UK cyber bill targets AI users, not the vendors building it

← Back to the feed

UK cyber bill targets AI users, not the vendors building it

The Register · 2 hours ago

The UK government has turned down proposals from members of the House of Lords to bring AI vendors and frontier model developers within the scope of the Cyber Security and Resilience Bill, opting instead to rely on voluntary safeguards. Cybersecurity minister Baroness Lloyd of Effra argued that regulating AI companies through the bill would not stop hostile actors misusing their products, and pointed instead to the AI Security Institute's work testing model security and a voluntary AI Cyber Security Code of Practice that fed into a new global standard. The decision matters because peers see it as leaving a gap in the UK's approach to AI-related national security risks, relying on industry self-regulation rather than statutory duties for AI developers.

During a Grand Committee debate, peers including Baroness Kidron and Lord Tarassenko pushed back, citing rogue agentic AI behaviour involving Anthropic and OpenAI, Bill Gates' warnings about commercial pressures undermining safety, and an OpenAI open letter cautioning that AI-driven cyberattacks could soon become unmanageable. Lloyd rejected further amendments, including one requiring AI vendors to prove their products could not cross "red lines" such as evading human oversight or aiding chemical weapons development, and another giving the Secretary of State emergency powers to shut down a datacentre or widely used AI system in a crisis. She maintained the bill is meant to be technology-agnostic, imposing cybersecurity duties on regulated organisations rather than AI providers themselves, though she indicated the government remains open to further discussion as the bill progresses.

  • UK rejects bringing AI vendors under new cybersecurity bill's scope
  • Government favours voluntary codes over mandatory AI safety rules
  • Peers criticise move, citing rogue AI and cyberattack risks

New here? Start with this

Cybersecurity has become a growing worry as artificial intelligence tools spread through business and government, since these systems can be misused by hackers or can misbehave in unexpected ways. In response, the UK government has been drawing up the Cyber Security and Resilience Bill, a law meant to strengthen the country's defences against cyber threats. A key question has been who the bill should cover: only the organisations that use digital services, or also the companies that build AI systems in the first place.

Ministers, represented in this debate by cybersecurity minister Baroness Lloyd of Effra, have decided not to bring AI developers directly under the bill's legal duties, preferring to rely on voluntary measures such as testing by the AI Security Institute and an industry code of practice. Members of the House of Lords, including Baroness Kidron and Lord Tarassenko, argue this leaves a gap, since it places obligations on the businesses using AI rather than on the vendors and frontier developers, such as those behind well-known AI systems, who build it.

This matters because AI is increasingly woven into critical infrastructure and everyday services, so how it is regulated affects national security as well as ordinary consumers. The debate reflects a broader, ongoing disagreement about whether powerful AI companies should be governed by binding rules or by voluntary commitments, a question being wrestled with by policymakers well beyond the UK.

AI Business Cybersecurity Government Markets Politics Technology UK World

Read the full article at the source →