39 Baroness Harding of Winscombe debates involving the Department for Digital, Culture, Media & Sport

Wed 19th Jul 2023
Mon 17th Jul 2023
Wed 12th Jul 2023
Mon 10th Jul 2023
Online Safety Bill
Lords Chamber

Report stage: Part 2
Mon 10th Jul 2023
Online Safety Bill
Lords Chamber

Report stage: Part 1
Thu 6th Jul 2023
Online Safety Bill
Lords Chamber

Report stage: Part 2

AI: Human Extinction

Baroness Harding of Winscombe Excerpts
Tuesday 15th September 2026

(2 weeks, 3 days ago)

Lords Chamber
Read Full debate Read Hansard Text Watch Debate Read Debate Ministerial Extracts
Baroness Twycross Portrait Baroness Twycross (Lab)
- View Speech - Hansard - - - Excerpts

The Government are clear that all parties involved in the development of AI need to be in agreement about a way forward.

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - -

My Lords, the tech companies, particularly the social media companies, have argued for a decade that their technology is global and, therefore, that local regulation is not the way to do it. Yet Australia, and now, I believe, this House have realised that local regulation is the only way you get global regulation in the end. Why do we think AI is any different?

Baroness Twycross Portrait Baroness Twycross (Lab)
- View Speech - Hansard - - - Excerpts

I apologise if I gave the impression that we do not think we should have any regulation relating to AI. What I was trying to get across was that we are taking an agile and context-based approach to AI regulation, which seeks to get a balance. The Government have put through a number of pieces of legislation that have AI-related elements. I will be very happy to write to the noble Baroness to outline what these are.

Cyber Security and Resilience (Network and Information Systems) Bill

Baroness Harding of Winscombe Excerpts
Baroness Neville-Jones Portrait Baroness Neville-Jones (Con)
- Hansard - - - Excerpts

My Lords, the campaign to reform the Computer Misuse Act is at least 10 years old, not just five. We—including me—have been working to try to get the provision that is contained in the amendment before us from the noble Lord, Lord Clement-Jones. I endorse every single word that he said; he put the case precisely as it needed to be set out. It is absolutely anomalous that we still have this legislation on the statute book, and we need an update to it.

We need to put our researchers, and those who help to protect us and keep us safe, in a safe position themselves, which they are not at the moment. They are subject to potential criminal prosecution, which is stupid and a great disincentive to doing what needs to be done. I very much hope that the Minister will be persuaded to take this opportunity—not to reject it—to put a clause, even if it needs modification to a form that the Government approve of, in this legislation.

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - -

My Lords, I will speak briefly in support of the amendment from the noble Lord, Lord Clement-Jones, which he so comprehensively set out. I did not mention this at Second Reading because I thought it was so self-evidently sensible that this needed to be fixed. I should know better, having been in this place for a decade, than to assume that something will happen just because it is self-evidently sensible.

The last three days in Committee have been rather depressing—my noble friend Lord Vaizey is lucky he was not here last week, although he managed to give an excellent speech that suggested he had at least been following us in Hansard or on TV—because it has been so clear that the most important issues are not being addressed in the Bill. This seems like something simple to fix. There are much bigger issues, such as the complete gaping hole of the absence of AI and the huge complexity of all the different regimes that the noble Lord, Lord Birt, set out. I am of the view that you cannot wait for the perfect, and there is a real risk that we are letting perfect be the enemy of the good. This is a straightforward and sensible proposal that I think the Government previously agreed with, but it was just not the right time. Surely, now is the time for us to do things rather than keep kicking the can down the road.

Lord Tarassenko Portrait Lord Tarassenko (CB)
- Hansard - - - Excerpts

My Lords, one of the advantages of being in this Committee Room for these debates in Committee is that I can use Claude—I hope that is allowed—to answer the question of what the cyber security community thinks about the Computer Misuse Act. The answer comes back in bold. I will read just the paragraph in bold: “The UK cyber security community’s view is that the Computer Misuse Act 1990 is dangerously out of date and reform efforts so far do not go far enough”. I rest my case.

Cyber Security and Resilience (Network and Information Systems) Bill

Baroness Harding of Winscombe Excerpts
Moved by
18: Clause 15, page 21, line 33, at end insert—
“(c) if requested by the designated competent authority following the full notification, an intermediate report containing such information on the status of the incident, and updating the information given under paragraph (2)(b), as the authority may specify, and(d) a final report containing the information listed in paragraph (5A) in relation to the incident.”Member’s explanatory statement
This amendment is part of a set of amendments in the name of Baroness Harding that strengthen the staged reporting requirements for OES, except so far as it provides an essential service of a kind referred to in paragraph 11(2) or (3) of Schedule 2 (data centre services).This amendment enables competent authorities to require an intermediate update from the affected regulated entity within 14 days and a final report within a month.
Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - -

My Lords, I rise to introduce a large number of amendments, for which I apologise: Amendments 18 to 23, 25 to 31, 33 to 39, 41 to 47 and 49 and 50.

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - -

Full house. Fear not—it is not as complex as it seems. These amendments, which I have introduced, and I am grateful for the support of the noble Baroness, Lady Kidron, and my noble friend Lord Holmes of Richmond, seek to strengthen the staged reporting requirements of the four different groups of entities, so each change must be repeated four times. Because of the way in which the Bill is drafted, I was unable to introduce the change just once; I had to put in each micro phrase, hence so many amendments. The aim is to strengthen the staged reporting requirements for operators of essential services, data centres, relevant digital service providers and relevant managed service providers, so everything is multiplied by four.

The Bill, as it stands, requires only an initial report within 24 hours and a full notification within 72 hours of an incident. My amendments would add two further stages: an intermediate report which is capped at 14 days after the incident has first been notified, or sooner if the relevant regulator requires, and a final report within one month. In all four cases, the reports must be given without undue delay, so that regulated entities cannot use the timeframes as an excuse to delay until the end of the time period.

These amendments are in line with the EU’s NIS2 directive. The reason why I have introduced them, as I said at Second Reading, is that I have lived this. I absolutely understand what the fog feels like. In the first moment when you have been attacked, you do not understand what has happened: you do not know who is attacking you, you do not know what they could have stolen, you do not know where they have gone, but you do know that it is serious. That is your first report. You start to understand, 72 hours later, quite how awful it could be. That is your second report, where you start to get real data, because your teams have worked all night, usually all around the world, to try to work out where the malign actors have gone. But it is really only after a couple of weeks that you have a proper sense of what has happened.

I recognise that my experience is, obviously, 10 years old, but quite recently I had a long conversation with some of the leaders at Marks & Spencer. The thing that scared me most was that it seemed so similar to my experience 10 years ago and that this basic process is likely to be the same. So we need the requirement to properly update whatever you learn two weeks on, and then a month later the fog starts to clear and you have a proper sense of the real scale of the problem.

The reason why we need to put this in legislation is that, throughout that entire period, all the incentives for you, as a corporate leader, are not to say anything. This is the biggest corporate taboo. Your board will be encouraging you not to tell everyone, the public will be telling you not to tell everyone and there is a real risk, unless you are forced to, that you just make it easier for the blackmailers to do their work. My personal experience was of being blackmailed during this process. Obviously, at the time, there were none of these regulations. I can tell your Lordships that there were so many voices saying, “Why don’t you just shut up? You don’t know what’s going on yet. Keep quiet”. Yet if, in the fog, you share this information with regulators and with law enforcement agencies, that is how the law can prevail. It is how regulators can work out what is happening and how they can warn others who might be affected. It is how the law enforcement agencies can do their work to try to find the bad guys.

This really matters if we want the rule of law to exist in the digital world, because the incentives, even for entirely well-meaning and upstanding leaders of corporations—and government departments, dare I say—are to keep quiet. We need to put these reporting requirements in the Bill. All the amendments would do is bring our own legislation in line with the NIS2 framework. To be honest, many of these companies and these incidents are likely to need to be reported in Europe at the same time as they are in the UK. As my noble friend Lady Neville-Jones said, there is a real primacy on keeping things simple. The more we can mirror and have exactly the same reporting requirements, the easier it will be when you are in that terrifying moment when you realise that you have a serious incident. I beg to move.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I think we all agree that we want a proportionate and clear regime. The noble Lord supports further incident reporting here—additional stages of incident reporting. In our impact assessment, we clearly set out the implications of that in its cost to business and so on. We will come on shortly to discuss potentially broadening the scope of incidents that would be reported. We have not been able to quantify that potential impact, as a sort of counterfactual, because we are only just discussing that.

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - -

My Lords, I have listened really carefully to the Minister and thank her for her response, but I feel that we just had a completely black and white no, which is extremely disappointing. We have had something almost worse than a black and white no, because if I heard her correctly—I will need to go back and read it again—I think she has added uncertainty, because suggesting that it is okay because regulators have the ability to ask for extra reporting is a company’s worst nightmare. What you want is really clear black and white guardrails, as we have been trying to introduce in these amendments.

I had hoped that we could have follow-up discussions between now and Report, but I feel like the door has been rather slammed in my face. I would be very keen to understand, as the noble Lord, Lord Clement-Jones, has just said, what consultation has really happened and to have a recognition that you need to consult organisations that have experienced a substantial cyber attack. If an organisation has not, then I am afraid it will want to keep quiet and will not want to report anything. It is easy to ask broad groups of organisations, “Would you like more reporting?” We all know what the answer to that would be. That is an easy consultation.

I would really value more detailed discussions with the Minister and her officials between now and Report, because I feel that we will come back to this, particularly given the support that my amendments have received from across the Committee, for which I am extremely grateful. I beg leave to withdraw the amendment.

Amendment 18 withdrawn.
--- Later in debate ---
Moved by
51: Clause 16, page 32, line 34, leave out “as soon as reasonably practicable” and insert “without delay and in any event within 24 hours of becoming aware of the incident”
Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - -

I apologise, I stand to speak to a whole other group of amendments that suffer from the same challenge of needing to be repeated four times, which is why I suggested to the clerks that we degroup them, otherwise we would have got into a real muddle.

This group seeks to address the obligation to report incidents to customers, as the Minister referenced in her remarks earlier. Currently, the Bill requires notification only where a customer is,

“likely to be adversely affected”.

The obligation is to explain the nature of the incident and why the customer is affected. My amendments seek to broaden and deepen that duty. Customers must be notified where an incident has caused or has the potential to cause severe operational damage or financial loss, where I hope my drafting has not fallen prey to the issue that my noble friend Lady Neville-Jones, addressed in Amendment 17. If it has done so, we obviously need to address that.

The duty is extended to cover related natural or legal persons who could suffer considerable damage as a result. The regulated entities must also advise customers on what measures to take in response. Probably most importantly in this group of amendments, the entities must keep customers updated until the incident is resolved, whereas at the moment the Bill only requires them to notify customers once and then leave them hanging, waiting to find out what is going on. Together these amendments would ensure that customers are told promptly what to do and are kept informed throughout the incident until it is resolved. They also follow the NIS2 directive in requiring advice on protective measures and go a little further by making it a requirement to communicate to related persons as well.

Sadly, I have personal experience in this, not from my TalkTalk times but much more recently. I suspect anybody who is on a board or who has chaired a business has experienced this. An organisation that I chair is the customer of a managed service provider that recently experienced an incident. It did not tell us. The incident was to do with some of our staff payroll information, so it was sensitive and important. When it did tell us, it then did not keep us informed about what was going on. So I feel that pain.

I know that some noble Lords may have concerns that we do not want to create panic by endless notification. I absolutely agree. Hence my attempt to define this as severe operational damage. I would very much welcome input between now and Report if we can tighten that wording to make sure that this does not represent lots of unnecessary email alerts telling you that a system three stages back in the tech stack might have been affected. But when your customers’ data has been exposed in a cyber attack through a managed service provider, data centre or digital service that you use, it is entirely reasonable that those companies have a requirement to inform and keep you updated during the incident. That is all that these amendments seek to do. I beg to move.

Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - - - Excerpts

My Lords, for reasons that I do not understand, I do not have my name on these amendments, given all the others from the noble Baroness that I do, but I support them. It is funny, because when I came back from holiday in August, I had no fewer than five emails from companies saying that there had been data breaches in which I was involved, and I had that exact thought—“What now? What do I do? What’s next? How serious?”—and did nothing.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank the noble Baroness for raising important points around customer communication. As set out in the Bill, it takes forward the current duties to notify customers that the Bill places on data centres, OESs, RDSPs and RMSPs. That duty was designed to ensure that providers of key digital and data infrastructure services consider whether their customers are likely to have been adversely affected by a reported incident—whether through disruption of service, compromise of their data or exposure of their systems to cyber threats—and to notify them.

I will explain the logic in response to the point of the noble Lord, Lord Clement-Jones, about the importance of meaningful communication with customers. The reason we have drafted the Bill so that customer notification follows the 72-hour incident report is to ensure that regulated entities can focus on understanding the nature of the incident and contact customers when they are more likely to understand its potential impacts.

We have discussed the question of what an organisation might reasonably be expected to know within 24 hours of identifying an incident. The point is that customers should be communicated with in a timely manner, with sufficient information, so that they can take the necessary action. On that point, the rationale for 72 hours was to time it, for simplicity, with the 72-hour report. I am happy to consult further with the noble Baroness to explain the logic of the 72-hour and 42-hour requirement to communicate with customers, because the motivation is exactly the same: to have actionable and meaningful communication with customers.

I turn to the degree of depth of communication, the advice that can reasonably be put on regulated entities on technical measures, and what technical mitigations customers should take on their own. It is reasonable that the regulated entity should share what they know about the nature of the incident. The question about whether the regulated entity is in the right position to provide advice to customers on what mitigations they should take is both practical and technical. Would they have enough insight to have an effective understanding of the situation of the customers and a detailed understanding of the customers and their businesses in order to give effective meaningful advice in that way—or would that just be a requirement on the entities that would not have the intended impact? On that point, I am not quite persuaded that the line is drawn in the right position.

On keeping in touch, mentioned by the noble Baronesses, Lady Kidron and Lady Harding, I am happy to come back to that on Report to make sure that we have the right balance between the initial notification and the right type of customer communication.

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - -

I thank all the noble Lords who, again, have supported my long list of amendments and I thank them for their excellent contributions. It feels as if we made a very small breakthrough, for which I am extremely grateful, and I thank the Minister. I will not delay anyone any longer as we have another group of my amendments to come, but I look forward to some detailed discussions between now and Report to see if we can bring this back in a form that we are all able to support. I beg leave to withdraw the amendment.

Amendment 51 withdrawn.
--- Later in debate ---
Moved by
72: After Clause 16, insert the following new Clause—
“Notification of near misses, cyber threats and sub-threshold incidentsAfter regulation 14G of the NIS Regulations (inserted by section 16) insert—“Notification of near misses, cyber threats and sub-threshold incidents(1) A regulated person must notify the designated competent authority without undue delay and in any event no later than 72 hours after becoming aware of—(a) a cyber threat,(b) a near miss, or(c) a sub-threshold incident,affecting the regulated person’s network and information systems.(2) A person other than a regulated person may notify the designated competent authority on a voluntary basis of a cyber threat or a near miss or a sub-threshold incident affecting that person’s network and information systems, regardless of whether that person is subject to any requirement under these Regulations.(3) Without prejudice to the prevention, investigation, detection and prosecution of criminal offences, a person who gives a notification under paragraph (1) or (2) is not, by reason only of that notification, subject to any additional duty, liability or requirement to which that person would not otherwise have been subject.(4) In this regulation—“cyber threat” means any potential circumstance, event or action that could, if it occurred, adversely affect the network and information systems of a person, or the users of a service provided by means of such systems;“near miss” means an event that could have compromised the availability, authenticity, integrity or confidentiality of data, or of a service provided by means of network and information systems, but that was prevented from having that effect or did not in fact have that effect;“regulated person” means an OES, an RDSP, an RMSP or a critical supplier;“sub-threshold incident” means an incident affecting the regulated person’s network and information systems which the regulated person is not otherwise required to notify under regulation 11(2), 11A(2), 12A(1) or 14E(1) but which is close to the thresholds for notification under those regulations.”” Member’s explanatory statement
This new clause seeks to ensure that regulated persons must report to their designated competent authority any near miss incident, cyber threat, or sub-threshold incident that could adversely affect the network and information systems of a person, or the users of a service provided by means of such systems.
Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - -

I am sorry, it is me again. In a break with tradition, we have only one amendment in this group. That is because this amendment would insert a proposed new clause, as opposed to lots of small changes to existing clauses. Amendment 72 is in my name and, once again, I thank the noble Baroness, Lady Kidron, for adding her name.

This proposed new clause seeks to ensure that organisations regulated under the Bill must report any near misses, cyber threats or incidents currently under the thresholds as set out in the Bill that could affect their network and information systems. I am, again, mindful that it is important that this is consistent with the extremely well-made points of my noble friend Lady Neville-Jones in Amendment 17. It is welcome to have discussions on whether the wording is right, because the purpose is to get the near miss, rather than a huge deluge of meaningless reporting.

As it stands, the Bill requires regulated entities to report only what has happened, and only if it crosses a threshold based on factors such as scale, duration and the number of people affected. However, my amendments look to close the gaps in the event of, for example, an attack an organisation has stopped before it has caused major damage, but had the attack had been successful, it would have had a substantial effect across the whole industry. Other examples are where there are very credible warnings of an expected attack that does not occur, or where there is an incident that falls just below the thresholds that could still be significant.

The intention of this amendment—unlike in my other two groups, it is quite a probing amendment to see if we can work together to capture the spirit of this—is to close a reporting gap where significant incidents may not be reported simply because of the way we have drawn up the definitions in the Bill.

As in the other two groups that I have led, this follows the EU NIS2 directive, although the NIS2 directive creates a voluntary rather than a mandatory reporting provision for this. My view is that the taboo for going public on cyber attacks is so great that voluntary reporting is not the way to do this. It is better for all organisations to know the black and white of what they can do, what they should do and what they do not have to do. In some sectors, certainly the one I worked in—telecoms—there is a fair amount of voluntary sharing. But even there, there is such a taboo about speaking to your regulator about a problem that this needs to be made this mandatory rather than voluntary. Other than that, this seeks to replicate what is in the EU NIS2 directives. With that—I think noble Lords have probably heard enough of me—I beg to move.

Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - - - Excerpts

My Lords, I support Amendment 72 and I have signed it. I recognise the probing nature of this, but I also recognise the problem it seeks to address. The knowledge that a cyber threat or cyber attack has failed may be incredibly important intelligence because, on the whole, someone trying to create a cyber threat will not retire after the first time that it did not work out; they will try somewhere else, so the intelligence element of this is so crucial.

Some of the people in cyber security talk about seven stages of cyber attack. The first stage is reconnaissance: you are just having a look round and trying to identify vulnerabilities. The second stage is weaponisation: you are developing the means to target that weakness, which can be as simple as an email. It is not until the third stage that the attack begins. But there are still three or four more stages, each of which can provide a barrier and each of which can be the place at which the attack stops. It is not uncommon for attackers to carry out multiple attempts to find or exploit a vulnerability, or indeed to do a small-scale attack in order to then do something larger down the line. In all these cases, there is something absolutely critical for the regulator and possibly the enforcement community to know.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

My Lords, I thank the noble Baroness for raising this question about the requirement for regulated entities to report cyber threats, near misses and sub-threshold incidents within a 72-hour deadline.

I turn first to the question of voluntary reporting, which we touched on a little in the context of discussing the industry groupings on Tuesday and the trust groups that exist and are often facilitated by the NCSC. These are incredibly valuable groups. We absolutely encourage voluntary reporting, whether through those groups or other industry bodies. There is a question about whether putting such groups and mechanisms on a statutory footing helps or hinders that objective, because we need to engender the confidence to share information, as the noble Baroness and others mentioned. There is a question about whether that is within the regulatory perimeter, as it were, and whether it encourages that or not. I am happy to come back to that on Report.

I turn to the question of reporting sub-threshold incidents. The amendment concerns incidents that have been successfully contained or have proved ineffective, incidents that fall somewhere below the current reporting thresholds and any potential circumstance or event that could, if it occurred, affect a regulated entity’s systems or the users of a service provided through these systems. We discussed that in the context of data centres. Let me answer the question from the noble Baroness, Lady Kidron. In the discussion on data centres, I was speaking about near misses. We made the point highlighted by the noble Baroness, Lady Neville-Jones: near misses and those types of incidents would be captured for data centres, given the particular role they play in our digital infrastructure.

The extension of similar requirements—although, as we read it, they are much broader requirements—to all regulated entities would increase regulatory reporting very significantly. The noble Baroness, Lady Neville-Jones, made the point right at the beginning—although it could have possibly been someone else—about the ability of our regulators to effectively utilise the threat intelligence and manage it so that it can be conveyed into actionable advice and trend data. These are the considerations that we take.

Another consideration is that the entities that have more sophisticated surveillance and mitigations may be able to identify attacks more effectively. We would not want to set up a situation where there were any perverse incentives in the system for those who have very adept surveillance and assessments away from reporting or developing that.

Even though I heard very clearly that the motivation is that the amendment is just to catch to those incidents that just fall below, our reading of it is that it would be much wider, and it may indeed have some other effects. At this stage, I would not support the amendment as drafted.

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - -

It was my suggestion to break up these amendments into different groups, otherwise we would have had about 100 amendments in one group. There is an awful lot of overlap in the discussion on this group in particular and Amendment 17 in the name of my noble friend Lady Neville-Jones. Would the Minister commit to having a joint meeting, where we could try to work this through together? I think we share a common goal of wanting to give as much relevant, immediate and up-to-date intelligence to the network as possible, without overwhelming, and recognising that, as the noble Lord, Lord Clement-Jones, said, time is absolutely everything in these cyber attacks. If we could discuss that together rather than separately, that would be extremely valuable.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

That would indeed be very valuable to discuss the questions around definition, scope, coverage, timeliness and impact on potential entities—sorry, I have just expanded our agenda.

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - -

I have heard very clearly the willingness to discuss and collaborate from the Minister, which is extremely welcome, as were the contributions from all noble Lords. If the last hour and half has shown anything, it is that there is a genuine cross-Committee desire to work—this is what the House does at its best—to genuinely improve, with a shared goal of a piece of legislation that the country will benefit from if we can get it right. I beg leave to withdraw the amendment.

Amendment 72 withdrawn.
--- Later in debate ---
Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - -

My Lords, I also support Amendments 74 and 167. My experience is that boards that tell you that their cyber security is really good are the ones you should be most worried about. Boards that are really worried about it and can tell you where they think they are exposed might be in a slightly better place. There are too many organisations that will tell you that they are fine. Boards that are not doing what is set out in Amendment 167 are in trouble. It is entirely appropriate, and I fully support that amendment.

On Amendment 74, I would just like to draw a thread between the financial services senior management regime, what we have learned in the Online Safety Act and Tuesday’s debate about whether frontier AI models are included in the scope of the Bill. We have learned from the financial services senior management regime that when you make individual human beings accountable, they change. There is no doubt that the senior management regime in financial services has served to move the dial on the culture in financial services, and all previous attempts have failed.

Through the Online Safety Act, we have learned that various companies—not ones regulated by this Bill—have not taken seriously fines from Ofcom and simply refused to obey. We are living through an era when the tech sector wants to believe that it is exceptional and that laws from individual countries do not apply to it. It is therefore very important that we put into the Bill liability for senior executives, precisely because of what we have learned: in a sector that is doing it, you get culture change. In other digital legislation, where we do not have this, regulators’ decisions have actively been flouted. This is even more important if the Minister were to accept the amendments we debated on Tuesday—the noble Lord, Lord Tarassenko, has arrived just in time—because I firmly believe that the single most important part of regulating AI is holding the creators of the model accountable for their actions. Given that the biggest cyber security threats we face are the actions of agentic AI, I want to be able to build the framework that enables us to hold the managers and leaders developing those models, who currently say that this has nothing to do with them, accountable for their actions. I may be stretching it a bit, but I hope that Amendment 74 would be the beginnings of a framework that would enable us to hold senior tech titans to account.

Baroness Berger Portrait Baroness Berger (Lab)
- Hansard - - - Excerpts

My Lords, I will speak quickly. I was just checking my records, particularly on Amendment 167. It was just under a year ago that I completed the FT board director programme, which was specifically around cyber risk for boards. In a room of around 50 people, we had a tabletop exercise on a real-life scenario about what one should do in the event of a very serious cyber crisis and cyber risk. I was struck by a number of things. In the room were people with vast waves of expertise and experience, none of whom was a technology expert. All said that no other members of their board had attended training like this. They were there because, having completed a board director programme, it piqued their interest, as it did mine, it was freely on offer and they decided to attend.

Having gone through that session, we covered things such as the regulatory experience, issues around how to challenge management in the event of one of these incidents, how you need to test organisational resilience, how you need to look at the risks involved, and how to respond decisively and to have the expertise and understanding to do so. It was very clear to me, even during that half-day exercise, that that training was not sufficient for me as a board director and member to be able to fulfil that role.

Having gone through that experience, I think for many reasons that this amendment is so important to ensure that boards across this country—be they private boards, FTSE boards or boards of regulated companies—can do their jobs effectively. In this world, which is extending—I echo the points made about AI—it is even more imperative that we have this amendment to ensure that boards are able to fulfil their roles effectively.

Lord Birt Portrait Lord Birt (CB)
- Hansard - - - Excerpts

My Lords, I think that this is profoundly unsatisfactory. It is not good parliamentary procedure to table so many amendments radically different from anything that we have seen before, which I, for one, have seen only at the last minute, so to speak—I have read them, but I will not claim to have studied them. I do not altogether know what I think, but I readily accept that the noble Lord, Lord Clement-Jones, has had a chance to scrutinise them in a lot more detail than I have.

I do not have anything substantial to say, but I would like to ask the Minister a question. Manifestly, there is a national security risk, which we would all recognise, and we all recognise that something needs to be done about it. But, if this is a national security issue, perhaps the Minister could explain to us why it cannot be dealt with under existing national security procedures. I have had time to go on to the GCHQ website, where one finds an impressive and considered approach to handling different security issues of this kind called the “equities process”—I did not know about it until the weekend, but it is impressive to read. I just do not understand why you would lodge such a set of issues with DCMS rather than the Cabinet Office. DCMS seems to me completely the wrong home for identifying, weighing and working out what to do about things that have such profound ramifications. Perhaps the Minister could explain to us why existing procedures, which are well tested and, by and large, involve GCHQ with a lot of consent in other areas of government activity, cannot be applied here with the same sensitivity that GCHQ has shown on other occasions. We cannot have a meaningful discussion about this today, but I think that the Minister has to think about how we can have a meaningful discussion before we reach the next stage of the Bill.

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - -

My Lords, if I may, I will reiterate points that the noble Lord, Lord Birt, has made. A number of us are struggling to keep up. Much of what the noble Lord, Lord Clement-Jones, said made a lot of sense, but I certainly do not feel sufficiently sighted on the amendments and I would like to request from the Minister a proper briefing as soon as we possibly can. We have multiple days in Committee and I feel that we will keep going round the issue of how AI is being addressed in the Bill. At the core, we are all trying to stand on both sides of the fence: we are very nervous of these powers, which appear to have been snuck in without much scrutiny, but, on the other hand, at Second Reading many of us were clear that we want to see AI captured in the Bill. I am very much in two minds and would welcome a proper briefing from the experts.

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - - - Excerpts

My Lords, I thank the noble Baroness the Minister for introducing this debate and for her helpful advance briefings on these amendments. I also welcome all noble Lords back for what, I am sure, will be a productive Committee stage. It is worth noting at the start of Committee that, sadly, our cyber adversaries did not take the summer off. In July, a small power generator was attacked and, in August, an attack on Manchester Airports Group compromised the data of 8.7 million of its customers.

That said, I begin by saying that we on these Benches support the intention behind the Government’s amendments. I absolutely recognise the concerns expressed by all the other speakers thus far; procedurally, this is a very unusual way to go about it, but we support the intention. We have been calling for an increase in the scope of the Bill and for cyber security measures to be undertaken by businesses and individuals, rather than the Government, where possible. We feel that these new amendments go some way to achieving that.

However, while we support the intentions, the context around them remains challenging. The difficulty that we face when trying to scrutinise and improve this Bill—and I am sure that we will return to this—is that it essentially exists, at least for now, in a vacuum. The Government’s goals are the right ones and their intentions seem to be clear, but we lack the overall holistic framework that is so important for systemic, strategic approaches to cyber security. Perhaps when the Minister stands up she can provide an update on the publication date of the national cyber action plan because, as I said at Second Reading, a cyber Bill can stand or fall only in the context of an overall cyber defence strategy, and we need to see it.

Most evident is that this currently seems to be a Bill without a department. The amendments delegating and separating powers between the Secretary of State and the Chancellor of the Duchy of Lancaster reflect this. I am really concerned—I would appreciate some reassurance from the Minister on this—that the decision to scrap DSIT, the Department for Science, Innovation and Technology, has left this Bill in limbo. A minimum of 30 teams are being split across at least three departments, and this seriously important Bill, which we are all counting on to protect us from enemies known and unknown, is adrift between departments. At the very least, the Government should set out as soon as possible who will have lead responsibility when this Bill is passed.

I thank the Minister for her clarifying remarks on the referral schemes that her amendments introduce. As I have noted, we support the attempt to expand the scope of this Bill and give businesses the ability to be self-sufficient. That support extends to the establishment of a voluntary referral scheme. However, this new voluntary scheme needs to have a clear and accessible framework and a timeline for implementation. If it is to act as an extra layer of security outside the Government’s immediate remit, vendors must know what they are expected to report and the mechanisms for doing so. There is little use setting it up if these are not made explicit at the earliest opportunity. The consultation is welcome, but some idea as to the form the Government intend this scheme to take would be helpful, alongside an indication on timing. I hope the Minister can give more clarity in her closing remarks. If not, I hope she will be able to write to me and all Members of this Committee.

I was originally going to make the point that the mandatory referral of a vendor outside current NIS regulations will necessarily be ad hoc and that, as such, defining “qualifying transactions” would not be proper. Instead, Amendment 153 was an attempt to provide clarity for decision-making without inhibiting the Government’s ability to act. However, given that the Minister said in opening that the Government have no intention of setting up a mandatory referral scheme, we must question why they feel the need to give themselves the powers to do so. Powers should not be granted and come into existence if they are never to be used. At the very least, given that the Minister has now said that the Government would consult on the definition of a qualifying transaction before any scheme is established, the amendment should ensure as much. The Government will now have the opportunity to bring these amendments back on Report. The mandatory referral scheme should be redrafted to reflect the Minister’s statement and be conditional on the defining of qualifying transactions. I hope the Minister will agree to this.

Finally, let me make a general point about the definitions used in these amendments and throughout the Bill. The proposed criterion of being “essential to the economy” is unworkably vague. It is not an adequate representation of the different types and scales of risks. I suggest, for example, the Cyber Monitoring Centre’s five-level severity scale as a model more reflective of the grades of threats facing the United Kingdom. I am not arguing that it is necessarily the right model, but it is at least tested and quantifiable. I look forward to the Minister’s response.

--- Later in debate ---
Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - - - Excerpts

My Lords, I am very sorry that I missed the early part of that debate because I feel it might impact on some of the things I say. However, when I read the government amendments, I could not see anything in them that made the amendments unnecessary, so I will read carefully all aspects of the first group but I intend to progress with the amendments that I have tabled. I will speak to Amendments 3, 8 and 13 in my name and in the names of the noble Baronesses, Lady Harding, Lady Berger and Lady Morgan. Together, they would expand the scope of services in the Bill so that so-called “small but risky” services were included.

Amendment 3 stipulates that smaller data centres could be included if Ofcom considers that an incident affecting the data centre would have a significant impact on the economy or on the day-to-day functioning of society in the UK, taking into account the data centre’s customer base and its role supporting other essential services. Currently, data centres that are for an enterprise purpose only are covered in the Bill only if the rated IT load is 10 megawatts or greater. This is a mid-size data centre. However, there are commercial data centres that can be much smaller than this and are threatening. Perhaps most notable is a recent example from Denmark where the small cloud hosting providers, CloudNordic and AzeroCloud, suffered a ransomware attack that resulted in the paralysing of all company systems and the servers being shut down. Their hundreds of customers lost all their data, and it was unrecoverable. “Customers” is a bland word, but imagine that you are a hospital treating patients, a university conducting years of scientific research or a small business with its entire operation at stake: the loss of your data risks lost livelihoods, and possibly even lives.

Meanwhile, many experts are calling for an expansion of smaller data centres. They are less taxing on the natural and local environment, more embedded in local communities and are in contrast to mid and large centres, whose environmental costs hit local communities, use up water, increase the strain on the grid, are possibly noisy and ugly and favour the hyperscale business models of big tech. If smaller data centres are an attractive alternative to unpopular larger ones, it is even more essential that they are in scope of these regulations.

Amendment 8 stipulates that a relevant digital service provider would be included if the ICO or AISI determines that the provision of a service poses a risk to public safety, national security or the security of network and information systems. Amendment 3 would do something similar for relevant managed service providers, with the ICO establishing whether a managed service provider poses a risk. Currently, services are excluded if they have fewer than 50 employees and a turnover equivalent to below £8.5 million—it is actually given in euros. I anticipate that the reasoning is not wanting to impose unnecessary burdens on small and micro-sized businesses with fewer employees and resources. I recognise that that is as a concern, but it is equally important to understand that small businesses of all kinds, including those that host critical services and infrastructure in the UK, are regularly victims of cyber attacks. The Government’s own Cyber Security Breaches Survey for 2025-26 records that 42% of micro-sized business and 46% of small businesses in the UK have been the target of cyber attacks. It is simply not the case that small means that risks are contained. The Government’s own figures show that, of the more than 100,000 UK tech companies, 95% have fewer than 50 employees.

These amendments would replicate the rationale of amendments to the then Online Safety Bill from the noble Baroness, Lady Morgan, on Report. I know that she would have liked to be here to speak to them, but she is unable to be here today. Her amendments stipulated that services under the Online Safety Bill should be categorised by risk or size. I will not rehearse what noble Lords have heard many times, but the lesson of that Bill is that the Government of the day got it wrong, as did the regulator. In the connected world, a small component of a global system can cause havoc.

When this Bill first entered the other place, I went to a briefing by Politico where its four experts spoke repeatedly about how narrow the Bill was and how focused it was on providing for a small subset of issues relating to cyber security and safety with a vision of hyperscale vendors. They were a combination of exasperated and incredulous that, even as we saw the increasing cost to the economy, the damage to businesses caught up in it and the devastation to individuals, as well as what all agreed was a national security threat, the Government had not sought to offer a vision for how all these might be protected. When it came to questions, the first was to ask why the experts thought the Government had been so unambitious. The answer was unedifying: to prevent the Lords hijacking the Bill.

I hope that the new Administration who start today have moved on and that we will have a more collegiate approach. I have read all the amendments currently laid, including the ones in this group, and in almost all cases they seek to do what is the stated intention of the Bill: to make the country more resilient. In the world of cyber security, size is not a proxy for risk; it is much more complex than that. The amendments in my name and those of others seek to ensure that we learn lessons from the Online Safety Act. I beg to move.

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - -

My Lords, I support Amendments 3, 8 and 13 in the name of the noble Baroness, Lady Kidron, to which I have added my name. I will not repeat too much all her comments on our learning from the Online Safety Act that small does not mean low risk. However, it should not be a surprise that those of us who championed that amendment to the then Online Safety Bill have again put our names to it. We have learned the hard way that, in online safety, risk can come from the smallest providers.

I have learned it personally. I retired from TalkTalk 10 years ago and I remember, what must have been 11 years ago—I promise this is not a cyber attack story—a mapping exercise across all the telcos, mobile and fixed, looking at our even then incredibly complex data centre networks across Europe. I am sure this has all changed and is much more complex, but I remember discovering, as a result of that exercise, that all of us were routing traffic through the same small data centre in central Europe and none of us was aware that we were doing so. These networks are expanding so fast and data centres and managed service providers are growing so fast that it is impossible for people to retain perfect knowledge 100% of the time, so a small provider really can be a node that brings down the whole network. It is not just in child safety that we have learned that small can mean very risky; it is also the case in the world of physical digital infrastructure, which we have known for some time in telecoms. That is why these amendments are so important.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- Hansard - - - Excerpts

My Lords, these amendments confront us immediately with some of the Bill’s most fundamental potential structural weaknesses—the danger of a static, arbitrary and pre-digital scope. The Government appear to have conceded this point already by tabling those infamous 65 high-risk vendor amendments in the previous group. Let us look first at Amendment 3 in the name of the noble Baroness, Lady Kidron, which I would have signed if there had been room.

As drafted, the Bill brings data centres into scope, relying entirely on rigid physical megawatt thresholds—specifically a rated IT load of 1 megawatt, or 10 megawatts for enterprise facilities. In the modern cloud ecosystem, physical power load is a crude and unreliable proxy for risk. A highly dense, interconnected facility drawing under 1 megawatt can host the critical patient records of multiple NHS trusts, emergency dispatch telemetry or core local government routing directories. If that facility is compromised, the societal and economic devastation will be catastrophic, regardless of how much electricity it pulls from the grid—the noble Baroness drew the parallels with NHS data centres.

Amendment 3 would provide the essential statutory fix. It would empower Ofcom to apply a risk-based designation that looks beyond physical power to evaluate the customer base, data sensitivity and critical interconnectivity. I listened with considerable interest and sympathy to what the noble Baronesses, Lady Kidron and Lady Harding, had to say about parallels with the Online Safety Act, which is engraved on our hearts.

--- Later in debate ---
There now seems to be an intention to fill, at least partially, the AI-shaped hole in the Bill through new government amendments. A logical conclusion of this is to give AISI proportionate regulatory powers to go with these amendments. Establishing AISI as an independent statutory body would give it the mandate and legislative framework needed to safeguard public safety in the face of fast-growing threats from agentic AI while maintaining its world-class evaluation capabilities.
Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - -

My Lords, I support Amendment 75 from the noble Baroness, Lady Kidron, and Amendment 84 in the name of the noble Lord, Lord Clement-Jones, both of which I have added my name to, but I also support all the amendments in the name of the noble Lord, Lord Tarassenko, that I was not smart enough to get my name to last week.

This group of amendments demonstrates not just the AI-shaped hole in the Bill but the complete absence of an AI Bill. It worries me that in one group, of a Tuesday afternoon, no more than 25 Peers are discussing such really big and important issues. We are really letting our country down and not building on the strengths that the noble Lord, Lord Tarassenko, set out that we have in this space by not debating this properly.

The Governor of the Bank of England also sent an open letter at the weekend, from the G20 Finance Ministers’ meeting:

“Recent developments have also highlighted to me that many jurisdictions do not have the protocols in place to manage the development, release, and deployment of advanced frontier AI models, heightening risks for the financial sector and beyond”.


He was speaking as the chair of the Financial Stability Board, the global financial stability regulator. He continued:

“Taking appropriate steps to support safe and responsible model release and deployment on a global basis should in my view be a priority and would benefit all sectors of the economy”.


We should not try to shoehorn this into a cyber security Bill but we have no other choice, which is why I have added my name to these two substantial amendments. I think that both the “red line” amendment, Amendment 75, and the “last resort” amendment, Amendment 84, provide two fundamental elements of regulating AI. I expect that we will hear that it is not appropriate to do it yet, to which the question is, “When?”

In the physical world, we know that just because you can do something, it does not mean that you should. We do not allow people to design new automatic weapons and carry them around on the streets, but it really worries me that, in the AI space, we are quite happy to let people launch things and then have a cyber security Bill to deal with the consequences after the event, whereas it seems entirely logical and just basic common sense to establish what should not be allowed, which is what Amendment 75 aims to do. And if someone launches something that is causing considerable harm, we need to be able to stop it, which is what Amendment 84 would do.

The amendments from the noble Lord, Lord Tarassenko, are great amendments because they are not creating a new regulator; they would give one that is not yet an official regulator but is doing outstanding global work the legal footing and legitimacy to build on that. I view all these, individually, as very substantive improvements in our nascent approach to AI regulation, and I fear that we and our successors will look back in sorrow at our inability to grasp this particular nettle now, because I do not know who else is going to. I think we actually have an opportunity in this country to do it, and it is set out in the scope of these amendments.

Lord Holmes of Richmond Portrait Lord Holmes of Richmond (Con)
- Hansard - - - Excerpts

My Lords, it is a pleasure to support all the amendments in this group. In one set of amendments in Committee, we have more on AI than in not just the cyber Bill but across most government legislation—past, present and, tragically, probably largely future.

As has already been mentioned and was covered, widely and rightly, at Second Reading, there is a huge gaping hole at the centre of this Bill, a silence that booms around the entire Bill, and that is all things AI. It seems unfortunate that we were told at Second Reading, and probably will be today, that the Bill is not the place for AI. Well, maybe it is not, but it certainly is in that no previous opportunities have been taken. As was mentioned, there was one line in the 2024 King’s Speech: something around frontier models with AI. There have been various other nods and winks. There was a Bill potentially ready to go at the end of autumn 2024; nothing came, and still we have nothing. So now we have a cyber Bill. It would be extraordinary if the Bill did not not only consider AI but have the thread of AI running right through it. What is behind so many of the difficulties, the clear, present and real dangers that the Minister has set out? Well, it may be said to be cyber at the front end, but AI is the grunt, brute force driving so much of this, and that is what all the amendments in this group speak to.

The noble Lord, Lord Tarassenko, was right to highlight the excellent work of AISI, but again, as we have seen with previous regulators, for want of proper action when it comes to AI, and indeed other technologies, numerous Governments have just piled on more and more requirements and obligations on various regulators, as if somehow they are going to be able to manage this. This is what we are already seeing with AISI. AISI is world-renowned and rightly respected, but it is already being asked to do an increasing number of tasks without the statutory footing or the resourcing to enable it to continue to do that at world class and at the leading edge. When the Minister comes to respond, I would be very interested if she would update the Committee on how she sees the role of AISI going forward. It is in the right position and is perfectly formed for the task, but statutory underpinning and resourcing would make such a significant difference.

If the Government fail to accept these amendments, or indeed, if they so prefer, fail to bring forward amendments of their own, we will have a very narrow and specific piece of cyber legislation. It will be good in that it is the first piece of legislation to have “Cyber” in its title—good in so far as that goes—but it is unfortunate that the legislation sees not only cyber but technology through the view, which has largely washed across from the United States, that it is all about big players, as if AI were only about these LLMs, or frontier models or whatever nomenclature one chooses. “The journey of AI has been up to this point; this is the zenith and the focus should be on these large so-called AI models.” Not a bit of it—they are but one element of a far more complex constellation.

Taking a broader view would enable the Government not only to have the right thread of AI running through the Bill but to be far more UK-focused and context rich, and it would put AI in the Bill in a way which would enable adaptability and agility going forward, rather than potentially trapping ourselves with one specific view of AI or leaving ourselves at the will of all these organisations, individuals and entities that use various AI to attack us. With no or little AI, or only euphemistic nods and winks to it, throughout the Bill, I believe we need to have a rewrite of the entire Bill. This group of amendments is a very good start in that direction.

Online Safety Bill

Baroness Harding of Winscombe Excerpts
Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- View Speech - Hansard - -

My Lords, I promise I will be brief. I, too, welcome what the Minister has said and the amendments that the Government have proposed. This is the full package which we have been seeking in a number of areas, so I am very pleased to see it. My noble friend Lady Newlove and the noble Baroness, Lady Kidron, are not in their places, but I know I speak for both of them in wanting to register that, although the thoughtful and slow-and-steady approach has some benefits, there also some real costs to it. The UK Safer Internet Centre estimates that there will be some 340,000 individuals in the UK who will have no recourse for action if the platforms complaints mechanism does not work for them in the next two years. That is quite a large number of people, so I have one very simple question for the Minister: if I have exhausted the complaints procedure with an existing platform in the next two years, where do I go? I cannot go to Ofcom. My noble friend Lord Grade was very clear in front of the committee I sit on that it is not Ofcom’s job. Where do I go if I have a complaint that I cannot get resolved in the next two years?

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - - - Excerpts

My Lords, I declare an interest as chair of Trust Alliance Group, which operates the energy and communications ombudsman schemes, so I have a particular interest in the operation of these ADR schemes. I thank the Minister for the flexibility that he has shown in the provision about the report by Ofcom and in having backstop powers for the Secretary of State to introduce such a scheme.

Of course, I understand that the noble Baroness, Lady Newlove, and the UK Safer Internet Centre are very disappointed that this is not going to come into effect immediately, but there are advantages in not setting out the scheme at this very early point before we know what some of the issues arising are. I believe that Ofcom will definitely want to institute such a scheme, but it may be that, in the initial stages, working out the exact architecture is going to be necessary. Of course, I would have preferred to have a mandated scheme, in the sense that the report will look not at the “whether” but the “how”, but I believe that at the end of the day it will absolutely obvious that there needs to be such an ADR scheme in order to provide the kind of redress the noble Baroness, Lady Harding, was talking about.

I also agree with noble Baroness, Lady Morgan, that the kinds of complaints that this would cover should include fraudulent adverts. I very much hope that the Minister will be able to answer the questions that both noble Baronesses asked. As my noble friend said, will he reassure us that the department and Ofcom will not take their foot off the pedal, whatever the Bill may say?

--- Later in debate ---
Moved by
240: Clause 82, page 74, line 25, leave out “presented by content”
Member’s explanatory statement
This amendment ensures that Ofcom is empowered to consider harms presented by features, functionalities, behaviours and the design and operation of services not just by content.
Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - -

My Lords, if I may, I shall speak very briefly, in the absence of my noble friend Lady Kidron, and because I am one of the signatories of this amendment, alongside the noble Lord, Lord Stevenson, and the right reverend Prelate the Bishop of Oxford. Amendment 240, together with a number of amendments that we will be debating today, turns on a fundamental issue that we have not yet resolved.

I came in this morning being told that we would be voting on this amendment and that other amendments later today would be consequential—I am a novice at this level of parliamentary procedure, so forgive me if I have got myself confused during the day—but I now understand that my noble friend considers this amendment to be consequential but, strangely, the amendments right at the end of the day are not. I just wanted to flag to the House that they all cover the same fundamental issue of whether harms can be unrelated to content, whether the harms of the online world can be to do with functionality—the systems and processes that drive the addiction that causes so much harm to our children.

It is a fundamental disagreement. I pay tribute to the amount of time the department, the Secretary of State and my noble friend have spent on it, but it is not yet resolved and, although I understand that I should now say that I beg leave to move the amendment formally, I just wanted to mark, with apologies, the necessity, most likely, of having to bring the same issue back to vote on later today.

Lord Parkinson of Whitley Bay Portrait Lord Parkinson of Whitley Bay (Con)
- View Speech - Hansard - - - Excerpts

My Lords, His Majesty’s Government indeed agree that this is consequential on the other amendments, including Amendment 35, which the noble Baroness, Lady Kidron, previously moved at Report. We disagreed with them, but we lost that vote; this is consequential, and we will not force a Division on it.

We will have further opportunity to debate the fundamental issues that lie behind it, to which my noble friend Lady Harding just referred. Some of the amendments on which we may divide later, the noble Baroness, Lady Kidron, tabled after defeating the Government the other day, so we cannot treat them as consequential. We look forward to debating them; I will urge noble Lords not to vote for them, but we will have opportunity to discuss them later.

--- Later in debate ---
Lord Kamall Portrait Lord Kamall (Con)
- Hansard - - - Excerpts

My Lords, I rise to speak in favour of my noble friend Lord Moylan’s amendment. Given that I understand he is not going to press it, and while I see Amendment 255 as the ideal amendment, I thank the noble Lords, Lord Stevenson and Lord Clement- Jones, for their Amendments 256, 257 and 259, and the noble Lords, Lord Clement-Jones and Lord Allan of Hallam, for Amendments 258 and 258ZA.

I will try to be as brief as I can. I think about two principles—unintended consequences and the history of technology transfer. The point about technology transfer is that once a technology is used it becomes available to other people quickly, even bad guys, whether that was intended or not. There is obviously formal technology transfer, where you have agreement or knowledge transfer via foreign investment, but let us think about the Cold War and some of the great technological developments—atomic secrets, Concorde and the space shuttle. In no time at all, the other side had that access, and that was before the advent of the internet.

If we are to open a door for access to encrypted messages, that technology will be available to the bad guys in no time at all, and they will use it against dissidents, many of whom will be in contact with journalists and human rights organisations in this country and elsewhere. Therefore, the unintended consequence may well be that in seeking to protect children in this country by accessing encrypted messages or unencrypted messages, we may well be damaging the childhoods of children in other countries when their parents, who are dissidents, are suddenly taken away and maybe the whole family is wiped out. Let us be careful about those unintended consequences.

I also welcome my noble friend Lord Parkinson’s amendments about ensuring journalistic integrity, such as Amendment 257D and others. They are important. However, we must remember that once these technologies are available, everyone has a price and that technology will be transferred to the bad guys.

Given that my noble friend Lord Moylan will not press Amendment 255, let us talk about some of the other amendments—I will make some general points rather than go into specifics, as many noble Lords have raised these points. These amendments are sub-optimal, but at least there is some accountability for Ofcom being able to use this power and using it sensibly and proportionately. One of the things that has run throughout this Bill and other Bills is “who regulates the regulators?” and ensuring that regulators are accountable. The amendments proposed by the noble Lords, Lord Stevenson and Lord Clement-Jones, and by the noble Lords, Lord Clement-Jones and Lord Allan of Hallam, go some way towards ensuring that safeguards are in place. If the Government are not prepared to have an explicit statement that they will not allow access to encrypted messages, I hope that there will be some support for the noble Lords’ amendments.

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- View Speech - Hansard - -

My Lords, I promise to speak very briefly. I welcome the Government’s amendments. I particularly welcome that they appear to mirror partly some of the safeguards that are embedded in the Investigatory Powers Act 2016.

I have one question for my noble friend the Minister about the wording, “a skilled person”. I am worried that “a skilled person” is a very vague term. I have been taken all through the course of this Bill by the comparison with the Investigatory Powers Act and the need to think carefully about how we balance the importance of privacy with the imperative of protecting our children and being able to track down the most evil and wicked perpetrators online. That is very similar to the debates that we had here several years ago on the Investigatory Powers Act.

The IPA created the Technical Advisory Board. It is not a decision-making body. Its purpose is to advise the Investigatory Powers Commissioner and judicial commissioners on the impact of changing technology and the development of techniques to use investigatory powers while maintaining privacy. It is an expert panel constituted to advise the regulator—in this case, the judicial commissioner—specifically on technology interventions that must balance this really difficult trade-off between privacy and child protection. Why have we not followed the same recipe? Rather than having a skilled person, why would we not have a technology advisory panel of a similar standing where it is clear to all who the members are. Those members would be required to produce a regular report. It might not need to be as regular as the IPA one, but it would just take what the Government have already laid one step further towards institutionalising the independent check that is really important if these Ofcom powers were ever to be used.

Baroness Stowell of Beeston Portrait Baroness Stowell of Beeston (Con)
- View Speech - Hansard - - - Excerpts

My Lords, I added my name to some amendments on this issue in Committee. I have not done so on Report, not least because I have been so occupied with other things and have not had the time to focus on this. However, I remain concerned about this part of the Bill. I am sympathetic to my noble friend Lord Moylan’s Amendment 255, but listening to this debate and studying all the amendments in this group, I am a little confused and so have some simple questions.

First, I heard my noble friend the Minister say that the Government have no intention to require the platforms to carry out general monitoring, but is that now specific in any of the amendments that he has tabled? Regarding the amendments which would bring further safeguards around the oversight of Ofcom’s use of this power, like my noble friend Lady Harding, I have always been concerned that the oversight approach should be in line with that for the Investigatory Powers Act and could never understand why it was not in the original version of the Bill. Like her, I am pleased that the Government have tabled some amendments, but I am not yet convinced that they go far enough.

That leads me to the amendments that have been tabled by the noble Lords, Lord Stevenson and Lord Clement-Jones, and particularly that in the name of the noble Lord, Lord Allan of Hallam. As his noble friend Lord Clement-Jones has added his name to it, perhaps he could answer my question when he gets up. Would the safeguards that are outlined there—the introduction of the Information Commissioner—meet the concerns of the big tech companies? Do we know whether it would meet their needs and therefore lead them not to feel it necessary to withdraw their services from the UK? I am keen to understand that.

There is another thing that might be of benefit for anyone listening to this debate who is not steeped in the detail of this Bill, and I look to any of those winding up to answer it—including my noble friend the Minister. Is this an end to end-to-end encryption? Is that what is happening in this Bill? Or is this about ensuring that what is already permissible in terms of the authorities being able to use their powers to go after suspected criminals is somehow codified in this Bill to make sure it has proper safeguards around it? That is still not clear. It would be very helpful to get that clarity from my noble friend, or others.

--- Later in debate ---
Moved by
281BA: Clause 208, page 175, line 5, at end insert—
“(3A) In this Act “functionality”, in relation to a regulated service, includes the design of systems and processes that engage or impact on users, particularly algorithms.”Member’s explanatory statement
This amendment clarifies the role that system design can impact on outcomes on users in light of the requirement for systems to be safe by design.
--- Later in debate ---
Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - -

My Lords, I note that the noble Lord, Lord Stevenson, is no longer in his place, but I promise to still try to live by his admonition to all of us to speak briefly.

I will speak to Amendments 281BA, 281FA, 286A and 281F, which has already been debated but is central to this issue. These amendments aim to fix a problem we repeatedly raised in Committee and on Report. They are also in the name of the noble Baroness, Lady Kidron, and the noble Lords, Lord Stevenson and Lord Clement-Jones, and build on amendments in Committee laid by the noble Lord, Lord Russell, my noble friend Lord Bethell and the right reverend Prelate the Bishop of Oxford. This issue has broad support across the whole House.

The problem these amendments seek to solve is that, while the Government have consistently asserted that this is a systems and processes Bill, the Bill is constructed in a manner that focuses on content. Because this is a rerun of previous debates, I will try to keep my remarks short, but I want to be clear about why this is a real issue.

I am expecting my noble friend the Minister to say, as he has done before, that this is all covered; we are just seeing shadows, we are reading the Bill wrong and the harms that we are most concerned about are genuinely in the Bill. But I really struggle to understand why, if they are in the Bill, stating them clearly on the face of the Bill creates the legal uncertainty that seems to be the Government’s favourite problem with each of the amendments we have been raising today.

My noble friend—sorry, my friend—the noble Baroness, Lady Kidron, commissioned a legal opinion that looked at the statements from the Government and compared it to the text in the Bill. That opinion, like that of the many noble Lords I have just mentioned, is that the current language in the Bill about features and functionalities only pertains as far as it relates to harmful content. All roads in this game of Mornington Crescent lead back to content.

Harmful content is set out in a schedule to the Bill, and this set of amendments ensures that the design of services, irrespective of content, is required to be safe by design. If the Government were correct in their assertion that this is already covered, then these amendments really should not pose any threat at all, and I have yet to hear the Government enunciate what the real legal uncertainty actually is in stating that harm can come from functionality, not just from content.

--- Later in debate ---
Lord Parkinson of Whitley Bay Portrait Lord Parkinson of Whitley Bay (Con)
- View Speech - Hansard - - - Excerpts

My Lords, this is not just a content Bill. The Government have always been clear that the way in which a service is designed and operated, including its features and functionalities, can have a significant impact on the risk of harm to a user. That is why the Bill already explicitly requires providers to ensure their services are safe by design and to address the risks that arise from features and functionalities.

The Government have recognised the concerns which noble Lords have voiced throughout our scrutiny of the Bill, and those which predated the scrutiny of it. We have tabled a number of amendments to make it even more explicit that these elements are covered by the Bill. We have tabled the new introductory Clause 1, which makes it clear that duties on providers are aimed at ensuring that services are safe by design. It also highlights that obligations on services extend to the design and operation of the service. These obligations ensure that the consideration of risks associated with the business model of a service is a fundamental aspect of the Bill.

My noble friend Baroness Harding of Winscombe worried that we had made the Bill worse by adding this. The new clause was a collaborative one, which we have inserted while the Bill has been before your Lordships’ House. Let me reassure her and other noble Lords as we conclude Report that we have not made it worse by so doing. The Bill will require services to take a safety by design approach to the design and operation of their services. We have always been clear that this will be crucial to compliance with the legislation. The new introductory Clause 1 makes this explicit as an overarching objective of the Bill. The introductory clause does not introduce any new concepts; it is an accurate summary of the key provisions and objectives of the Bill and, to that end, the framework and introductory statement are entirely compatible.

We also tabled amendments—which we debated last Monday—to Clause 209. These make it clear that functionalities contribute to the risk of harm to users, and that combinations of functionality may cumulatively drive up the level of risk. Amendment 281BA would amend the meaning of “functionality” within the Bill, so that it includes any system or process which affects users. This presents a number of concerns. First, such a broad interpretation would mean that any service in scope of the Bill would need to consider the risk of any feature or functionality, including ones that are positive for users’ online experience. That could include, for example, processes designed for optimising the interface depending on the user’s device and language settings. The amendment would increase the burden on service providers under the existing illegal content and child safety duties and would dilute their focus on genuinely risky functionality and design.

Second, by duplicating the reference to systems, processes and algorithms elsewhere in the Bill, it implies that the existing references in the Bill to the design of a service or to algorithms must be intended to capture matters not covered by the proposed new definition of “functionality”. This would suggest that references to systems and processes, and algorithms, mentioned elsewhere in the Bill, cover only systems, processes or algorithms which do not have an impact on users. That risks undermining the effectiveness of the existing duties and the protections for users, including children.

Amendment 268A introduces a further interpretation of features and functionality in the general interpretation clause. This duplicates the overarching interpretation of functionality in Clause 208 and, in so doing, introduces legal and regulatory uncertainty, which in turn risks weakening the existing duties. I hope that sets out for my noble friend Lady Harding and others our legal concerns here.

Amendment 281FA seeks to add to the interpretation of harm in Clause 209 by clarifying the scenarios in which harm may arise, specifically from services, systems and processes. This has a number of concerning effects. First, it states that harm can arise solely from a system and process, but a design choice does not in isolation harm a user. For example, the decision to use algorithms, or even the algorithm itself, is not what causes harm to a user—it is the fact that harmful content may be pushed to a user, or content pushed in such a manner that is harmful, for example repeatedly and in volume. That is already addressed comprehensively in the Bill, including in the child safety risk assessment duties.

Secondly, noble Lords should be aware that the drafting of the amendment has the effect of saying that harm can arise from proposed new paragraphs (a) (b) and (c)—

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- View Speech - Hansard - -

Can I just double-check what my noble friend has just said? I was lulled into a possibly false sense of security until we got to the point where he said “harmful” and then the dreaded word “content”. Does he accept that there can be harm without there needing to be content?

--- Later in debate ---
Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - -

My Lords, being the understudy for the noble Baroness, Lady Kidron, is quite a stressful thing. I am, however, reliably informed that she is currently offline in the White House, but I know that she will scrutinise everything I say afterwards and that I will receive a detailed school report tomorrow.

I am extremely grateful to my noble friend the Minister for how he has just summed up, but I would point out two things in response. The first is the circularity of the legal uncertainty. What I think I have heard is that we are trying to insert into the Bill some clarity because we do not think it is clear, but the Government’s concern is that by inserting clarity, we then imply that there was not clarity in the rest of the Bill, which then creates the legal uncertainty—and round we go. I am not convinced that we have really solved that problem, but I may be one step further towards understanding why the Government think that it is a problem. I think we have to keep exploring that and properly bottom it out.

My second point is about what I think will for evermore be known as the marshmallow problem. We have just rehearsed across the House a really heartfelt concern that just because we cannot imagine it today, it does not mean that there will not be functionality that causes enormous harm which does not link back to a marshmallow, multiple marshmallows or any other form of content.

Those two big issues are the ones we need to keep discussing: what is really causing the legal uncertainty and how we can be confident that unimaginable harms from unimaginable functionality are genuinely going to be captured in the Bill. Provided that we can continue, maybe it is entirely fitting at the end of what I think has been an extraordinarily collaborative Report, Committee and whole process of the Bill going through this House—which I have felt incredibly proud and privileged to be a part of—that we end with a commitment to continue said collaborative process. With that, I beg leave to withdraw the amendment.

Amendment 281BA withdrawn.

Online Safety Bill

Baroness Harding of Winscombe Excerpts
Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- View Speech - Hansard - -

My Lords, I will speak briefly on a couple of amendments and pick up from where the noble Lord, Lord Allan, just finished on Amendment 186A. I associate myself with all the comments that the noble Baroness, Lady Kidron, made on her Amendment 191A. As ever, she introduced the amendment so brilliantly that there is no need for me to add anything other than my wholehearted support.

I will briefly reference Amendment 253 from the noble Lord, Lord Clement-Jones. Both his amendment and my noble friend Lord Moylan’s point to one of the challenges about regulating the digital world, which is that it touches everything. We oscillate between wanting to compartmentalise the digital and recognising that it is interconnected to everything. That is the same challenge faced by every organisation that is trying to digitise: do you ring-fence or recognise that it touches everything? I am very supportive of the principles behind Amendment 253 precisely because, in the end, it does touch everything. It is hugely important that, even though this Bill and others still to come are creating an extraordinarily powerful single regulator in the form of Ofcom, we also recognise the interconnectivity of the regulatory landscape. The amendment is very well placed, and I hope my noble friend the Minister looks favourably on it and its heritage from the pre-legislative scrutiny committee.

I will briefly add my thoughts on Amendment 186A in this miscellaneous group. It feels very much as if we are having a Committee debate on this amendment, and I thank my noble friend Lord Moylan for introducing it. He raises a hugely important point, and I am incredibly sympathetic to the logic he set out.

In this area the digital world operates differently from the physical world, and we do not have the right balance at all between the powers of the big companies and consumer rights. I am completely with my noble friend in the spirit in which he introduced the amendment but, together with the noble Lord, Lord Allan, I think it would be better tackled in the Digital Markets, Competition and Consumers Bill, precisely because it is much broader than online safety. This fundamentally touches the issue of consumer rights in the digital world and I am worried that, if we are not careful, we will do something with the very best intentions that actually makes things slightly worse.

I worry that the terms and conditions of user-to-user services are incomprehensible to consumers today. Enshrining it as a contract in law might, in some cases, make it worse. Today, when user-to-user services have used our data for something, they are keen to tell us that we agreed to it because it was in their terms of service. My noble friend opens up a really important issue to which we should give proper attention when the Digital Markets, Competition and Consumers Bill arrives in the House. It is genuinely not too late to address that, as it is working its way through the Commons now. I thank my noble friend for introducing the amendment, because we should all have thought of the issue earlier, but it is much broader than online safety.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - - - Excerpts

My Lords, even by previous standards, this is the most miscellaneous of miscellaneous groups. We have ranged very broadly. I will speak first to Amendment 191A from the noble Baroness, Lady Kidron, which was so well spoken to by her and by the noble Baroness, Lady Harding. It is common sense, and my noble friend Lord Allan, as ever, put his finger on it: it is not as if coroners are going to come across this every day of the week; they need this kind of guidance. The Minister has introduced his amendments on this, and we need to reduce those to an understandable code for coroners and bereaved parents. I defy anybody, apart from about three Members of this House, to describe in any detail how the information notices will interlock and operate. I could probably name those Members off the top of my head. That demonstrates why we need such a code of practice. It speaks for itself.

I am hugely sympathetic to Amendment 275A in the name of the noble Baroness, Lady Finlay, who asked a series of important questions. The Minister said at col. 1773 that he would follow up with further information on the responsibility of private providers for their content. This is a real, live issue. The noble Baroness, Lady Kidron, put it right: we hope fervently that the Bill covers the issue. I do not know how many debates about future-proofing we have had on the Bill but each time, including in that last debate, we have not quite been reassured enough that we are covering the metaverse and provider content in the way we should be. I hope that this time the Minister can give us definitive chapter and verse that will help to settle the horses, so to speak, because that is exactly what the very good amendment in the name of the noble Baroness, Lady Finlay, was about.

--- Later in debate ---
For that reason, I again ask the Government, as a minimum, to accept the shorter date that was proposed or perhaps to think again before Third Reading.
Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- View Speech - Hansard - -

My Lords, I associate myself with my noble friend Lady Fraser of Craigmaddie’s incredibly well-made points. I learned a long time ago that, when people speak very softly and say they have a very small point to make, they are often about to deliver a zinger. She really did; it was hugely powerful. I will say no more than that I wholeheartedly agree with her; thank you for helping us to understand the issue properly.

I will speak in more detail about access to data for researchers and in support of my noble friend Lord Bethell’s amendments. I too am extremely grateful to the Minister for bringing forward all the government amendments; the direction of travel is encouraging. I am particularly pleased to see the movement from “may” to “must”, but I am worried that it is Ofcom’s rather than the regulated services’ “may” that moves to “must”. There is no backstop for recalcitrant regulated services that refuse to abide by Ofcom’s guidance. As the noble Baroness, Lady Kidron, said, in other areas of the Bill we have quite reasonably resorted to launching a review, requiring Ofcom to publish its results, requiring the Secretary of State to review the recommendations and then giving the Secretary of State backstop powers, if necessary, to implement regulations that would then require regulated companies to change.

I have a simple question for the Minister: why are we not following the same recipe here? Why does this differ from the other issues, on which the House agrees that there is more work to be done? Why are we not putting backstop powers into the Bill for this specific issue, when it is clear to all of us that it is highly likely that there will be said recalcitrant regulated firms that are not willing to grant access to their data for researchers?

Before my noble friend the Minister leaps to the hint he gave in his opening remarks—that this should all be picked up in the Data Protection and Digital Information Bill—unlike the group we have just discussed, this issue was discussed at Second Reading and given a really detailed airing in Committee. This is not new news, in the same way that other issues where we have adopted the same recipe that includes a backstop are being dealt with in the Bill. I urge my noble friend the Minister to follow the good progress so far and to complete the package, as we have in other areas.

Lord Moylan Portrait Lord Moylan (Con)
- View Speech - Hansard - - - Excerpts

My Lords, it is valuable to be able to speak immediately after my noble friend Lady Harding of Winscombe, because it gives me an opportunity to address some remarks she made last Wednesday when we were considering the Bill on Report. She suggested that there was a fundamental disagreement between us about our view of how serious online safety is—the suggestion being that somehow I did not think it was terribly important. I take this opportunity to rebut that and to add to it by saying that other things are also important. One of those things is privacy. We have not discussed privacy in relation to the Bill quite as much as we have freedom of expression, but it is tremendously important too.

Government Amendment 247A represents the most astonishing level of intrusion. In fact, I find it very hard to see how the Government think they can get away with saying that it is compatible with the provisions of the European Convention on Human Rights, which we incorporated into law some 20 years ago, thus creating a whole law of privacy that is now vindicated in the courts. It is not enough just to go around saying that it is “proportionate and necessary” as a mantra; it has to be true.

This provision says that an agency has the right to go into a private business with no warrant, and with no let or hindrance, and is able to look at its processes, data and equipment at will. I know of no other business that can be subjected to that without a warrant or some legal process in advance pertinent to that instance, that case or that business.

My noble friend Lord Bethell said that the internet has been abused by people who carry out evil things; he mentioned terrorism, for example, and he could have mentioned others. However, take mobile telephones and Royal Mail—these are also abused by people conducting terrorism, but we do not allow those communications to be intruded into without some sort of warrant or process. It does not seem to me that the fact that the systems can be abused is sufficient to justify what is being proposed.

My noble friend the Minister says that this can happen only offline. Frankly, I did not understand what he meant by that. In fact, I was going to say that I disagreed with him, but I am moving to the point of saying that I think it is almost meaningless to say that it is going to happen offline. He might be able to explain that. He also said that Ofcom will not see individual traffic. However, neither the point about being offline nor the point about not seeing individual traffic is on the face of the Bill.

When we ask ourselves what the purpose of this astonishing power is—this was referred to obliquely to some extent by the noble Baroness, Lady Fox of Buckley—we can find it in Clause 91(1), to which proposed new subsection (2A) is being added or squeezed in subordinate to it. Clause 91(1) talks about

“any information that they”—

that is, Ofcom—

“require for the purpose of exercising, or deciding whether to exercise, any of their online safety functions”.

The power could be used entirely as a fishing expedition. It could be entirely for the purpose of educating Ofcom as to what it should be doing. There is nothing here to say that it can have these powers of intrusion only if it suspects that there is criminality, a breach of the codes of conduct or any other offence. It is a fishing expedition, entirely for the purpose of

“exercising, or deciding whether to exercise”.

Those are the intrusions imposed upon companies. In some ways, I am less concerned about the companies than I am about what I am going to come to next: the intrusion on the privacy of individuals and users. If we sat back and listened to ourselves and what we are saying, could we explain to ordinary people—we are going to come to this when we discuss end-to-end encryption—what exactly can happen?

Two very significant breaches of the protections in place for privacy on the internet arise from what is proposed. First, if you allow someone into a system and into equipment, especially from outside, you increase the risk and the possibility that a further, probably more hostile party that is sufficiently well-equipped with resources—we know state actors with evil intent which are so equipped—can get in through that or similar holes. The privacy of the system itself would be structurally weakened as a result of doing this. Secondly, if Ofcom is able to see what is going on, the system becomes leaky in the direction of Ofcom. It can come into possession of information, some of which could be of an individual character. My noble friend says that it will not be allowed to release any data and that all sorts of protections are in place. We know that, and I fully accept the honesty and integrity of Ofcom as an institution and of its staff. However, we also know that things get leaked and escape. As a result of this provision, very large holes are being built into the protections of privacy that exist, yet there has been no reference at all to privacy in the remarks made so far by my noble friend.

I finish by saying that we are racing ahead and not thinking. Good Lord, my modest amendment in the last group to bring a well-established piece of legislation—the Consumer Rights Act—to bear upon this Bill was challenged on the grounds that there had not been an impact assessment. Where is the impact assessment for this? Where is even the smell test for this in relation to explaining it to the public? If my noble friend is able to expatiate at the end on the implications for privacy and attempt to give us some assurance, that would be some consolation. I doubt that he is going to give way and do the right thing and withdraw this amendment.

--- Later in debate ---
Lord Parkinson of Whitley Bay Portrait Lord Parkinson of Whitley Bay (Con)
- Hansard - - - Excerpts

My Lords, we have had some productive discussions on application stores, commonly known as “app stores”, and their role as a gateway for children accessing online services. I am grateful in particular to my noble friend Lady Harding of Winscombe for her detailed scrutiny of this area and the collaborative approach she has taken in relation to it and to her amendments, to which I will turn in a moment. These share the same goals as the amendments tabled in my name in seeking to add evidence-based duties on app stores to protect children.

The amendments in my name will do two things. First, they will establish an evidence base on the use of app stores by children and the role that app stores play in children encountering harmful content online. Secondly, following consideration of this evidence base, the amendments also confer a power on the Secretary of State to bring app stores into scope of the Bill should there be a material risk of significant harm to children on or through them.

On the evidence base, Amendment 272A places a duty on Ofcom to publish a report on the role of app stores in children accessing harmful content on the applications of regulated services. To help build a greater evidence base about the types of harm available on and through different kinds of app stores, the report will consider a broad range of these stores, which could include those available on various devices, such as smartphones, gaming devices and smart televisions. The report will also assess the use and effectiveness of age assurance on app stores and consider whether the greater use of age assurance or other measures could protect children further.

Publication of the report must be two to three years after the child safety duties come into force so as not to interfere with the Bill’s implementation timelines. This timing will also enable the report to take into account the impact of the regulatory framework that the Bill establishes.

Amendment 274A is a consequential amendment to include this report in the Bill’s broader confidentiality provisions, meaning that Ofcom will need to exclude confidential matters—for example, commercially sensitive information—from the report’s publication.

Government Amendments 236A, 236B and 237D provide the Secretary of State with a delegated power to bring app stores into the scope of regulation following consideration of Ofcom’s report. The power will allow the Secretary of State to make regulations putting duties on app stores to reduce the risks of harm presented to children from harmful content on or via app stores. The specific requirements in these regulations will be informed by the outcome of the Ofcom report I have mentioned.

As well as setting out the rules for app stores, the regulations may also make provisions regarding the duties and functions of Ofcom in regulating app stores. This may include information-gathering and enforcement powers, as well as any obligations to produce guidance or codes of practice for app store providers.

By making these amendments, our intention is to build a robust evidence base on the potential risks of app stores for children without affecting the Bill’s implementation more broadly. Should it be found that duties are required, the Secretary of State will have the ability to make robust and comprehensive duties, which will provide further layers of protection for children. I beg to move.

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- View Speech - Hansard - -

My Lords, before speaking to my Amendment 239A, I thank my noble friend the Minister, the Secretary of State and the teams in both the department and Ofcom for their collaborative approach in working to bring forward this group of amendments. I also thank my cosignatories. My noble friend Lady Stowell cannot be in her place tonight but she has been hugely helpful in guiding me through the procedure, as have been the noble Lords, Lord Stevenson, Lord Clement-Jones and Lord Knight, not to mention the noble Baroness, Lady Kidron. It has been a proper cross-House team effort. Even the noble Lord, Lord Allan, who started out quite sceptical, has been extremely helpful in shaping the discussion.

I also thank the NSPCC and Barnardo’s for their invaluable advice and support, as well as Snap and Match—two companies which have been willing to stick their heads above the parapet and challenge suppliers and providers on which they are completely dependent in the shape of the current app store owners, Apple and Google.

I reassure my noble friend the Minister—and everyone else—that I have no intention of dividing the House on my amendment, in case noble Lords were worried. I am simply seeking some reassurance on a number of points where my amendments differ from those tabled by the Government—but, first, I will highlight the similarities.

As my noble friend the Minister has referred to, I am delighted that we have two packages of amendments that in both cases recognise that this was a really significant gap in the Bill as drafted. Ignoring the elements of the ecosystem that sell access to regulated services, decide age guidelines and have the ability to do age assurance was a substantial gap in the framing of the Bill. But we have also recognised together that it is very important that this is an “and” not an “or”—it is not instead of regulating user-to-user services or search but in addition to. It is an additional layer that we can bring to protect children online, and it is very important that we recognise that—and both packages do.

Viscount Colville of Culross Portrait Viscount Colville of Culross (CB)
- View Speech - Hansard - - - Excerpts

My Lords, the codes of practice are among the most important documents that Ofcom will produce as a result of the Bill—in effect, deciding what content we, the users of the internet, will see. The Government’s right to modify these drafts affects us all, so it is absolutely essential that the codes are trusted.

I, too, welcome the Government’s Amendments 134 to 138, which are a huge improvement on the Clause 39 that was presented in Committee. I am especially grateful that the Government have not proceeded with including economic conditions as a reason for the Secretary of State to modify draft codes, which the noble Baroness, Lady Harding, pointed out in Committee would be very damaging. But I would like the Minister to go further, which is why I put my name to Amendments 139, 140, 144 and 145.

Amendment 139 is so important at the moment. My fear is about the opt-out from publishing these directions from the Secretary of State for Ofcom to modify the draft codes, which will then allow them to be made behind closed doors between the Government and the regulator. This should not be allowed to happen. It would happen at a time when trust in the Government is low and there is a feeling that so many decisions affecting us all are taken without our knowledge. Surely it is right that there should be as much transparency as possible in exposing the pressure that the Minister is placing on the regulator. I hope that, if this amendment is adopted, it will allow Parliament to impose the bright light of transparency on the entire process, which is in danger of becoming opaque.

I am sure that no one wants a repeat of what happened under Section 94 of the Telecommunications Act 1984, which gave the Secretary of State power to give directions of a “general character” to anyone, in the “interests of national security” or international relations, as long as they did not disclose important information to Parliament. The Minister’s power to operate in total secrecy, without any accountability to Parliament, was seen by many as wrong and undemocratic. It was subsequently repealed. Amendments 139 and 140 will prevent the creation of a similar problem.

Likewise, I support Amendment 144, which builds on the previous amendments, as another brake on the control of the Secretary of State over this important area of regulations. Noble Lords in this House know how much the Government dislike legislative ping-pong—which we will see later this evening, I suspect. I ask the Minister to transfer this dislike to limiting ping-pong between the Government and the regulator over the drafting of codes of practice. It would also prevent the Secretary of State or civil servants expanding their control of the draft codes of practice from initial parameters to slightly wider sets of parameters each time that they are returned to the Minister for consideration. It will force the civil servants and the Secretary of State to make a judgment on the limitation of content and ensure that they stick to it. As it is, the Secretary of State has two bites of the cherry. They are involved in the original shaping of the draft codes of practice and then they can respond to Ofcom’s formulation. I hope the Minister would agree that it is sensible to stop this process from carrying on indefinitely. I want the users of the digital world to have full faith that the control of online content they see is above board —and not the result of secretive government overreach.

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- View Speech - Hansard - -

My Lords, not for the first time I find myself in quite a different place from my noble friend Lord Moylan. Before I go through some detailed comments on the amendments, I want to reflect that at the root of our disagreement is a fundamental view about how serious online safety is. The logical corollary of my noble friend’s argument is that all decisions should be taken by Secretaries of State and scrutinised in Parliament. We do not do that in other technical areas of health and safety in the physical world and we should not do that in the digital world, which is why I take such a different view—

Lord Moylan Portrait Lord Moylan (Con)
- Hansard - - - Excerpts

My Lords—

--- Later in debate ---
Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - -

Perhaps the noble Lord will allow me to make my point. I really welcome the government amendments in this group. I thank my noble friend the Minister for bringing them forward and for listening hard to the debates that we had at Second Reading and in Committee. I am very pleased to see the removal of economic policy and the burdens to business as one of the reasons that a Secretary of State could issue directions. I firmly believe that we should not be putting Secretaries of State in the position of having to trade off safety for economic growth. The reality is that big tech has found it impossible to make those trade-offs too. People who work in these companies are human beings. They are looking for growth in their businesses. Secretaries of State are rightly looking for economic growth in our countries. We should not be putting people in the position of trying to make that trade-off. The right answer is to defer to our independent regulator to protect safety. I thank my noble friend and the Government very much for tabling these amendments.

I also support my noble friend Lady Stowell, as a member of the Communications and Digital Committee that she chairs so ably. She has brought forward a characteristically thoughtful and detailed set of amendments in an attempt to look around the corners of these powers. I urge my noble friend the Minister to see whether he can find a way in the specific issues of infinite and secretive ping-pong. Taking the secretive, my noble friend Lady Stowell has found a very clever way of making sure that it is not possible for future Governments to obscure completely any direction that they are giving, while at the same time not putting at risk any national secrets. It is a very thoughtful and precise amendment. I very much hope that my noble friend the Minister can support it.

On the infinite nature of ping-pong, which I feel is quite ironic today—I am not sure anyone in this House welcomes the concept of infinite ping-pong right now, whatever our views on business later today—friends of mine in the business world ask me what is different about working in government versus working in the business world; I have worked in both big and small businesses. Mostly it is not different: people come to work wanting to do a good job and to further the objectives of the organisation that they are part of, but one of the biggest differences in government is that doing nothing and continuing to kick the can down the road is a much more viable option in the body politic than it is in the business world. Rarely is that for the good.

One of the things you learn in business is that doing nothing is often the very worst thing you can do. My worry about the infinite nature of the ping-pong is that it refers to a technical business world that moves unbelievably fast. What we do not need is to enshrine a system that enables government essentially to avoid doing anything. That is a particularly business and pragmatic reason to support my noble friend’s amendment. I stress that it is a very mild amendment. My noble friend Lady Stowell has been very careful and precise not to put unreasonable burdens on a future Secretary of State. In “Yes Minister”-speak, the bare minimum could be quite a lot. I urge my noble friend the Minister to look positively on what are extremely constructive amendments, delivered in a very thoughtful way.

Online Safety Bill

Baroness Harding of Winscombe Excerpts
I have another question, on Amendment 249, which is on information notices specifically about child deaths. I do not want to broaden this out, but we need to flag that we will need some clarity around what assistance can be given to people where the death is of someone who is not a child. There will be situations that are important to families and where everyone has a huge amount of sympathy but where we are not dealing with a child. Again, it is right that we have this specific set of measures around deceased children, but we should expect that Ofcom will be asked, “What about other circumstances?” We need a reasonable answer to that: that other things are in place. I hope that the answer will be that, if it is a serious enough case, without the information notice powers Ofcom could still, under Amendment 273 as I read it, look into other deaths that involve adults, as well as the specific powers it has in relation to children. I would appreciate clarification from the Minister.
Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- View Speech - Hansard - -

My Lords, given the hour, I will be brief. I wanted to thank my noble friend the Minister and the Secretary of State, and to congratulate my friend the noble Baroness, Lady Kidron, on such an important group. It is late at night and not many of us are left in the Chamber, but this is an important thing that they have succeeded in doing together, and it is important that we mark that. It is also a hugely important thing that the bereaved families for justice have achieved, and I hope that they have achieved a modicum of calm from having made such a big difference for future families.

I will make one substantive point, referencing where my noble friend the Minister talked about future Bills. In this House and in this generation, we are building the legal scaffolding for a digital world that already exists. The noble Lord, Lord Allan of Hallam, referenced the fact that much of this was built without much thought—not maliciously but just without thinking about the real world, life and death. In Committee, I was taken by the noble Lord, Lord Knight, mentioning the intriguing possibility of using the Data Protection and Digital Information Bill to discuss data rights and to go beyond the dreadful circumstances that these amendments cover to make the passing on of your digital assets something that is a normal part of our life and death. So I feel that this is the beginning of a series of discussions, not the end.

I hope that my noble friend the Minister and whichever of his and my colleagues picks up the brief for the forthcoming Bill can take to heart how we have developed all this together. I know that today has perhaps not been our most wholly collaborative day, but, in general, I think we all feel that the Bill is so much the better for the collaborative nature that we have all brought to it, and on no more important a topic than this amendment.

Lord Clement-Jones Portrait Lord Clement-Jones (LD)
- View Speech - Hansard - - - Excerpts

My Lords, I will be extremely brief. We have come a very long way since the Joint Committee made its recommendations to the Government, largely, I think, as a result of the noble Baroness, Lady Kidron. I keep mistakenly calling her “Baroness Beeban”; familiarity breeds formality, or something.

I thank the Minister and the Secretary of State for what they have done, and the bereaved families for having identified these issues. My noble friend Lord Allan rightly identified the sentiments as grief and anger at what has transpired. All we can do is try to do, in a small way, what we can to redress the harm that has already been done. I was really interested in his insights into how a platform will respond and how this will help them through the process of legal order and data protection issues with a public authority.

My main question to the Minister is in that context—the relationship with the Information Commissioner’s Office—because there are issues here. There is, if you like, an overlap of jurisdiction with the ICO, because the potential or actual disclosure of personal data is involved, and therefore there will necessarily have to be co-operation between the ICO and Ofcom to ensure the most effective regulatory response. I do not know whether that has emerged on the Minister’s radar, but it certainly has emerged on the ICO’s radar. Indeed, in the ideal world, there probably should be some sort of consultation requirement on Ofcom to co-operate with the Information Commissioner in these circumstances. Anything that the Minister can say on that would be very helpful.

Again, this is all about reassurance. We must make sure that we have absolutely nailed down all the data protection issues involved in the very creative way the Government have responded to the requests of the bereaved families so notably championed by the noble Baroness, Lady Kidron.

Online Safety Bill

Baroness Harding of Winscombe Excerpts
Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - - - Excerpts

My Lords, I rise to speak to all the amendments in this group. It is a cause of great regret that, despite many private meetings with officials, government lawyers and Ministers, we have not yet come to an agreement that would explicitly include in the Bill harm that does not derive from content. I will be listening very carefully to the Minister, if he should change his mind during the debate.

The amendments in this group fall into three categories. First, there is a series of amendments in my name and those of the noble Lord, Lord Stevenson, the noble Baroness, Lady Harding, and the right reverend Prelate the Bishop of Oxford: Amendments 35, 36, 37A and 85. I hope the Government will accept them as consequential because, in meetings last week, they would not accept that harm to children can arise from the functionality and design of services and not just from the content. Each of these amendments simply makes it clear that harm can arise absent from content: nothing more, nothing less. If the Minister agrees that harm may derive from the design of products and services, can he please explain, when he responds, why these amendments are not acceptable? Simply put, it is imperative that the features, functionalities or behaviours that are harmful to children, including those enabled or created by the design or operation of the service, are in scope of the Bill. This would make it utterly clear that a regulated company has a duty to design its service in a manner that does not harm children.

The Government have primary priority harmful content, priority content or non-designated harmful content, the latter being a category that is yet to be defined, but not the harm that emerges from how the regulated company designs its service. For example, there are the many hundreds of small reward loops that make up a doomscroll or make a game addictive; commercial decisions such as Pokémon famously did for a time, which was to end every game in a McDonald’s car park; or, more sinister still, the content-neutral friend recommendations that introduce a child to other children like them, while pushing children into siloed groups. For example, they deliberately push 13 year-old boys towards Andrew Tate—not for any content reason, but simply on the basis that 13 year-old boys are like each other and one of them has already been on that site.

The impact of a content-neutral friend recommendation has rocked our schools as female teachers and girls struggle with the attitudes and actions of young boys, and has torn through families, who no longer recognise their sons and brothers. To push hundreds of thousands of children towards Andrew Tate for no reason other than to benefit commercially from the network effect is a travesty for children and it undermines parents.

The focus on content is old-fashioned and looks backwards. The Bill is drafted as if it has particular situations and companies in mind but does not think about how fast the business moves. When we started the Bill, none of us thought about the impact of TikTok; last week, we saw a new service, Threads, go from zero to 70 million users in a single day. It is an act of stunning hubris to be so certain of the form of harm. To be unprepared to admit that some harm is simply design means that, despite repeated denials, this is just a content Bill. The promise of systems and processes being at the heart of the Bill has been broken.

The second set of amendments in this group are in the name of my noble friend Lord Russell. Amendments 46 and 90 further reveal the attitude of the Government, in that they are protecting the companies rather than putting them four-square in the middle of their regime. The Government specifically exempt the manner of dissemination from the safety duties. My noble friend Lord Russell’s amendment would leave that out and ensure that the manner of dissemination, which is fundamental to the harm that children experience, is included. Similarly, Amendment 240 would take out “presented by content” so that harm that is the result of the design decisions is included in the Bill.

The third set are government Amendments 281C and 281D, and Amendment 281F, in my name. For absence of doubt, I am totally supportive of government Amendments 281C to 281E, which acknowledge the cumulative harms; for example, those that Molly Russell experienced as she was sent more and more undermining and harmful content. In as far as they are a response to my entreaties, and those of other noble Lords, that we ensure that cumulative harmful content is the focus of our concerns, I am grateful to the Government for tabling them. However, I note that the Government have conceded only the role of cumulative harm for content. Amendments 281D and 281E once again talk about content as the only harm to children.

The noble Lord, Lord Stevenson, the noble Baroness, Lady Harding, and the right reverend Prelate the Bishop of Oxford have added their names to Amendment 281F, and I believe I am right in saying that if there were not a limit to four names, there were a great many Peers who would have added their names also. For the benefit of the House, I will quote directly from the amendment:

“When in relation to children, references to harm include the potential impact of the design and operation of a regulated service separately and additionally from harms arising from content, including the following considerations … the potential cumulative impact of exposure to harm or a combination of harms … the potential for harm to result from features, functionalities or behaviours enabled or created by the design and operation of services … the potential for some features and functionalities within a service to be higher risk than other aspects of the service … that a service may, when used in conjunction with other services, facilitate harm to a child on a different service … the potential for design strategies that exploit a child’s developmental vulnerabilities to create harm, including validation metrics and compulsive reward loops … the potential for real time services, features and functionalities such as geolocation, livestream broadcasts or events, augmented and virtual environments to put children at immediate risk … the potential for content neutral systems that curate or generate environments, content feeds or contacts to create harm to children … that new and emerging harms may arise from artificial intelligence, machine generated and immersive environments”.


Before I continue, I ask noble Lords to consider which of those things they would not like for their children, grandchildren or, indeed, other people’s children. I have accepted that the Government will not add the schedule of harms as I first laid it: the four Cs of content, conduct, contact and commercial harms. I have also accepted that the same schedule, written in the less comfortable language of primary priority, priority and non-designated harms, has also been rejected. However, the list that I just set out, and the amendment to the duties that reflect those risks, would finally put the design of the system at the heart of the Bill. I am afraid that, in spite of all our conversations, I cannot accept the Government’s argument that all harm comes from content.

Even if we are wrong today—which we are most definitely not—in a world of AI, immersive tech and augmented reality, is it not dangerous and, indeed, foolish, to exclude harm that might come from a source other than content? I imagine that the Minister will make the argument that the features are covered in the risk assessment duties and that, unlike content, features may be good or bad so they cannot be characterised as harmful. To that I say: if the risk assessment is the only process that matters, why do the Government feel it necessary to define the child safety duties and the interpretation of harm? The truth is, they have meaning. In setting out the duty of a company to a child, why would the Government not put the company’s design decisions right at the centre of that duty?

As for the second part of the argument, a geolocation feature may of course be great for a map service but less great if it shows the real-time location of a child to a predator, and livestreaming from a school concert is very different from livestreaming from your bedroom. Just as the noble Lord, Lord Allan, explained on the first day on Report, there are things that are red lines and things that are amber; in other words, they have to be age-appropriate. This amendment does not seek—nor would it mean—that individual features or functionalities would be prevented, banned or stopped. It would mean that a company had a duty to make sure that their features and functionalities were age-appropriate and did not harm children—full stop. There would be no reducing this to content.

Finally, I want to repeat what I have said before. Sitting in the court at Molly Russell’s inquest, I watched the Meta representative contest content that included blood cascading down the legs of a young woman, messages that said, “You are worthless”, and snippets of film of people jumping off buildings. She said that none of those things met the bar of harmful content according to Meta’s terms and conditions.

Like others, I believe that the Online Safety Bill could usher in a new duty of care towards children, but it is a category error not to see harm in the round. Views on content can always differ but the outcome on a child is definitive. It is harm, not harmful content, that the Bill should measure. If the Minister does not have the power to accede, I will, with great regret, be testing the opinion of the House. I beg to move.

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- View Speech - Hansard - -

My Lords, as so often in the course of the Bill, I associate myself wholeheartedly with the comments that the noble Baroness, Lady Kidron, just made. I, too, thank my noble friend the Minister and the Secretary of State for listening to our debates in Committee on the need to be explicit about the impact of cumulative harmful content. So I support Amendments 281C, 281D and 281E, and I thank them for tabling them.

--- Later in debate ---
Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- View Speech - Hansard - -

My Lords, as somebody who is only five feet and two inches, I have felt that size does not matter for pretty much all my life and have long wanted to say that in a speech. This group of amendments is really about how size does not matter; risk does. I will briefly build on the speech just given by the noble Lord, Lord Allan, very eloquently as usual, to describe why risk matters more than size.

First, there are laws for which size does matter—small companies do not need to comply with certain systems and processes—but not those concerned with safety. I have in my mind’s eye the small village fête, where we expect a risk assessment if we are to let children ride on rides. That was not the case 100 years ago, but is today because we recognise those dangers. One of the reasons why we stumbled into thinking that size should matter in this Bill is that we are not being honest about the scale of the risk for our children. If the risk is large enough, we should not be worrying about size; we should be worrying about that risk. That is the first reason why we have to focus on risk and not size.

The second reason is subsequent to what I have just said—the principles of the physical world should apply to the online world. That is one of the core tenets of this Bill. That means that if you recognise the real and present risks of the digital world you have to say that it does not matter whether a small number of people are affected. If it is a small business, it still has an obligation not to put people in harm’s way.

Thirdly, small becomes big very quickly—unfortunately, that has not been true for me, but it is true in the digital world as Threads has just shown us. Fourthly, we also know that in the digital world re-engineering something once it has got very big is really difficult. There is also a practical reason why you want engineers to think about the risks before they launch services rather than after the event.

We keep being told, rightly, that this is a Bill about systems and processes. It is a Bill where we want not just the outcomes that the noble Lord, Lord Allan, has referred to in terms of services in the UK genuinely being safer; we are trying to effect a culture change. I would argue one of the most important culture changes is that any bright, young tech entrepreneur has to start by thinking about the risks and therefore the safety procedures they need to put in place as they build their tech business from the ground up and not once they have reached some artificial size threshold.

Baroness Kidron Portrait Baroness Kidron (CB)
- View Speech - Hansard - - - Excerpts

My Lords, I have to admit that it was incompetence rather than lack of will that meant I did not add my name to Amendment 39 in the name of the noble Lord, Lord Bethell, and I would very much like the Government to accept his argument.

In the meantime, I wonder whether the Minister would be prepared to make it utterly clear that proportionality does not mean a little bit of porn to a large group of children or a lot of porn to a small group of children; rather, it means that high-risk situations require effective measures and low-risk situations should be proportionate to that. On that theme, I say to the noble Lord, Lord Allan, whose points I broadly agree with, that while we would all wish to see companies brought into the fold rather than being out of the fold, it rather depends on their risk.

This brings me neatly to Amendments 43 and 87 from the noble Lord, Lord Russell, to which I managed to add my name. They make a very similar point to Amendment 39 but across safety duties. Amendment 242 in my name, to which the noble Lord, Lord Stevenson, the noble Baroness, Lady Harding, and the right reverend Prelate the Bishop of Oxford have added their names, makes the same point—yet again—in relation to Ofcom’s powers.

All these things are pointing in the same direction as Amendment 245 in the name of the noble Baroness, Lady Morgan, which I keep on trumpeting from these Benches and which offers an elegant solution. I urge the Minister to consider Amendment 245 before day four of Report because if the Government were to accept it, it would focus company resources, focus Ofcom resources and, as we discussed on the first day of Report, permit companies which do not fit the risk profile of the regime and are unable to comply with something that does not fit their model yet leaves them vulnerable to enforcement also to be treated in an appropriate way.

Collectively, the ambition is to make sure that we are treating things in proportion to the risk and that proportionate does not start meaning something else.

Online Safety Bill

Baroness Harding of Winscombe Excerpts
Lord Parkinson of Whitley Bay Portrait The Parliamentary Under-Secretary of State, Department for Culture, Media and Sport (Lord Parkinson of Whitley Bay) (Con)
- View Speech - Hansard - - - Excerpts

My Lords, the Government are committed to protecting children against accessing pornography online. As technology evolves, it is important that the regulatory framework introduced by the Bill keeps pace with emerging risks to children and exposure to pornography in new forms, such as generative artificial intelligence.

Part 5 of the Bill has been designed to be future-proof, and we assess that it would already capture AI-generated pornography. Our Amendments 206 and 209 will put beyond doubt that content is “provider pornographic content” where it is published or displayed on a Part 5 service by means of an automated tool or algorithm, such as a generative AI bot, made available on the service by a provider. Amendments 285 and 293 make clear that the definition of an automated tool includes a bot. Amendment 276 clarifies the definition of a provider of a Part 5 service, to make clear that a person who controls an AI bot that generates pornography can be regarded as the provider of a service.

Overall, our amendments provide important certainty for users, providers and Ofcom on the services and content in scope of the Part 5 duties. This will ensure that the new, robust duties for Part 5 providers to use age verification or age estimation to prevent children accessing provider pornographic content will also extend to AI-generated pornography. I beg to move.

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- View Speech - Hansard - -

My Lords, the noble Baroness, Lady Kidron, has unfortunately been briefly detained. If you are surprised to see me standing up, it is because I am picking up for her. I start by welcoming these amendments. I am grateful for the reaction to the thought-provoking debate that we had in Committee. I would like to ask a couple of questions just to probe the impact around the edges.

Amendment 27 looks as if it implies that purely content-generating machine-learning or AI bots could be excluded from the scope of the Bill, rather than included, which is the opposite of what we were hoping to achieve. That may be us failing to understand the detail of this large body of different amendments, but I would welcome my noble friend the Minister’s response to make sure that in Amendment 27 we are not excluding harm that could be generated by some form of AI or machine-learning instrument.

Maybe I can give my noble friend the Minister an example of what we are worried about. This is a recent scenario that noble Lords may have seen in the news, of a 15 year-old who asked, “How do I have sex with a 30 year-old?”. The answer was given in forensic detail, with no reference to the fact that it would in fact be statutory rape. Would the regulated service, or the owner of the regulated service that generated that answer, be included or excluded as a result of Amendment 27? That may be my misunderstanding.

This group is on AI-generated pornography. My friend, the noble Baroness, Lady Kidron, and I are both very concerned that it is not just about pornography, and that we should make sure that AI is included in the Bill. Specifically, many of us with teenage children will now be learning how to navigate the Snap AI bot. Would harm generated by that bot be captured in these amendments, or is it only content that is entirely pornographic? I hope that my noble friend the Minister can clarify both those points, then we will be able to support all these amendments.

Lord Allan of Hallam Portrait Lord Allan of Hallam (LD)
- View Speech - Hansard - - - Excerpts

My Lords, I rise briefly to welcome the fact that there is a series of amendments here where “bot” is replaced by

“bot or other automated tool”.

I point out that there is often a lot of confusion about what a bot is or is not. It is something that was largely coined in the context of a particular service—Twitter—where we understand that there are Twitter bots: accounts that have been created to pump out lots of tweets. In other contexts, on other services, there is similar behaviour but the mechanism is different. It seems to me that the word “bot” may turn out to be one of those things that was common and popular at the end of the 2010s and in the early 2020s, but in five years we will not be using it at all. It will have served its time, it will have expired and we will be using other language to describe what it is that we want to capture: a human being has created some kind of automated tool that will be very context dependent, depending on the nature of the service, and they are pumping out material. It is very clear that we want to make sure that such behaviour is in scope and that the person cannot hide behind the fact that it was an automated tool, because we are interested in the mens rea of the person sitting behind the tool.

I recognise that the Government have been very wise in making sure that whenever we refer to a bot we are adding that “automated tool” language, which will make the Bill inherently much more future-proof.

--- Later in debate ---
Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- View Speech - Hansard - -

My Lords, I also speak in support of Amendments to 281, 281A and 281B, to which I have added my name, tabled by the noble Lord, Lord Russell. He and, as ever, the noble Baroness Kidron, have spoken eloquently, I am not going to spend much time on these amendments but I wanted to emphasise Amendment 281A.

In the old world of direct marketing—I am old enough to remember that when I was a marketing director it was about sending magazines, leaflets and letters—one spent all of one’s time working out how to build loyalty: how to get people to engage longer as a result of one’s marketing communication. In the modern digital world, that dwell time has been transformed into a whole behavioural science of its own. It has developed a whole set of tools. Today, we have been using the word “activity” at the beginning of the Bill in the new Clause 1 but also “features” and “functionality”. The reason why Amendment 281A is important is that there is a danger that the Bill keeps returning to being just about content. Even in Clause 208 on functionality, almost every item in subsection (2) mentions content, whereas Amendment 281A tries to spell out the elements of addiction-driving functionality that we know exist today.

I am certain that brilliant people will invent some more but we know that these ones exist today. I really think that we need to put them in the Bill to help everyone understand what we mean because we have spent days on this Bill—some of us have spent years, if not decades, on this issue—yet we still keep getting trapped in going straight back to content. That is another reason why I think it is so important that we get some of these functionalities in the Bill. I very much hope that, if he cannot accept the amendment today, my noble friend the Minister will go back, reflect and work out how we could capture these specific functionalities before it is too late.

I speak briefly on Amendments 28 to 30. There is unanimity of desire here to make sure that organisations such as Wikipedia and Streetmap are not captured. Personally, I am very taken—as I often am—by the approach of the noble Baroness, Lady Kidron. We need to focus on risk rather than using individual examples, however admirable they are today. If Wikipedia chose to put on some form of auto-scroll, the risk of that service would go up; I am not suggesting that Wikipedia is going to do so today but, in the digital world, we should not assume that, just because organisations are charities or devoted to the public good, they cannot inadvertently cause harm. We do not make that assumption in the physical world either. Charities that put on physical events have to do physical risk assessments. I absolutely think that we should hold all organisations to that same standard. However, viewed through the prism of risk, Wikipedia—brilliant as it is—does not have a risk for child safety and therefore should not be captured by the Bill.

Lord Bishop of Oxford Portrait The Lord Bishop of Oxford
- View Speech - Hansard - - - Excerpts

My Lords, I broadly support all the amendments in this group but I will focus on the three amendments in the names of the noble Lord, Lord Russell, and others; I am grateful for their clear exposition of why these amendments are important. I draw particular attention to Amendment 281A and its helpful list of functions that are considered to be harmful and to encourage addiction.

There is a very important dimension to this Bill, whose object, as we have now established, is to encourage safety by design. An important aspect of it is cleaning up, and setting right, 20 years or more of tech development that has not been safe by design and has in fact been found to be harmful by way of design. As the noble Baroness, Lady Harding, just said, in many conversations and in talking to people about the Bill, one of the hardest things to communicate and get across is that this is about not only content but functionality. Amendment 281A provides a useful summary of the things that we know about in terms of the functions that cause harm. I add my voice to those encouraging the Minister and the Government to take careful note of it and to capture this list in the text of the Bill in some way so that this clean-up operation can be about not only content for the future but functionality and can underline the objectives that we have set for the Bill this afternoon.

--- Later in debate ---
Baroness Fox of Buckley Portrait Baroness Fox of Buckley (Non-Afl)
- View Speech - Hansard - - - Excerpts

My Lords, interestingly, because I have not discussed this at all with the noble Lord, Lord Moylan, I have some similar concerns to his. I have always wanted this to be a children’s online safety Bill. My concerns generally have been about threats to adults’ free speech and privacy and the threat to the UK as the home of technological innovation. I have been happy to keep shtum on things about protecting children, but I got quite a shock when I saw the series of government amendments.

I thought what most people in the public think: the Bill will tackle things such as suicide sites and pornography. We have heard some of that very grim description, and I have been completely convinced by people saying, “It’s the systems”. I get all that. But here we have a series of amendments all about content—endless amounts of content and highly politicised, contentious content at that—and an ever-expanding list of harms that we now have to deal with. That makes me very nervous.

On the misinformation and disinformation point, the Minister is right. Whether for children or adults, those terms have been weaponised. They are often used to delegitimise perfectly legitimate if contrary or minority views. I say to the noble Baroness, Lady Kidron, that the studies that say that youth are the fastest-growing far-right group are often misinformation themselves. I was recently reading a report about this phenomenon, and things such as being gender critical or opposing the small boats arriving were considered to be evidence of far-right views. That was not to do with youth, but at least you can see that this is quite a difficult area. I am sure that many people even in here would fit in the far right as defined by groups such as HOPE not hate, whose definition is so broad.

My main concerns are around the Minister’s Amendment 172. There is a problem: because it is about protected characteristics—or apes the protected characteristics of the Equality Act—we might get into difficulty. Can we at least recognise that, even in relation to the protected characteristics as noted in the Equality Act, there are raging rows politically? I do not know how appropriate it is that the Minister has tabled an amendment dragging young people into this mire. Maya Forstater has just won a case in which she was accused of being opposed to somebody’s protected characteristics and sacked. Because of the protected characteristics of her philosophical views, she has won the case and a substantial amount of money.

I worry when I see this kind of list. It is not just inciting hatred—in any case, what that would mean is ambivalent. It refers to abuse based on race, religion, sex, sexual orientation, disability and so on. This is a minefield for the Government to have wandered into. Whether you like it or not, it will have a chilling effect on young people’s ability to debate and discuss. If you worry that some abuse might be aimed at religion, does that mean that you will not be able to discuss Charlie Hebdo? What if you wanted to show or share the Charlie Hebdo cartoons? Will that count? Some people would say that is abusive or inciteful. This is not where the Bill ought to be going. At the very least, it should not be going there at this late stage. Under race, it says that “nationality” is one of the indicators that we should be looking out for. Maybe it is because I live in Wales, but there is a fair amount of abuse aimed at the English. A lot of Scottish friends dole it out as well. Will this count for young people who do that? I cannot get it.

My final question is in relation to proposed subsection (11). This is about protecting children, yet it lists a person who

“has the characteristic of gender reassignment if the person is proposing to undergo, is undergoing or has undergone a process (or part of a process) for the purpose of reassigning the person’s sex by changing physiological or other attributes of sex”.

Are the Government seriously accepting that children have not just proposed to reassign but have been reassigned? That is a breach of the law. That is not meant to be happening. Your Lordships will know how bad this is. Has the Department for Education seen this? As we speak, it is trying to untangle the freedom for people not to have to go along with people’s pronouns and so on.

This late in the day, on something as genuinely important as protecting children, I just want to know whether there is a serious danger that this has wandered into the most contentious areas of political life. I think it is very dangerous for a government amendment to affirm gender reassignment to and about children. It is genuinely irresponsible and goes against the guidance the Government are bringing out at the moment for us to avoid. Please can the Minister clarify what is happening with Amendment 172?

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- View Speech - Hansard - -

My Lords, I am not entirely sure how to begin, but I will try to make the points I was going to make. First, I would like to respond to a couple of the things said by the noble Baroness, Lady Fox. With the greatest respect, I worry that the noble Baroness has not read the beginning of the proposed new clause in Amendment 172, subsection (2), which talks about “Content which is abusive”, as opposed to content just about race, religion or the other protected characteristics.

One of the basic principles of the Bill is that we want to protect our children in the digital world in the same way that we protect them in the physical world. We do not let our children go to the cinema to watch content as listed in the primary priority and priority content lists in my noble friend the Minister’s amendments. We should not let them in the digital world, yet the reality is that they do, day in and day out.

I thank my noble friend the Minister, not just for the amendments that he has tabled but for the countless hours that he and his team have devoted to discussing this with many of us. I have not put my name to the amendments either because I have some concerns but, given the way the debate has turned, I start by thanking him and expressing my broad support for having the harms in the Bill, the importance of which this debate has demonstrated. We do not want this legislation to take people by surprise. The important thing is that we are discussing some fundamental protections for the most vulnerable in our society, so I thank him for putting those harms in the Bill and for allowing us to have this debate. I fear that it will be a theme not just of today but of the next couple of days on Report.

I started with the positives; I would now like to bring some challenges as well. Amendments 171 and 172 set out priority content and primary priority content. It is clear that they do not cover the other elements of harm: contact harms, conduct harms and commercial harms. In fact, it is explicit that they do not cover the commercial harms, because proposed new subsection (4) in Amendment 237 explicitly says that no amendment can be made to the list of harms that is commercial. Why do we have a perfect crystal ball that means we think that no future commercial harms could be done to our children through user-to-user and search services, such that we are going to expressly make it impossible to add those harms to the Bill? It seems to me that we have completely ignored the commercial piece.

I move on to Amendment 174, which I have put my name to. I am absolutely aghast that the Government really think that age-inappropriate sexualised content does not count as priority content. We are not necessarily talking here about a savvy 17 year-old. We are talking about four, five and six year-olds who are doomscrolling on various social media platforms. That is the real world. To suggest that somehow the digital world is different from the old-fashioned cinema, and a place where we do not want to protect younger children from age-inappropriate sexualised material, just seems plain wrong. I really ask my noble friend the Minister to reconsider that element.

I am also depressed about the discussion that we had about misinformation. As I said in Committee several times, I have two teenage girls. The reality is that we are asking today’s teenagers to try to work out what is truth and what is misinformation. My younger daughter will regularly say, “Is this just something silly on the internet?” She does not use the term “misinformation”; she says, “Is that just unreal, Mum?” She cannot tell about what appears in her social media feeds because of the degree of misinformation. Failing to recognise that misinformation is a harm for young people who do not yet know how to validate sources, which was so much easier for us when we were growing up than it is for today’s generations, is a big glaring gap, even in the content element of the harms.

I support the principle behind these amendments, and I am pleased to see the content harms named. We will come back next week to the conduct and contact harms—the functionality—but I ask my noble friend the Minister to reconsider on both misinformation and inappropriate sexualised material, because we are making a huge mistake by failing to protect our children from them.

--- Later in debate ---
Lord Moylan Portrait Lord Moylan (Con)
- Hansard - - - Excerpts

My Lords, these words have obviously appeared in the Bill in one of those unverified sections; I have clicked the wrong button, so I cannot see them. Where does it say in Amendment 172 that it has to be a consistent flow?

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - -

May I attempt to assist the Minister? This is the “amber” point described by the noble Lord, Lord Allan: “priority content” is not the same as “primary priority content”. Priority content is our amber light. Even the most erudite and scholarly description of baby eating is not appropriate for five year-olds. We do not let it go into “Bod” or any of the other of the programmes we all grew up on. This is about an amber warning: that user-to-user services must have processes that enable them to assess the risk of priority content and primary priority content. It is not black and white, as my noble friend is suggesting; it is genuinely amber.

Lord Parkinson of Whitley Bay Portrait Lord Parkinson of Whitley Bay (Con)
- Hansard - - - Excerpts

My Lords, we may be slipping back into a Committee-style conversation. My noble friend Lord Moylan rightly says that this is the first chance we have had to examine this provision, which is a concession wrung out of the Government in Committee. As the noble Lord, Lord Stevenson, says, sometimes that is the price your Lordships’ House pays for winning these concessions, but it is an important point to scrutinise in the way that my noble friend Lord Moylan and the noble Baroness, Lady Fox, have done.

I will try to reassure my noble friend and the noble Baroness. This relates to the definition of a characteristic with which we began our debates today. To be a characteristic it has to be possessed by a person; therefore, the content that is abusive and targets any of the characteristics has to be harmful to an individual to meet the definition of harm. Further, it has to be material that would come to the attention of children in the way that the noble Baronesses who kindly leapt to my defence and added some clarity have set out. So my noble friend would be able to continue to criticise the polytheistic religions of the past and their tendencies to his heart’s content, but there would be protections in place if what he was saying was causing harm to an individual—targeting them on the basis of their race, religion or any of those other characteristics—if that person was a child. That is what noble Lords wanted in Committee, and that is what the Government have brought forward.

My noble friend and others asked why mis- and disinformation were not named as their own category of priority harmful content to children. Countering mis- and disinformation where it intersects with the named categories of primary priority or priority harmful content, rather than as its own issue, will ensure that children are protected from the mis- and disinformation narratives that present the greatest risk of harm to them. We recognise that mis- and disinformation is a broad and cross-cutting issue, and we therefore think the most appropriate response is to address directly the most prevalent and concerning harms associated with it; for example, dangerous challenges and hoax health advice for children to self-administer harmful substances. I assure noble Lords that any further harmful mis- and disinformation content will be captured as non-designated content where it presents a material risk of significant harm to an appreciable number of children.

In addition, the expert advisory committee on mis- and disinformation, established by Ofcom under the Bill, will have a wide remit in advising on the challenges of mis- and disinformation and how best to tackle them, including how they relate to children. Noble Lords may also have seen that the Government have recently tabled amendments to update Ofcom’s statutory media literacy duty. Ofcom will now be required to prioritise users’ awareness of and resilience to misinformation and disinformation online. This will include children and their awareness of and resilience to mis- and disinformation.

My noble friend Lady Harding of Winscombe talked about commercial harms. Harms exacerbated by the design and operation of a platform—that is, their commercial models—are covered in the Bill already through the risk assessment and safety duties. Financial harm, as used in government Amendment 237, is dealt with by a separate legal framework, including the Consumer Protection from Unfair Trading Regulations. This exemption ensures that there is no regulatory overlap.

The noble Lord, Lord Russell of Liverpool, elaborated on remarks made earlier by the noble Lord, Lord Stevenson of Balmacara, about their meeting looking at the incel movement, if it can be called that. I assure the noble Lord and others that Ofcom has a review and report duty and will be required to stay on top of changes in the online harms landscape and report to government on whether it recommends changes to the designated categories of content because of the emerging risks that it sees.

The noble Baroness, Lady Kidron, anticipated the debate we will have on Monday about functionalities and content. I am grateful to her for putting her name to so many of the amendments that we have brought forward. We will continue the discussions that we have been having on this point ahead of the debate on Monday. I do not want to anticipate that now, but I undertake to carry on those discussions.

In closing, I reiterate what I know is the shared objective across your Lordships’ House—to protect children from harmful content and activity. That runs through all the government amendments in this group, which cover the main categories of harmful content and activity that, sadly, too many children encounter online every day. Putting them in primary legislation enables children to be swiftly protected from encountering them. I therefore hope that noble Lords will be heartened by the amendments that we have brought forward in response to the discussion we had in Committee.