Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Science, Innovation & Technology

Cyber Security and Resilience (Network and Information Systems) Bill

Viscount Colville of Culross Excerpts
Viscount Colville of Culross Portrait Viscount Colville of Culross (CB)
- View Speech - Hansard - -

My Lords, I, too, welcome much of the Bill. It could not be more important in a world in which warfare is not just physical but digital. It is essential as part of our national security that our Government step in to protect us from such attacks.

Most noble Lords, I think, welcome the list of bodies to be regulated in Part 2. I am very glad that data centres, large load controllers and specified management services have been brought within the scope of the Bill. After all, the Government celebrated the huge investments of AWS and DC01UK in data centres. It is important that they are now covered by the Bill as an essential part of our national security.

There has obviously been an attempt to future-proof the Bill against the fast-changing world of tech. At the beginning of Part 3, Clause 24 gives the Secretary of State enormous and flexible powers to designate what is essential activity for the economy of the United Kingdom and the day-to-day functioning of society. This flexibility is then reinforced in Clause 43 in Part 4, which gives powers to issue directions to regulated persons and to decide what should be reported and to whom it should be reported.

My fear is that the Bill does not go far enough to address the present threats, let alone the future ones. Noble Lord after noble Lord has raised concerns about the failure to mention AI in the Bill at all. I, too, was at the terrifying meeting mentioned by my noble friend Lady Kidron, which was held earlier this month, by the Institute for AI Policy and Strategy and the Centre for Long-Term Resilience. They guided us through the world of software vulnerabilities and patches. In the arms race that is the search for software vulnerabilities, it is a fight between the attacker and the defender to find the flaw first. Even then, the rollout of patches to downstream defenders can be slow and leave them open to further attacks.

Having absorbed these concerns, we were then told about automated AI attacks, in which an automated AI agent can carry out all the steps of a cyber attack on its own as an autonomous operator. AI agents no longer need skilled labour to develop an attack—expertise can be rented from AI systems—and the attacks can vary in their approach and learn from each failure so that initial defences can be breached once again.

The AI Security Institute found that, between December 2005 and December 2006, a single hacker weaponised the Claude and GPT-4.1 systems to bypass safety guardrails and develop 400 attack scripts. The breach exposed the personal data of 195 million citizens in Mexico, including their tax and electoral registers. At the very least, if data centres can be added in at a later stage in the shaping of the Bill, frontier AI models operating in this country can and should be added in as well. They need to be protected from attack by foreign agents and rivals.

I am aware that, as Ministers have often said, regulation can be an obstacle to new start-ups. If that is the case, there needs to be a threshold on the size of the frontier AI models that would need to abide by the demands of the Bill. There also needs to be in the Bill a new clause in which AI frontier providers are designated as essential models.

The noble Baroness, Lady Harding, was right: I am going to repeat what other noble Lords have said. The Bill leaves lacunae over large sectors of the economy, which I am sure most noble Lords regard as essential services. The Bill must include critical manufacturing and retail, both of which suffered devastating cyber attacks in the past few months. Many noble Lords have mentioned the huge attack on Marks & Spencer. Noble Lords only have to imagine the effect on the country if there were successful attacks on one or two of our big supermarket chains. The result would throw the national food supply chain into crisis. Surely supermarkets, which provide much of our nation’s food and other services, need to be considered very carefully for coming within the scope of the Bill.

I understand that, unlike the finance, telecom and digital sectors, the manufacturing and retail sectors do not have a regulator. Nevertheless, Clause 24 allows for flexibility in this space, so I support the calls from the noble Lord, Lord Birt, and the noble Baroness, Lady Harding, for a cross-sectoral regulator. Perhaps the Government need to set up a second tier of essential service sectors that should be preparing to be brought within the scope of the Bill. In the longer term, it might be important to ensure that they are building the highest resilience to AI-powered cyber attacks.

This work must further strengthen resilience at board level. It cannot be left to AI departments to work out resilience on their own. I suggest that the Minister makes further changes to the UK Corporate Governance Code straightaway so that more responsibility for reporting incidents is taken at board level. The Minister is in a unique position to do this, being the Digital Economy Minister and having previously been in the DBT.

My other area of concern about the Bill is the importance of co-ordinating the reporting of cyber attacks, especially AI cyber attacks, to build cyber resilience. There should be an extensive list of sectors that are brought into scope, as the EU legislation has suggested. It is terrifying that so many of the automated AI attacks are what the industry calls “misalignments”, meaning that their outcome is not what the original design of the model had intended. Not only do they create outcomes that were not the original intention of the creators of the model but those creators do not even know that these misalignments have taken place.

I know that the Government have created the Cyber Resilience Pledge for our FTSE 350 companies, which means that they will sign up to the NCSC’s early cyber attack alerts and recommend a Cyber Essentials suppliers kit. The Government have put aside £90 million for resilience centres to give advice against attacks on SMEs. However, these all depend on voluntary responses by the affected companies. The Government need to mandate a reporting requirement so that effective defences can be rolled out across the economy.

I understand the flexibility on reporting given by Clause 43, but this country is confronted with the prospect of automated AI attacks. It is essential that the widest range of reporting of these attacks is included in the Bill. There must also be a mechanism for mandating the co-ordination of reporting these attacks. The Government must ensure that information about the attacks is brought together and that advice is co-ordinated on how to build a defence against those attacks. The information is crucial for AI frontier model companies to know that their agents are creating misalignments and for downstream companies affected by the attacks to build secure defences. The essential reporting on attacks needs to be brought together by the NCSC or the AISI. The Bill then must ensure that there is a cross-cutting regulator in the longer term.

The Bill recognises that we live in an ever more dangerous digital world. The introduction of autonomous AI into the digital world will affect us all and could do so to a disastrous degree. I call on the Government to ensure that AI is in the Bill, both in the sectors in scope and in the reporting requirements for these and other sectors. Failure to do so will open our country to attacks which will devastate our economy and our society for years to come.