Cyber Security and Resilience (Network and Information Systems) Bill

Debate between Baroness Kidron and Baroness Lloyd of Effra
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I am happy to write to explain how the security and resilience requirements fit into the structure of the Bill and the consultation and scrutiny that they will undergo.

Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - -

The noble Lord, Lord Clement-Jones, has done a lot of my work for me. I thank everyone who contributed. I was really struck by the expertise in this Room. We started this afternoon by talking about the importance of lived experience. I say very strongly to the Minister that I have been in the House long enough to see Acts of Parliament pass, be regulated and fail because we did not really understand how they were going to hit when they were in the world.

The comments on this group are really worth listening on, particularly those on Amendment 167. I say both to the noble Viscount, Lord Camrose, and to the Minister that there is such a high bar of connivance in Amendment 74. There is no accident. The words are “deliberately”, “knowingly”, et cetera—I read them out as part of my introduction. I will take up the noble Viscount’s offer to come to speak to him and persuade him, and I ask the Minister to really think about this, because we have heard that culture does not change without an incentive. This is an incentive to say that if you are seen to grossly mislead and undermine the regulation, then you are liable. That is what good law does. I beg leave to withdraw the amendment.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

Going back to the point made by the noble Lord in an earlier intervention, the Bill is a substantive Bill that substantially increases coverage of the digital infrastructure on which much of our economy relies. That is a very important point. As I mentioned at the start of my remarks just now, the question of whether the Bill is the right place to articulate the breadth of many of the issues that have been raised is, indeed, a good one. I am not sure that it is the right place to articulate all the very good questions that have been asked, because some are much more wide-ranging than the scope of the Bill.

Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - -

My Lords, I thank all who have spoken for their excellent contributions. I will make three quick points. First, in the course of the afternoon, I opened the Explanatory Notes, which is always a bit of a danger. I just want to put on the record that paragraph 2 states:

“These reforms are intended to better protect the services and other activities that are essential to the day-to-day functioning of society in the UK, and the economy, through safeguarding relevant network and information systems (the systems that allow computers and other devices to communicate with each other) and their surrounding environment”.


I do not think that the Bill, as it stands, does that job, and the last two groups have absolutely illustrated that.

The second thing that I would like to say to the Minister, and I absolutely recognise all the things that she mentioned, is that I did find myself counting, and it was 11. We do not have a strategy. It is 11, but it does not cover the scope of what we are discussing; it does not even cover the scope of security.

The third thing, which I am slightly loath to say but will now say, because otherwise we will get nowhere, is that I have been in the room with Ministers when they have indicated directly that they cannot do something because of America’s desire—absolutely categorically, yeah? That is the bit that we did not get from the Minister. Sovereignty is about being able to impose and choose our laws, and to decide what we can and cannot do and what we are willing to risk and give up for it.

I am not saying that it is easy, but I think everybody in the Committee has been completely reasonable in saying that we are not trying to replace the stack; we are trying to talk about chokeholds and we are trying to be strategic. What we are really trying to do is make the country safe and secure and, dare I say, make it respond to its own laws. I do not think that anything that the Minister said has dealt with that fact. It was not asking for much to actually have a think about what strategy is and have a look at how we might get to a better place. Let us have a vision of where we want to go and work out how to get there. Individual things and departments and leaving things out is not the answer.

This is an easy amendment for the Government to say yes to and I hope that, by Report, they will. I beg leave to withdraw the amendment.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank the noble Baroness, Lady Kidron, for her introduction and my noble friend Lady Harding for setting out the motivation for ensuring that we have the right balance of risk and regulation here. The amendments from the noble Baroness, Lady Kidron, seek to allow for the designation of systemically important data centres, RDSPs and RMSPs which do not already meet the threshold. The Government have considered this issue in the development of the regime and have taken an approach which reflects the markets of the various digital services in scope of the regime.

In respect of data centres, the Government agree that a data centre’s significance is not determined solely by size and recognise that smaller facilities may play an important role in supporting the economy and wider society. For that reason, the Bill already provides a route for such operators to be brought into scope outside the standard threshold requirements. The competent authority, Ofcom, has powers to gather information from operators and assess whether designation is appropriate in individual cases.

However, with respect to the RDSP and RMSP measures, the existing small and micro-enterprise exclusions have been designed to be proportionate and avoid imposing undue burden on entities with limited resources and market coverage, while focusing on providers whose disruption would have significant societal impact or economic risk to the UK. Although many small and micro-enterprises operate in the digital and managed services market, large MSPs hold a disproportionate share of market value. The largest MSPs account for 86% of revenue in the UK, despite representing just 4% of all MSPs. It is the disruption of these services that is most likely to cause significant harm to the UK.

The Bill also has measures in place to bring small or micro digital or managed service providers into the scope of the Bill if they are considered to provide a critical service to a regulated entity. If these entities meet the designation criteria, they can be designated as a critical supplier and be subject to mandatory cyber security and resilience requirements. I assure the noble Baroness that I recognise the discrepancy between these two regimes and her concerns, and I am content to explore this, and the points made by the noble Lord, Lord Markham, further, and to provide a more detailed response on Report.

On the issue raised by the noble Lord, Lord Clement-Jones, for his amendment which would amend the relevant managed services definition by excluding specific services, I take seriously the importance of providing clear definitions in the Bill. That is why the definition in the Bill is designed to capture services posing a risk to the UK economy and society, both today and beyond. I reassure the noble Lord that the relevant managed services that would be excluded by this amendment are already likely to be excluded by virtue of them not meeting the definition in the Bill. However, we cannot and should not list every service not in scope or we risk providing a definition that quickly becomes outdated and fails to accommodate new trends in both technology and services—a point frequently made by noble Lords in respect of the development of technology and online services. The Bill requires a delicate balance to ensure that the definition includes the right level of detail. The regulator, the Information Commission, will provide guidance on the application of the regulations prior to commencement of the RMSP provisions, including elements of the RMSP definitions.

On the point raised by the noble Lord, Lord Clement-Jones, on privileged access, MSPs pose risks because they provide ongoing management of customers’ IT services and often have deep and broad access to the networks, infrastructure and data those customers rely on, so the Bill focuses on any connection or access to network and information systems relied on by the customer rather than only access whether privileged or administrative. That is because requiring privileged access would narrow the definition and include some firms we intend to regulate as providers composed of cyber risks through non-privileged access without holding elevated administrative rights. For that reason, I caution against adding these exclusions to the definition of a managed service.

Finally, Amendments 4 and 5 are tabled in my name. They are targeted and technical amendments that improve the clarity and consistency of the Bill by strengthening the definition of load control in Clause 6. They clarify that the relevant activity must be carried out for system balancing purposes. System balancing purposes are defined as purposes which contribute to the,

“balancing, flexibility, security or stability of the electricity system”.

The policy intention has not changed. This amendment simply provides greater clarity about the activities the regime is intended to capture. It will reduce the risk of misinterpretation, provide greater certainty for industry and regulators and support effective regulatory oversight. This will ensure that the regime captures the activities intended to fall within scope and reduces the risk of inadvertently capturing activities that are not relevant to the operation and resilience of the electricity system.

Regarding the questions about the further scope of the Bill in respect of local government and the Government’s cyber action plan, I believe we will return to that in later groups.

Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - -

I am very grateful to the Minister for suggesting that there will be some consideration of the gap, as she put it, and I look forward to that. I want to raise one thing, which is that I was very struck by her reference to a small number of companies having 86% of the market. In a sector that is dominated by the concentration of power in very small numbers of companies owning many pieces of the stack, is she not worried that making those companies protected and safe and the smaller ones not may further serve to increase the concentration of power and market concentration? Is that not a problem for the future?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

The purpose of the Cyber Security and Resilience (Network and information Systems) Bill is to further enhance the scope and powers we have to protect essential services connected through network and information services. The market as it exists today is as I described. What is within the scope is not the totality of our approach to supporting the further cyber resilience of the UK economy. That is why, for example, we have CRCs locally to support SMEs so that whatever size they are, they can get assistance on the best cyber protection they can take. It is why we have Cyber Essentials and why the NCSC provides advice—all that the economy needs to take appropriate action to be secure. That is one aspect. The second aspect is that small and micro digital managed service providers are in scope of the Bill if they are considered to provide a critical service to a regulated entity, so even very small entities could possibly be in scope if they are so designated.

The last point I shall make—and I am sure we will come on to this further when we come to talk about AI—is that the Government are doing a huge amount in regulation and funding through public finance institutions to support the development of UK technology companies and UK innovators and to ensure that they have the right procurement contracts with the public sector so that they can grow and so that the entirety of our companies can benefit from the best global managed service providers and the best UK managed service providers.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank noble Lords for their amendments, and I recognise the concerns that have been expressed. Technology is evolving at a rapid pace, and it is important that we harness the benefits and, equally, protect against the risks it may pose.

The noble Lord, Lord Holmes of Richmond, asked about the approach that we take. We understand how quickly technology is evolving, and it is important that we have a flexible and future-proof approach. If we limit ourselves to specific technologies, we will not capture new developments. For instance, when the NIS regulations were introduced in 2018, we could not have predicted the role that AI and quantum would play in cyber. That is why the Bill takes an “all hazards, all threats, all technologies” approach. This requires regulated entities to manage all the risks relevant to their network and information systems. For example, if AI forms a part of the system that the essential service relies on—for example, in the provision of drinking water—that entity must assess and mitigate the risks it poses.

More generally, the Government take the concerns very seriously. The UK is taking a leading role with our approach to AI security. I will set out my response to each amendment in turn, but while we do not consider the amendments proposed to be the right approach, I reassure noble Lords that the Government are exploring whether additional targeted interventions may be needed in future to address the most significant AI-related national security risks. As the Government’s thinking is at an early stage, I would be open to future engagement with noble Lords on potential options. Any future approach would need to have carefully designed measures, with the evidence base proportionate to and targeted at the risks in question, while minimising unintended impacts on growth, innovation and the operation of critical services.

I turn to the amendments. The intention of the NIS regime is to require organisations to protect themselves from risks that could compromise their network and information systems, which could include a cyber attack, a natural disaster or even human error. That protection would be appropriate and proportionate to the risks faced by those organisations, including state-of-the-art technology such as AI. I reassure noble Lords that this would include relevant risks from AI embedded within the systems of regulated organisations. To take one example, healthcare providers in scope of the regime would be required to manage risks associated with the AI products they use to provide their services. This is because essential services in scope must look at, and work to mitigate, risks posed to their network and information systems.

As AI is increasingly becoming embedded across the economy, we will keep its impact on the regulatory landscape under review. The Bill is focused on the cyber security and resilience of network and information systems; broader questions about the regulation of AI systems are more appropriately addressed through separate discussions, for example on online safety.

Bringing providers of AI services—those companies at the cutting edge of frontier AI development—and their products into the scope of the NIS regime, which Amendment 6 seeks to do, would not address the harms that can be posed by some AI products and services. Specifically, it would not prevent their misuse by hostile actors. Instead, the Government are already taking firm action in more appropriate ways, which also speaks to the concerns that Amendment 75 would aim to address and which the noble Baroness, Lady Foster, asked about.

First, the UK AI Security Institute, as noble Lords are well aware, is world leading in its research on advanced AI capabilities. AISI was set up to build a rigorous scientific understanding of the capabilities of the most advanced AI systems and the risks they pose. It works with developers to strengthen security before models are released and ground policy decisions in evidence rather than speculation, especially as they relate to national security matters.

Secondly, the UK Government are taking a leading role in addressing these risks in both the domestic and international setting. As the noble Lord, Lord Tarassenko, and others have set out, including the noble Viscount, Lord Camrose, it is critical that this approach has global impact. Our AI cyber security code of practice has formed the basis of the world’s first global standard, EN 304 223, which sets baseline security requirements for developers and deployers across the AI life cycle. This demonstrates our global leadership and commitment to shaping international technical standards, which go wider than some of the issues raised in this Bill.

Underpinning all this is a simple but powerful message, which was set out in a joint Five Eyes statement in June. It recommended that as AI capabilities evolve all industry, including vendors, should seek to step up their cyber defences. This is a clear call to action for all organisations, including the Government, and a reminder that the key tenets of cyber hygiene still stand strong. That is also why we are committed to building a national-scale AI-enabled cyber defence for the UK, Cyber Shield. It will scan UK systems continuously to discover vulnerabilities and apply national-level mitigations.

The noble Baroness, Lady Kidron, tabled Amendment 75, which sets out several red lines on AI capabilities that would enable an AI system to facilitate significant risks to the UK. The noble Baroness will recognise that AI is one of many technologies that can be used for beneficial and harmful purposes, as she has mentioned on previous occasions. In addition to the example of chemistry questions, banking services can be used to connect families but might also be used to finance illegal terrorist activities. Equally, while powerful AI capabilities can be used by malicious actors to cause harm to the UK, they might also be used by the national security community to defend the UK and by UK organisations and companies to protect themselves from harm. It is therefore not in the UK’s national interest to restrict UK organisations and the public sector accessing powerful AI capabilities, especially given the global nature of AI risks. It is also unlikely that AISI would be able to give conclusive assurances regarding AI models in the way envisaged in this amendment. Testing shows what a model can do, but not conclusively what it cannot, as the noble Viscount, Lord Camrose, pointed out.

The noble Lord, Lord Tarassenko, tabled Amendment 12, which would require RDSPs to follow guidance issued by the AI Security Institute. For the reasons I set out on Amendment 6 and because it is not AISI’s role to provide guidance of this nature, I do not think it would be appropriate. I will set out more detail on AISI’s role later in my response.

On Amendment 84, tabled by the noble Lord, Lord Clement-Jones, we have chosen to go further than our EU counterparts and the NIS2 regime to respond to these risks by bringing forward powers in the Bill to direct regulated entities if there is a national security risk in relation to their network and information system. This may be used, for instance, to require a regulated entity to cease using and isolate an AI model.

We believe this is a more proportionate and effective response, as data centres operate in highly complex ecosystems and AI systems are often distributed across different data centres and jurisdictions. It is much less desirable to direct multiple data centres to shut down, with the impact this could have on services that rely on them, than to direct them to cease using an AI model. This is important, as our economic security will grow as UK companies grow as they increase AI adoption as we develop our domestic capabilities and attract global talent, underpinned by our data centre and digital infrastructure.

I refer to my introductory remarks on exploring further targeted interventions. This includes examining whether proportionate containment powers could provide a more effective and targeted response, including powers to restrict access to specific AI systems where necessary to prevent or mitigate serious harm. The amendment tabled by the noble Lord, Lord Clement-Jones, also seeks a regular report on AI security. In December 2025, the AI Security Institute published Frontier Al Trends Report, which sets out high-level trends on AI progress based on two years of government-led testing of leading models.

Amendments 85, 86, 92 and 98, tabled by the noble Lords, Lord Tarassenko and Lord Clement-Jones, are a testament to AISI’s leading role and expertise. They seek to provide AISI with powers to address potential risks arising from frontier AI models. I have already set out the important role that AISI plays building a rigorous scientific understanding of the capabilities of the most advanced AI systems and the risks they pose, working with developers to strengthen security before models are released and grounding policy decisions in evidence rather than speculation. These amendments would give AISI a role that it was not designed to fulfil. AISI’s focus on frontier technology and trusted relationships with the world’s leading AI labs allow it to keep pace with the fast-moving technology, thereby providing critical awareness of the most novel and serious AI risks. This amendment would undermine the voluntary collaboration on which AISI operates. A regulatory role for AISI is therefore the wrong answer, but the Government remain committed to ensuring that AISI is equipped to fulfil its vital role and will continue to keep the House updated on its work as appropriate.

As I have just set out, such amendments raise a real risk of placing barriers on AI adoption and deployment in the UK. Due to the scope of the Bill, the amendments cannot address wider AI harms or cyber security in the wider economy. I share concerns about the potential of hostile actors using frontier AI models against our essential services. Placing these restrictions on their deployment in the UK, as amended, would not be effective.

I shall respond to the direct question asked by the noble Baroness, Lady Kidron, on large language models. Large language models are not typically considered online search engines in respect of the CSRB. While some LLMs can be seen to share similar characteristics and may utilise online search engines, their functions tend to be much broader.

I hope that I have addressed the points raised—well, I hope that I have at least touched on all the points raised today. On the points made on changes to the Government, I very well recall the numerous discussions that we have had on AI over the past few months and continue to be the point of continuity on them. As I have said, the Government will be happy to engage with noble Lords as options are being considered. We always stand ready to protect our national and economic security.

Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - -

If I have understood what the Minister said, the NHS must protect itself, but the AI that is attacking it has no duties or obligations under the Bill to check itself before it is used in those ways. That is what I think is the Government’s position, and I would be grateful, when she responds, if she could answer that.

I also want to say two other things. One is that I think these issues will come back on Report, so I would be grateful for some proper discussion before then, so that we can see whether we come to a certain place. I do not have it at my fingertips—I may be helped by one of my colleagues—the amount of search that now happens through AI, but it is almost ludicrous to suggest that LLMs are not search. It is deliberate that I got that answer.

EU Technological Sovereignty Package

Debate between Baroness Kidron and Baroness Lloyd of Effra
Monday 20th July 2026

(2 months, 1 week ago)

Lords Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

Northern Ireland is an incredibly important region for us. It has, as the noble Baroness knows, very high levels of digital connectivity, which puts it in a great place. I know that it also benefits from a thriving and growing cyber security sector and is thus able to tap into many of the adjacent industries that are part of the AI economy as it grows. We are backing cyber businesses in Northern Ireland and supporting them to export and scale.

Baroness Kidron Portrait Baroness Kidron (CB)
- View Speech - Hansard - -

My Lords, the EU’s tech sovereignty package recognises the importance of procurement in developing a wider sovereign technological regime. Yet, here in the UK, we are increasingly seeing extensive use of lock-in deals across Defence, Health, the Treasury and so on. Can the Minister say what actions the Government will take to prevent tech dependency when they offer public contracts to foreign-based firms to ensure that the UK retains the ultimate say over its policies across all departments?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

The noble Baroness highlights the importance of having clear guidance and a clear framework for the public sector as it makes various procurements. That is why, for example, we have published the Cloud Challenge Book 2026, which helps to identify how the public sector can strengthen resilience, improve competition and reduce unnecessary dependency on individual suppliers. That is part of our approach to cloud procurement for the whole of the public sector.

Online Hate Speech

Debate between Baroness Kidron and Baroness Lloyd of Effra
Tuesday 16th June 2026

(3 months, 2 weeks ago)

Lords Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Baroness Kidron Portrait Baroness Kidron (CB)
- View Speech - Hansard - -

My Lords, social media is where many people and most young people get their news, but it is owned or controlled by a handful of tech billionaires whose views are shared disproportionately and who represent an existential risk to democracy—as we saw when Elon Musk, the owner of X, tweeted in support of the riots. Does the Minister agree with me that our public square has now been privatised and that, for the future of democracy and news, we need to consider an alternative way of sharing news with young people?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

The importance of accurate, trusted news is essential. The noble Baroness touched on many different matters in her question. In respect of young people and their access to social media, as I will be talking about shortly, we have put down proposals that will restrict social media platforms in providing content to under-16s. Providing accurate news is hugely important more generally and, as I mentioned on the previous question, we are looking at the role that algorithms play in social cohesion and the spread of online hate. The noble Baroness raises the very important point of media literacy, and we are working with young people and more generally through our media literacy plan to improve the ability of all people, whether young or old, to discern misinformation and disinformation in this important area.

Artificial Intelligence: National Security Implications

Debate between Baroness Kidron and Baroness Lloyd of Effra
Tuesday 16th June 2026

(3 months, 2 weeks ago)

Lords Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Baroness Kidron Portrait Baroness Kidron
- View Speech - Hansard - -

To ask His Majesty’s Government, in light of the decision of the government of the United States to restrict foreign national access to Anthropic’s Claude AI models, Mythos 5 and Fable 5, what assessment they have made of the implications for the United Kingdom’s security; and what alternative sovereign UK systems or partnerships they are pursuing, if any.

Baroness Lloyd of Effra Portrait The Parliamentary Under-Secretary of State, Department for Business and Trade and Department for Science, Innovation and Technology (Baroness Lloyd of Effra) (Lab)
- View Speech - Hansard - - - Excerpts

My Lords, no Government take AI sovereignty and security more seriously than this one. The UK is not a bystander when it comes to the security of AI. Our world-leading AI Security Institute was one of only a handful of organisations with access to both Mythos and Fable before they were released; they were used to identify risks in advance. We are investing £1.6 billion in the UK’s sovereign AI capabilities, made up of £500 million directly in UK AI firms via our sovereign AI fund and £1.1 billion via our AI hardware plan.

Baroness Kidron Portrait Baroness Kidron (CB)
- View Speech - Hansard - -

I thank the Minister for that response. President Trump gave less than 90 minutes for Anthropic to make Mythos and Fable unavailable to any non-US citizens. In doing so, the White House went from a position of no AI regulation at all to 100% control. These systems are extremely powerful and anticipated to be able to break any other AI system, putting all critical industries and systems into meltdown, and we know other systems of the same ilk will shortly follow. In light of these developments, will the Government ask the AI Security Institute to develop red lines for AI systems deployed in the UK, including those used by government, and bring them forward in the promised AI Bill? Does the Minister not agree that the Government’s increasing dependency on US companies in health, education and security is creating a critical vulnerability for national security?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

We continue to support the AI Security Institute. It is very well respected by developers. That is why it has early access and is able to test the risks. Those risks are obviously going to develop as the models themselves evolve. It is also looking closely at the question of alignment, and that is something we are supporting in particular. In respect of sovereign AI, our approach is about building strength over key parts of the value chain to bring to the table technologies that no one else can do without.

For the UK, one of the most promising sectors is in AI hardware. We have brilliant start-ups in that area. That is why we announced the ÂŁ1.1 billion AI hardware plan, which includes up to ÂŁ400 million to purchase these new types of chips. In respect of regulation, as the noble Baroness knows, we are working with our regulators to support them to take account of the risks posed by AI and the opportunities brought by AI for increased productivity and effective regulation.

Sovereign AI Fund

Debate between Baroness Kidron and Baroness Lloyd of Effra
Monday 1st June 2026

(4 months ago)

Lords Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

The UK benefits from access to many international service providers, whether from America or elsewhere. The way we think about sovereignty is in ensuring that the UK has the capability, access and influence it needs to ensure that the technologies that will shape our economy do so in the interests of the UK. The reason we have focused on the areas I mentioned before for the AI sovereign fund is to increase our economic resilience and reduce strategic dependency by building areas where the UK can realistically develop a comparative advantage.

Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - -

Representatives of the sovereign AI unit have repeatedly said that the companies it funds or supports with compute must comply with “applicable UK law”, including when copyright law applies to their training activity. However, they have been unwilling to say whether they will fund or support companies that scrape UK copyrighted material overseas without a licence. Will the Minister confirm that the UK sovereign AI fund will not use taxpayers’ money to support companies that train on copyrighted work without a licence, irrespective of where that training happens, whether in the UK or elsewhere? If she is unable to answer categorically, will she undertake to write with a complete answer?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

The noble Baroness is correct to highlight that we have been clear that copyright rules should be respected and the use of copyright works to train AI in the UK requires a licence unless an exception applies. Companies supported by the sovereign AI fund are expected to comply with applicable UK law, including copyright. When we are talking about compliance in relation to grant-funded compute allocations, they equally must comply with copyright law while undertaking that funded activity.

Social Media: Non-consensual Sexual Deepfakes

Debate between Baroness Kidron and Baroness Lloyd of Effra
Wednesday 14th January 2026

(8 months, 2 weeks ago)

Lords Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

I thank the noble Baroness for her remarks, and for her expertise and input over the course of many years in this area. On the take-down time, we are looking at the experience in other jurisdictions, as I mentioned. We are also looking at the experience of the timelines that are implemented in this country; that is something that Ofcom will look at. We will look at both the scope and the speed of both those jurisdictions. As I think noble Lords have seen, we will look at measures, and if we believe that they are effective and speak to the harms that we are seeing, we will take action.

Baroness Kidron Portrait Baroness Kidron (CB)
- View Speech - Hansard - -

My Lords, I was in the other place when the Secretary of State made her Statement. I commend her for the strength of her words, but we are beyond words now. We are living in a country where any woman or child can be stripped to a bikini and turned into abuse material, as the price and entry point of being online. I do not accept the Government’s defence. There are many ways to communicate with the electorate, and to choose a company that monetises the humiliation and degradation of women and girls as part of its business proposition is to demonstrate that this is business as usual. It is not action for change.

I also disagree very strongly with the Minister: it has not been shocking. We have had the amendments that the noble Baroness referred to—most of those came from Members of this House, including the AI CSAM amendment that she referred to. In the last few weeks, the Government have pushed back on the amendments to the Crime and Policing Bill and, before that, to the data Bill. We have amendments on these issues. We foresaw it and, to be honest, we foresaw it in the Online Safety Act, so even on the other side this is not a shock.

I ask the Minister now to commit to placing the violence against women and girls guidance on a statutory footing, accepting amendments on chatbots and LLM risk assessments, and making a move with Ofcom to say that companies are not required only to do a risk assessment; they must, on a mandatory basis, mitigate those very risks that they find. We must not legitimise a platform which sows division, degrades women and sexually humiliates children.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

I thank the noble Baroness for her points and for her expertise that she brings to the House. I should have mentioned that I commend all those who have been speaking up from a position of experience. It is a very difficult thing to do, and it brings a unique perspective into the debate.

I spoke before about the Government withdrawing from using these platforms; we do not think that would be effective. We understand why people feel strongly about it. It is something that we keep under review.

The noble Baroness raised a number of other important issues. We are monitoring how Ofcom’s code on violence against women is being implemented. We think it is very important. I will discuss the many other areas she raised with my colleague who is taking that Bill through and, indeed, with the noble Baroness outside the House if that would be of interest.