Breaking
Tech NewsDeveloping Story

UK AI cyber rules skip vendors

UK rejects extending cyber bill to AI vendors, citing misuse concerns and preferring voluntary safeguards.

··2 hours ago·4 min read
multicolored lighted building
Photo by Luca Campioni on Unsplash

The UK government has pushed back against efforts to bring AI vendors and frontier model developers under the scope of its proposed Cyber Security and Resilience (Network and Information Systems) Bill, arguing that such regulation would do little to stop malicious actors from abusing their products. The decision, which surfaced during a House of Lords committee session, sets the stage for a potential clash between those who see hard legal duties as essential and those who prefer voluntary safeguards.

Minister rejects vendor regulation

Cybersecurity minister Baroness Lloyd of Effra told the Grand Committee that regulating the companies building AI services, particularly those at the cutting edge of frontier development, would not address the core harms. She argued that including these providers in the bill would not prevent hostile actors from misusing their tools.

Instead, Lloyd pointed to what she called “firm action” through other routes, including support for the AI Security Institute (AISI), which tests models with vendors before release. She also cited the voluntary AI Cyber Security Code of Practice, which informed the first global AI cybersecurity standard, ETSI EN 304 223.

“This demonstrates our global leadership and commitment to shaping international technical standards which go wider than some of the issues raised in this bill,” she claimed.

— Baroness Lloyd of Effra, Cybersecurity minister

Peers push for accountability

Members of the House of Lords offered a range of arguments for bringing AI within the bill’s remit. They cited reports of rogue agentic behavior involving Anthropic and OpenAI, as well as Bill Gates’ concerns that commercial incentives are pushing AI development forward without adequate safeguards.

Lawmakers also questioned whether companies unable to prevent their agents from misbehaving should be trusted to follow voluntary ethical guidelines they can rewrite at will. Baroness Kidron, a Crossbench peer and campaigner for online safety, posed a pointed question about the wisdom of letting tech companies set their own rules.

“Have we not learned from countless experiences before in online safety, privacy, and in AI itself that allowing tech companies to set and mark their own homework endangers the public and our national security?” she asked.

Clash over healthcare and AI attacks

Kidron and Lloyd clashed after the minister used a hypothetical healthcare organization to illustrate how the bill would require regulated bodies to secure systems containing AI. Kidron pressed the point, asking whether the NHS must protect itself while the AI attacking it has no duties under the bill.

Lloyd responded that the bill is designed to be technology-agnostic, imposing stricter cybersecurity requirements on key organizations rather than regulating individual technology providers. She acknowledged the government’s willingness to continue discussions on AI, with Kidron predicting the issue would return later in the bill’s passage.

Rejected amendments and red lines

The minister also dismissed several other amendments, including one that would require certain AI vendors to prove their products could not cross specified red lines, such as evading human oversight or assisting with chemical weapons development. Another proposal would have given the Secretary of State last-resort powers to order the shutdown of a datacenter or widely deployed AI system during an emergency.

Lloyd explained that the bill would instead allow the government to direct regulated entities, such as datacenter operators, to stop using specific AI models when they present a qualifying risk. A power station, for instance, could be ordered to cease using a particular AI model.

“We believe this is a more proportionate and effective response, as datacenters operate in highly complex ecosystems and AI systems are often distributed across different datacenters and jurisdictions,” said Baroness Lloyd. “It's much less desirable to direct multiple datacenters to shut down, and the impact this could have on services that rely on them, than to direct them to cease using an AI model.”

Bill's background and fines

The CSR Bill was first proposed in the 2024 King's Speech and introduced in Parliament in November 2025. It initially proposed daily fines of up to £100,000 for in-scope organizations that failed to protect against specific threats.

The legislation builds on existing categories of operators of essential services and relevant digital service providers, extending the regime to managed service providers, datacenter operators, and designated critical suppliers. Managed service providers were previously slated for inclusion via the abandoned 2022 update to NIS regulations.

The bill aims to update the NIS 2018 regulations and future-proof the UK’s critical infrastructure from cyber threats.

Continued scrutiny and criticism

This week’s Grand Committee review is not the first time the bill has faced criticism. In January, shadow deputy PM Sir Oliver Dowden called on the government to rethink its exclusion of local and central government from the CSR bill.

The UK’s Government Cyber Action Plan, launched hours before the former digital secretary’s remarks, promised to hold government to the same standards proposed in the CSR Bill. Like the AI Cyber Security Code of Practice, the action plan lacks any legal obligations.

The Grand Committee is scheduled to resume discussions of the CSR Bill when it reconvenes on Thursday.

For organizations relying on AI and datacenter services, the practical effect of this decision is that they remain responsible for securing their own systems, even as the AI tools they use are not directly regulated under the bill. This could mean that businesses must navigate a patchwork of voluntary codes and indirect obligations, potentially leaving gaps in accountability if AI vendors are not compelled to meet baseline security standards.

#uk cyber bill#ai regulation#cybersecurity#nis#house of lords

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories