(3 weeks, 6 days ago)
General Committees
Victoria Collins (Harpenden and Berkhamsted) (LD)
It is an honour to serve under your chairmanship, Dr Murrison. The Liberal Democrats of course support this instrument; Ofcom has fulfilled its duties under the original direction and the legislative housekeeping is sensible. However, the Minister talks about modern mobile services, innovation and investment, and in light of that it is right to use this opportunity to highlight that for millions of people across the UK, high-speed mobile broadband and mobile services remain a distant promise rather than a daily reality.
In my own constituency, just 20 minutes from London, constituents regularly write to me about patchy or non-existent mobile coverage. That is not just a problem of rural remoteness; there are people living on streets where their neighbour has full signal and they have none. Michael from Gaddesden Row, for example, has no 4G signal and very slow wi-fi, while his neighbours just down the street have double his speed of connection.
I have also heard from many constituents who cannot reliably pay for parking on their own high streets because the connectivity is simply not there. We are happy to support the removal of a direction that has served its purpose, but can the Minister tell me when constituents across the country will genuinely be able to access the high-speed mobile broadband infrastructure that this legislation was supposed to help to deliver?
(1 month, 1 week ago)
Commons Chamber
Victoria Collins (Harpenden and Berkhamsted) (LD)
I beg to move, That the clause be read a Second time.
With this it will be convenient to discuss the following: “Local Government Local Government The Secretary of State for Housing, Communities and Local Government” “Elections Electoral infrastructure The Electoral Commission” “Government Political parties The Secretary of State for Housing, Communities and Local Government” “Food supply Food supply chain The Secretary of State for Environment, Food and Rural Affairs (United Kingdom)”
New clause 3—Review of high-risk bodies—
“(1) The Secretary of State must, within six months of the passing of this Act, publish and lay before Parliament a review of the national security risks posed to relevant network and information systems by foreign state ownership or control of relevant bodies.
(2) A review under this section must assess—
(a) the number of relevant bodies which are owned, in whole or in part, by a foreign state or a foreign state-owned enterprise;
(b) the risk of such bodies being compelled to facilitate unauthorised access to, or surveillance of, network and information systems in the United Kingdom; and
(c) the adequacy of current powers under Part 4 (Directions for national security purposes) to mitigate such risks posed to the security and resilience of essential activities.
(3) In this section—
“relevant body” means—
(a) an operator of an essential service,
(b) a relevant digital service provider,
(c) a relevant managed service provider, or
(d) a critical supplier,
within the meaning of the NIS Regulations.
“foreign state-owned enterprise” means a body corporate in which a foreign state has a controlling interest;
“network and information systems” has the meaning given by section 24(1).”.
This new clause would require the Government to review the security risks posed by critical suppliers and essential service providers linked to foreign states and evaluate whether current powers are sufficient to address these threats.
New clause 4—Critical manufacturing and retail sectors—
“(1) The Secretary of State must, within six months of the passing of this Act, introduce regulations under section 24(3) to specify the following as essential activities—
(a) the manufacture of critical transport equipment;
(b) the industrial production and processing of food products; and
(c) the retail sale of food and essential goods via large-scale distribution chains.
(2) Regulations made under subsection (1) must designate appropriate regulatory authorities for these sectors.”.
This new clause would require the Secretary of State to designate the manufacturing of critical transport equipment and retail of food and essential goods (when part of a large-scale distribution chain) as essential activities, bringing them within the scope of Part 3 of the Bill.
New clause 5—Local authorities to be regulated as essential services—
“(1) The NIS Regulations are amended as follows.
(2) In the table in Schedule 1 (designated competent authorities), after the entry relating to the energy sector, insert—
(3) In Schedule 2 (essential services and threshold requirements), after paragraph 11 insert—
“The Local Government Sector
12 — (1) This paragraph describes the threshold requirements which apply to specified kinds of essential services in the local government subsector.
(2) For the essential service of the maintenance of electoral registers, the threshold requirement is that the entity is a local authority responsible for the maintenance of an electoral register.
(3) For the essential service of the management of social care records, the threshold requirement is that the entity is a local authority responsible for the management of social care records.
(4) In this paragraph “local authority” means—
(a) in England, a county council, a district council, a London borough council, the Common Council of the City of London or the Council of the Isles of Scilly;
(b) in Wales, a county council or a county borough council;
(c) in Scotland, a council constituted under section 2 of the Local Government etc. (Scotland) Act 1994;
(d) in Northern Ireland, a district council constituted under section 1 of the Local Government Act (Northern Ireland) 1972.”.
This new clause would bring local authorities within the scope of the NIS Regulations as operators of essential services in relation to their functions managing electoral rolls and social care records. This ensures that public sector bodies holding sensitive data such as electoral rolls and social care records are subject to the same statutory protections as other critical infrastructure.
New clause 6—Computer Misuse Act 1990: security and resilience of network and information systems—
“(1) The Secretary of State must, within twelve months of the passing of this Act, review whether amendments to the Computer Misuse Act 1990 may be conducive to ensuring, maintaining or improving the security and resilience of network and information systems used or relied upon in connection with the carrying on of essential activities.
(2) Following the conclusion of the review under subsection (1), the Secretary of State must lay before Parliament a report which outlines—
(a) the potential amendments to the Computer Misuse Act 1990 which were considered as part of the review;
(b) the review’s conclusions as to whether the potential amendments considered could be beneficial in ensuring, maintaining or improving the security and resilience of relevant network and information systems; and
(c) the Government’s intentions to make amendments to the Computer Misuse Act 1990 or act on any other recommendations of the review.”.
This new clause would require the Secretary of State to review, within 12 months, whether amending the Computer Misuse Act 1990 could improve the resilience of network and information systems, and to report the government’s intentions to Parliament.
New clause 7—Consultation on resourcing of regulatory authorities and regulated persons—
“(1) The Secretary of State must, within one year of the passing of this Act, carry out a consultation with regulatory authorities and regulated persons for the purpose of assessing—
(a) whether regulatory authorities and regulated persons have resources and capabilities adequate to fulfil their requirements under this Act; and
(b) whether further government support is needed.
(2) The Secretary of State must publish a report setting out the findings of the assessment carried out under subsection (1).”.
This new clause would require the Secretary of State to consult and report within one year on whether regulatory authorities and regulated persons have sufficient resources and capabilities to meet their statutory obligations, and whether additional government support is required.
New clause 8—Electoral infrastructure to be regulated as an essential service—
“(1) The NIS Regulations are amended as follows.
(2) In the table in Schedule 1 (designated competent authorities), after the entry relating to digital infrastructure insert—
(3) In Schedule 2 (essential services and threshold requirements), after paragraph 11 insert—
“The electoral infrastructure subsector
12 — (1) This paragraph describes the threshold requirements which apply to specified kinds of essential services in the electoral infrastructure subsector.
(2) For the essential service of the administration of an election or the maintenance of an electoral register in the United Kingdom, the threshold requirement is that the service relies on network and information systems to—
(a) maintain a register of electors containing more than 50,000 entries;
(b) issue, receive, or process postal ballots for a parliamentary or local government election; or
(c) count or aggregate votes cast in a parliamentary, mayoral or local government election.
(3) In this paragraph—
“parliamentary election” means an election of a Member to serve in the Parliament of the United Kingdom;
“network and information system” has the meaning given by section 24(1) of the Cyber Security and Resilience (Network and Information Systems) Act 2026.
(4) In regulation 8A (nomination by an OES of a person to act on its behalf in the United Kingdom), after paragraph 1(b) insert—
‘(c) provides an essential service of a kind referred to in paragraph 11 of Schedule 2 (elections sector) within the United Kingdom.’”.
This new clause would designate the administration of elections and maintenance of voter registers as an “essential service” within the meaning of the NIS Regulations.
New clause 9—Political parties to be regulated as an essential service—
“(1) The NIS Regulations are amended as follows.
(2) In the table in Schedule 1 (designated competent authorities), after the entry relating to digital infrastructure insert—
(3) In Schedule 2 (essential services and threshold requirements), after paragraph 11 insert—
“The political parties subsector
12 — (1) This paragraph describes the threshold requirements which apply to specified kinds of essential services in the political parties subsector.
(2) For the essential service of the management and operation of a registered political party in the United Kingdom, the threshold requirement is that the political party is represented by at least two Members of the House of Commons.
(3) In this paragraph—
“registered political party” means a party registered under Part 2 of the Political Parties, Elections and Referendums Act 2000.”.
This new clause would designate political parties as providing essential services for the purposes of cyber security.
New clause 10—Board oversight of security and resilience of network and information systems—
“(1) Where a relevant body is governed by a board or equivalent management body, that body must exercise oversight of arrangements relating to the security and resilience of the body’s network and information systems.
(2) In exercising oversight, the management body must—
(a) approve the approach taken by the body to the management of risks to the security and resilience of the body’s network and information systems; and
(b) satisfy itself, on a periodic basis, that appropriate and proportionate measures are in place to manage those risks.
(3) The management body may be held accountable for failures by the body to comply with duties relating to the security and resilience of its network and information systems.
(4) Members of the management body must undertake training designed to enable them to identify risks and assess appropriate risk-management practices.
(5) For the purposes of this section, a relevant body is one which is—
(a) an operator of an essential service,
(b) a relevant digital service provider,
(c) a relevant managed service provider, or
(d) a critical supplier,
within the meaning of the NIS Regulations.”.
This new clause would require active board oversight of, and accountability for, security and resilience measures, where a relevant body is governed by a board or similar body.
New clause 11—Requirement for regular testing of network and information systems—
“(1) A relevant body must undertake regular testing of the security and resilience of the network and information systems on which it relies in the provision of its services.
(2) Testing undertaken in accordance with this section must—
(a) be proportionate, having regard to the size, nature and risk profile of the business; and
(b) be conducted periodically, at intervals that are appropriate to the risks identified by the body.
(3) A relevant body must document—
(a) the outcomes of testing undertaken in accordance with this section; and
(b) any remedial actions required or taken in response to the testing.
(4) Information documented under subsection (3) must be provided to the relevant regulatory authority upon request.
(5) For the purposes of this section, a relevant body is one which is—
(a) an operator of an essential service,
(b) a relevant digital service provider,
(c) a relevant managed service provider, or
(d) a critical supplier,
within the meaning of the NIS Regulations.”.
This new clause would require bodies to carry out proportionate, periodic testing of the security and resilience of their network and information systems and provide the results to regulatory bodies upon request.
New clause 12—“Last-resort” powers in respect of data centres and AI models—
“(1) Regulations under section 29(1) may confer on the Secretary of State powers (“last-resort powers”) to direct the shutdown of—
(a) data centres, or
(b) AI systems used or deployed by a data centre,
in the event of an AI security or operational emergency.
(2) For the purposes of this section—
“data centre” has the meaning given in paragraph 11 of the NIS Regulations (as amended by this Act);
“AI system” means a machine-based system that, from the input it receives, can infer how to—
(a) generate predictions, digital content, recommendations, decisions or other similar outputs, or
(b) influence a physical or virtual environment,
with a view to achieving an explicit or implicit objective;
“used or deployed” means made available to—
(a) a substantial number of individuals within the United Kingdom; or
(b) providers and operators of essential services;
“AI security or operational emergency” means a situation where the Secretary of State has reasonable grounds to believe that—
(a) there is a security or operational compromise to one or more relevant network and information systems,
(b) this compromise is caused, or contributed to, by the use or operation of an AI system used or deployed by a data centre, whether through autonomous or non-autonomous means; and
(c) this compromise poses a catastrophic risk;
“catastrophic risk” means a risk carrying a reasonable likelihood of causing or contributing to—
(a) large-scale disruption to critical infrastructure or essential services;
(b) significant degradation of the national security, national defence, or intelligence capabilities of the United Kingdom; or
(c) severe, large-scale harm to human life;
“data centre operator” means a person who operates a data centre;
(3) As soon as reasonably practicable after, and in any event within seven days of, giving a direction under subsection (1), the Secretary of State must—
(a) lay a report before Parliament setting out the direction and the reasons for it; and
(b) take all reasonable steps to arrange for the report to be the subject of a debate in each House as soon as is reasonably practicable.
(4) Regulations relating to last-resort powers must establish requirements on data centre operators in relation to data centres used for the training, deployment or operation of AI systems, including relating to—
(a) the possession or installation of technical infrastructure necessary for compliance with last-resort powers;
(b) the provision of secure communication channels for use by the Secretary of State when utilising last-resort powers;
(c) the implementation of regular emergency exercises to ensure that a direction under this section can be received safely and implemented; and
(d) post-mortem processes to be followed before a data centre is allowed to resume operations after the use of last-resort powers, including—
(i) incident reporting; and
(ii) implementation of mitigation measures to prevent recurrence.
(5) A person commits an offence if they fail to comply with any requirement imposed by regulations made under subsection (4).
(6) Regulations relating to last-resort powers may—
(a) confer on the Secretary of State, or on a person designated by the Secretary of State, powers to act where they reasonably believe that an offence under subsection (5) is being, has been, or may be about to be committed;
(b) include, for the purposes of paragraph (a), powers to—
(i) close premises;
(ii) turn off systems or require that they be turned off;
(iii) take any other action necessary to control the risk arising from an AI security or operational emergency.
(7) Regulations must require that, where powers under subsection (6) are exercised, the Secretary of State must—
(a) give written notice of the action taken, and the reasons for the action taken, to the operator or provider as soon as reasonably practicable; and
(b) inform the operator or provider of their right to apply to the High Court for relief.
(8) The High Court may make any order it thinks fit on an application under subsection (7)(b), including—
(a) confirming, varying or cancelling the requirements;
(b) imposing additional requirements;
(c) ordering compensation.
(9) The Secretary of State must publish guidance on the use by licensing authorities, planning authorities and other public authorities of their statutory powers to facilitate compliance with regulations relating to this section.
(10) A public authority must have regard to guidance issued under subsection (9) when exercising any function to which the guidance relates.
(11) The Secretary of State must, within six months of the commencement of this section and subsequently at six-monthly intervals, prepare a report on the causes and potential causes of AI security or operational emergencies and lay a copy of the report before Parliament.
(12) The causes and potential causes of AI security or operational emergencies considered in any report under subsection (11) must include —
(a) adversarial uses of AI systems by state and non-state actors;
(b) the capabilities for cyber-attacks by autonomous AI systems; and
(c) the development of AI systems that can autonomously compromise national security, escape human oversight, and upend international stability, including systems described as “superintelligent AI”.”.
This new clause would enable the Secretary of State to be granted “last-resort powers” to ensure that the government can intervene in case of an emergency caused by AI used or deployed by a data centre which can cause large-scale harm.
New clause 13—Digital Sovereignty Strategy on risks posed by foreign interference and reliance on foreign technologies—
“(1) The Secretary of State must, within 12 months of the passing of this Act, publish a strategy (“a Digital Sovereignty Strategy”) which sets out the Government's approach to maintaining the security and resilience of relevant network and information systems by—
(a) assessing, managing and mitigating risks—
(i) associated with foreign interference,
(ii) arising from reliance on foreign-supplied technologies, and
(b) preventing over-reliance on foreign providers by building domestic capacity.
(2) For the purposes of this section, a “relevant network and information system” is a network and information system belonging to—
(a) an operator of an essential service,
(b) a relevant digital service provider,
(c) a relevant managed service provider, or
(d) a critical supplier, within the meaning of the NIS Regulations.
(3) A Digital Sovereignty Strategy published under this section must—
(a) include risks associated with—
(i) hardware,
(ii) software,
(iii) supply chains, and
(iv) procurement processes;
(b) include a specific focus on security and resilience in government digital procurement processes, detailing how the Government intends to reduce strategic dependencies on foreign-owned service providers to mitigate the risk of systemic disruption;
(c) include a commitment to prioritise the use of technologies developed in the UK by UK organisations in relevant network and information systems to reduce reliance on foreign technologies, and
(d) where risks are identified under subsection (1)(a)(i), state how the Government intends to address these risks by supporting the use of domestic technologies or systems for the purpose of ensuring the security of those systems.”.
This new clause would require the Government to publish a Digital Sovereignty Strategy setting out how it intends to address risks to relevant network and information systems posed by foreign interference and reliance on foreign technologies, including by supporting the use of domestic technologies.
New clause 14—Register of foreign powers for the purposes of Part 4—
“(1) For the purposes of informing action taken under Part 4 of this Act, the Secretary of State must by regulations, and within six months of the passing of this Act, establish and subsequently maintain a register of foreign powers that the Secretary of State believes present a risk to the United Kingdom’s critical network and information systems.
(2) Foreign powers determined by the Secretary of State as eligible for inclusion on the register under subsection (1) must include states which have been confirmed by GCHQ as posing a risk to the security or resilience of the network or information systems of one or more operators of an essential service or critical suppliers, including where the relevant risk is posed by state affiliated groups.
(3) Regulations under this section are subject to the affirmative resolution procedure.
(4) In this section, “foreign power” means—
(a) the sovereign or other head of a foreign state in their public capacity;
(b) a foreign government, or part of a foreign government;
(c) an agency or authority of a foreign government, or of part of a foreign government;
(d) an authority responsible for administering the affairs of an area within a foreign country or territory, or persons exercising the functions of such an authority; or
(e) a political party which is a governing political party of a foreign government. A political party is a governing political party of a foreign government if persons holding political or official posts in the foreign government or part of the foreign government—
(i) hold those posts as a result of, or in the course of, their membership of the party, or
(ii) in exercising the functions of those posts, are subject to the direction or control of, or significantly influenced by, the party.”
This new clause would require the Government to maintain a register of state actors posing a threat to UK cyber security for the purposes of exercising the Secretary of State’s powers under Part 4 of the Act, which enable the giving of directions in the interests of national security.
New clause 15—Review of the cyber security risk posed by foreign powers—
“(1) The Secretary of State must, within 12 months of the passing of this Act and annually thereafter, review the extent and nature of the risk posed by relevant foreign powers to the network and information systems of operators of essential services and critical suppliers.
(2) A review under this section must identify whether any risk arises from—
(a) activities undertaken outside of the UK, or
(b) foreign owned or controlled infrastructure or locations within the UK.
(3) For the purposes of subsection (1), “relevant foreign powers” include states which have been confirmed by GCHQ as posing a risk to the security or resilience of the network or information systems of one or more operators of an essential service or critical suppliers, including where the relevant risk is posed by state departments, state agencies or affiliate groups.
(4) Within three months of each review under subsection (1), the Secretary of State must—
(a) lay before Parliament a report containing the findings and conclusions of the review; and
(b) where information is not included in a report on the grounds of being prejudicial to the UK’s national security, send such information to the Intelligence and Security Committee of Parliament.”
This new clause would require the Government to report on the risk to relevant network and information systems posed by specified foreign powers, considering whether such risks arise from extra-territorial activities and/or UK infrastructure or premises owned or controlled by foreign powers.
New clause 16—Digital Sovereignty Strategy (relevant network and information systems)—
“(1) The Secretary of State must prepare and maintain a Digital Sovereignty Strategy (“the Strategy”) in relation to relevant network and information systems.
(2) The Strategy must—
(a) set out the Government’s assessment of the risks to relevant network and information systems arising from or related to—
(i) dependence on hardware, software, or digital services that may be subject to foreign interference;
(ii) extra-territorial legal requirements that may be imposed on non-domiciled suppliers;
(iii) vulnerabilities, undue control, or supply-chain dependency on foreign states or entities;
(b) technological developments, market concentration, or strategic dependencies that may affect the security or resilience of relevant network and information systems;
(c) set out the Government’s approach to mitigating the risks identified under subsection (2); and
(d) include an assessment of—
(i) the role of open source software, open standards, and open architectures in strengthening the resilience, transparency, and security of relevant network and information systems;
(ii) the security and maintenance needs of open source software components used, or proposed to be used, in relevant network and information systems;
(iii) the skills, capabilities, and capacity of United Kingdom-based developers, maintainers, and technical experts required to support the use of open source components in relevant network and information systems;
(iv) options to increase the use of open source components and to diversify open source suppliers, reduce strategic dependencies, and enhance domestic capability in key technologies used in relevant network and information systems;
(v) options for international collaboration in the production of open source components used in relevant network and information systems;
(vi) any legislative, regulatory, procurement, or policy measures the Government considers necessary to support digital sovereignty through open source components and reduce systemic risk in relation to relevant network and information systems.
(3) The Secretary of State must publish the Strategy and any revisions to it, subject to the redaction of information the publication of which would be reasonably likely to prejudice national security.
(4) The Strategy must be reviewed at least once in every three-year period but may be updated whenever the Secretary of State considers that significant new risks have arisen.
(5) In this section—
“relevant network and information system” means a network and information system belonging to—
(a) an operator of an essential service,
(b) a relevant digital service provider,
(c) a relevant managed service provider, or
(d) a critical supplier,
within the meaning of the Network and Information Systems Regulations 2018;
“digital sovereignty” means the ability of the United Kingdom to maintain secure, resilient, and reliable access to and control over the hardware, software, data, and digital services on which relevant network and information systems depend;
“open source” has the meaning given to it in the definition published by the Open Source Initiative.”
New clause 18—Review of the number of bodies providing cloud computing services—
“(1) The Secretary of State must, within six months of the passing of this Act, publish and lay before Parliament a review of the risks posed to relevant network and information systems by the number of different bodies providing or supplying cloud computing services.
(2) For the purposes of this section, “cloud computing services” has the meaning given in paragraph 1 of the NIS Regulations.”
This new clause would require the Government to review the risks posed to relevant network and information systems by the number of different bodies providing or supplying cloud computing services.
New clause 19—Review of risks posed by foreign state ownership or control of providers of cellular Internet of Things modules—
“(1) The Secretary of State must, within six months of the passing of this Act, publish and lay before Parliament a review of the risks posed to relevant network and information systems by foreign state ownership or control of providers of cellular Internet of Things modules.
(2) For the purposes of this section–
“cellular Internet of Things modules” means devices that communicate over public mobile networks for the purposes of enabling autonomous machine to machine communication;”.
This new clause would require the Government to review the risks posed to relevant network and information systems by providers of cellular Internet of Things modules owned or controlled by foreign states.
New clause 20—Specification of retail commerce as an essential activity—
“(1) The Secretary of State must, within six months of the passing of this Act, introduce regulations under section 24(3) to specify as an essential activity retail commerce carried out by companies with an annual turnover in excess of £12 billion.
(2) Regulations introduced under subsection (1) must designate appropriate regulatory authorities for this sector.”
This new clause would require the Secretary of State to designate retail commerce carried out by companies with an annual turnover in excess of £12 billion as an essential activity, bringing it within the scope of Part 3 of the Bill.
New clause 21—Food supply chain to be regulated as an essential service—
“(1) The NIS Regulations are amended as follows.
(2) In the table in Schedule 1 (designated competent authorities), after the entry relating to digital infrastructure insert—
(3) In Schedule 2 (essential services and threshold requirements), after paragraph 11 insert—
“The food supply chain subsector
12 — (1) This paragraph describes the threshold requirements which apply to essential services in the food supply chain subsector.
(2) For the essential service of the food supply chain in the United Kingdom the threshold requirement is that the person is in the food supply chain and does not qualify as small or a micro-entity (or is excluded) within the meaning of Part 15 of the Companies Act 2006.
(3) For the purposes of this paragraph—
(a) a “food supply chain” is a supply chain for providing individuals with items of food or drink for personal consumption, where the items consist of or include, or have been produced to any extent using—
(i) anything grown or otherwise produced in carrying on agriculture, or
(ii) anything taken, grown or otherwise produced in carrying on fishing or aquaculture;
(b) a person is “in” a food supply chain if that person is a producer or an intermediary in a food supply chain.
(4) In paragraph (3)(b)—
(a) “producer” means a person who is carrying on agriculture, fishing or aquaculture;
(b) “intermediary” means a person in the food supply chain between a producer and the individuals referred to in paragraph (3)(a).
(5) In this paragraph—
“agriculture” includes any growing of plants, and any keeping of animals, for the production of food or drink;
“aquaculture” means the breeding, rearing, growing or cultivation of—
(a) any fish or other aquatic animal,
(b) seaweed or any other aquatic plant, or
(c) any other aquatic organism.
“plants” includes fungi.
(6) In regulation 8A of the NIS Regulations (nomination by an OES of a person to act on its behalf in the United Kingdom), after paragraph 1(b) insert—
‘(c) provides an essential service of a kind referred to in paragraph 12 of Schedule 2 (food supply chain sector) within the United Kingdom.’”
This new clause would designate those in the food supply chain that rely on network and information systems as “operators of essential services” within the meaning of the Network and Information Systems Regulations 2018, thereby placing them under duties to manage risks to those systems and to provide notification regarding any incidents that have an impact on the food supply chain.
Amendment 1, in clause 8, page 7, line 36, at end insert—
“(1A) In paragraph (1), after “risks” insert “, including risks arising from fraud,””.
This amendment would explicitly include fraud as one of the risks to the security of network and information systems that relevant digital service providers must identify and manage.
Amendment 28, in clause 10, page 9, line 33, at end insert—
“(2A) The measures taken by an RMSP under paragraph (1) must ensure that the number of customers to whom the RMSP provides services does not exceed the critical risk threshold.
(2B) In paragraph (2A), the “critical risk threshold” is the number of customers within a sector or subsector where an incident affecting the provision of services to those customers by the RMSP would result in disruption that is likely to have a significant impact on the economy or the day-to-day functioning of society in the whole or any part of the United Kingdom.
(2C) Paragraph (2D) applies where the number of customers to whom an RMSP provides services exceeds the critical risk threshold by virtue of contracts entered into before the coming into force of section 10 of the Cyber Security and Resilience (Network and Information Systems) Act 2026.
(2D) The RMSP must take steps to reduce the number of customers to below the critical risk threshold, including exercising any right to terminate a contract or vary the terms of a contract.”
This amendment would place a duty on relevant managed service providers (“RMSPs”) to ensure that they do not provide services to manage the technology systems for a number of customers that exceeds a critical risk threshold, such that an incident affecting those services would be likely to result in significant disruption in the United Kingdom. This would prevent an RMSP managing the technology systems for a whole sector or subsector. Provision is also made for a situation where an RMSP is in breach of the critical risk threshold because of contracts entered into before the enactment of the Bill.
Government amendments 7 to 11.
Amendment 6, in clause 18, page 40, line 12, at end insert—
“(8A) Where the CSIRT receives notification of an incident under regulation 11, 11A, 12A or 14E which it considers to materially involve autonomous or adaptive systems based on machine learning, the CSIRT must share relevant technical information with the relevant body within 72 hours.
(8B) For the purposes of this regulation, a “relevant body” means the AI Security Institute or any successor or replacement body designated by the Secretary of State.”.
This amendment would require incident data relating to AI systems in critical national infrastructure to be sent to the body designated by the Government as responsible for AI safety and security.
Government amendments 12 to 14.
Amendment 3, in clause 18, page 41, line 15, at end insert—
“Exemption from disclosure: right to a fair trial
(1) Nothing in sub-paragraphs (1)(d) to (1)(f) of regulation 6, or regulation 6A, permits a NIS enforcement authority to share information with another NIS enforcement authority or with a person within paragraph (2) of regulation 6 if the Secretary of State determines that—
(a) the receiving jurisdiction is one in which the right to a fair trial cannot be guaranteed, or
(b) the disclosure could result in actions being taken that would be incompatible with the right to a fair trial.
(2) For the purposes of making a determination under paragraph (1) above, the Secretary of State must have regard to the opinion of—
(a) subject matter experts, and
(b) competent civil society groups.
(3) The Secretary of State must, within 12 months of the passing of the Cyber Security and Resilience (Network and Information Systems) Act 2026, publish and lay before Parliament an annual report detailing the determinations made under paragraph (1) above in the previous 12 months.”
This amendment would prevent the sharing of information with overseas authorities for the purpose of prosecuting crimes not committed in the UK if the Secretary of State determines that the receiving country is one in which the right to a fair trial cannot be guaranteed.
Government amendments 15 to 17.
Amendment 4, in clause 29, page 54, line 9, at end insert
“, including the risks arising from the use of embedded communications components manufactured outside the UK;”.
This amendment would make explicit that regulations could concern the risks arising from the use of embedded components within the systems (such as cellular internet of things modules).
Amendment 2, in clause 40, page 63, line 7, leave out “5” and insert “3”.
This amendment would increase the frequency of the reports that must be published under Clause 40, from every five years to every three years.
Amendment 5, in clause 43, page 66, line 18, at end insert—
“(i) a requirement relating to embedded communications components manufactured outside the UK.”
This amendment would provide an additional requirement that may be imposed on a regulated person, in relation to an embedded communications component manufactured outside the UK.
Government amendments 18 to 27.
Victoria Collins
As the director of the National Cyber Security Centre has said,
“Every organisation delivering the UK’s critical services…relies on uninterrupted digital operations. Disruptions to those operations isn’t simply an IT issue; it’s a…national resilience issue”.
The Liberal Democrats wholeheartedly support that point, and it is why we welcome the measures introduced by this Bill, which strengthen existing cyber protections to enhance national security. However, as the Liberal Democrats have made clear throughout the Bill’s stages so far, there are many missed opportunities to truly future-proof our country’s cyber-security to protect our democracy, economy and national security. I will speak to the Liberal Democrat amendments to the Bill, which we think would achieve that.
First, on the scope of the Bill, last year we saw the costliest cyber-incident in UK history. The financial damage caused by the attack on Jaguar Land Rover is estimated to have cost between £1.6 billion and £2.1 billion—a cost shared between JLR directly and its supply chain. In the public sector, cyber-attacks are causing eye-watering costs too—just look at Redcar’s cyber-attack, which cost them a staggering £10.4 million. Despite that, the Bill takes no consideration of the significant economic cost of such cyber-attacks, excluding retail and manufacturing industries as well as local government from the scope of the Bill.
New clauses 4 and 5 address a crucial gap. New clause 4 would bring the manufacturing of critical transport equipment and the retail of food and essential goods, where they form part of a large-scale distribution chain, within the scope of essential categories under the Bill. That means that companies such as Jaguar Land Rover would finally receive the protections that their strategic importance demands and protect their supply chains too. New clause 5 extends that same recognition to local authorities, whose digital infrastructure underpins the delivery of services that millions of people depend on.
The Government’s own industrial strategy recognises that sustainable and secure growth requires strong levels of cyber-resilience across the economy, but their own cyber Bill does not live up to this. If a cyber-attack brought JLR’s production lines to a halt or crippled the digital infrastructure of a council, the damage to our economy and people’s daily lives would be enormous.
Those are not the only issues within the scope of the Bill. Safeguarding our democratic processes must be treated as a national security priority, and here, too, the Bill falls short. At a time when foreign interference in our elections is not a hypothetical but a documented and growing threat, the Government have chosen not to act. New clauses 8 and 9 would begin to change that. New clause 8 would designate the administration of elections and voter registers as essential services within the meaning of the network and information systems regulations—a straightforward recognition that the machinery of our democracy is as critical as any power grid or hospital network.
New clause 9 would designate political parties as essential services for the purposes of cyber-security, extending meaningful protection to the organisations through which the British people exercise their democratic voice. I understand that the Bill is not a silver bullet for cyber-security, but these amendments make the modest, targeted and entirely reasonable ask that vehicle manufacturing, food retail supply chains, local authorities, our elections and our political parties are brought within scope.
In turning to online-generated fraud and scams, we can see the impact of a lack of action to secure online and cyber-spaces. Fraud makes up 44% of all UK crime, and online technologies—especially artificial intelligence—are supercharging that. According to reporting in The Times a few weeks ago, research by Lloyds bank found that Meta’s social media sites are a starting point for 76% of purchase scams in the UK, with the value of losses to UK customers estimated at around £66 million in the last year alone. Not only does the Government’s fraud strategy completely overlook the role of social media giants and big tech in the proliferation of online scams, but the Bill fails to address explicitly the risks that fraud and scams pose to critical infrastructure and organisations. That is especially striking when we consider that the Government’s official statistics on cyber-security breaches show that phishing attacks—scams—remain the most prevalent type of breach or attack by far in the UK.
Amendment 1 would change that. It would amend clause 8 to add “risks arising from fraud” explicitly to the list of security threats facing relevant digital services so that those threats can be identified and managed. That is also why the Liberal Democrats are calling for social media giants to be financially liable for scams originating on their platforms and for an online crime agency to tackle these issues and standardise AI labelling.
We must not forget that these threats do not fall solely on large institutions and critical infrastructure. Small and medium-sized enterprises are on the frontline of cyber-crime; they are disproportionately targeted and too often without the resources or expertise to defend themselves. Many of the businesses caught up in the supply chains of our critical industries and exposed to the fraud and cyber-risks that I have described are SMEs, yet there are no provisions in the Bill to help potentially under-resourced SMEs cope with the increasing threat of cyber-attacks. New clause 2 would require the establishment of dedicated cyber-security support services for those businesses. For the Liberal Democrats, backing British small businesses means ensuring that they are not left to face those threats alone.
The Liberal Democrats have also tabled a series of further measures that would make the legislation fit for purpose over the long term. A law is only as good as its enforcement, which is why we are pressing for board-level accountability for cyber-resilience under new clause 10, regular proportionate testing of systems under new clause 11 and more frequent Government reporting every three years—rather than every five years—under amendment 2.
Last week, at London Tech Week, as I was surrounded by experts across the industry, one thing became clear. We think that technology is moving quickly now, but with the growth and development of AI this is the slowest we will ever see change happen. That is why we need the framework to evolve, which means reviewing the security risks posed by foreign-linked critical suppliers, which new clause 3 would do, modernising the outdated Computer Misuse Act 1990, which new clause 6 would do, and assessing whether regulators have the resources they actually need to do their job, which new clause 7 would do. Those are not radical tasks; they are basic conditions for a cyber-security regime that works today and will continue to work in the future.
If there is one matter that cuts to the heart of what the Bill should be about, and asks the fundamental question about Britain’s place in a contested digital world, it is digital sovereignty. All the protections we have discussed for our industries, our democracy and our small businesses will mean little if we do not first answer who controls the digital infrastructure on which all of them depend, and question whether, at every level of the stack, we have critical control over that.
That is echoed loudly by the industry itself. A study by Civo, a UK sovereign cloud provider, found that 83% of IT decision makers in this country worry about the impact of geopolitical developments on their data sovereignty. When we look at the numbers, it is not hard to see why. About 55% of central Government organisations report that over 60% of their estate is on the cloud, and the vast majority of that is with just two providers, both of which are American.
We have handed the keys to significant parts of our national digital infrastructure to foreign corporations, subject to foreign laws and exposed to foreign decisions entirely outside our control. That includes our public services. The Liberal Democrats are alarmed at the NHS’s growing reliance on complex, opaque digital systems set up by Palantir. With Palantir’s background in security and surveillance, that marks a divergence from the traditional relationship between the NHS and firms with specialised medical knowledge. The procurement process for the federated data platform, which was awarded to Palantir in 2023, is worryingly opaque.
Peter Fortune (Bromley and Biggin Hill) (Con)
I recognise the importance of sovereignty, but there are real challenges. How can we deal with the prevalence of, for example, Taiwanese chips in our tech market?
Victoria Collins
I thank the hon. Member for his question. That is why we need a strategy—we need to be clear about the Government’s priorities. On procurement, we have heard from the National Audit Office that cost is often a priority, but at what cost? When the Government are looking for suppliers, what do we value? There must be a strategy for that, and we need to have that conversation so that the direction is clear, whether on hardware or software.
Working internationally is vital, but it is also important to be clear about what is important for us, especially in the tech stack. That is the thing: it is about our security and resilience as well as our economy, strengthening those developing technologies as well as using technology. It is also about working together internationally and knowing that we have the resilience to look after and trade our technology stack.
It is about our security, our cyber-security and our resilience. Within a three-mile radius of Belfast, we have some of the best cyber-security resilience in the whole of the United Kingdom. It is about those 2,750 employees and the £258 million of direct gross value added. Does the hon. Lady recognise that powerhouses like Belfast must be fully integrated into our national cyber strategy? Will she put on the record that that is what we should be aiming for?
Victoria Collins
I thank the hon. Member for his intervention. I absolutely agree. Across the United Kingdom, including in Northern Ireland, there are incredible British tech firms. Many of them have said to me that their services are being procured by other Governments in Europe and around the world, yet they find their own British Government not using them or getting the value out of that British technology here by developing skills and jobs.
The Liberal Democrats welcome the Government’s hardware strategy, announced last week, which at least acknowledges the importance of British procurement, but acknowledgment is not a strategy. New clause 13, which I am pleased to say has drawn support from across the House, would make it one. In an increasingly unstable world, the case for British digital resilience, British technology and British sovereign capability has never been stronger. I therefore urge hon. Members to vote for the new clause.
Cyber-security is no longer a technical matter confined to server rooms and IT departments. It is a question of national resilience, economic strength and democratic integrity. The Bill before us takes important steps, but important steps are not enough in today’s digital age. With these amendments, we have the opportunity to close the gaps, broaden the protections and build a framework that is genuinely fit for the digital age.
I call the Chair of the Select Committee on Science, Innovation and Technology.
Victoria Collins
I do not think that the hon. Member has understood our amendment, which is about having a strategy. It does not say that everything should be sovereign, but we need to look at our tech stack and have a strategy for what is sovereign and what requires the procurement of elements. I ask him to look at our amendment again.
I refer the hon. Member to her new clause 13, particularly subsection 3(c), which makes it very clear that companies would need to deviate from “foreign technologies”, which would be quite a burden.
We need to back Britain in key sectors, from quantum and photonics to chip design and innovation. In so many areas, we lead the world. We should not try to restrict the influence and access of global markets. We must engage not in protectionism, but in leverage, to back Britain and position ourselves so that we are indispensable in the modern global tech sector and supply chains.
Kanishka Narayan
I can confirm that the Government will be very happy to engage on this question further with my hon. Friend and the right hon. Member for Chingford and Woodford Green (Sir Iain Duncan Smith). I commend the Bill to the House.
Victoria Collins
Before I withdraw new clause 2, I want to draw Members’ attention to my entry in the Register of Members’ Financial Interests in reference to my earlier speech. I beg to ask leave to withdraw the clause.
Clause, by leave, withdrawn.
New Clause 13
Digital Sovereignty Strategy on risks posed by foreign interference and reliance on foreign technologies
“(1) The Secretary of State must, within 12 months of the passing of this Act, publish a strategy (“a Digital Sovereignty Strategy”) which sets out the Government's approach to maintaining the security and resilience of relevant network and information systems by—
(a) assessing, managing and mitigating risks—
(i) associated with foreign interference,
(ii) arising from reliance on foreign-supplied technologies, and
(b) preventing over-reliance on foreign providers by building domestic capacity.
(2) For the purposes of this section, a “relevant network and information system” is a network and information system belonging to—
(a) an operator of an essential service,
(b) a relevant digital service provider,
(c) a relevant managed service provider, or
(d) a critical supplier, within the meaning of the NIS Regulations.
(3) A Digital Sovereignty Strategy published under this section must—
(a) include risks associated with—
(i) hardware,
(ii) software,
(iii) supply chains, and
(iv) procurement processes;
(b) include a specific focus on security and resilience in government digital procurement processes, detailing how the Government intends to reduce strategic dependencies on foreign-owned service providers to mitigate the risk of systemic disruption;
(c) include a commitment to prioritise the use of technologies developed in the UK by UK organisations in relevant network and information systems to reduce reliance on foreign technologies, and
(d) where risks are identified under subsection (1)(a)(i), state how the Government intends to address these risks by supporting the use of domestic technologies or systems for the purpose of ensuring the security of those systems.”—(Victoria Collins.)
This new clause would require the Government to publish a Digital Sovereignty Strategy setting out how it intends to address risks to relevant network and information systems posed by foreign interference and reliance on foreign technologies, including by supporting the use of domestic technologies.
Brought up, and read the First time.
Question put, That the clause be read a Second time.
Victoria Collins
I reiterate the importance of a digital sovereign strategy for our cyber-security. It is about our resilience, our security and our economic strength as a country and collaborative sovereignty. We very much welcome the extended scope of the Bill and we support it moving forward.
Question put and agreed to.
Bill accordingly read the Third time and passed.
Calum Miller (Bicester and Woodstock) (LD)
On a point of order, Madam Deputy Speaker. I seek your guidance. There are reports that a Russian warship has today fired warning shots near a UK-registered yacht in the English channel, south of the Isle of Wight. If verified, this action would be of grave concern to the House and would represent a significant escalation in the hostilities shown by Russian actors towards UK interests. Can you guide me on how the House might seek to be urgently updated by a Defence Minister on this development and guided as to the Government’s proposed response?
(4 months, 2 weeks ago)
Westminster HallWestminster Hall is an alternative Chamber for MPs to hold debates, named after the adjoining Westminster Hall.
Each debate is chaired by an MP from the Panel of Chairs, rather than the Speaker or Deputy Speaker. A Government Minister will give the final speech, and no votes may be called on the debate topic.
This information is provided by Parallel Parliament and does not comprise part of the offical record
Victoria Collins (Harpenden and Berkhamsted) (LD)
It is a pleasure to serve under your chairmanship, Mr Betts. I commend the hon. Member for Bromley and Biggin Hill (Peter Fortune) on securing this essential debate.
Entrepreneurship is in my blood. Both my parents ran their own businesses. My mum launched the website for her business over 15 years ago and was so tech-savvy that she had a larger Twitter following than me—and that is when it was called Twitter. As someone who went on to launch my own tech company and took part in the New Entrepreneurs Foundation, I have met so many fantastic entrepreneurs and I am so pleased that we are debating Government support for UK tech, but, boy, do we need more from the Government.
On one hand, the UK tech sector is an immense success story, and one that we should be proud of, built on the legacy of Ada Lovelace, Alan Turing and Tim Berners-Lee. My hon. Friend the Member for Tunbridge Wells (Mike Martin) mentioned DeepMind. We have the third most valuable tech ecosystem in the world at nearly £1 trillion. On the other hand, the UK tech sector is a story of frustration, stifled potential and a looming threat that great companies and ideas that are incubated here will be sold off because of a ceiling of funding.
I felt that the most powerful way to tell that story today was to amplify the voices of tech leaders themselves. These are the people who are passionate about growing world-class companies here in the UK, but their frustrations are real. It often seems more of a fight to innovate than a celebration of progress. I thank the scores of tech leaders who shared their views with me. Sadly, I cannot get them all in today, but that shows how vital this debate is. I hope that the Government will give this issue more time at some point.
I have five requests, and I ask the Minister to address as many as he can. The first one is “procurement, procurement, procurement”. Even the National Audit Office concluded that the Government’s procurement strategy actively favours large, predominantly foreign suppliers, which was brought up in a debate yesterday. Stephen Kines, the co-founder of Goldilock, an award-winning cyber-hardware company, called for the Government to buy UK products and said,
“Don’t endlessly innovate in ‘innovation theatre’ programmes only”.
I also heard from Doug Monro, the CEO of Adzuna—I am pleased to hear from the hon. Member for Tunbridge Wells that Adzuna was able to get a public contract eventually, after two and a half years. Doug urges the Government to
“buy tech and AI from British startups, not build in-house or buy from massive American companies”.
He shared the powerful message that,
“We can transform public services, cut the welfare bill, and reduce taxes if you’d only let us.”
The Government should be celebrating “made in Britain” by buying “made in Britain”. That is why the Lib Dems have called for a comprehensive public sector technology policy and investment plan and tabled digital sovereign strategy amendments to the cyber Bill. As the hon. Member for Tunbridge Wells mentioned, this is about growth.
My second call is to fix funding fast. The funding desert for scale-ups, that valley of death that we heard about, is well known, but it is worrying how normalised it has become. Ben Rose, the co-founder of Supercede, warns that many tech firms are forced to attract capital from overseas to continue growing at pace—we all know that story, unfortunately. Mark Thomas, the CEO of Appnalysis, notes that the £250,000 limit of the celebrated seed enterprise investment scheme has been eroded by inflation and rising costs to the point that it barely buys 12 months of runway. He asks that the Government look at increasing the limit of the scheme. Leo Rogers, the CEO of Curvo AI, calls for R&D tax credits to be extended to cover compute costs, which in the world of AI are really important. The hon. Member for Weston-super-Mare (Dan Aldridge) mentioned the important issue of financing smaller start-ups, which was mentioned by several entrepreneurs who contacted me. They said that would be helpful to get off the ground and to keep going. Sometimes the funding is there, but the communication of where to find it is not.
That is why the Lib Dems have called for, among other policies, an increase in R&D spending to 3.5% of GDP and better support from the National Wealth Fund and the British Business Bank to de-risk and unlock innovation. We also want a review of IR35, because that is where a lot of the workforce in tech are. The university spin-out support that the hon. Member for Caerphilly (Chris Evans) mentioned is important. The hon. Member for Tunbridge Wells talked about pension funds, and the use of those mega pension funds and where that money can go will be vital to unlocking a lot of innovation in the UK.
My third point is that we must treasure our talent. Great talent helps to grow great companies, not only by upskilling at home but by attracting experts from overseas. There are many calls to align, for example, the innovator founder visa with Innovate UK. Claudia Radu, the CEO of Circe, says that we must make sure that talent visas are easier to get. The hon. Member for Strangford (Jim Shannon) talked about the skills for the next generation, and we must ensure that our talent and workforce planning as a country is aligned with the skills we need for the future. That is why the Lib Dems believe that there needs to be a national people strategy alongside an industrial strategy, because without those skills and that talent, we cannot deliver on economic ambition.
My fourth call is to “think smart regulation”. Tech founders understand the importance of avoiding a race to the bottom, but they are often bogged down in red tape. The App Association warns that tech companies are
“overburdened with regulation, tax, and uncertainty caused by ever-changing rules”.
That is why I increasingly believe in standards and smart, outcome-focused regulation that supports innovation—and the pace it requires—and helps to build trust. The hon. Member for Bromley and Biggin Hill talked about the use of competition, which is a vital aspect of that.
The fifth call, which is also vital, is to lift up small businesses and start-ups—do not forget them. Not only are SMEs and start-ups the backbone of our economy, but all scale-ups started there; several were mentioned today. Karen Atkinson, the CEO of Mediaholix, says,
“I don’t feel that there is any support for small companies. It feels like the government are focusing on the big companies like Meta and Google, which really doesn’t benefit this country in the long run. Quick wins and vanity rather than a true understanding of what it takes and how. Overall the Government are making it exceptionally difficult for small companies to grow.”
Another founder put it more starkly, saying,
“Currently, Parliament has gamified the system against the success of British SME and micro-SME innovators.”
That support in the beginning, whether staff costs or business rates, is something that the Liberal Democrats have raised the alarm on. We call on the Government to do more. Finally, Alex from Synthesia sums it up well. He says,
“Buy software made in the UK, simplify procurement for British start-ups, and keep regulation simple and outcome-focused.”
I have a dream that we will grow our fantastic UK tech landscape. As my Friend the hon. Member for West Dorset (Edward Morello) mentioned, we can solve the biggest problems, such as climate change. We can drive that change, but more than that, we could be the country that takes in scale-ups and does not fear that the companies that incubate here will go elsewhere. Anthropic, for example, may not be welcome in the US; I hope it would be welcomed in the UK. The Government must do more to back British tech for our security, economy and the great people driving innovation in Great Britain and around the globe.
(4 months, 2 weeks ago)
Westminster HallWestminster Hall is an alternative Chamber for MPs to hold debates, named after the adjoining Westminster Hall.
Each debate is chaired by an MP from the Panel of Chairs, rather than the Speaker or Deputy Speaker. A Government Minister will give the final speech, and no votes may be called on the debate topic.
This information is provided by Parallel Parliament and does not comprise part of the offical record
Victoria Collins (Harpenden and Berkhamsted) (LD)
It is a pleasure to serve under your chairship, Ms Vaz. I massively thank the hon. Member for Newcastle upon Tyne Central and West (Dame Chi Onwurah), the Chair of the Science, Innovation and Technology Committee, not only for securing this debate on one of the biggest issues of our time, but for opening it so eloquently and constructively.
We do indeed live in a digital world: our jobs, our banks, our transport and our national security all run on technology. The question of who owns that technology and who controls the data that it generates is not an abstract one; instead, it is the defining question of our time. It is about choice for our Government and for consumers, it is about growth for British tech in a global world, and it is about creating resilience by diversifying risk. A bold strategy on technological sovereignty is how we meet the challenge that we face.
Such a strategy means backing British tech, supporting innovation by British businesses that pay British taxes, strengthening our economy and—crucially—protecting our national economy. As Members from across the House, including the hon. Member, have discussed, such a strategy is also about security. The hon. Member for South Derbyshire (Samantha Niblett) talked about the risks of foreign interference, and the hon. Member for Milton Keynes Central (Emily Darlington) highlighted that Palantir felt it was too big to follow national law. This issue is about our security, so it is vital.
Across the pond, President Donald Trump has demonstrated his willingness to weaponise American power, and especially American technology, to exercise his own political will. Even at home in the US, we see what has happened with Anthropic: he called the people who run it “left wing nut jobs” and directed all Government agencies to stop using it just because the company refused to allow the military unfettered use of its AI tools.
We have also seen that approach with the International Criminal Court. The chief prosecutor of the ICC was personally sanctioned by the Trump Administration, including through the disconnection of his Microsoft email last May. Such episodes expose the reality of the world’s increasing vulnerability. The digital infrastructure underpinning international institutions—and by extension our own public services—increasingly can be disrupted at the discretion of a foreign Government.
Such concerns are shared. In June last year, a study by Civo, a UK provider of sovereign cloud, found that of 1,000 UK-based IT decision makers, 83% were worried about the impact of international developments on their data sovereignty, with the majority considering data sovereignty a strategic priority. Yet even though the hon. Member for Newcastle upon Tyne Central and West highlighted the statistics on the technology used, it seems that that is not a concern of Government.
We directly asked the Secretary of State for Science, Innovation and Technology how dependent our public services are on US-based cloud technology but the answer was that the Government do not know: it is not being measured at a Government level. That is a serious concern. One of the most basic requirements for resilience is knowing what we depend on. I ask the Minister: do we intend to start collecting that data? At this moment, our essential public services may be running at the mercy of Donald Trump and these big tech firms, yet the Government cannot even tell us by how much.
Sovereign technology is not just a matter of national security. As many hon. Members have highlighted in this debate, it is about our economic advantage, growth in this country, improving national standards for technological development, boosting public trust in modern technology, and increasing tax revenues for the UK. Luca Leone, the chief executive officer of Kahootz, wrote for techUK,
“The crucial question is no longer only who builds our platforms, but who owns and operates the systems that underpin our most critical capabilities. This is where digital sovereignty meets supply chain resilience.”
The hon. Member for Southend East and Rochford (Mr Alaba) spoke eloquently about the skills, the businesses, the spin-outs, and the university research that is so strong in the UK. We need to help those things stay here and scale up—scale-up finance was talked about a lot in this debate. We can be that global leader and we should be.
This debate has also highlighted that much of the money set aside for technological investment is not going to UK companies. The National Audit Office concluded that the Government’s procurement strategy actively favours large, predominantly foreign suppliers. The Government have a budget of £14 billion for such investments; where does that money go?
Dan Jones, the defence account manager of 4Secure, wrote for techUK that
“Digital sovereignty…is not just a single procurement decision. It is an ongoing commitment to control, assurance, and resilience”.
Public service contracts go worryingly against that trend. We talked about the contract for Palantir in the NHS, and we talked about Palantir in defence. The hon. Member for Newcastle upon Tyne Central and West eloquently questioned how much the leaders of such tech firms are aligned with British values, and talked about ensuring that the tech we have is aligned with such values. I ask the Minister to explain why Palantir was prioritised over UK tech in the NHS contract, and what work is being done to review our Government processes. This is about not just software but our telecoms infrastructure—the reliance on Starlink is increasingly worrying—and of course our cloud.
I will wrap up by saying that, ultimately, sovereign tech is about power over our everyday lives. Does the Minister agree that now is the time to secure our technology sovereignty? Will he support our new clauses to the Cyber Security and Resilience (Network and Information Systems) Bill about digital sovereignty—
(5 months ago)
Commons Chamber
Kanishka Narayan
The Government are seeing both urgency and responsibility in the correspondence that we are receiving and the consultation we are engaging with, not the desperate lurch to a specific answer that the Liberal Democrats are exemplifying in this instance. I want to take this opportunity to set out our approach.
Victoria Collins (Harpenden and Berkhamsted) (LD)
I say gently to the Minister that if he were to look at the Liberal Democrat’s track record over the past few years, he will see that we have worked really hard to put forward concrete proposals about putting online safety first.
Victoria Collins
No, but we have tried to push that agenda. It is not as if social media came into existence yesterday—Facebook was launched 22 years ago—and the Government brought forward the consultation after pressure from across the House. So I say gently to the Minister that we are trying to work together and that we want to continue to work together in that vein.
Kanishka Narayan
I take the hon. Member’s point about wanting to work together. The Government are committed to doing exactly that. It is not a question of whether we act, but how we implement specific changes to secure our children’s future. I encourage her and the entire Liberal Democrat party to engage with the consultation.
This is a Conservative amendment in the Lords that has gained cross-party support, so it will be coming back to us. The hon. Member raises an important point about why this policy was not brought in under the Online Safety Act. That Act tried to do many, many things. In many ways, it took so long because it risked becoming a Christmas tree Bill, and many good causes were hung off it. That did cause challenges.
I think that as the debate has moved on we have realised that it is not just about illegal content that children are being exposed to and some of the things that the Online Safety Act was trying to change. There is an issue in general about children being in this space: there are addictive algorithms, and it is not just about illegal material but the fact that it is changing how children are thinking about interacting. Maybe we have to stand back as a society and say, “This is simply not the right place for children to be. We can create adult online spaces, but for children we think that there are other ways in which they should be interacting with the world.”
Victoria Collins
You are talking about the Online Safety Act. Do you think the fact that—
Victoria Collins
Apologies. The hon. Member talks about the Online Safety Act and what happened under the Conservatives. Do you think—
Victoria Collins
Apologies. Does she think that the fact that the Leader of the Opposition tried to water down that Bill and said that we do not legislate for feelings has anything to do with the can being kicked down the road and us not having made the necessary progress?
There were very real and important debates during the passage of that Bill about legal but harmful material and whether people should be able to speak freely online. Our approach was to seek to create a space where adults can speak freely while accepting that children should not be in some of these spaces. That was the point that the Leader of the Opposition was trying to make.
We were moving very dangerously into the realms of free speech, and it is not for an online regulator to start telling people what they can and cannot say online when it is not something that is illegal to speak of in the real world. That was the challenge that we got ourselves into as a Government, and that is why we changed parts of the approach that we were taking to the Online Safety Bill. I appreciate the concerns that are being raised, and I am trying to answer them as honestly and straightforwardly as I can.
When we consider the amendment from Lord Nash, this House will have its opportunity to make an unequivocal statement of principle: that when we believe that something is harming children at scale, we accept that it is insufficient to leave the status quo unchallenged or simply to commission a consultation. That applies especially when it is a consultation to which this Government have provided absolutely no political direction or view and that has been much trailed but still not actually launched. In truth, this consultation was not ready. It was a mechanism to get the Prime Minister out of another of his tight fixes.
The Tech Secretary might be very good at emoting and telling us all how impatient she is for change, how she cares, and indeed for how many years she has cared, but when she made her statement on social media for children in this Chamber a few weeks ago, she said nothing about what the Government would actually do, beyond seeking more time to take a position. I commend the hon. Member for Twickenham for pointing that out, and I have sympathy with why she is trying to use this mechanism today, because we are all trying to tease out what the Government are seeking to do.
It was extraordinary to listen to the Government Minister, who said with great sincerity, “We will act robustly in responding to a consultation.” What does he actually believe? What do the Government think we should do on this issue? Nobody has a clue. They are talking about a huge range of things that could be done, but it is for a Government to provide political direction; it is not for a Government to seek consensus. [Interruption.] It is for a Government to take a position and to take a view. It is for a Government to have opinions. It is for a Government to have policy positions. It is not for a Government to try to make sure that everybody in this House agrees. [Interruption.] It is pathetic to see those on the Labour Benches getting out of their tree about this.
Victoria Collins (Harpenden and Berkhamsted) (LD)
I have been quite shocked at some of the procedural discussion for several reasons. First, we are acting like this has just come up, but even in the House of Commons under this mandate, as my hon. Friend the Member for South Devon (Caroline Voaden) mentioned, the safer phones Bill was put forward in 2024. As Liberal Democrats, we put forward amendments to change the age of data consent to ban addictive algorithms. There have also been calls to act on doomscroll caps, and we have highlighted the harms of AI chatbots. Yet we are at a point—I absolutely respect what the hon. Member for Aberdeen North (Kirsty Blackman) was saying on this—where a consultation was proposed by the Government over a month ago, but we still do not know the details. There are things going through the House of Lords that, again, we do not know the details of. At the very least, Liberal Democrats are trying to give the space for that and say, “Yes, we need to start putting forward that legislation.” If there is another chance to debate that, what is the harm in this motion because this is such a crucial issue?
Secondly, it is not as if this is an issue that turned up yesterday. As the hon. Member for Newcastle upon Tyne Central and West (Dame Chi Onwurah) talked about, these harms have been happening for years—over 22 years for Facebook. I will go on to say more about that in a moment. Other countries around the world are showing leadership on this and saying that we have to act now. My point is that at the very least, a consultation could have been launched earlier. This is not something new in this Parliament. We are saying that action needs to be taken.
Most importantly, the parents, children and experts watching this debate want to see us taking this issue seriously. Children and young people are at the heart of this. I think back to the first time I met some of the sixth-form students at Ashlyns school in Berkhamsted. I will never forget sitting around that table with one sixth-former—let’s call him James. He told me about his fears for the mental health of his friends. He warned about the self-harm that he was seeing among his peers, which his teachers were not even aware of, and he talked about the role of social media. A few weeks later, I was pulled to one side at St George’s school in Harpenden, where some young women shared with me their concerns about the growing misogyny lived out by young men, which started on social media.
Since then, I have carried out a “Safer Screens” tour meeting young people. Students have talked about brain rot and seeing the extreme content that the algorithm continues to push on them, even when they try to block it—the hon. Member for North West Cambridgeshire (Sam Carling) talked about that. One student said, “It is as addictive as a drug”, and they see the harms of it every day.
This is the tipping point, and I am surprised that many Members think that it is not. This is that moment. Parents, teachers, experts and even young people are crying out for action, and have been for a long time, to tackle the social media giants that have no care for their mental health. As I said, this tipping point has been years in the making. Facebook was launched 22 years ago. Indeed, a Netflix documentary from six years ago started to highlight the warnings from people who worked in tech about social media. One expert said that it is
“using your own psychology against you.”
Having worked in tech myself, I have read the books and received the training on how these social media giants get us hooked—it is built in.
Awareness is growing. I thank Smartphone Free Childhood, Health Professionals for Safer Screens, the Molly Rose Foundation, the Internet Watch Foundation and the Online Safety Act Network, along with projects such as Digital Nutrition—the hon. Member for Milton Keynes Central (Emily Darlington) and others have made the analogy of an online diet—that have worked to ask what the guidance should be. Those are just a few of the organisations I could name that have worked tirelessly to ensure these voices are heard.
I also thank pupils in my constituency from Roundwood Park, St George’s, Sir John Lawes, Berkhamsted and Ashlyns schools, and students who have openly shared their experiences, hopes and concerns about the online world. Their concerns are not just about content; they are also about addiction. Let me be clear: as my hon. Friend the Member for Mid Dunbartonshire (Susan Murray) mentioned, the core of this issue is that this is the attention economy, so our children are the product. Their attention, focus and time are being sold to line the pockets of tech billionaires. Governments around the world are taking finally action. This is a seatbelt moment where we need to say, “Enough is enough.”
The hon. Member for Stoke-on-Trent Central (Gareth Snell) talked about trying to get this right. I respect that, but I often think that if we were able to walk down the street and see a 3D version of what young people are seeing in their online world, action would have been taken much sooner. My hon. Friend the Member for Eastleigh (Liz Jarvis) talked about holding tech companies to account. We need to start unpacking what children are seeing and finally take action.
The Online Safety Act has done great work, but it does not go far enough. It sets out illegal harms and a code for inappropriate content for children and over-18s, but not a framework of legal harms or age-appropriate content. The social media age of 13 is based on data processing that is managed by the Information Commissioner’s Office and has nothing to do with what is age-appropriate in that context. Dr Kaitlyn Regehr, the author of “Smartphone Nation”, talks about how the Act is reactive, not proactive, and leaves it up to the user to report problems rather than putting the burden of safety on tech giants.
We must ensure that we build on the OSA and learn the lessons from Australia. The hon. Member for Milton Keynes Central talked about this. In Australia, a wide definition of social media has left it to a small group to decide what is appropriate. That has meant that YouTube has been banned for under-16s, but YouTube Kids has not, with no real framework for why apart from the fact that they deem YouTube Kids safer. WhatsApp has not been banned, which is possibly the right thing, but legislators are left to play whack-a-mole as new social media apps pop up. There is no framework for harm from AI.
Australia just bans children from holding accounts; it does not ban them from using any of the platforms. They can still use YouTube; they just cannot have an account.
Victoria Collins
Absolutely. YouTube is everywhere. It is embedded in almost every website that has videos.
The hon. Member for Aberdeen North (Kirsty Blackman) asked about AI chatbots. In the proposals we put forward in the Lords, the user-to-user services are the AI chatbots. We have highlighted for a long time that potential harms from AI chatbots are not covered. That is absolutely the case, but Ofcom has clarified that AI chatbots are the user-to-user service. The harms, such as AI psychosis, which my hon. Friend the Member for Winchester (Dr Chambers) alluded to, are not covered. That is why the harms-based approach we are putting forward is so important.
As my hon. Friend the Member for Twickenham (Munira Wilson) said when she opened the debate, the Liberal Democrats have been leading the work on online safety in this Parliament. We were the first party to push a vote on banning addictive algorithms. We have called for health warnings and a doomscroll cap. Today, we are calling for a vote on the age for social media and online harms. We are calling for a ban on harmful social media based on a film-style age rating. That harms-based approach holds tech companies to account, sets a pioneering approach to online standards and prepares for the future of AI chatbots and games like Roblox, which has already arrived.
In the offline world, anyone buying a toy for young children at this point would expect age ratings so that they know it is appropriate and safe, and films have had age ratings for over 100 years, yet we have not had that in the online world. The harms-based approach is backed by 42 charities and experts who work to protect children, stop violence against women and girls and make the internet a safer place.
We are also calling for a reset, because enough is enough. That includes a minimum age of 16 for social media and real accountability for tech companies with film-style age ratings. We need to make sure that we get the best out of the internet for young people and protect them from harms.
For me, it comes back to James, his friends and the young women and children I have spoken to around my constituency. We do not have time to waste—that is why we are pushing for these Bills. We are calling for action, and I call on MPs across the House to put children before politics, exactly as we did in the Lords. The amendment in the Lords could mean a blanket ban. We were uncomfortable with that approach—we much prefer ours—but we knew that the future of children came first. We must help the next generation to get the best of the online world—including those young people who have spoken out and shared their concerns and horror stories—and protect them from the worst of it.
(6 months, 1 week ago)
Commons Chamber
Victoria Collins (Harpenden and Berkhamsted) (LD)
Last year, I carried out a “safer screens” tour in my constituency, hearing directly from young people, because the Liberal Democrats consider children and young people to be at the heart of this issue. Teenagers shared concerns about extreme content pushed by algorithms, but also about being glued to their screens alongside their younger siblings. One said, “It’s as addictive as a drug, and I feel the negative impacts every day.” Another pleaded, “Help—I just can’t stop.” Last week, more than 1,700 parents emailed me calling for a social media ban. One mother said that the social media used by her two boys “fills me with dread.” Another highlighted the way in which
“anxiety, reduced attention, online bullying, and exposure to harmful content are becoming common topics among families.”
Parents, teachers, experts and young people themselves are crying out for action, which is why the Liberal Democrats have long raised this as a public health issue. We pushed for the digital age of data consent to be raised to 16, and for the tackling of addictive algorithms. We voted to ban phones in schools, and called for health warnings. Now the Liberal Democrats have tabled an amendment in the other place to ban harmful social media for under-16s, based on film-style age ratings extending to 18. We would reset the default age for social media to 16 now, with strong age assurance, because enough is enough.
This world-pioneering approach brings age-appropriate standards to online safety. We are learning from Australia, and preparing for today’s reality. Our risk-based approach, supported by more than 40 charities and experts including the NSPCC, the Molly Rose Foundation and the Internet Watch Foundation, will stop new platforms slipping through the net while addressing harmful games and AI chatbots, and protecting educational sites such Wikipedia and safe family connections. Crucially, it does not let social media companies off the hook.
We have had age-appropriate safety standards offline, for toys and films, for decades. After 20 years of social media platforms clearly prioritising profit over children, building addictive algorithms that keep children and adults hooked, it is time to take action. We do not need consultation—we need that action now—but at least in this consultation we must look into how, not if, we will implement a ban on harmful social media for under-16s. I urge the Government to consider such a ban, with swift timelines, to address this growing public health crisis, and to act on our proposals now. Our children’s future is not something to be played with.
The hon. Lady explains very well the views of children, young people and parents who are grappling with these issues. I disagree with her: I think we need a short, sharp consultation because there are different views, but we definitely want to act. I am very interested in the idea of age classification, and I would be more than happy to talk to her about that. We all see how this issue affects our own children, and we need to help them cope at different ages. I am sure that many hon. Members will raise different options, and I am more than happy to discuss those with them.
(6 months, 2 weeks ago)
Commons Chamber
Victoria Collins (Harpenden and Berkhamsted) (LD)
For over a week, Grok has generated illegal sexual abuse material—non-consensual images of women and children—without restraint on X, which took the disgraceful step of putting it behind a paywall. That is abhorrent, and those images are illegal. Unlike the Conservatives, we very much welcome the action being taken and absolutely want to work together to stop this illegal, abhorrent use of AI technology. That is why the Liberal Democrats have called on the National Crime Agency to launch a criminal investigation into X and for Ofcom to restrict access immediately. We also called for Reform MPs to donate their earnings from X to those charities working for those victims of sexual exploitation.
Where there are loopholes around AI creation of these horrific images, we are pleased to hear the Secretary of State announce the establishment of a criminal offence to create, or seek to create, such horrific content and the work to criminalise nudification apps. Regulatory gaps, however, are not the only problem; enforcement is failing, too. While other countries have acted decisively to ban X, Ofcom has taken over a week to start an investigation and lacks the resources to take on these tech giants. What has become clear is that with the pace of technology, the Government must look to future-proof online safety from new harms and harmful features.
The Liberal Democrats have long been raising the alarm. We tabled amendments to raise the age of data consent, proposed a doomscroll cap to curb addiction and called for public health warnings on social media. Protecting women and children from online abuse cannot wait, so will the Government support our calls on these actions? This matters in real life—to my constituent who was harmed by strangulation in a nightclub following online videos, and to the victims of sexual abuse and violence, which often starts online. Given the pace of change, does the Secretary of State have full faith in Ofcom’s ability to enforce the Online Safety Act? Will she meet me because, unlike the Conservatives, I would like us to work together on this important issue and discuss the action needed on AI chatbots and emerging technologies?
This is a moment for the House to act together. Inaction sends the message that abuse online is acceptable, and we must prove otherwise.
I thank the hon. Lady for her questions. I think I have said to the House before that patience is not my greatest virtue, but that is because the public and, most importantly, victims want to see this happen quickly. I said in my statement that I expect—because the public expects—Ofcom to do this swiftly. We do not want to wait months and months for action. I am of course happy, as is the Online Safety Minister, to meet her to discuss further steps. There are clear responsibilities here in terms of enforcement of the law on individuals and their behaviour, but the Online Safety Act, which I know her party voted for, does place some of those requirements on Ofcom. We have to see action, and I am sure that that message will be heard loud and clear today.
(7 months, 2 weeks ago)
Westminster HallWestminster Hall is an alternative Chamber for MPs to hold debates, named after the adjoining Westminster Hall.
Each debate is chaired by an MP from the Panel of Chairs, rather than the Speaker or Deputy Speaker. A Government Minister will give the final speech, and no votes may be called on the debate topic.
This information is provided by Parallel Parliament and does not comprise part of the offical record
Victoria Collins (Harpenden and Berkhamsted) (LD)
It is a pleasure to serve under your chairmanship, Ms Butler. I congratulate the hon. Member for Dewsbury and Batley (Iqbal Mohamed) on securing this incredible debate. That so many issues have been packed into 90 minutes shows clearly that we need more time to debate this subject, and I think it comes down to the Government to say that an AI Bill, or further discussions, are clearly needed. The issue now pervades our lives, for the better but in many aspects for the worse.
As the Liberal Democrat spokesperson on science, innovation and technology, I am very excited about the positive implications of AI. It can clearly help grow our economy, solve the big problems and help us improve our productivity. However, it is clear from the debate that it comes with many risks that have nothing to do with growing our economy—certainly not the kind of economy we want to grow—including the use of generative AI for child sexual abuse material, children’s growing emotional dependency on chatbots, and the provision of suicide advice.
I have said for a long time the trust element is so important. It is two sides of the same coin: if we cannot trust this technology then we cannot develop as a society, but it is also really important for business and our economy. I find it fascinating that so many more businesses are now talking about this and saying, “If we can’t trust this technology, we can’t use it, we can’t spend money on it and we can’t adopt it.” Trust is essential.
If the UK acts fast and gets this right, we have a unique opportunity to be the leader on this. From talking to industry, I know that we have incredible talent and are great at innovating, but we also have a fantastic system for building trust. We need to take that opportunity. It is the right thing to do, and I believe we are the only country in the world that can really do it, but we have to act now.
Sarah Russell
Does the hon. Lady agree that we should be looking hard at the EU’s regulation in this area, and considering alignment and whether there might be points on which we would like to go further?
Victoria Collins
Absolutely, and the point about global co-operation has been made clearly across the Chamber today. The hon. Member for Leicester South (Shockat Adam) talked about what is now the AI Security Institute—it was the AI Safety Institute—and that point about leading and trust is really important. Indeed, I want to talk a little more about safety, because security and safety are slightly different. I see safety as consumer facing, but security is so important. Renaming the AI Safety Institute as the AI Security Institute, as the hon. Member mentioned, undermines the importance of both.
The first point is about AI psychosis and chatbots—this has been covered a lot today, and it is incredibly worrying. My understanding is that the problem of emotional dependency on AI chatbots is not covered by the Online Safety Act. Yes, elements of chatbots are covered—search functionality and user to user, for example—but Ofcom itself has said that there are certain harms from AI chatbots, which we can talk about, that are not covered. We have heard that 1.2 million users a week are talking to ChatGPT about suicide—we heard the example of Adam, who took his own life in the US after talking to a chatbot—and two thirds of 23 to 34-year-olds are turning to chatbots for their mental health. These are real harms.
Of course, the misinformation that is coming through chatbots also has to be looked at seriously. The hon. Member for York Outer (Mr Charters) mentioned the facts and the advice coming through. We can achieve powerful outcomes, but we need to make sure that chatbots are built in a way that ensures that advisory element, perhaps by linking with NHS or other proper advice.
The hon. Member for Milton Keynes Central (Emily Darlington), who has been very passionate about this issue, mentioned the Molly Rose Foundation, which is doing incredible work to show the harms coming through this black hole—many do not see the harms, which have an impact on children that parents do not understand, as well as on adults.
The harm of deepfakes, including horrific CSAM and sexual material of all ages, has also been mentioned, and it is also impacting our economy. Just recently, a deepfake was unfortunately made of the hon. Member for Mid Norfolk (George Freeman). The Sky journalist Yalda Hakim was also the victim of a deepfake. She mentioned her worry that it was shared thousands of times, but also picked up by media in the subcontinent. These things are coming through, and no one who watches them can tell the difference. It is extremely worrying.
As the hon. Member for Congleton (Sarah Russell) said, “Rubbish in, rubbish out.” What is worrying is that, as the Internet Watch Foundation has said, because a lot of the rubbish going in is online sexual content that has been scraped, that is what is coming out.
Then there is AI slop, as the right hon. Member for Oxford East (Anneliese Dodds) mentioned. Some of that is extreme content, but what worries me is that, as many may know, our internet is now full of AI slop—images, stories and videos—where users just cannot tell the difference. I do not know about others, but I often look at something and think, “Ah, that’s really cute. Oh no—that is not real.” What is really insidious is that this is breaking down trust. We cannot tell any more what is real and what is not, and that affects trust in our institutions, our news and our democracy. What we say here today can be changed. Small changes are breaking down trust, and it is really important that that stops. What is the Minister doing about AI labelling and watermarking, to make sure we can trust what we see? That is just one small part of it.
The other thing, which my hon. Friend the Member for Newton Abbot (Martin Wrigley) mentioned, is that often AI threats magnify what is already a threat, whether it is online fraud or a security threat. I believe that AI scams in just the first three months of this year cost Brits £1 billion. One third of UK businesses said in the first quarter they had been victims of AI fraud. And I have not got on to what the hon. Member for Dewsbury and Batley said about moving towards AI in security and defence, and superintelligence. What are the “exaggerated” threats that actually will become extremely threatening? What are the Government doing to clamp down on these threats, and what are they doing on AI fraud and online safety?
Another issue is global working. One of the Liberal Democrats’ calls is for an AI safety agency, which could be headquartered in the UK; we could take the lead on it. I think that is in line with what the hon. Member for Dewsbury and Batley was talking about. We have this opportunity; we need to take it seriously, and we could be a leader on that.
I will close by reiterating the incredible work that AI could do. We all know that it could solve the biggest problems of tomorrow, and it could improve our wellbeing and productivity, but the threats and risks are there. We have to manage them now, and make sure that trust is built on both sides.
Mr Adnan Hussain (Blackburn) (Ind)
I just want to reaffirm what the hon. Member has said. Does she agree that innovation and safety are not opposites? This is reminding me of when Google and online banking first came in. We need clear rules so that we can increase public trust and not stifle technology.
Victoria Collins
Absolutely. What is interesting about innovation is that it often thrives with constraints. As I have said, safety is about trust, which is good for business and our economy, and not just for our society.
When will the AI Bill come to Parliament? We really need it; we need to discuss these things. What are the Government doing to reassess the Online Safety Act? Beyond that, in determining how we react to this rapid shift in technology, will they consider the Lib Dems’ call for a digital Bill of Rights to make sure that standards are set and can adapt to that? What are the Government doing about international co-operation on safety and security? As the hon. Member for Blackburn (Mr Hussain) mentioned, we can—we must—have innovation and safety, and safety by design. We can choose both, but only if we act now.
(8 months, 1 week ago)
General Committees
Victoria Collins (Harpenden and Berkhamsted) (LD)
It is a pleasure to serve under your chairmanship, Mr Vickers. The Liberal Democrats support this statutory instrument, which updates the Online Safety Act’s priority offences to reflect changes in intimate image abuse law. It is absolutely right to tackle the non-consensual sharing of intimate photographs and films, and to tackle self-harm.
However, this is also an important opportunity to say that the Act must go further still. The Internet Watch Foundation reminds us that it is not currently illegal to retain, re-upload or trade abusive intimate image material long after initial distribution. The Molly Rose Foundation and Samaritans have raised the issue of self-harm, and I am pleased to hear that being addressed today, but the point about AI chatbots is really important. As I mentioned in DSIT questions, the legislation on user to user and search seems pretty clear, but what about one-to-one chatbots when there is a single user? It is not clear who is accountable when self-harm content comes through chatbots that are not user to user. I appreciate that the Minister said the Department is looking into that issue with Ofcom.
The Act must also go further to address emerging online threats. The Internet Watch Foundation also reports that intimate images online are increasingly generated by deepfake AI, and that expert analysis now struggles to distinguish AI-generated content from real images or videos. At the beginning of this year alone, the IWF found 1,200 photorealistic videos of child sexual abuse material online. The Online Safety Act must do more to hold big tech companies to account, and to protect users from intimate image abuse at source, both real and AI-generated. Importantly, it must also tackle self-harm that is linked to AI chatbots, which are increasingly used by people of all ages.
Although this statutory instrument is a step forward, we need regulation that keeps pace with the rapidly evolving technology, not just changes in statute. We must ensure that Ofcom is sufficiently equipped and resourced to deal with emerging technologies. Will the Minister confirm what assessment has been done of the adequacy of Ofcom’s resourcing to ensure that this statutory instrument and the Online Safety Act can be applied and enforced in this fast-moving environment? When can we expect updates on AI chatbots and the scope of regulation? Will the Minister also confirm what the Government are doing to effectively regulate deepfake intimate content? What steps are being taken to hold tech companies to account for the continued harm facing children, vulnerable people and, given that experts can no longer differentiate between deepfake and real images, all internet users?
(8 months, 3 weeks ago)
General Committees
Victoria Collins (Harpenden and Berkhamsted) (LD)
It is a pleasure to serve under your chairmanship, Dr Murrison. The Liberal Democrats support the statutory instrument, as it will simplify market access for manufacturers, reduce duplication in testing and certification, and facilitate UK exporters’ entry into Japan and Singapore for smart connected consumer products. It demonstrates the important principle that cutting red tape is vital to promoting economic growth and reducing compliance costs for businesses—which is why the Liberal Democrats, alongside many businesses, are also calling for a customs union with the EU. That would similarly break down the bureaucracy holding British businesses back and boost our economy.
We must, however, ensure that safeguards remain. Given the critical importance of maintaining robust cyber-security protections, can the Minister confirm what oversight mechanisms are in place to monitor ongoing alignment with these international schemes, and how these measures will be integrated into the long-awaited cyber-security and resilience Bill, which will be vital in keeping our economy safe?