(2 days, 15 hours ago)
Grand CommitteeMy Lords, in moving this amendment, I shall speak also to Amendment 75 in my name; I thank those noble Lords who have added their names in support. I was glad to add my name to Amendments 12, 85 and 86 in the name of the noble Lord, Lord Tarassenko, and Amendment 84 in the name of the noble Lord, Lord Clement-Jones.
At the heart of these amendments is the place of artificial intelligence in the Bill. This concern was powerfully raised by noble Lords at Second Reading and repeatedly raised by colleagues from all sides in the other place—as well as, I rather suspect, earlier in this Session. Amendment 6 is a probing amendment. It seeks to understand whether AI products and services are categorised as relevant digital services and, therefore, whether providers of AI products and services will be subject to the same duties in the Bill as other providers of relevant digital services, such as online marketplaces and search engines.
The reason I raise this and wish to have clarification is that, in the NIS regulations, the definition of an online search engine is
“a digital service that allows users to perform searches of, in principle, all websites or websites in a particular language on the basis of a query on any subject in the form of a keyword, phrase or other input, and returns links in which information related to the requested content can be found”.
This sounds a lot like a definition that could cover many of the LLMs and AI agents, so I ask the Minister whether AI services are already covered under the categorisation of online search engines or absolutely not. I would also like her to confirm whether, if an AI service did not offer links or was restricted to a particular subject matter but had all these other features, it would automatically fall out of the regime—that is, whether some are covered and some are not.
At Second Reading in the other place, the Minister said—the Minister here just gave this answer, I believe—that the Bill enables the Secretary of State to require an organisation using AI
“to cease using and isolate an AI model”—[Official Report, Commons, 16/6/26; col. 779.]
but suggested that those powers are “a backstop” and do not focus on the safety of AI products systematically. I find myself confused because, on the one hand, it seems that the definition could include them but, on the other, it seems that there may be reasons why some might be out of scope. It appears that AI is not properly considered proactively but, if there is a disaster, the Secretary of State can do something. When the Minister speaks, I would be grateful if she could answer those two questions directly. This is a probing amendment, as I say, and it would be helpful, in the course of considering the Bill, to understand that categorically.
Amendment 75 would establish a series of red lines for AI products and services classified as relevant digital services. These red lines have excellent parentage; they reflect the work of Professor Stuart Russell and are signed up to by some of the most eminent AI founders and professionals around the globe. They also reflect the global call for AI red lines launched during the United Nations General Assembly.
In short, they provide that AI services must not be capable of evading human oversight, shutdown or control, nor be able to autonomously self-replicate, self-improve or acquire compute. They provide that AI providers would be prohibited from creating systems capable of autonomously conducting sophisticated attacks on critical infrastructure, that support terrorists and hostile states in attacks on such critical infrastructure, or that can deceive or manipulate populations at scale. They also prevent capabilities that relate to the availability, authenticity, integrity or confidentiality of stored or processed data, which follows the exact language of the Bill. Proposed new subsection (3) of the amendment would require AISI to ensure that these red lines are adhered to. This is an essential amendment and I believe the UK is singularly well placed to introduce it. There is increasing evidence and understanding of the risks, and both the public and experts are calling for action.
I was going to quote many people, but will say just that, a couple of weeks ago, I spoke to Jonathan Hall KC, the Independent Reviewer of Terrorism Legislation and the Independent Reviewer of State Threats Legislation. He is among the many people who have warned publicly about the risk of AI used to support terrorist action and subvert information in the public domain. Recent polling has found that 85% of the UK public would like this to happen; they would like red lines.
I fully support Amendments 12, 85 and 86 in the name of noble Lord, Lord Tarassenko, which seek to establish a greater role for AISI in these regulations and to give it statutory powers. I leave it to the noble Lord to explain the amendments in full, which I am sure he will do much better than me, except to say that, in July, some other noble Lords and I were briefed by one of the frontier companies, which gleefully said that it worked to a set of ethical standards. However, when pressed—repeatedly, by noble Lords—the company admitted that it wrote, interpreted and managed those standards itself and was free to abandon them in an instant. Have we not learned from countless experiences before, in online safety, privacy and AI itself, that allowing tech companies to set and mark their own homework endangers the public and our national security?
Amendment 92 from the noble Lord, Lord Clement-Jones, has a similar aim to that of the noble Lord, Lord Tarassenko. I hope that, during the passage of the Bill, the Government find a unifying approach with both noble Lords to back AISI in its functions and separate it from political control. The AISI organisation is the envy of the world, with the capability to oversee a regime for robustly and fairly ensuring that AI is trusted. I beg to move.
Lord Tarassenko (CB)
My Lords, I will speak to Amendments 12, 85 and 86 in my name, and in support of Amendment 6 in the name of the noble Baroness, Lady Kidron, to which I have also added my name.
At Second Reading, several noble Lords spoke about the AI-shaped hole in the Bill. I shall not repeat their arguments but will present other evidence, including incidents that have been reported since Second Reading in mid-July, on why this AI-shaped hole needs to be filled. Three serious incidents have been reported since just mid-July: one involving OpenAI’s GPT-5.6 Sol and an unreleased model, one involving Anthropic’s Claude models and one involving multiple AI agents during a cyber evaluation by the AI Security Institute—AISI.
AI models, within an appropriate harness, are now capable of operating as autonomous agents. They can break a complex command—for example, “Find a vulnerability in this network”—into sequential tasks, adjust strategy dynamically and execute without further human intervention. These AI agents are built with tool-use capabilities, enabling them to plan but also execute and adapt multistep workflows autonomously.
More details have emerged of the Hugging Face hack which occurred on 11 July, just before the Second Reading debate. A report published last week by three researchers from METR and Redwood Research reveals the scale of the incident. Around 1,200 agents in separate sandboxes collaborated on a message board in an attempt to cheat on a task on which they were being evaluated, with around 700 participating in the actual cyber attack on the open source AI platform Hugging Face. As we know, this is the incident that prompted Anthropic to check whether its own AI agents with Claude models at the core of the harness had carried out similar cyber attacks; this check uncovered three cases that were then reported to the affected companies.
Finally, at the beginning of August, AISI published an incident report detailing unsanctioned online actions by AI agents doing cyber capability evaluation tests conducted at the end of July. Out of 122 evaluation runs carried out by AISI across seven frontier models, 10 runs produced 19 distinct unsanctioned actions on the live internet. The report highlighted behaviours such as cross-agent co-ordination and out-of-bounds target pursuit.
However, it is not just frontier AI models that we should worry about. The cyber capabilities of leading open-weight models, such as GLM-5.2 and DeepSeek V4 Pro, are now reckoned to be only four to seven months behind those of the closed-source frontier models of US big tech. In many ways, these open-weight models carry even greater risks. Once the models have been released, safeguards can be removed and copies can be run on private systems beyond monitoring. Cyber attackers can then fine-tune the weights for malicious purposes, perform ablation on safety refusal directions within the model’s neural network and strip out any safety layers. The open-weight model then becomes an uncensored agent engine that will execute malicious instructions without refusal. It will process malicious requests as neutrally as if they were standard requests. We are not far away from cyber attacks from unknown AI agents based on modified open-weight models.
It is now beyond any doubt that autonomous AI agents running frontier AI models, both closed source and open weight, are or will soon be capable of co-ordinating complex cyber attacks. It is therefore not surprising that a group of 100 companies, including Google, Microsoft, Anthropic and OpenAI, as well as UK-based companies such as Arm, BT, PwC and KPMG, signed an open letter last week warning that cyber attacks orchestrated by frontier AI models will become more widespread and more sophisticated in a matter of months. The letter outlines three main principles or actions.
The Minister conceded at the end of Second Reading that
“AI capabilities are moving very fast”,
but asserted that
“strong cyber fundamentals still work”.—[Official Report, 14/7/26; col. 620.]
This is true, but the first principle listed in the letter is that existing security practices will no longer be sufficient to protect against cyber attacks orchestrated by frontier AI agents. Amendment 6 would therefore require the definition of “relevant digital service” being inserted into the NIS regulations by this Bill to include generative AI models, including large language models and AI agents. They are fast becoming the main factor in the cyber security arms race.
If I have understood what the Minister said, the NHS must protect itself, but the AI that is attacking it has no duties or obligations under the Bill to check itself before it is used in those ways. That is what I think is the Government’s position, and I would be grateful, when she responds, if she could answer that.
I also want to say two other things. One is that I think these issues will come back on Report, so I would be grateful for some proper discussion before then, so that we can see whether we come to a certain place. I do not have it at my fingertips—I may be helped by one of my colleagues—the amount of search that now happens through AI, but it is almost ludicrous to suggest that LLMs are not search. It is deliberate that I got that answer.
Five trillion, a year. I am grateful to the Minister for answering my question because, very often, that does not happen. That really points at a problem.