Read Bill Ministerial Extracts
Cyber Security and Resilience (Network and Information Systems) Bill Debate
Full Debate: Read Full DebateBaroness Berger
Main Page: Baroness Berger (Labour - Life peer)Department Debates - View all Baroness Berger's debates with the Department for Science, Innovation & Technology
(2 weeks, 1 day ago)
Lords ChamberMy Lords, I strongly welcome the intention of the Bill to strengthen the United Kingdom’s defences by updating our cyber security legislation as it applies to critical national infrastructure. That is good and overdue. As my noble friend Lady Gill pointed to, there is barely a week, if not a day, that passes without a significant business, hospital, local authority or supplier to government reporting a serious cyber incident. Every part of our infrastructure is vulnerable, and a legislative update to reflect that reality is one that this House should have absolutely no hesitation in supporting.
Noble Lords have already raised concerns about a number of things relating to what is or is not in the Bill, and things that perhaps need to be tweaked—how we should consider the economic impact of cyber attacks, as well as issues around insurance, reporting, workforce development and training, making AISI a statutory body and the lack of joined-up work across 12 different regulators. These are all concerns that I share.
I want to use the time I have available to add some details on the significant gap that has already been shared by others: the Bill currently makes no provision at all for artificial intelligence or, connected to that, for cyber sovereignty. This is not a hypothetical concern. Our allies have already grasped that, if their critical systems, their public services and their citizens’ data will depend increasingly on AI, relying entirely on foreign-built, foreign-hosted models is itself a national security question and diminishes those countries’ resilience. This is now the direction of travel right across Europe, and we should not assume that we can simply stand outside it.
The Netherlands has built GPT-NL, a sovereign open language model developed by a consortium led by the research institute TNO alongside SURF and the Netherlands Forensic Institute and funded by the Dutch Government. It exists explicitly so that Dutch public bodies are not routing sensitive data through services they do not control, governed by laws they did not write and using models they did not develop or test. Germany has gone further still with Soofi—Sovereign Open Source Foundation Models—a government-backed initiative bringing together German research institutions and industry to build an open foundation model of around 100 billion parameters intended to underpin domestic industry and to handle complex technical and analytical tasks. These are not vanity projects; they are deliberate decisions by Governments to secure and keep control of the systems their public services are increasingly relying on.
The strategic logic is plain. A handful of foreign providers now sit upstream of much of the world’s AI capability, and a dependency that concentrated is a single point of failure that no Government should accept for their critical national infrastructure. Sovereignty over the AI that runs our critical systems cannot be an optional extra; it should be treated as part of our national cyber security and national resilience decisions. The Bill as currently presented is entirely silent on that question.
I will raise two specific areas where this absence should concern your Lordships. The first is education infrastructure, specifically exams and marking, which are increasingly stored and processed online. I understand that awarding bodies in this country are already exploring AI-assisted marking. If AI becomes embedded in that process, the accuracy of a child’s marks will depend partly on how that AI model behaves, and yet it will sit outside the Bill’s jurisdiction. We are creating a critical dependency for the life chances of every child in this country, resting on a model we may neither own nor be able to scrutinise, with no corresponding legislative safeguard. We would have all the risk of a critical dependency with none of the legal guardrails that the Bill is designed to provide.
The second area is electoral services and the data held on the electoral register. I do not think I need to labour the point about why the integrity, security and sovereignty of electoral roll datasets matter. If AI systems come to play any role in how our electoral registers are compiled, verified or protected—we should assume that they will—we must be able to answer three questions: who controls the model, where does the data go, and what happens if that dependency is disrupted or compromised? A register we cannot fully account for is a register that we all cannot fully trust. The Bill should be equipping us to answer those questions.
None of these points is an argument against the Bill; they are an argument for finishing it. As many noble Lords have already alluded to, technology is moving faster than any Bill can be introduced. There are many stats on the speed of tech evolution; the one that consumes me the most is that the maximum length of tasks that AI models can successfully complete is now doubling roughly every four months. We owe it to the public to build in adaptability from the start, rather than returning to primary legislation each time the landscape shifts.
We have here in the United Kingdom one of the largest and richest bodies of public data anywhere in the world, not least from our NHS and our public service broadcasters. As the cost of building capable AI systems continues to fall, we have a genuine opportunity to harness that data ourselves; to help clinicians reach diagnoses faster; to ease the administrative burden that weighs so heavily on our public servants; and to build public services that reflect our own standards, accountability and values, rather than simply adopting whatever the market happens to offer.
Building this capability at home is also how we ensure that the guardrails and safety measures that we believe are necessary are actually built in to bolster the opportunity for full cyber security, rather than inheriting it from systems designed to other standards and other priorities without any concern for real safety and security. This is something for which I will continue to advocate and which, I believe, will supercharge the realisation of the aims of the Bill. I therefore welcome my noble friend the Minister’s reflections on whether AI and cyber sovereignty might yet find a place in this legislation.
I look forward to the rest of this debate and to playing my part in scrutinising and enhancing this legislation.