UK Cyber Bill Puts the Burden on AI Users, Lets the Builders Off the Hook
The UK government has knocked back House of Lords amendments that would have pulled AI vendors into the scope of the Cyber Security and Resilience Bill. The message from ministers is clear: if you use AI and something goes wrong, that's your problem to manage, not the AI company's.
Cybersecurity minister Baroness Lloyd of Effra told the Grand Committee on Tuesday that dragging frontier model developers into the bill's scope wouldn't actually stop bad actors from weaponising their products. Which is technically true, in the same way that regulating car manufacturers wouldn't stop drunk driving. It doesn't really address the question of whether the car should have been roadworthy in the first place.
Instead, the government is pointing to the AI Security Institute, which tests models before release in collaboration with vendors, and the voluntary AI Cyber Security Code of Practice. The latter fed into ETSI EN 304 223, billed as the world's first global AI cybersecurity standard. Lloyd presented this as evidence of UK leadership on the international stage. Peers were less impressed.
Baroness Kidron cut straight to the heart of it: companies that can't stop their own AI agents from misbehaving are now being trusted to police themselves through guidelines they can rewrite whenever it suits them. She drew an uncomfortable parallel with the failures of self-regulation in online safety and privacy, fields where the tech industry's track record speaks for itself.
Lord Tarassenko, a Crossbench peer with decades of AI research behind him, pointed to OpenAI's recent open letter warning that AI-orchestrated cyberattacks are becoming a serious threat. The letter was widely criticised for its alarmist framing, particularly given that the signatories profit directly from the technology they're warning about. But peers argued the underlying concern still supports the case for binding regulation.
The exchange got pointed when Lloyd used an NHS scenario to explain how the bill would require regulated organisations to secure systems that include AI. Kidron's follow-up was blunt: the NHS is on the hook for protecting itself, but the AI potentially being used against it faces no obligations whatsoever under the bill. Lloyd's response was that the legislation is technology-agnostic and aimed at raising cybersecurity standards across key organisations, not at managing individual tech providers.
Several other amendments were also rejected. One would have required certain AI vendors to prove their products couldn't cross defined red lines, covering things like evading human oversight or assisting in the development of chemical weapons. Another would have given the Secretary of State emergency powers to order the shutdown of a datacenter or widely deployed AI system during a security crisis.
On the shutdown question, Lloyd's position was that the bill would allow the government to instruct regulated entities, including datacenter operators, to stop using a particular AI model rather than pulling the plug on entire infrastructure. Her argument was that AI systems tend to be distributed across multiple datacenters and jurisdictions, making a blanket shutdown clumsy and disproportionate.
Despite rejecting every amendment, Lloyd said the government is willing to keep talking about AI regulation given how much is riding on it economically. Kidron predicted the issue would resurface at later stages of the bill. That seems like a safe bet.
The Cyber Security and Resilience Bill has been in the works since the 2024 King's Speech and formally entered Parliament in November 2025. It updates the 2018 NIS regulations and extends cybersecurity obligations to managed service providers, datacenter operators, and designated critical suppliers. Managed service providers were supposed to be brought in scope back in 2022, but that update was quietly shelved.
The bill has faced criticism from multiple directions. In January, shadow deputy PM Sir Oliver Dowden questioned why central and local government had been left out of scope entirely. The Government Cyber Action Plan, which arrived the same day as Dowden's remarks, promised to hold government departments to equivalent standards, but without any legal force behind it.
Voluntary commitments and codes of practice are a recurring theme here. Whether that approach holds up when the first serious AI-enabled attack hits critical infrastructure remains to be seen.