Skip to main content
Cybersecurity

UK Tightens Cyber Bill Focus on Users, Not AI Vendors

British government minister addresses meeting on cybersecurity regulations at podium.

"Bringing providers of AI services, those companies which are at the cutting edge of frontier AI development and their products, into the scope… would not address the harms that can be posed by some AI products and services, or specifically, it would not prevent their misuse by hostile actors," said Baroness Lloyd of Effra.

Baroness Lloyd of Effra: exclude vendors, focus on users and operational controls

At Grand Committee scrutiny on Tuesday, the cybersecurity minister argued the Cyber Security and Resilience (Network and Information Systems) Bill (the CSR Bill) should not be used to regulate AI vendors or frontier model developers. Lloyd said the government will take "firm action" through other channels instead — notably supporting the AI Security Institute (AISI), which works with vendors to test models before release, and promoting the voluntary AI Cyber Security Code of Practice. She pointed to the Code's role in informing ETSI EN 304 223 as evidence of the UK's contribution to international technical standards.

House of Lords peers: evidence and ethical doubts about voluntary controls

Peers on the crossbenches and elsewhere pushed back. Baroness Kidron cited concerns that companies can "set and mark their own homework," asking whether lessons from online safety and privacy mean voluntary guidance is inadequate for public safety and national security. Lord Tarassenko drew attention to an open letter penned by OpenAI warning of a near-future rise in AI-orchestrated cyberattacks. Peers also referenced reported rogue agentic behaviour involving Anthropic and OpenAI and Bill Gates' warning about commercial incentives outpacing safeguards as reasons to press for vendor obligations under the Bill.

Amendments rejected: red lines, emergency shutdown powers, and their alternatives

The minister rejected several Lord amendments. One would have required certain AI vendors to demonstrate their products could not cross specific red lines — for example, evading human oversight or assisting with chemical weapons development. Another sought to grant the Secretary of State last-resort powers to order the shutdown of a datacenter or a widely deployed AI system during a security or operational emergency; that proposal was dismissed. Instead, Lloyd described a model in which the government could direct regulated entities — including datacenter operators but not AI vendors — to take or cease specified actions when their systems presented a qualifying risk. She used the hypothetical of a power station being instructed to stop using a particular AI model to illustrate that directing users may be a more proportionate and practicable response than ordering multiple datacenters to shut down, given the distributed nature of AI systems across datacenters and jurisdictions.

What the CSR Bill currently covers: operators, datacentres, and the bill's lineage

The CSR Bill was first proposed in the 2024 King's Speech and introduced in Parliament in November 2025. It aims to update the NIS 2018 regulations and to "future-proof" critical infrastructure. The bill extends the regime beyond existing operators of essential services and relevant digital service providers to include managed service providers, datacenter operators, and designated critical suppliers. The legislation attracted attention for a previously reported proposal to impose £100,000 daily fines on in‑scope organisations that failed to protect against specified threats. Managed service providers were set to be brought into scope under a 2022 update to the NIS regulations that was abandoned; the CSR Bill seeks to capture similar categories via primary legislation.

Critics have previously urged changes: in January, the shadow deputy prime minister Sir Oliver Dowden called on the government to rethink excluding local and central government from the CSR Bill. The government's own Government Cyber Action Plan, launched hours before Dowden's remarks, promised to hold government to the same standards proposed in the Bill — but, like the AI Cyber Security Code of Practice, that action plan has no legal obligations.

What this means for technologists, policymakers, and the NHS

  • Technologists and security teams: will watch AISI-led pre-release testing and the voluntary AI Cyber Security Code closely, but the Bill does not place statutory duties on AI vendors, leaving vendors' controls and voluntary standards as the main levers cited by the minister.
  • Policymakers and regulators: will rely on the Bill's ability to direct regulated entities (for example, datacenter operators and managed service providers) to take or cease using specific models during qualifying risks, rather than exercising shutdown powers over vendors or multiple datacenters.
  • Healthcare providers and other regulated organisations (illustrated by the NHS example): will remain subject to stricter cybersecurity duties under the Bill to secure systems that contain AI, even though the AI models themselves would not be directly regulated under this legislation.

The Grand Committee is due to reconvene on Thursday to continue scrutiny. The government says it is willing to continue discussing AI regulation, but for now the CSR Bill deliberately targets users and critical infrastructure operators rather than the vendors and frontier model developers whose products peers argue can misbehave. The practical test now is whether a mix of statutory duties on users, voluntary vendor testing through AISI, and international standards such as ETSI EN 304 223 will be sufficient to blunt the public‑safety and national‑security risks peers raised — or whether parliament will press again to place vendors within statutory scope as the Bill moves through later stages.

Original story