Digital and Technology Policy: National Sovereignty

Baroness Ramsey of Wall Heath Excerpts
Thursday 23rd July 2026

(5 days, 8 hours ago)

Lords Chamber
Read Full debate Read Hansard Text Watch Debate Read Debate Ministerial Extracts
Baroness Uddin Portrait Baroness Uddin (Non-Afl)
- View Speech - Hansard - - - Excerpts

My Lords, it is a pleasure to follow the noble Lord, Lord Holmes, and I thank him for all his work. Echoing all the praises, I, too, express my gratitude to my friend, the noble Baroness, Lady Kidron, for her very powerful leadership, including in this debate.

My contribution today is framed in the context of having organised numerous discussions and meetings in relation to the APPG on digital transformation, of which I declare my membership, and policy on technology as it affects society. In this context, sovereignty is a matter of national security, and promoting our national security is an absolute objective for all Members of the House of Lords and across the other House.

For their support, I acknowledge the Library briefing, ControlAI, and Tasmina Ahmed-Sheikh for her ambitious efforts in relation to advancing sovereign AI stack, which I will make some reference to later. I also thank Dowshan Humzah for his precious time, wisdom and foresight.

Sovereignty used to be visible: in borders, laws, currency and armed forces. Today, much of it is indiscernible: it sits in cloud contracts, chips, codes, data and algorithms. The question is not whether Britain can govern Britain; as the noble Baroness, Lady Kidron, said, it is whether Britain can still choose when the systems supporting our public services, businesses and families are designed, owned and operated elsewhere, outside our legal reach.

Digital sovereignty is therefore not technological isolation. Britain cannot, and need not, build every chip, cloud or frontier model, as has been said. It is about retaining the agency, capability and alternatives to act when circumstances change and to build the foundation of the economic power needed for public services, national security and statecraft itself.

Digital sovereignty shapes national sovereignty in at least three critical ways. The first is strategic autonomy, as has been repeated in this House. Can Britain continue to provide essential services, to protect sensitive data and to change direction if a supplier, another state or dominant monopolies dictate trade terms that are not acceptable to our national requirements and standards?

The second is economic resilience. Consider what plans are in place to improve investment that addresses British capability and expands skills and employment. Will these fast-paced developments leave us permanently renting access from elsewhere, which may endanger future-proofing the protection of national procurement? In this context, I refer to the work I have convened in the House on the Sovereign AI Power Index, which was developed by Tasmina Ahmed-Sheikh, a former MP. It is one disciplined way to measure whether our current trajectory will deliver real sovereignty.

The third is citizen protection and rights, especially those of our children. Can a citizen challenge an automated decision? Can a parent reach a competent human being? Can a child grow up without their attention, identity and vulnerability becoming somebody else’s commercial asset? Tasmina Ahmed-Sheikh’s Sovereign AI Power Index offers a system to measure whether investment is translating into genuine national capability, control and resilience.

Dowshan Humzah, a futurologist, technology practitioner and author, says that technology should be our servant, not our master—as it seems to be now. Yet, too often, digital transformation removes human competence, quality and kindness. Digitising a broken service does not transform it; it industrialises the failures. AI can make a good institution better, but it can also make a bad institution fail faster and more consistently, and with no one held accountable. There are sombre considerations ahead of us regarding the governance and accountability of major public services, including the criminal justice system, education and the autonomous use of weapons in warfare.

On daily matters, I ask the House to imagine two different UK parents in 2031 whose children use AI tutors at school. For one of those parents, the system is transparent, independently tested and subject to UK law. A teacher can explain its recommendations. That parent can challenge an error, and the school can change the supplier without losing the child’s history. Technology is serving the family and society. For the second parent, the child is labelled “low potential” by the system, and nobody can explain why or locally override it. The school is locked in, the data cannot easily be moved, and the human teacher becomes the administrator of the machine’s judgment, with a consequential impact on that child for many years. One parent is a citizen using technology; the other will be captured in a never-ending circle of machine-centric decisions that are difficult to challenge or manage.

In five years, AI agents may mediate education, employment, welfare, health and even warfare. In 10 years, AI will be the infrastructure of the state. In 20 years, today’s primary school children will be the workers, parents and leaders. The defaults we tolerate now—opacity, manipulation and dependency—may become the unwritten constitution of their digital lives.

Digital sovereignty is not about building walls; it is about keeping the keys to our own doors and ensuring that our children inherit them. It is about our children’s future. We cannot place our sovereign digital system in anyone else’s grasp, while we do everything we can to ensure—

Baroness Uddin Portrait Baroness Uddin (Non-Afl)
- Hansard - - - Excerpts

I am finishing. We must do everything we can to ensure that AI does not become sovereign over Britain. We cannot wait for others to determine the future of our citizens and our children.

Baroness Ramsey of Wall Heath Portrait Baroness Ramsey of Wall Heath (Lab)
- Hansard - -

I must ask the noble Baroness to conclude her remarks, please.

Baroness Uddin Portrait Baroness Uddin (Non-Afl)
- Hansard - - - Excerpts

We must invent it with honour and dignity for human lives.

Baroness Ramsey of Wall Heath Portrait Baroness Ramsey of Wall Heath (Lab)
- Hansard - -

My Lords, I remind some Members that the speaking time limit is six minutes for Back-Benchers. I urge all noble Lords to keep within that limit so that the debate may conclude within the time allowed, without cutting short the Minister’s remarks.

Baroness Neville-Jones Portrait Baroness Neville-Jones (Con)
- View Speech - Hansard - - - Excerpts

My Lords, I support this Bill. I rather agree with those who have spoken previously that it is not particularly ambitious in its aims, but, if successful, it will be a largely useful piece of legislation. It is modest in its aims but liable to be of service for a period.

What it does not do is look forward very much. The threat landscape is deteriorating. I will not describe it, as that has been done well by others, but the criminals, and indeed other state operators, are leaders in technology adoption. We can be sure that AI is going to be used against us, and so we must be in a position to exploit it ourselves.

One of the conclusions that I draw from the discussion so far is that we will somehow have to learn to both legislate and make policy faster than we are doing at the moment. This Bill has taken a long time to get through the Commons. I hope that it will not take so long to get through this House. I suspect that we are already behind the curve again.

We have to learn to be willing to experiment and to change course if it is not working. We can take many views on the subject of whether we should have sectoral regulation or a single regulator—there are arguments in both directions. At the moment, I am, on the whole, willing to try sectoral regulation, which brings with it potentially more flexibility, as well as more complexity. If it does not work, we will need to be prepared to say that it is not working and that we will do something different. Changes of gear, and willingness to change gear, are things that we will have to come to terms with. When it is the case that we have not got it quite right, we will need to be prepared to say so.

The thrust of the Bill is certainly in the right direction. I will focus on some of the more detailed points in the drafting where I think we need to try to accomplish some improvements. There is quite a lot of looseness in the drafting, which needs tightening up. For example, terms such as “managed service provider” and “critical supplier”, as well as the wide definition of the notion of “incident”, all need greater precision. We need to avoid situations where words such as “incident” become a way in which companies that have no particular involvement get tangled up in regulation. If part of a company provides managed services, we need to know, and the company needs to know, whether the whole company is caught by the Bill or whether it is simply that part that provides managed services.

There is plenty of implementation detail on which we will need to have a closer fix. I am willing to give the Government the power to fill in the detail and update the law through secondary legislation, as it seems to me that we cannot always have primary legislation doing everything. However, we will need a duty to consult written into the Bill for it to be a safe proposition. One thing I would like to ask the Minister is about the timetable for secondary legislation. Will the Government be willing to consult when it comes to putting that through? That will be a very substantial part of the Bill.

I want to make a couple of comments about the effects of the scope of the Bill. First of all, with the exception of service providers, who are classed as “critical suppliers”, and data centres, the Bill, as other people have remarked, is exclusively concerned with the public sector. As the Government Minister and indeed others have pointed out, some of the biggest losses have occurred in the private sector. I do not need to describe these, as they have been described already.

The Government may argue that they properly seek not to regulate the private sector. I certainly have considerable sympathy with that, but it is not satisfactory from the point of view of the taxpayer that the Government had to bail out with public finance Jaguar Land Rover. Under current conditions, I do not think that that breach, which was expensive, is likely to be the last one with sizeable financial effect.

The Government have recognised the problem and are encouraging private sector companies to make a pledge to improve the management of cyber security at board level. I am all in favour of that: improve reporting in the corporate code and increase activity by the audit committee, whose members, if properly equipped with cyber expertise, will make a valuable contribution. That is part of the way that we must move forward. Having said all that, private sector security self-help, while essential, is not sufficient. So what should we do?

The Government correctly tell us that their first duty is the defence and security of the nation. Cyber security strategy—which I know something about, having been involved in it—was founded on the proposition that the protection of the economy involved active partnership between public and private sectors. The NCSC does a vital job in increasing understanding about the threat and giving advice and guidance on countering it, but it could do an even more important and larger job. It was intended at the outset to be more public-facing than is currently the case. It has, to some extent, retreated from its previous public start. I would like to see the NCSC re-emerge from the shadows with more threat analysis, advice and guidance, and its funding increased to do this.

This would be particularly helpful to SMEs. We have all been worried about their access to expertise and considered that the cost to them of security, which is not insignificant, should be somehow alleviated. They are valuable to us. Small companies provide very important parts of larger systems. If the NCSC were to be a much more active security partner to the corporate world, there would be a strong case for financial support from the private sector to it, to make this much more of a joint enterprise.

I urge the Government to put their intelligence capabilities to greater effect in supporting the private sector to raise its level of security. I do not think this is beyond us. We ought to try to do something where there is much closer co-operation between public and private sectors. The banking world, though different, gives us some pointers on the way in which that could be done.

Secondly, within the public sector, the scope of the Bill is puzzlingly selective, as other speakers have touched on. There is palpable anxiety among the general public about the security of One Login and accessing government services safely. This is a moment when the Government could increase confidence. However, not all government services are covered. To take an example, DWP has in its possession detailed personal—not to say intimate—information about its clients and beneficiaries. Surely it should be a candidate for coverage, but it is not. What are the criteria that govern whether a public sector service is covered or not? On the face of it, I do not think selectivity looks wise. The Government have chosen—

Baroness Ramsey of Wall Heath Portrait Baroness in Waiting/Government Whip (Baroness Ramsey of Wall Heath) (Lab)
- Hansard - -

I gently remind the noble Baroness that there is an eight minute advisory Back-Bench speaking time.

Baroness Neville-Jones Portrait Baroness Neville-Jones (Con)
- Hansard - - - Excerpts

I will conclude. The Bill recognises the need for regulatory co-operation, and it is certainly going to be very important if it is made to work. I also agree with those who think that we should align with things such as NIS2 to reduce the potential conflict between us and other international regulators.

My last thought is that we need to ensure that another definitional issue in the Bill, the level of security

“appropriate to the risk posed”,

is pinned down. There is a great deal in the Bill that we will want to talk about in Committee so that those implicated know exactly where their limits lie.