Digital and Technology Policy: National Sovereignty

Lord Moraes Excerpts
Thursday 23rd July 2026

(5 days, 21 hours ago)

Lords Chamber
Read Full debate Read Hansard Text Watch Debate Read Debate Ministerial Extracts
Lord Moraes Portrait Lord Moraes (Lab)
- View Speech - Hansard - -

My Lords, I, too, welcome the initiative from the noble Baroness, Lady Kidron. I have just finished her book, and it is a good read, but I have only one niggle: I really gasp at the cost of hardbacks. Maybe I am stingy, but they told me it is a whole year or so until there is a paperback so more people can read it. That was just a thought—I digress and should get back to the point. I welcome my noble friend the Minister back to her place, and I am happy that she can continue her work in this important area.

Digital sovereignty means agency. It is such a profound thing: the capacity for we in this country to make choices about everything, from the online safety of our children to the smooth running of our economy. That is a vast area in which to have damaged sovereignty, or a sovereignty gap. Yet, we are now in the simple position whereby a handful of US firms own the digital infrastructure the UK economy runs on, including search browsers, the cloud, app distribution and business software. As my noble friend said, those same companies are now also monopolising the AI stack. In simple terms, this leaves UK firms, public services and consumers dependent on suppliers who are governed elsewhere. That is a very profound thing. We need to understand it, but the more difficult part is how we deal with that reality.

This process did not begin with this Government—it is of neither their making, nor the last Government’s, nor the Government before that. It began in one country in the 2010s, with another country slightly catching up. An extraordinary thing happened in the 2010s: the US tech companies determined that they would weaken oversight of the digital space and not have federal legislation. Today, there is the extraordinary position in the United States whereby there is no federal regulation, as the noble Baroness, Lady Kidron, said, or regulation at all in this space. I repeat that because it is hard to believe. It all exists at state level, with the weakened oversight of the Federal Trade Commission and all the other organs which are traditionally very powerful in American democracy. Congress has no say and does not want to have a say—that is a whole other debate. This reality affects our reality, because those are the organisations that exist in relation to our economy. This is a factual situation, and I want to get on to the issue of how we at least try to deal with this sovereignty gap.

I also want to mention what has happened to this country and its sovereignty in the digital space from that period up until today. We were in the European Union, which has a regulatory weakness. Unlike the United States and China, it does not have the digital infrastructure, and yet it is the best regulator we have globally—there are only three global regulators. When were in the EU, we had that benefit of not only EU legislation and regulation but the protection in court of limiting the cross-border transfers of our citizens, because that is what those companies are monetising. That is point of all this.

In the 2010s, I chaired the Facebook inquiry and I met Mark Zuckerberg. He literally said to us that GDPR is a great thing. He went to Congress and said so—you can see it on YouTube. He admitted that regulation was essential for human beings in the United States, China, here and all around the world. However, they determinedly went on an opposite path, and we are now left with this situation.

There are a number of things we can start doing, because we have to do something—there is no point in just throwing up our hands and saying that this is how it is going to be. I will suggest a couple of things. First, we have to understand what we can do as a country to re-establish that kind of sovereignty. They seem small things, but they are within our capacity. I ask a specific question of the Minister. Take Palantir, which at least everyone knows about. Palantir is trying to take health data, make a cross-border transfer to the United States and sell it. That is what it is doing, and why it is paying us very little for the contract. Even the public, and certainly those who work in the NHS, are aware that the systems are not even that good.

One of the things we need to do, which is within our capacity, is a cost-benefit analysis of the contracts we undertake, because there will be sovereignty issue to that. Are we actually doing that? Secondly, we need to be really clear about what is happening here and what we can do about the blockages. For example, the US CLOUD Act grants US authorities the power to request access to data held anywhere in the world from providers subject to US jurisdiction, with no legal requirement for providers to inform customers. The whole issue of the US CLOUD Act has been raised in Parliament, and I know the Minister in the other place has commented on it, but DSIT has not made any central assessments of what the US CLOUD Act is or what it is doing to our infrastructure and sovereignty. These are the kinds of questions we need to try to answer and make progress on.

Another area—very quickly—is EU alignment; we have safety in numbers if we align. We have good data adequacy agreements with Europe and the European Union. We do not have a good data adequacy agreement with the US, for obvious reasons. Can we at least align on regulatory aspects that help us in this country, and our sovereignty: not everything from the European Union, but at least those aspects where we can align with a data adequacy agreement to help our sovereignty position?

Lord Moraes Portrait Lord Moraes (Lab)
- View Speech - Hansard - -

My Lords, it is a pleasure to follow the noble Lord, Lord Holmes. The noble Baroness, Lady Harding, has inspired me, as I am so low down the list—nearly at the end—not to do that thing of saying, “Everything has already been said, but not yet by everyone”, which I was thinking of while she was speaking. I will not do that; I am going to dump my very boring speech, inspired by the noble Baroness, Lady Ludford, who reminded me of what we used to do for a living. This contextualises exactly what the Government are trying to do.

My noble friend the Minister has a very tough job—I will explain a little why I think it is so difficult—but it is a job that we said we would do. We wanted to update the NIS regulation in 2018 and, as the noble Baroness, Lady Neville-Jones, said, to move fast and have some urgency. I know why she said that: I will come on to what the intelligence services are dealing with every single day, with hacking and what the Russians are doing. She knows that, as that is part of her DNA. We have to move fast, and we have to do something. That is exactly what the Government are doing. I want to try to contextualise what they are doing, why this is a national priority and how we can be as constructive as we can in building cyber security and cyber resilience.

A number of noble Lords, including the noble Baroness, Lady Harding, mentioned the EU network and information systems directive, which is very much the context of what we are doing. The noble Baroness, Lady Northover, spoke in some detail about our alignment with it and the noble Baroness, Lady Ludford, had some critical views about where we are in terms of our alignment. This really contextualises the complexity, as well as the urgency, of what we are doing here in the UK.

Noble Lords have said this because there are really only three global regulators doing this now—in the United States, the European Union and China—and they are diverging very badly. China does its own thing. In the United States, you may remember Mark Zuckerberg coming to the EU inquiry, going to Congress and saying, “Well, we need a GDPR, obviously”, but most of the legislation in the United States on cyber is in fact state led. The FTC looks at it, but it is really not national legislation. The EU is one of the few places, whether you like it or not, which has decided that it is a global regulator and that the cyber threat and cyber resilience are very much a global issue.

That does not take away from or dilute in any way some of the things that have been said, for example by the noble Lord, Lord Vaizey, about the United Kingdom’s special position as a country. We have the best intelligence services in the world, which is very relevant to this area. We have GCHQ and all that, and the technologists and companies close to this area, which are some of the best in the world. But the issue is with global regulation, and that is why it is so difficult.

The noble Baroness, Lady Ludford, made exactly the point that I was going to make, except I come to a different conclusion. She talked about the way that the two Ministers, Ian Murray and Kanishka Narayan, seem to be saying two different things. One is saying that we are taking a big hit and that real businesses and people are being hit by cyber breaches; whether or not it is 0.5% of our GDP, it is a big problem for the United Kingdom. Our other Minister said that we need the 12 regulators, to which the noble Lord, Lord Birt, referred, because they have the expertise, and that that is why it is so complicated and if we do anything else it is a huge burden on business. But I believe that both are true.

This is where the complexity of enacting good-quality cyber legislation happens. I know this because, as the noble Baroness, Lady Ludford, will testify, I chaired many of the GDPR legislative trilogues and the ePrivacy trilogues and I had to scrutinise many of the cyber conventions that are part of the EU treaties and body of law. I will cite the latest AI rapporteur—we now have another AI Act forthcoming in the EU because the older Act is out of date, the GDPR is out of data and the ePrivacy legislation is out of date. I said to the AI rapporteur, “You have the latest AI legislation”, and he said, “Yes, it’s a bit like you just jump off the cliff and build your wings on the way down”. Why somebody from Italy was quoting Ray Bradbury I do not know, but it is kind of correct. I know that the Minister has wings already—she has wings and she need not worry; she will be fine—but the point is that you have to move with such speed. The point that the noble Baroness, Lady Neville-Jones, made is that somehow you just have to move. The urgency is great.

The noble Lord, Lord Vaizey, who is not in his place, has inspired me to depart from my notes. He explained very eloquently, having been a Minister at that time, how complicated this is for our current Ministers in government. He talked about encryption and said that we knew that the companies—Microsoft, Facebook, which is now Meta, Reddit, Snap Inc, and all of them—wanted end-to-end encryption and did not want it weakened. Why? Because with strong end-to-end encryption, you deal with cyber threats. At the time, as noble Lords will remember, there were a lot of terrorism threats around, so most enforcement agencies were saying, “No, we need a backdoor to encryption”. That was the prevailing wisdom, and that argument won out. But the companies, in my view, were right. They were talking about the banking system, privacy and all the threats that we now have if we weaken encryption.

The noble Lord, Lord Vaizey, said that because the context here is that it is extremely complex to come up with good cyber security and resilience legislation. The noble Lord, Lord Birt, is so good with his communication that I almost think the OCR is a real thing. That is because he is who he is—he could persuade anyone. Of course, everyone is saying, “Let’s get rid of the 12”, but I caution about the complexity of dealing with cyber threats. I will give one last example about the daily threats we have from foreign actors—this is very different from the corporate threats, some of which come from within the United Kingdom and need a very different response, as we also saw in the European Union.

My time is up, but I just want to contextualise how tough this is going to be. Let us jump off the cliff, build the wings on the way down, get this done and do what we can in Committee, because this is a national priority. Is it perfect? Of course it is not. But we need to get moving, because the threats are very real.