities in relation to online safety. For example, in the future, it may be that changes in the online experience mean that the Government of the day wish to set out their high-level overarching priorities. In comparison, the guidance allows for clarification of what Parliament and Government intended in passing this legislation—as I hope we will—by providing guidance on specific elements of the Bill in relation to Ofcom’s functions. There are no plans to issue guidance under this power but, for example, we are required to issue guidance to Ofcom in relation to the fee regime.

On the respective requirements, the statement of strategic priorities requires Ofcom to explain in writing what it proposes to do in consequence of the statement and publish an annual review of what it has done. Whereas Ofcom must “have regard” to the guidance, the guidance itself does not create any statutory requirements.

This is a new regime and is different in its nature from other established areas of regulations, such as broadcasting. The power in Clause 159 provides a mechanism to provide more certainty, if that is considered necessary, about how the Secretary of State expects Ofcom to carry out its statutory functions. Ofcom will be consulted before guidance is issued, and there are checks on how often it can be issued and revised. The guidance document itself, as I said, does not create any statutory requirements, so Ofcom is required only to “have regard” to it.

This will be an open and transparent way to put forward guidance appropriately with safeguards in place. The independence of the regulator is not at stake here. The clause includes significant limitations on the power, and the guidance cannot fetter Ofcom’s operational independence. We feel that both clauses are appropriate for inclusion in the Bill, so I hope that the noble Lord will withdraw his amendment.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - -

I thank the Minister for that more extended reply. It is a more reassuring response on Clause 159 than we have had before. On Clause 158, the impression I get is that the media literacy power is being used as a smokescreen for the Government telling social media what it should do, indirectly via Ofcom. That seems extraordinary. If the Government were telling the mainstream media what to do in circumstances like this, we would all be up in arms. However, it seems to be accepted as a part of the Bill and that we should trust the Government. The Minister used the phrase “special circumstances”. That is not the phraseology in the clause; it is that “circumstances exist”, and then it goes on to talk about national security and public health. The bar is very low.

I am sure everyone is getting hungry at this time of day, so I will not continue. However, we still have grave doubts about this clause. It seems an extraordinary indirect form of censorship which I hope is never invoked. In the meantime, I beg leave to withdraw my amendment.

Amendment 219 withdrawn.
--- Later in debate ---
Lord Allan of Hallam Portrait Lord Allan of Hallam (LD)
- View Speech - Hansard - - - Excerpts

My Lords, the noble Lord, Lord Moylan, and the noble Baroness, Lady Fox, have a very strong point to make with this amendment. I have tried in our discussions to bring some colour to the debate from my own experience so I will tell your Lordships that in my former professional life I received representations from many Ministers in many countries about the content we should allow or disallow on the Facebook platform that I worked for.

That was a frequent occurrence in the United Kingdom and extended to Governments of all parties. Almost as soon as I moved into the job, we had a Labour Home Secretary come in and suggest that we should deal with particular forms of content. It happened through the coalition years. Indeed, I remember meeting the Minister’s former boss at No. 10 in Davos, of all places, to receive some lobbying about what the UK Government thought should be on or off the platform at that time. In that case it was to do with terrorist content; there was nothing between us in terms of wanting to see that content gone. I recognise that this amendment is about misinformation and disinformation, which is perhaps a more contentious area.

As we have discussed throughout the debate, transparency is good. It keeps everybody on the straight and narrow. I do not see any reason why the Government should not be forthcoming. My experience was that the Government would often want to go to the Daily Telegraph, the Daily Mail or some other upright publication and tell it how they had been leaning on the internet companies—it was part of their communications strategy and they were extremely proud of it—but there will be other circumstances where they are doing it more behind the scenes. Those are the ones we should be worried about.

If those in government have good reason to lean on an internet company, fine—but knowing that they have to be transparent about it, as in this amendment, will instil a certain level of discipline that would be quite healthy.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - -

My Lords, clearly, there is a limited number of speakers in this debate. We should thank the noble Lord, Lord Moylan, for tabling this amendment because it raises a very interesting point about the transparency—or not—of the Counter Disinformation Unit. Of course, it is subject to an Oral Question tomorrow as well, which I am sure the noble Viscount will be answering.

There is some concern about the transparency of the activities of the Counter Disinformation Unit. In its report, Ministry of Truth, which deals at some length with the activities of the Counter Disinformation Unit, Big Brother Watch says:

“Giving officials an unaccountable hotline to flag lawful speech for removal from the digital public square is a worrying threat to free speech”.


Its complaint is not only about oversight; it is about the activities. Others such as Full Fact have stressed the fact that there is little or no parliamentary scrutiny. For instance, freedom of information requests have been turned down and Written Questions which try to probe what the activities of the Counter Disinformation Unit are have had very little response. As it says, when the Government

“lobby internet companies about content on their platforms … this is a threat to freedom of expression”.

We need proper oversight, so I am interested to hear the Minister’s response.

Lord Parkinson of Whitley Bay Portrait Lord Parkinson of Whitley Bay (Con)
- View Speech - Hansard - - - Excerpts

My Lords, the Government share the view of my noble friend Lord Moylan about the importance of transparency in protecting freedom of expression. I reassure him and other noble Lords that these principles are central to the Government’s operational response to addressing harmful disinformation and attempts artificially to manipulate our information environment.

My noble friend and others made reference to the operational work of the Counter Disinformation Unit, which is not, as the noble Baroness, Lady Fox, said, the responsibility of my department but of the Department for Science, Innovation and Technology. The Government have always been transparent about the work of the unit; for example, recently publishing a factsheet on GOV.UK which sets out, among other things, how the unit works with social media companies.

I reassure my noble friend that there are existing processes governing government engagements with external parties and emphasise to him that the regulatory framework that will be introduced by the Bill serves to increase transparency and accountability in a way that I hope reassures him. Many teams across government regularly meet industry representatives on a variety of issues from farming and food to telecoms and digital infrastructure. These meetings are conducted within well-established transparency processes and frameworks, which apply in exactly the same way to government meetings with social media companies. The Government have been open about the fact that the Counter Disinformation Unit meets social media companies. Indeed, it would be surprising if it did not. For example, at the beginning of the Russian invasion of Ukraine, the Government worked with social media companies in relation to narratives which were being circulated attempting to deny incidents leading to mass casualties, and to encourage the promotion of authoritative sources of information. That work constituted routine meetings and was necessary in confirming the Government’s confidence in the preparedness and ability of platforms to respond to new misinformation and disinformation threats.

To require additional reporting on a sector-by-sector or department-by-department basis beyond the standardised transparency processes, as proposed in my noble friend’s amendment, would be a disproportionate and unnecessary response to what is routine engagement in an area where the Government have no greater powers or influence than in others. They cannot compel companies to alter their terms of service; nor can or do they seek to mandate any action on specific pieces of content.

I reassure the noble Baroness, Lady Fox, that the Counter Disinformation Unit does not monitor individual people, nor has it ever done so; rather, it tracks narratives and trends using publicly available information online to protect public health, public safety and national security. It has never tracked the activity of individuals, and there is a blanket ban on referring any content from journalists or parliamentarians to social media performs. The Government have always been clear that the Counter Disinformation Unit refers content for consideration only where an assessment has been made that it is likely to breach the platform’s own terms of service. It has no role in deciding what action, if any, to take in response, which is entirely a matter for the platform concerned.

As I said, the Bill will introduce new transparency, accountability and freedom of expression duties for category 1 services which will make the process for any removal or restriction of user-generated content more transparent by requiring category 1 services to set terms of service which are clear, easy for users to understand and consistently enforced. Category 1 services will be prohibited from removing or restricting user-generated content or suspending or banning users where this does not align with those terms of service. Any referrals from government will not, and indeed cannot, supersede these duties in the Bill.

Although I know it will disappoint my noble friend that another of his amendments has not been accepted, I hope I have been able to reassure him about the Government’s role in these processes. As the noble Lord, Lord Clement-Jones, noted, my noble friend Lord Camrose is answering a Question on this in your Lordships’ House tomorrow, further underlining the openness and parliamentary accountability with which we go about this work. I hope my noble friend will, in a similarly post-prandial mood of generosity, suppress his disappointment and feel able to withdraw his amendment.

--- Later in debate ---
Baroness Kidron Portrait Baroness Kidron (CB)
- View Speech - Hansard - - - Excerpts

My Lords, I support Amendment 228. I spoke on this issue to the longer amendment in Committee. To decide whether something is illegal without the entire apparatus of the justice system, in which a great deal of care is taken to decide whether something is illegal, at high volume and high speed, is very worrying. It strikes me as amusing because someone commented earlier that they like a “must” instead of a “maybe”. In this case, I caution that a provider should treat the content as content of the kind in question accordingly, that something a little softer is needed, not a cliff edge that ends up in horrors around illegality where someone who has acted in self-defence is accused of a crime of violence, as happens to many women, and so on and so forth. I do not want to labour the point. I just urge a gentle landing rather than, as it is written, a cliff edge.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - -

My Lords, this has been a very interesting debate. Beyond peradventure my noble friend Lord Allan and the noble Viscount, Lord Colville, and the noble Baroness, Lady Fox, have demonstrated powerfully the perils of this clause. “Lawyers’ caution” is one of my noble friend’s messages to take away, as is the complexities in making these judgments. It was interesting when he mentioned the sharing for awareness’s sake of certain forms of content and the judgments that must be taken by platforms. His phrase “If in doubt, take it out” is pretty chilling in free speech terms—I think that will come back to haunt us. As the noble Baroness, Lady Fox, said, the wrong message is being delivered by this clause. It is important to have some element of discretion here and not, as the noble Baroness, Lady Kidron, said, a cliff edge. We need a gentler landing. I very much hope that the Minister will land more gently.

Lord Stevenson of Balmacara Portrait Lord Stevenson of Balmacara (Lab)
- View Speech - Hansard - - - Excerpts

My Lords, this has been a good debate. It is very hard to see where one would want to take it. If it proves anything, it is that the decision to drop the legal but harmful provisions in the Bill was probably taken for the wrong reasons but was the right decision, since this is where we end up—in an impossible moral quandary which no amount of writing, legalistic or otherwise, will get us out of. This should be a systems Bill, not a content Bill.

--- Later in debate ---
Lord Allan of Hallam Portrait Lord Allan of Hallam (LD)
- View Speech - Hansard - - - Excerpts

My Lords, I will make a brief contribution because I was the misery guts when this was proposed first time round. I congratulate the noble Baroness, Lady Harding, not just on working with colleagues to come up with a really good solution but on seeking me out. If I heard someone be as miserable as I was, I might try to avoid them. She did not; she came and asked me, “Why are you miserable? What is the problem here?”, and took steps to address it. Through her work with the Government, their amendments address my main concerns.

My first concern, as we discussed in Committee, was that we would be asking large companies to regulate their competitors, because the app stores are run by large tech companies. She certainly understood that concern. The second was that I felt we had not necessarily yet clearly defined the problem. There are lots of problems. Before you can come up with a solution, you need a real consensus on what problem you are trying to address. The government amendment will very much help in saying, “Let’s get really crunchy about the actual problem that we need app stores to address”.

Finally, I am a glass-half-full kind of guy as well as a misery guts—there is a contradiction there—and so I genuinely think that these large tech businesses will start to change their behaviour and address some of the concerns, such as getting age ratings correct, just by virtue of our having this regulatory framework in place. Even if today the app stores are technically outside, the fact that the sector is inside and that this amendment tells them that they are on notice will, I think and hope, have a hugely positive effect and we will get the benefits much more quickly than the timescale envisaged in the Bill. That feels like a true backstop. I sincerely hope that the people in those companies, who I am sure will be glued to our debate, will be thinking that they need to get their act together much more quickly. It is better for them to do it themselves than wait for someone to do it to them.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - -

My Lords, I add my congratulations to the noble Baroness, Lady Harding, on her tenacity, and to the Minister on his flexibility. I believe that where we have reached is pretty much the right balance. There are the questions that the noble Baroness, Lady Harding, and others have asked of the Minister, and I hope he will answer those, but this is a game-changer, quite frankly. Rightly, the noble Baroness has paid tribute to the companies which have put their head above the parapet. That was not that easy for them to do when you consider that those are the platforms they have to depend on for their services to reach the public.

Unlike the research report, they have reserved powers that the Secretary of State can use if the report is positive, which I hope it will be. I believe this could be a turning point. The digital markets and consumers Bill is coming down the track this autumn and that is going to give greater powers to make sure that the app stores can be tackled—after all, there are only two of them and they are an oligopoly. They are the essence of big tech, and they need to function in a much more competitive way.

The noble Baroness talked about timing, and it needs to be digital timing, not analogue. Four years does seem a heck of a long time. I hope the Minister will address that.

Then there is the really important aspect of harmful content. In the last group, the Minister reassured us about systems and processes and the illegality threshold. Throughout, he has tried to reassure us that this is all about systems and processes and not so much about content. However, every time we look, we see that content is there almost by default, unless the subject is raised. We do not yet have a Bill that is actually fit for purpose in that sense. I hope the Minister will use his summer break wisely and read through the Bill to make sure that it meets its purpose, and then come back at Third Reading with a whole bunch of amendments that add functionalities. How about that for a suggestion? It is said in the spirit of good will and summer friendship.

The noble Baroness raised a point about transparency when it comes to Ofcom publishing its review. I hope the Minister can give that assurance as well.

The noble Baroness, Lady Kidron, asked about the definition of app store. That is the gatekeeper function, and we need to be sure that that is what we are talking about.

I end by congratulating once again the noble Baroness and the Minister on where we have got to so far.

Lord Knight of Weymouth Portrait Lord Knight of Weymouth (Lab)
- View Speech - Hansard - - - Excerpts

My Lords, I will start with the final point of the noble Lord, Lord Clement-Jones. I remind him that, beyond the world of the smartphone, there is a small company called Microsoft that also has a store for software—it is not just Google and Apple.

Principally, I say well done to the noble Baroness, Lady Harding, in deploying all of her “winsome” qualities to corral those of us who have been behind her on this and then persuade the Minister of the merits of her arguments. She also managed to persuade the noble Lord, Lord Allan of Misery Guts, that this was a good idea. The sequence of research, report, regulation and regulate is a good one, and as the noble Lord, Lord Clement-Jones, reminded us it is being deployed elsewhere in the Bill. I agree with the noble Baroness about the timing: I much prefer two years to four years. I hope that at least Ofcom would have the power to accelerate this if it wanted to do so.

I was reminded of the importance of this in an article I read in the Guardian last week, headed:

“More than 850 people referred to clinic for video game addicts”.


This was in reference to the NHS-funded clinic, the National Centre for Gaming Disorders. A third of gamers receiving treatment there were spending money on loot boxes in games such as “Fortnite”, “FIFA”, “Minecraft”, “Call of Duty” and “Roblox”—all games routinely accessed by children. Over a quarter of those being treated by the centre were children.