Digital and Technology Policy: National Sovereignty

Baroness Gill Excerpts
Thursday 23rd July 2026

(4 days, 15 hours ago)

Lords Chamber
Read Full debate Read Hansard Text Watch Debate Read Debate Ministerial Extracts
Baroness Gill Portrait Baroness Gill (Lab)
- View Speech - Hansard - -

My Lords, my congratulations and gratitude go to the noble Baroness, Lady Kidron, for securing this debate. Though it feels like we have an almost weekly debate in your Lordships’ House on one aspect or another of AI, I think it is most welcome, given that this is one of the most concerning, unregulated areas that affects our daily lives, and is likely to remain so in the future. Nevertheless, there has been little debate about how our national sovereignty is being slowly eroded, in real time, by those who control our data, our infrastructure and our algorithms. Most worryingly, they are not bound by our laws. I believe we are standing at a critical crossroads.

As we have heard from noble Lords who spoke before me, not controlling our own digital destiny risks our becoming a digital colony of the American monopolies and being subject to powers who are, let us say, our fleeting friends. That is why I strongly welcome Prime Minister Burnham’s decision to bring the AI Minister, Kanishka Narayan, to the Cabinet table. This structural promotion signals and recognises that artificial intelligence is the very foundation of our future national security and public services, ensuring economic growth. However, while this is a welcome change, our defensive and regulatory framework remains dangerously behind the curve. Building fences for the large language models of today could mean being completely defenceless against the autonomous threats of tomorrow.

I agree with what the noble Baroness, Lady Stowell, said: yesterday, we heard about another example of AI moving rapidly from a contained tool to an agentic system that can actively operate across networks without any human intervention. The true threat to our national sovereignty is from the weaponisation of rogue, cross-border AI. Future frontier models will have the capability to bypass localised testing sandboxes, dynamically rewriting their own code to evade containment protocols. Once free, these models can act as borderless, self-replicating digital entities, infiltrating critical national infrastructure, military networks and private cloud storage across the globe. Just imagine if they were subverted by an adversarial foreign nation or cyber-criminal syndicate. These autonomous agents could execute co-ordinated, low-observable attacks on our financial systems and power grids without leaving a traditional digital footprint.

One of my hobby horses when we are talking about AI is how predatory bots are aggressively scraping valuable copyright content from UK website owners without their consent, starving our homegrown creative industries, a major contributor to our economy. True digital sovereignty requires us to protect our creators from intellectual property theft, to break up market monopolies and to build predictive and hardened defences.

I have a couple of questions for my noble friend the Minister. When will the Government issue a refreshed strategic steer to the CMA to reaffirm its independence and inject urgency into its enforcement, ensuring that it acts at a pace that matches the speed at which the AI stack is being monopolised? Secondly, will the Government explicitly rule out new copyright exceptions for AI and support legislative efforts to give UK content creators the legal certainty and transparency they need to block predatory scraping bots?

EU Technological Sovereignty Package

Baroness Gill Excerpts
Monday 20th July 2026

(1 week ago)

Lords Chamber
Read Full debate Read Hansard Text Watch Debate Read Debate Ministerial Extracts
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

The Government are taking the approach of reducing overreliance and building up our own capability. We welcome foreign investment, including in our AI growth zones, and the ability of UK companies and citizens to access the best technology available, whether it is in the UK or elsewhere. That is an important part of our being able to benefit from the developments in AI. However, I absolutely agree that AI compute is the engine behind every AI breakthrough. That is why we are investing up to £2 billion in public compute infrastructure to 2030, so that researchers, start-ups, SMEs and public services can have free access to the computing power they need to work at the frontier of AI.

Baroness Gill Portrait Baroness Gill (Lab)
- View Speech - Hansard - -

My Lords, the UK’s AI Security Institute does evaluate frontier models, but it lacks pre-market enforcement powers to block software releases. Pre-market enforcement would force developers to proactively prove that their models meet rigorous safety standards, such as we have for aviation, pharmaceuticals and medical devices. Are the Government open to setting a global standard for AI by backing upfront, rigorous safety evaluations?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

The AI Security Institute is one of the pre-eminent institutions in the UK in AI development and the transformations we are seeing. It works very closely with other AI security institutes. I think it was only two weeks back that it was meeting other similar institutions, developing common standards and approaches to assessment, which is one of the important ways that we keep a baseline across the globe for how we should appraise frontier models as they are developed.

Baroness Gill Portrait Baroness Gill (Lab)
- View Speech - Hansard - -

My Lords, too often we hear in the news that our local hospital cannot access patient records, or that the transport network in our cities has stalled, or, as I experienced last year, that the power has gone on and off for over a month as the local electricity grid is affected by cyber attacks. A decade ago, some of this would have sounded like the plot of a Hollywood movie. Today, it is a weekly briefing on the desk of our cyber security data centres.

Our world has fundamentally changed. We are no longer just fighting off rogue teenagers or opportunistic hackers looking for a quick payout. The UK is currently navigating a highly sophisticated and aggressive digital battlefield. Malign actors are often directed, tolerated or unleashed by hostile nation states such as Russia, Iran and China, which are actively infiltrating key UK assets. They are mapping our infrastructure, stealing government credentials and probing our defences. That is why I welcome the introduction of the cyber security and resilience Bill. It is a critical and long-overdue overhaul of our national baseline defence. It marks the moment that the UK stops playing catch-up with hostile states and starts to dictate the terms of its own digital safety.

To understand why the Bill matters, we have to look at how our digital ecosystem functions. Hostile actors do not just knock on the front door; they look for the weakest link in the supply chain. Look at what happened in September 2025, with the devastating cyber attack on Jaguar Land Rover. Russian-linked hackers deployed sophisticated ransomware that completely paralysed JLR’s IT networks and forced a total shutdown of production lines across major UK plants for weeks, which had a major impact on the workforce in my old West Midlands constituency. The disruption that cascaded down into the automotive supply chain affected thousands of component manufacturers, mostly SMEs, with many workers in the region facing lay-offs. It had a major impact on the regional economy. Likewise, the attack did not just hurt the brand; it cost the British economy an estimated £1.9 billion, directly denting our national GDP. This was not just a corporate crime; it was an act of economic sabotage.

The threat extends far beyond manufacturing. Just weeks later, a massive cyber incident crippled electronic check-in and baggage systems at Heathrow Airport and across Europe. Was Heathrow’s central system breached directly? No. The attackers targeted a third-party vendor, Collins Aerospace, and scrambled the shared MUSE software that multiple airlines rely on. The result was chaos at terminals, hundreds of disrupted flights, and over 1.5 million passenger records being compromised. This new legislation fundamentally expands our defensive perimeter to address this exact vulnerability. For the first time, it brings data centres, managed service providers and supply chain partners directly into the regulatory spotlight, establishing a framework to name designated critical suppliers. The Bill recognises a hard truth: our infrastructure is only as secure as the third-party software we plug into it

Because of these aggressive state threats, a wider net is useless without sharper teeth. The Bill introduces two massive shifts in how organisations must run: rapid transparency and genuine board-level accountability. Under the new rules, if a covered organisation suffers a significant incident, or even a near miss capable of causing harm, it must file a notification within 24 hours, followed by a full report within 72 hours. In a cyber crisis, time is our most valuable currency. When assets such as Heathrow or JLR go down, an early warning allows the National Cyber Security Centre and regulators to contain the digital contagion before it spreads.

There are real consequences of negligence. For too long, cyber security has been treated by some boards as a minor IT issue, tucked away obscurely in finance or some other department. I am very pleased that the Bill changes this calculation. Companies that do not comply face financial penalties of up to £17 million, or 4% of their worldwide turnover. This will force executives to realise that robust cyber security is a core fiduciary duty. If you do not protect your network, you are jeopardising your entire business.

Crucially, this legislation is built to outpace our adversaries. Nation states use criminal proxies because they are fast, scalable and disguise geopolitical motives. Static laws become obsolete within months. The Bill grants the Government agile powers to update regulations swiftly through secondary legislation. This means that, as new state-sponsored threats emerge—whether through weaponised artificial intelligence or quantum decryption —the UK can adapt its defences instantly, without waiting years for a new Act of Parliament. The Bill also mandates companies immediately to notify their own customers if a breach puts those customers at risk.

To conclude, let us be entirely clear that the Bill is demanding. It will require an unprecedented level of capital investment and profound cultural change in every boardroom in this country, though I urge the Minister to consider undue burden on the SME sector, while recognising that it can sometimes be the weakest link. But we cannot ignore the reality of implementation. Cultural change does not happen purely through good will; it happens when the risk of non-compliance becomes completely indefensible. I ask my noble friend the Minister a fundamental question. While the target of the Bill is correct, the level of commercial investment and cultural transformation needed to meet these 24-hour deadlines is staggering. Beyond the immense financial stick, what mechanisms, support and enforcement frameworks will the Minister use to ensure this legislation drives genuine resilience, rather than just defensive corporate box-ticking? How will she guarantee that this heavy stick builds a shield?