(3 weeks, 6 days ago)
Grand Committee
Baroness Lloyd of Effra (Lab)
I resume with Amendments 174A and 174B, which were introduced by the noble Lord, Lord Markham. They would require the Secretary of State to create a register of “foreign powers” that pose a threat to UK cyber security, to review this register and to lay the report in Parliament. This is intended to inform the use of the powers granted under Part 4 of the Bill. The noble Lord is right that hostile foreign actors pose a clear risk to our essential services. National security is the first responsibility of any Government, which is why we are addressing these risks actively, including through the Bill.
The Bill will grant the Secretary of State important new powers to issue national security directions to regulated entities or regulators, where their compromise poses a national security risk. We will seek to strengthen the Government’s national security toolkit further, to protect our supply chains from hostile actors. That is why we put forward a package of amendments to introduce new powers that would enable the UK to address vendor-related cyber risks by hostile actors in our critical infrastructure supply chains. I look forward to engaging noble Lords further on this essential package ahead of Report.
Any decision to use the powers in the Bill will be informed by expert national security advice, including from GCHQ. The direction powers provide a strategic case-by-case basis to safeguarding our national security, irrespective of the specific actor. As a result, a country-specific approach lacks the nuance required to assess and respond comprehensively to all relevant risks. We also need to proceed responsibly in how we categorise and present these risks in the public sphere.
That is not to say that we shirk transparency about these kinds of risk. The Government are already able to communicate with Parliament and the public about such cyber risks where it is appropriate to do so. As the noble Lord, Lord Markham, set out, the NCSC annual report highlights risks posed by foreign actors; we work with the NCSC to mitigate these risks.
I note that noble Lords have confronted this question before, notably during the passage of the Telecommunications (Security) Act, where there was cross-party support for vendors to be assessed on a case-by-case basis, rather than by designating nations themselves as hostile actors. I hope that, in that vein, noble Lords are reassured that the Government have the tools to act strategically, acting on the right intelligence where hostile states seek to do us harm.
I thank the Minister for her response and the noble Lords, Lord Vaizey and Lord Markham, for their contributions. I cannot help feeling that the approach to this by the noble Lord, Lord Vaizey, is coloured by his history as a Minister. I can understand that because I saw the frustration within Ofcom over the type of judicial review. It was a particular type of judicial review: it was not a full merits-based appeal, but it allowed merits to be considered as part of the judicial review process. Subsequently, that was changed, which has probably calmed the way in which appeals are carried on.
However, in this particular case, although he said that he was not sighted as to the secrecy aspects of this, it was quite interesting to hear what the noble Lord, Lord Markham, had to say. He started by saying that he supported the amendment, then—rather coloured, I think, by the response of the noble Lord, Lord Vaizey—he did a bit of a U-turn halfway through what was a speech originally written in support. I am sure that he knows in his heart that this is the right one.
Really, the argument in this case is expediency versus justice. I think that choosing expediency, especially in the light of what the Constitution Committee had to say, would be extremely inadvisable. I was encouraged by the fact that the Minister is producing a memorandum in response to the Constitution Committee; we all wait with bated breath for when that arrives. In the meantime, I beg leave to withdraw my amendment.
Baroness Lloyd of Effra (Lab)
I am grateful to the noble Lord for raising this topic through his amendment, and I recognise the strength of feeling on reforming the Computer Misuse Act. I agree that the UK should have the right legislative framework to allow us to tackle the threats posed by cyber criminals.
The Home Office has already carefully reviewed the Computer Misuse Act and proposes to introduce a defence to Section 1 for accredited cyber security researchers when carrying out certain cyber security activity that would currently be unlawful under Section 1 of the CMA. The Home Office has worked closely with the NCSC, law enforcement and the cyber security industry to refine these proposals. The noble Lord, Lord Clement-Jones, was briefed by Home Office officials on these proposals in February, and I hope this is able to demonstrate meaningful progress that the Government are making on this issue. The Home Office recognises that legislating in this area is a priority and will do so as parliamentary time allows. As noble Lords here are all aware, the King’s Speech in May included a commitment to a national security Bill, with measures to update the Computer Misuse Act, and work is ongoing to bring forward this legislation.
The review proposed by this particular amendment would be undesirable because it would be limited to the scope of the NIS regulations. This would be too narrow for the scope of the Computer Misuse Act; it is also unlikely to provide the Government with new information on how the Act should be reformed. I am sure that the noble Lord and others in this Room will be active in the passage of this legislation once introduced. I have read his correspondence with the Home Office, including the activities that the noble Viscount, Lord Camrose, referenced, and his expertise across all these areas will be hugely welcomed once it is introduced.
I thank the Minister for that response. The noble Lord, Lord Vaizey, said that we know what the Minister will say: that it will be in a future piece of legislation. To that extent, we are pleased that at least we have a commitment to it, but this has been going on for an awfully long time. We tabled amendments during the passage of the Crime and Policing Act and the Data (Use and Access) Act. There has been plenty of time for the Home Office, or any other department to address this—DSIT could have taken this by the scruff of the neck—because it is such an egregious aspect of the current legislation.
I am pleased to hear that the Minister has read the correspondence. I hope she did not fall asleep while doing so; it is pretty interminable. She may well find that we come back to this on Report because, as she said at the beginning, feelings are running high about it. It is almost a demonstration of how not to run a Government. If you cannot get to grips with something as straightforward and important as this and just make a decision about it, that speaks volumes.
I thank noble Lords who have spoken today and demonstrated support across the board. On a light-hearted note, I say to the noble Lord, Lord Tarassenko, that of course Claude said that; it is trained on my speeches. As the noble Baroness, Lady Harding, said, this is self-evidently sensible. The trouble is, it is self-evident to us, but we despair sometimes, and the perfect must not be the enemy of the good. As the noble Baroness, Lady Neville-Jones, said, the objective is to put researchers in a safe position.
Finally, the noble Lord, Lord Vaizey, exhorted me to make sure that we have a date and a timeline. When will the national security Bill come forward? We saw it in the King’s Speech but I have had no contact from anybody in the Home Office about what they might insert in the Bill. I do not know whether anybody in this Committee has had notice of when a Bill might come forward. I think the Minister recognises the sheer impatience that most of us feel in this field, and I very much hope that, between Committee and Report, we can get some more clarity in this area for the benefit of all those researchers. In the meantime, I beg leave to withdraw the amendment.
My Lords, despite the fact that this is the last group, it is a really important area and this amendment rightly reflects that. We strongly support Amendment 174E. It would introduce a fundamentally elegant and highly necessary cyber security principle that the Bill has otherwise completely ignored: that of data minimisation and the proactive reduction of what is called our national data attack surface.
The most sophisticated cyber defence system in the world cannot protect data that has already been stolen. Conversely, the most ruthless ransomware gang or hostile state-sponsored actor cannot compromise data that was never collected or which has already been securely deleted. In the realm of digital defence, we must move past the narrow defensive mindset of simply building thicker walls around our databases. We must begin to ask a more fundamental strategic question: why are we keeping these massive, un-anonymised and highly vulnerable data honeypots in the first place?
The empirical evidence from our public sector is deeply alarming. We have received detailed and coruscating briefings from the Centre for Long-Term Resilience and our technical authorities. The National Audit Office’s January 2025 report on government cyber resilience revealed that approximately 28% of government technology is legacy software, leaving our public bodies highly vulnerable to attack.
Consider the catastrophic ransomware attack on the British Library in October 2023. When the library refused to pay a ransom of 20 bitcoins, the Rhysida ransomware group released 600 gigabytes of stolen customer and staff data on to the dark web. The library’s own subsequent post-mortem was clear: its reliance on legacy applications and older network designs substantially and unnecessarily increased the volume of sensitive customer data sitting on the network. This was data hoarding, plain and simple, and the price was paid by the British citizens whose personal details are now permanently compromised.
Consider the hack by ExfilSquad, when normal teenagers living with their parents managed to breach a public database, leaking the sensitive personal details of 100,000 police officers and staff on the dark web, alongside data from the Ministry of Defence and the Department for Education. How did they do it? They did not deploy supercomputers or advanced zero-day exploits, they simply exploited a basic, misconfigured Power Pages database. The hackers’ own boast on the dark web was chilling. They said the data was accessible without any authentication whatever.
Why are these databases so large? Because our public bodies routinely collect and indefinitely retain vast, sprawling, unanonymised datasets, from birth certificates and benefit records to housing benefits and electoral roles, without any systematic statutory drive to minimise or anonymise them. That is why the Association of British Insurers and the NCSC both advise that data encryption and data minimisation are critical to reducing the leverage that a threat actor has in ransomware attacks. By rendering exfiltrated data unreadable through encryption—or better yet, non-existent through deletion—we take away the hackers’ ammunition.
While the Bill focuses heavily on the administrative paper exercise of incident reporting, it remains completely silent on the contents of the databases themselves. Amendment 174E would provide a strategic corrective. It would legally oblige the Secretary of State to open a public consultation within one month of the Bill’s passing to evaluate the cyber-resilience benefits of minimising data collection and increasing data anonymisation across our public bodies. By forcing our public sector to lead by example, this amendment could begin the vital work of shifting the UK towards a genuine resilience-by-design model. It would reduce our vulnerability, harden our national defences and protect the digital lives of our citizens. I urge the Minister to accept this vital safeguard.
Baroness Lloyd of Effra (Lab)
I thank the noble Lord, Lord Markham, for raising this important issue again. Good data hygiene and security is essential to ensuring that public bodies are resilient to cyber attacks. Through the Bill, we are better protecting data, to make our essential services safer and more secure for all those who rely on them. This includes through security and resilience requirements, which will form part of the duties placed on regulated entities and which I have mentioned at previous sittings of this Committee. In our consultation later this year, we will propose that these requirements cover data security.
Let me emphasise that where personal data is concerned, all public bodies must already comply with the data protection principles in the UK GDPR. This includes requirements to keep personal data secure, process only the minimum amount needed to deliver their objectives, periodically review whether this data is relevant and adequate for the public body’s purposes and not to retain this data for longer than is necessary. The Information Commission regulates the data protection legislation independently of the Government. It has a range of powers at its disposal to investigate alleged breaches and require public bodies to address non-compliant practices.
Significant obligations exist under the UK GDPR. In addition, our upcoming consultation will examine measures to strengthen data security within the security and resilience regulations. A separate consultation, as proposed by the noble Lord, would not be a good route through, but it would be a good idea for us to meet and think about the most appropriate route for advice on data security in the context of the SRRs. I suggest that we focus our discussion on the SRRs in the intervening period.
As this is the last time I will speak in Committee, I want to reflect on some of the points made by noble Lords. Obviously, productivity and growing the UK economy are big themes for all of us. It is true that we have progressed through Committee faster than perhaps people anticipated, but I have heard very clearly the points that have been made very succinctly, both on fundamental structural issues—to which, as I have said, I think the approach in the Bill is right, I am just logging the fact that I have absolutely heard the motivation for that, around consistency and so on—and indeed on some of the more technical points that noble Lords have made about some of the details of the Bill, some of which I have already undertaken to come back on.
I thank the Committee for its scrutiny and noble Lords for the experience they have brought to the Committee from their practical walks of life.
(1 month ago)
Grand CommitteeMay I interrupt the Minister before she moves on to the next set of amendments? I do not intend to ambush her as regards her amendments this time around, but I seek an assurance, given that there seems to be quite a philosophical difference between her amendments today and those put forward by the noble Baroness, Lady Neville-Jones. There is considerable industry concern about the disproportionality involved. I seek an assurance from the Minister that, between Committee and Report, she will actively consult on the impact of this part of the Bill—Clause 15—and not just when it is in black-letter form. There is quite a lot of concern from many industry voices. It is incumbent on the Government to listen to those voices on the impact of this reporting structure and these duties before they go ahead in a way that many of us believe will not be helpful for the running of these businesses.
Baroness Lloyd of Effra (Lab)
We have already undertaken some consultation and I am happy to commit to contact affected businesses and business organisations and have further conversations between now and Report. Perhaps if I progress a little more, I may be able to answer some of the questions that may have given rise to some of this but, equally, there are different rationales for some different thresholds in the Bill, which, again, I am just about to come on to. I will set out the rationale for those because I think that they are well motivated and are linked to the risk profile that we see in the country and the connectedness of certain regulated entities in the country.
I turn to the amendments tabled by the noble Baroness, Lady Neville-Jones, and her questions to me on the link between the definitions and whether they apply beyond incident reporting. They apply to the security duties within the Bill, which means that regulated entities have a duty to prevent or minimise the impact of incidents. The amendments from the noble Baroness would limit this and reduce their security and resilience. We think that not every incident should be reportable but that organisations need to take appropriate and proportionate steps to mitigate the risks before, during and after a broader set of incidents.
On the second part of the noble Baroness’s amendments and her second question, the Government have recognised that the reporting threshold for data centres is broader than that for other regulated entities under the Bill. This reflects the distinctive role and risk profile of data centres. They are the physical infrastructure underpinning digital services across the economy and the public sector. Unlike the virtual cloud layer, for instance, they combine cyber, physical, personal and operational technology risks. This is particularly important in collocation facilities where infrastructure belonging to numerous customers is concentrated in one location. Then they need physical access to the premises and information about facilities or operational systems. A single incident could therefore exploit both physical and digital vulnerabilities, potentially affecting the confidentiality, integrity or availability of services belonging to multiple customers and sectors. The consequences may also extend beyond the facility’s immediate geographic location, because the hosted service can support users and central services elsewhere. That is the rationale for having this threshold applying to data centres.
To come on to the questions raised, including by the noble Lord, Lord Clement-Jones, on the use of the phrase “capable of”, and the points made in the amendment from the noble Baroness, Lady Neville-Jones, replacing “could have had” or “capable of having” with “likely to have” would exclude some incidents because their eventual impact was uncertain or successfully contained. It would also constrain the security duties, as I mentioned. In reference to the incident reporting definitions introduced by Clause 15, the subsequent detail sets out how the notification of incidents applies in each regulated sector, except for data centres. That is how the definition is made for regulated sectors other than data centres.
There are a lot of safeguards in the Bill to ensure that reporting remains proportionate. It is intended to capture significant near misses, not routine scanning, unsuccessful low-level attacks or ordinary operational events, and clear guidance will ensure that the industry understands this threshold. As the noble Baroness, Lady Neville-Jones, pointed out, we will set this out in secondary legislation and that will allow the consultation to take place that the noble Lord, Lord Clement-Jones, emphasised is so important—we agree with that. We have undertaken extensive engagement to date and will continue to do so.
My Lords, before the noble Baroness, Lady Harding, stands up, I heard what the Minister had to say about consulting across sectors. I was reminded that, at Second Reading, I mentioned the fact that the law firm with which I am associated, DLA Piper, was subjected to a NotPetya ransomware attack back in 2017. What the Minister said is completely at odds with not only what the noble Baroness, Lady Harding, said, but the experience that we had in the way that we needed to understand how these events unfold. It would be really helpful to know from the Minister, or for her to publish, the sectors where the Government have had those discussions and which parts of industry have agreed that this is an appropriate form of incident reporting.
What we are trying to do, throughout the Bill, is to ground it in what is practical. At the moment, despite the fact that we are letting through some government amendments, it seems that we are heading in the wrong direction with this clause. It is going to be disproportionate in the way that it impacts on business and is not even going to be fit for purpose, despite the disproportionality. It is just not going to work.
Baroness Lloyd of Effra (Lab)
I think we all agree that we want a proportionate and clear regime. The noble Lord supports further incident reporting here—additional stages of incident reporting. In our impact assessment, we clearly set out the implications of that in its cost to business and so on. We will come on shortly to discuss potentially broadening the scope of incidents that would be reported. We have not been able to quantify that potential impact, as a sort of counterfactual, because we are only just discussing that.
Baroness Lloyd of Effra (Lab)
I thank the noble Baronesses who introduced their amendments, including the noble Baroness, Lady Kidron, who did so on behalf of the noble Baroness, Lady Morgan, for raising the incredibly important topic of board accountability and senior management oversight. It is absolutely right that organisations, especially those delivering our essential services, are held properly accountable for their activities. That is why the Bill creates a more meaningful enforcement regime in terms of the maximum fines that can be levied—up to £17 million or 4% of turnover, whichever is higher—alongside a simpler process for taking that forward.
I also agree with the points made by the noble Baronesses, Lady Ludford and Lady Neville-Jones, and by my noble friend Lady Berger, on the extent of this being within the regulatory perimeter as well as the non-regulatory perimeter. Boards upskilling themselves and taking training seriously is absolutely imperative. That is why we have our Cyber Governance Code of Practice, which is at the heart of our approach to board and executive accountability. I personally feel that I am an extremely active proponent of this. For those who feel that we are not doing enough, I request their support in continuing to highlight that important code of practice in their own organisations, and on all the numerous boards they sit on, to make sure that we are governing cyber risk appropriately—and that many of the board directors they sit alongside are aware of it.
That is obviously not the limit of the approach that we are taking. We are going to introduce new security and resilience requirements in our secondary legislation. Our proposals will include a dedicated requirement on board-level governance, which will be consistent with the NCSC’s cyber assessment framework. It will cover issues such as organisational capability, senior responsibility, accountability for security and resilience, and effective risk escalation. In that way, we will connect the clarity on what is expected of boards with accountability through the enforcement regime.
I will touch on the point alluded to by the noble Lord, Lord Clement-Jones, on the EU’s regime. Individual liability for board-level members is not mandatory under NIS2. Different EU member states have taken different approaches to implementing the directive in this respect, so there is not a single model of implementation that the EU is following.
To conclude, I would also concur with the point that the noble Viscount, Lord Camrose, made on the importance of attracting those with cyber expertise to take on board-level roles and be able to contribute as part of the board accountable to shareholders in that way. We do not want to introduce anything that might disincentivise either senior executives with cyber expertise or those at board level from taking these very important roles.
I believe that, together with the enforcement regime and the security and resilience requirements, those two things will cement the importance of board and executive accountability firmly into the regime, in the way that noble Lords have highlighted today. That is the right approach.
My Lords, can I just check something before the noble Baroness, Lady Kidron, rises? The Minister has uttered some very warm words about the responsibilities of directors, but am I right in thinking that in nothing of what she said is there any intent for the Bill to create a legal liability that compels directors in the way that these two amendments do, or any form of personal financial fiduciary duty on a director? What she is arguing for, despite the warm words, is, essentially, a voluntary scheme.
Baroness Lloyd of Effra (Lab)
We will consult on the security and resilience requirements that will come out of the Bill. They will contain a requirement on board governance and those expectations will be set out as a result of the Bill. The regulators and others enforcing the Bill will take that into account in their enforcement regime.
I am sorry to press, but the Minister is saying that these are expectations. Will she write to us? There is a huge lack of clarity in the middle of those warm words. We take encouragement from the fact that the Government want to see boards take responsibility, but where are the teeth?
Baroness Lloyd of Effra (Lab)
Obviously, we have not yet gone out to consultation on the security and resilience requirements; we will do that after the Bill passes. I can certainly update on the process, the expectation and how that links with the enforcement duties in further detail.
The Minister is also going to have to point out the power under which the Government are going to act to actually fix that liability, or make sure that the guidance, or whatever it is, is complied with, because we are talking about the power and the duties in primary legislation. It is all very well for the Government to say, “We’re going to produce guidance”, but unless there is something in the Bill that permits that and makes sure that the Government can make it stick, we are all going to feel dissatisfied.
Baroness Lloyd of Effra (Lab)
I am happy to write to explain how the security and resilience requirements fit into the structure of the Bill and the consultation and scrutiny that they will undergo.
Baroness Lloyd of Effra (Lab)
My Lords, I thank noble Lords for raising so many aspects of the scope of the Bill. I recognise the sentiment among noble Lords today about the importance of expanding its scope. Our approach has been to target regulatory requirements on a select number of essential services, while using non-regulatory but effective measures to improve the cyber security and resilience of the wider economy.
As I set out at Second Reading, I have asked my officials to work across government to consider what additional services would merit being brought into scope of the regime in future. This will allow us to make a holistic and considered approach. To ensure our assessment is appropriately prioritised, I would first like to focus on the CNI sectors not already covered by the NIS regime.
I share the intent behind the objective from the noble Viscount, Lord Camrose—which the noble Lord, Lord Markham, spoke to—that the process to expand the scope of the regime should be rigorous and evidence based. As set out in the Bill, for something to be defined as a new essential activity under its powers, the Secretary of State must be satisfied that the activity is essential to the economy or the day-to-day functioning of society in all or part of the UK. This is reserved for the most vital activities in our nation. To the point raised by the noble Lord, Lord Birt, I believe that that is a clear test. In reaching a decision, the relevant departments would need to carry out a risk assessment and any economic assessments, and consider whether inclusion is proportionate. This is part of normal policy development. After that, proposals would be subject to consultations and the affirmative procedure.
The noble Viscount proposed in his amendment that assessment for inclusion be carried out on an entity-by-entity basis, which obviously differs from the sectoral approach we have taken thus far. Setting out the detail that would need to be published according to the amendment could lead to a release of information about individual companies that could pose commercial or national security risks, due to their criticality. I think that the sectoral approach is better. As others have said today, looking at a systemic approach to the sectors is the right way to look at what is in the statutory approach.
I am sorry to interrupt the Minister, but clarification along the way would be very helpful. She has asked her officials to see what other sectors should be brought in and has given an indication of the kind of test, but we are dealing with a bit more fog here. Is she promising us something in primary legislation or will it appear in secondary legislation? Will it just be something that government policy will cover, and we will have no say on the kinds of sectors that should be included?
For instance, the Minister is the Space Minister. Do we have an indication that space, or any of the key activities within space, will be included? Do we have any white smoke from the department as to whether that sector will be included? Will we hear by Report what sectors might be included? It is all a bit vague, and that does not give us a great deal of assurance.
Baroness Lloyd of Effra (Lab)
I was referring to the process by which sectors can be brought into scope of the Bill, as set out in it and using the powers in the Bill. That would follow the process I just mentioned, which would be subject to consultation and the affirmative procedure. That is the process that I am referring to.
But the powers are further down the track; they are under secondary legislation. I am assuming the Minister is promising that the Secretary of State will set out the criteria by which a new sector is brought in. Is that right? Do we have any indication, apart from what the Minister has said today in response to the noble Lord, Lord Markham, as to what those criteria will be?
Baroness Lloyd of Effra (Lab)
I have highlighted a few of those criteria regarding the extent to which the activity is essential to the economy or the day-to-day functioning of society in all or part of the UK. Obviously, we already have the list of critical national infrastructure. We need to go through a whole process, as others have mentioned. We would need to make our assessment and then consult with industry on that, so there is a process to go through here. That process of consultation and talking to industry, or any affected sector, is absolutely critical. I am absolutely happy to update noble Lords and engage further ahead of Report on this.
In terms of the report referenced in Amendment 92A, I do not think we would need a statutory obligation to bring this report back, as set out. I mentioned the focus on entities rather than sectors, and it is better to look at the sectoral approach.
My Lords, if the Minister could commit to adding that to the conversations we are bound to have to have between now and Report—
Baroness Lloyd of Effra (Lab)
I am not only committing; I am offering, so I am happy to have the noble Lord confirm that that would be good. I am absolutely offering that as part of the engagement ahead of Report.
I have heard the numerous areas that have been raised for inclusion in the Bill. We should look in a methodical and sensible way at these and at the implications—as we have previously discussed—for the obligations that will placed on any entities that come within the scope of the Bill, such as incident reporting, board accountability and so on, so that we do this in a very sensible manner. That is why this is the right approach to take.
My Lords, at the risk of irritating the Minister even further, it is great to hear of some of this activity, but that is not the same as bringing it under the terms of the Bill.
Baroness Lloyd of Effra (Lab)
It is not the same. I wish to stress that the importance of strengthening cyber resilience can happen outside of legislation being put in place. There are many efforts that can go on to improve cyber resilience.
Moving on to the amendment of the noble Baroness, Lady Ludford, and her question about the scope, as well as the questions of the noble Lord, Lord Russell of Liverpool, about CRMs and so on, I do not know the specifics of this CRM. I am very happy to write after hearing of the attributes that were enumerated for its characteristics. Businesses that offer software as a service are in scope of the NIS regulations as cloud computing services, under the RDSP definition, if they meet the definitions in the Bill. In the case of the particular company that was mentioned, I do not know whether that would meet any definitions in the Bill.
Data protection legislation is obviously in place already, and processors are meant to have the systems in place for regularly testing, assessing and evaluating the effectiveness of their measures for ensuring the security of that processing. That legislation is already in place.
Moving on to the public sector, I will respond to the questions from the noble Lords, Lord Birt and Lord Clement-Jones. The Government are already taking equivalent steps to secure their own essential activities through the Government Cyber Action Plan, published in January this year. That plan applies to government departments, arm’s-length bodies and wider public sector organisations. It sets out clear expectations, targets and milestones at all levels to transform cyber security and resilience in the public sector. The outcomes of the plan are aligned with those of the Bill; there will be a consistent approach to strengthening cyber resilience across the public sector. Government departments are accountable for setting expectations and overseeing resilience across the sectors and organisations within their purview, while individual organisations remain responsible for managing their own cyber security and resilience.
This brings me on to Amendment 81A—
Baroness Lloyd of Effra (Lab)
Let me work backwards here. The noble Baroness makes a very good point: the services delivered at local level often mirror those at central government level. At the moment, we are consulting on the question of the best value duty to give additional prominence. One of the issues with mapping these requirements into local government is that many different services are indeed provided. We may need to come back to that in more detail.
The government cyber unit now resides within DCMS. The team has transferred over and is up and running; I have spoken to them many times recently. The unit is very active in progressing the government cyber action plan as per the timetable and the target plan.
On the question about the approach to looking at other sectors to bring in, that is why I mentioned at Second Reading that I had already asked my officials to work across government to consider what additional services would merit being brought in. I mentioned earlier today that focusing on CNI services not already covered by the NIS regime would be the right place to start.
My Lords, will the Minister show some greater enthusiasm for her own regulatory scheme? I hope that the criteria that she adopts within the department as to whether certain sectors are going to be brought in will be about not only the criticality of the services but the need for transparency on the incidents themselves. We have had this whole debate about notification being beneficial so that organisations such as the NCSC actually know what is going on, that we the public know what is going on and the level of threat, and that our intelligence services are fully apprised.
The noble Baroness, Lady Neville-Jones, was entirely right on critical sectors, such as space. If there is no duty of notification on, say, a satellite manufacturer or something, we will all be in the dark. The Government rightly introduced this Bill to introduce greater transparency and duties on some very important sectors. We simply want to make sure that we capture all the important sectors and that they are all subject to the duty. This shying away from the Government’s own framework seems completely contrary.
My Lords, I thank all noble Lords who have added their names to the amendments and who have spoken in this debate. Both amendments in this group are underpinned by the same principle that national security and national technological capabilities deserve a unified plan—not one that targets some sectors and entities and not others, but a holistic plan that brings together all sectors and industries into a single framework. His Majesty’s Opposition therefore support the intention behind the amendments.
However, at risk of repetition, the Government could avoid the need for these propositions. They could do away with your Lordships’ worries if they would commit, as mentioned by my noble friend Lord Camrose, to publishing a national cyber action plan within a set timeframe, and commit to including national digital sovereignty as part of that plan. In light of Tuesday’s debate on AI, we request a review and update of the previous Government’s AI White Paper to ensure that AI regulation and cyber regulation are aligned. They need to operate in lockstep, and this Bill is an appropriate place to do it. It is evident that national sovereignty and a reduced reliance on foreign technology is vital to ensuring national wholesale cyber security. I commend these amendments in their aims to achieve that, and I look forward to the Minister’s reply.
Baroness Lloyd of Effra (Lab)
I thank noble Lords for continuing the debate with which we ended the previous session: the very important topic of the technological and digital sovereignty of the UK. That is very important to this Government and we are taking action on it. It possibly has not been focused on enough in past years but, across many areas, that is what we are doing.
We are clear that we need a coherent approach and a clear direction. We obviously need to take into account that technologies and markets evolve, and the core of that approach was set out in the modern industrial strategy and the Digital and Technologies Sector Plan. That set out the direction of travel, and the Government will continue to consider how our priorities are best articulated.
Our objective, as I articulated at the end of July, is not complete independence but strategic resilience through a combination of domestic capability, diversified international partnership and targeted management of critical dependencies. This allows us to access the best of global markets while capitalising on our domestic capabilities. That is why we already have in place a range of regulatory and non-regulatory frameworks that enable us to embed those objectives through existing industrial, technological and resilience strategies. I will talk to some of those now.
For essential services in scope of the network and information systems regime, such as drinking water, health and energy, all entities are required to manage and mitigate the risks posed to their systems that deliver essential services. This includes the risks set out in the amendment of the noble Baroness, Lady Ludford.
On market concentration, which the noble Baroness, Lady Kidron, and the noble Lord, Lord Clement-Jones, referred to, the CMA is acting. It concluded an investigation into the cloud services market in July last year, highlighting competition issues arising from market concentration. It has since announced packages of actions to improve competition in cloud services. This work has directly informed our thinking, as we develop a more strategic approach to how the public sector procures cloud services.
My Lords, I point out to the Minister that not all is rosy in that particular cloud services garden. The CMA failed to designate those major US hyperscalers as having strategic market status, which, for many of us, was a rather extraordinary outcome.
Baroness Lloyd of Effra (Lab)
It has announced a series of measures, including actions from Microsoft and Amazon, to support greater choice for UK businesses and the public sector.
On my noble friend Lady Berger’s question, it is true that cloud spend is distributed across departments and managed through a range of departmental contracts and commercial arrangements. We have established a cross-government cloud consumption dashboard to improve the visibility of cloud usage across the public sector, and we are working with both suppliers and departments to further improve the quality and completeness of our cloud infrastructure spend data to provide a joined-up view today and for the future. That is something that the Government are acting on.
(1 month ago)
Grand Committee
The Parliamentary Under-Secretary of State, Department for Business, Innovation, Science and Trade and Department for Digital, Culture, Media and Sport (Baroness Lloyd of Effra) (Lab)
My Lords, I will also speak to the other amendments in my name in this group. I thank noble Lords for their constructive engagement on this topic over the Summer Recess. I particularly thank the noble Viscount, Lord Camrose, and his colleagues for sending their questions in advance. I will seek to address those in my opening remarks.
This package of amendments introduces new powers that will enable the UK to address vendor-related cyber risks in our critical infrastructure. The principal new clause introduces a new direction power. It enables the Secretary of State to direct entities in scope of the power where they are using, or may potentially use, vendor-supplied goods, services or facilities in connection with their network and information systems that could create national security risks.
It is becoming increasingly clear that there are axes of cyber risks that the Government need to address. These risks arise from goods or services supplied by another company being harnessed as tools for sabotage, surveillance or espionage. But they also exist where goods or services constitute critical points of failure due to their defective design or vulnerabilities. Noble Lords would have had some sense of these risks from debates during this Bill—in particular, discussions about remote access in embedded products such as cellular modules and the scope for hostile interference and control.
GCHQ has also raised escalating concerns about supply-chain vulnerabilities in the wider geopolitical context. The director of GCHQ explicitly called out those risks in her annual lecture in May this year when discussing the challenges posed by a relationship with China and the threats posed by Russian cyber operations. That is why we have tabled Amendment 102 to tackle decisively these risks and protect our national security. Our intention is to limit the use of this power to operators of essential services in the first instance, although we will review the case for bringing other entities into scope in the future.
Supplementary amendments contain the mechanisms needed to operationalise the power. They enable the Secretary of State to set statutory timeframes for decision-making, to specify and update which entities are in scope of the vendor-related direction power and to introduce mandatory procurement screening should this ever be considered necessary to protect national security. They also introduce a power to bring more entities into scope of the existing direction power in Clause 43.
The powers to bring entities into scope of this framework are rightly restricted. To be brought into scope, the Secretary of State or Chancellor of the Duchy of Lancaster must be satisfied that the entity is essential to the economy or the day-to-day functioning of society in all or part of the UK. This is consistent with the Bill’s definition of essential activity in Clause 24. Either Minister can exercise the power. It has been drafted like this to accommodate machinery of government changes.
The decision to introduce the amendments has not been taken lightly. The Bill already includes important national security powers to direct regulated entities whose systems have been compromised, or which are at risk of being compromised, by hostile actors. This new power allows the Government to act before vendors become embedded in supply chains and before taking action becomes costly and disruptive. It will give operators greater confidence in their procurement planning and avoid the need for costly interventions down the line.
Crucially, we are not proposing to introduce these powers in isolation. They will be part of a broader framework which will also include procurement guidance for operators and a voluntary referral route into government where operators have identified potentially risky procurements. The voluntary self-referral route will enable the Government to assist operators with vendor-related concerns, provide them with guidance on how to proceed and, where necessary, inform decisions about the issuing of a direction.
We intend to consult on the implementation of the framework in due course. This will include the criteria for referral and how the mechanism will work in practice. In the event that this Government ever determined a mandatory referral scheme was necessary, we would intend to consult on the definition of a “qualifying transaction” before laying the necessary secondary legislation. However, I emphasise that it is not our current intention to set up a mandatory scheme.
Ultimately, we expect this wider framework will minimise the need for formal interventions using the new powers. However, it is crucial that the power is in place as a backstop to guarantee the Government’s ability to protect the UK’s national security. I beg to move.
My Lords, I assume that there are no Back-Bench contributions at this point, so I will speak on behalf of the Liberal Democrats to this very significant group of amendments tabled by the Minister as recently as 24 August. I thank her for her introduction today and for her brief meeting shortly after their tabling.
At the outset, from these Benches we express our strong concern about the timing and the sheer scale of the Government’s package of new amendments. To drop 65 amendments of this nature on the eve of Committee, which will completely reshape the architecture of this Bill, after its passage through the Commons, is a major challenge to effective parliamentary scrutiny. The Minister’s letter, also dated 24 August, came alongside these 65 new amendments, so we have had very little time to consider them. As far as I can see, a full Ministerial Statement did not accompany them; we had to rely on the coverage of Computer Weekly to understand the Government’s motives.
The Government have quietly established a major parallel high-risk vendor regime. Under Amendments 102 and 103, the Secretary of State—and now, crucially, under Amendment 101, the Chancellor of the Duchy of Lancaster—are granted unilateral powers to issue vendor-related directions. They can legally order an organisation to prohibit, restrict, remove, disable or modify any software, hardware or digital facility supplied by a designated high-risk vendor. Furthermore, under Amendment 105 they are given the power to establish a mandatory referral scheme, legally forcing companies to submit technology procurement contracts to the Cabinet Office for security clearance before signing.
Let us look closely at the operational mechanism in Amendment 103, which ISC2 has rightly highlighted. The proposed new clause mandates that a company appoints a “skilled person” to oversee compliance and, under subsection (5) of the proposed new clause, permits the Secretary of State to rely on a list of persons published by GCHQ. I ask the Minister: what is this list? Is it public or classified? What objective criteria will govern inclusion? How will conflicts of interest be avoided, and how will independent professional competence be assured? To create statutory compliance roles backed by secret lists is entirely unacceptable.
Under Amendment 108, the Secretary of State can make regulations bringing any specific company into the scope of the Clause 43 directions without bringing them into the NIS regulations as a whole. Under Amendment 127, the Government will insert an emergency “made affirmative” procedure allowing regulations and vendor bans to take effect immediately without prior parliamentary debate. Furthermore, under Amendment 148 the Secretary of State can prohibit a company disclosing that they have received a direction or are in consultation, backed by civil penalties of up to £10 million or £50,000 per day.
There is also a second critical implication—the backdoor regulation of advanced artificial intelligence systems. At Second Reading, the Minister assured the House that advanced AI systems and LLMs were out of scope. These amendments appear to reverse that position. Under Amendment 108, any entity providing essential goods or services can be specified. As our critical infrastructure increasingly integrates agentic AI models, such as GPT-5 or Anthropic’s Mythos, these developers become points of supply chain risk concentration. It seems that, under Amendment 102, the Government can designate AI developers as high-risk vendors and mandate pre-procurement vetting. Is that the case and, if so, why not say so?
The Government will no doubt resist the transparent, legally bounded emergency shutdown power proposed by Amendment 84, with its High Court backstops and seven-day parliamentary reporting, yet here the Government demand sweeping, secretive executive powers to ban software, veto procurement and gag businesses with zero judicial checks. These Benches cannot give these 65 government amendments a free pass. I remind the Minister that, in Grand Committee, unanimity is required for amendments to carry. We insist that the Government come back on Report with strict guardrails and clear limits on executive market intervention without parliamentary consent before these new powers can be exercised.
Quite apart from that, both the Constitution Committee and the Delegated Powers and Regulatory Reform Committee had something to say about the existing powers in the Bill, but neither committee has had a chance to look at these amendments. I am sure that they will have comments to make in due course.
Baroness Lloyd of Effra (Lab)
I will need to write to the noble Lord on that specific question of how GCHQ’s powers are executed in respect of operational decisions such as this. I am aware that in other areas they are within Secretary of State responsibility, whether they are exercised by a Secretary of State, advised by GCHQ or whether, as the noble Lord suggests, they are actually undertaken by GCHQ.
My Lords, I thank the Minister for her gracious, intended withdrawal of Amendment 1, and I am sure we will have a much better debate on Report as a result, particularly once we have had a chance to read her remarks on both interventions today. However, I hope she will agree with me, especially in terms of what she said about being technology agnostic through the Bill, that we will have a much better debate as we come to talk about specific AI issues as a result of not having already incorporated those in the Bill. So, all the way around we will have a much better debate about the proper shape of the Bill as a result of those amendments being withdrawn.
Baroness Lloyd of Effra (Lab)
With that, I believe now is the time where I beg to leave to withdraw Amendment 1.
(2 months, 2 weeks ago)
Lords ChamberTo ask His Majesty’s Government what assessment they have made of the EU’s technological sovereignty package; and what plans they have to introduce equivalent instruments to protect and promote the UK’s artificial intelligence capabilities.
The Parliamentary Under-Secretary of State, Department for Science, Innovation and Technology (Baroness Lloyd of Effra) (Lab)
We have undertaken an initial assessment and are working through a detailed assessment of the EU’s technological sovereignty package. This includes proposals on CADA and chips. Our current assessment is that the package presents both opportunities and risks to UK industry. We will continue to engage with industry and European partners as proposals evolve. For the UK, AI sovereignty means reducing overdependencies, strengthening resilience and backing British capability, including through the £1.1 billion AI hardware plan and our sovereign AI fund.
My Lords, I declare an interest as a consultant to DLA Piper on AI policy and regulation. The EU’s Cloud and AI Development Act will set out a framework with sovereignty criteria for public sector procurement. The Government’s AI hardware plan, mentioned by the Minister, is welcome, but it contains no equivalent procurement-linked sovereignty framework. Given that the Government’s public procurement overwhelmingly relies on US hyperscalers, can the Minister commit to introducing a UK AI sovereignty assurance framework to ensure that public sector services and critical national infrastructure are nationally resilient?
Baroness Lloyd of Effra (Lab)
The Government have already set out their intention to use public sector buying power more strategically. The January 2025 blueprint for modern digital government noted that public sector organisations often contract locally and individually, limiting the impact of the £26 billion of annual technology spend, and committed to continue working on whole of public sector agreements. We are also developing the national cloud infrastructure programme, a strategic initiative to co-ordinate how the public sector buys cloud services. This programme will use the collective buying power of the whole of the public sector to secure better value for taxpayers, strengthen digital resilience and create new opportunities for British businesses.
(2 months, 2 weeks ago)
Lords Chamber
Baroness Lloyd of Effra (Lab)
The Government are acting to ensure that the UK can grasp the transformative potential of AI. That includes developing our sovereign capability and, as the noble Lord mentioned, relying on the advice of the AI Security Institute. Our approach is that we will legislate where we need to. We have done so through the Online Safety Act and we are doing so in other areas where we see the need. We believe that the best way of regulating is through context-specific regulation, which will take into account the specific issues that arise when AI is adopted by particular sectors.
My Lords, I declare an interest as an adviser to DLA Piper on AI regulation and policy. The Government followed Australia in its approach to access to social media for under-16s. Will they do the same with AI, now that Australia will be adopting mandatory standards for AI, as nine in 10 of the British public clearly want?
Baroness Lloyd of Effra (Lab)
The UK’s approach is to develop our sovereign capabilities. We are investing in infrastructure and in AI growth zones. We are working to ensure that everyone in this country benefits from the potential of AI and are upskilling 10 million workers. In respect of the regulatory environment, AI can be adopted in many different areas: it can advance drug discovery, or it can support teachers in classrooms so that they have more face-to-face time with pupils. It is right to take a context-specific regulatory approach.
(2 months, 3 weeks ago)
Lords Chamber
Baroness Lloyd of Effra (Lab)
My noble friend is right about the potential of AI and that many people are uncertain about how it will develop in the future. The critical point that I think he and I agree on is that the best way of approaching this technological development is equipping people in all regions of the country—young people and those who need retraining—which is exactly the approach we are taking. With our AI skills boost, we will upskill 10 million people in work, and we have already reached 1.7 million. In that way, workers in this country will be able to make the most of this technological revolution.
My Lords, the Milburn interim report, Young People and Work, found that a growing share of entry-level roles are now filtered by algorithmic screening before a human has even seen an application. Given that NEET numbers are shockingly high, what specific assessment have the Government made of the extent to which AI-driven recruitment tools are narrowing rather than widening life chances for these young people? Will the Minister commit to mandatory algorithmic impact assessments, as suggested by the TUC, for recruitment algorithms so that employers and platforms are required to test for bias before these tools are deployed at scale?
Baroness Lloyd of Effra (Lab)
The Government previously set out guidance on recruitment in the age of AI. The new future of work unit will look at what is developing in the labour market and at whether guidance such as that needs updating and in what respect. In the meantime, we are supporting young people, through our youth guarantee and through provision of early training opportunities for them, so that they can get into work now and continue to advance through their careers.
(2 months, 3 weeks ago)
Grand Committee
The Parliamentary Under-Secretary of State, Department for Science, Innovation and Technology (Baroness Lloyd of Effra) (Lab)
My Lords, I beg to move this draft order. Wireless connectivity underpins a vast range of everyday services, from mobile phones and wifi to broadcasting and satellite communications. All these rely on access to radio spectrum. Spectrum is a finite and valuable resource, and it must be carefully managed to ensure that different services can operate without interference, that networks function reliably and that consumers and businesses benefit from competition and innovation.
In the UK, Ofcom, the independent communications regulator, manages spectrum by issuing licences, setting conditions and promoting efficient use. Government set the overall policy and strategic priorities for spectrum, including through the statement of strategic priorities that Ofcom must have regard to when discharging its functions. Maintaining a clear and effective framework for managing spectrum is therefore an important part of supporting investment in digital infrastructure and the wider economy. This instrument contributes to that by improving legal clarity without changing existing services, business models or regulatory requirements.
This draft order revokes a direction given to Ofcom in 2010. At the time, the Government used this direction to ensure that a specific set of reforms to support the rollout of mobile broadband was implemented clearly and at pace, alongside Ofcom’s existing statutory framework and in line with wider European measures to harmonise the use of key spectrum bands. These measures included allowing operators greater flexibility in how they could use key spectrum bands, enabling spectrum trading so that licences could be bought and sold, updating licence conditions to support long term investment, setting licence fees to reflect full market value and preparing for major spectrum auctions. Together, these changes helped operators transition from older mobile technologies towards newer ones, enabling the rollout of 3G and 4G services more quickly and efficiently and supporting the widespread availability of modern mobile services across the UK. The reforms also reflected wider European measures to harmonise the use of key mobile spectrum bands and support this transition.
All the obligations set out in the direction have now been fully implemented by Ofcom through a series of regulatory actions over the past decade. As a result, the direction no longer has any practical effect and is now redundant. This instrument therefore revokes that direction. Its removal will improve the clarity of the legal framework and remove the risk of confusion that could arise from retaining obsolete provisions. For example, when Ofcom looks to set annual licence fees for mobile spectrum, we want to minimise the risk of unnecessary legal challenge. The direction requires Ofcom to have particular regard to the outcome of the 800 megahertz and 2.6 gigahertz auction when setting certain licence fees. That auction took place in 2013; retaining the direction could create uncertainty about whether those historic auction outcomes should continue to carry special weight today.
This instrument does not introduce any new policy or change the way that spectrum is managed in the UK. Ofcom will continue to exercise its functions under its existing statutory framework, including duties set out in the Communications Act 2003 and powers under the Wireless Telegraphy Act 2006. These provide the framework for managing spectrum efficiently, promoting competition and investment and protecting consumers. This step will help ensure that the framework underpinning wireless connectivity remains clear and effective and supports continued investment. I beg to move.
My Lords, I thank the Minister for introducing this order. I am somewhat intrigued as to why we are privileged to have two Ministers for these orders, which are both under the heading of electronic communications. No doubt the mystery will be resolved. Of course we do not oppose this instrument and I do not intend to detain the Committee long on what are, on the face of it, tidying-up measures. However, they raise a question or two worth putting to the Minister.
We have no quarrel with removing a direction that has plainly served its purpose. As the Minister said, Ofcom completed the work that the 2010 direction required years ago. However, can she say a little more about why now? The Explanatory Memorandum notes that retaining the 2010 direction risks creating
“legal challenge against Ofcom if they proceed with changes to licence charging arrangements”.
That is not a housekeeping observation but a forward-looking one; it suggests that Ofcom already has changes to spectrum licence fees in contemplation. Can the Minister tell the Committee what those changes are and on what timetable we might expect to see them?
Looking further ahead, can the Minister say something about how the Government see the framework for spectrum direction-making evolving to meet the demands of 5G and 6G rollout, non-terrestrial and satellite networks, and the rising spectrum needs of AI-related infrastructure? The 2010-era framework, tied as it was to 3G liberalisation, was never designed to anticipate those needs.
(3 months, 1 week ago)
Lords Chamber
Baroness Lloyd of Effra (Lab)
My noble friend is right to draw attention to the strengths of the UK in AI. Given the pace of change, the UK is determined to shape AI and not be shaped by it. These are issues that countries do not face alone, so we are working with international partners to seize the opportunities and address the challenges that AI presents, both bilaterally and multilaterally. The UK is well placed to lead, including through our AI Security Institute, working with allies to share expertise, build capability and strengthen our resilience together.
My Lords, I declare an interest as a consultant to DLA Piper on AI policy and regulation. The UK signed the Council of Europe Framework Convention on Artificial Intelligence nearly two years ago. Can the Minister tell the House when the UK intends to ratify the convention, and what steps the Government intend to take to implement it, given their own statement that
“existing laws and measures will be enhanced”
once ratification occurs? Has the moment arrived for the UK to champion binding international obligations on AI, rather than continuing to place its faith in voluntary commitments that have clearly failed to hold either Governments or developers to account?
Baroness Lloyd of Effra (Lab)
The convention on AI is flexible and does not create new human rights obligations. Contracting states are given broad discretion when it comes to selecting the appropriate form of implementation, including sector-led regulation. That fits with our mission to highlight the benefits of AI for working people in a way that recognises that regulation largely is based on a sector-based approach.
(3 months, 2 weeks ago)
Lords Chamber
Baroness Lloyd of Effra (Lab)
The Government support clean competition in sport, and the Department for Culture, Media and Sport supports UK Anti-Doping and UK Sport in their efforts to protect clean sport and educate athletes on the risks of performance-enhancing drugs. The Online Safety Act covers situations where illegal products are marketed, and it is for Ofcom to enforce that area. As I mentioned, the children’s harms guidance makes it clear that sponsor or influencer-promoted content can be in scope where it actively encourages children to consume harmful substances.
My Lords, the BBC investigation found that these illegal substances are readily available from online sellers based both in the UK and overseas, yet there is no systematic requirement for platforms to know who is placing these advertisements, particularly of the kind that the noble Lord, Lord Winston, referred to. Will the Government ensure that forthcoming work on online advertising standards includes a requirement for platforms to verify the identity of those placing advertisements for health and physique-enhancing products so that enforcement bodies can identify and pursue those responsible?
Baroness Lloyd of Effra (Lab)
The noble Lord is right that the Online Safety Act already covers illegal content and child safety duties. Those duties are in force. Ofcom is now turning its focus to the additional duties for categorised services, which will include protections against fraudulent advertising. We are expecting Ofcom’s consultation on the additional duties next month, which should cover a number of the issues that the noble Lord raises.
(3 months, 2 weeks ago)
Lords ChamberMy Lords, I, too, thank the Minister for taking the Statement today and for her alert. On these Benches we welcome the fact that the Government have finally responded to the overwhelming public demand to protect our children online, especially from the bereaved parents: like the noble Viscount, Lord Camrose, I pay tribute to them and to their campaign. We share the Government’s diagnosis. There is a genuine children’s mental health crisis and the platforms have for far too long been allowed to profit from it.
However, we fundamentally disagree with the Government’s prescription. After months of insisting that a drawn-out consultation was absolutely necessary before any action could be taken, what has been announced appears to be a panicked policy cobbled together ahead of a by-election and a Back-Bench rebellion. It appears that DSIT’s own expert panel flagged a “substantial” lack of evidence to justify key aspects of the plans. Can the Minister tell the House what steps the Government are taking to address those evidence gaps before the regulations are laid?
The Australian model the Government are adopting is based on definitions and lists. It bans specific platforms while trying to carve out exemptions for messaging or education. As my honourable friend Caroline Voaden pointed out in the Commons, the internet moves far too fast for lists. The moment one platform is banned, another unnamed platform launches. This is, at its heart, a “dangerous dogs” approach to regulation, focusing on arbitrary categories rather than the actual risk of harm.
The Secretary of State made a startling admission at the Dispatch Box. She openly acknowledged that children will find workarounds, using VPNs or fake IDs, stating that
“kids will get around this … That is what kids do”.—[Official Report, Commons, 15/6/26; col. 606.]
If the Government themselves acknowledge that children will bypass this ban, how exactly does a policy built purely on exclusion protect them? Does it not simply give parents a false sense of security and, worst of all, let the tech giants completely off the hook?
As the noble Baroness, Lady Kidron, has tirelessly argued in this House, with our support, we must regulate the product, not just the child. This is about safety by design. Instead of an outright ban, the Liberal Democrats have consistently called for a targeted and coherent harms-based framework: films-style age ratings for platforms. Under our approach, platforms that deploy addictive algorithmic feeds or host inappropriate content would be legally restricted to users over 16 and the most extreme sites rated 18-plus. Will the Minister explain why the Government have rejected this approach and why the burden of proof is not being shifted to the tech companies themselves, forcing them to remove toxic, addictive features such as infinite scrolling, autoplay and manipulative algorithms.
As the Molly Rose Foundation has rightly warned, relying on blanket bans risks migrating bad actors, groomers and violent groups from banned platforms to permitted ones or into the dark web. We will end up playing a desperate, endless game of whack-a-mole with children’s safety. What assessment have the Government made of that migration risk?
There is also a dangerous cliff edge in what is proposed. DSIT’s own expert panel warned in writing that a sudden transition at 16 could lead to intensive uptake and increased risks. We risk keeping children in a sterile digital environment until their 16th birthday, only to suddenly expose them to harmful, unfiltered content the moment they come of age, without having helped them to safely develop the digital and emotional resilience they will need throughout their lives. What specific measures does the Minister propose to address that cliff edge?
The Statement is also glaringly silent on the commercial exploitation at the heart of this crisis. Will the Minister confirm when the Government intend to raise the digital age of consent from 13 to 16?
Finally, any ban or restriction is entirely meaningless if the regulator lacks statutory teeth. We have a fundamental enforcement deficit. The Australian experiment already demonstrates the immense difficulties with enforcement and circumvention: six in 10 children there are still on social media six months after the ban came into force. Will the Minister commit today to a formal review of Ofcom’s enforcement powers within six months to ensure that the regulator has the necessary tools—business disruption measures, injunctive relief— to compel tech giants to change their business models?
We will rigorously scrutinise the forthcoming regulations and continue to press the Government to move away from blunt exclusion towards a robust harms-based framework that holds these tech giants properly to account. This must be indeed big tech’s seat-belt moment, but a seat belt protects a passenger within a vehicle; it does not simply ban them from the road. We need a smart approach that allows young people to benefit from the best of the digital world—and indeed, as the noble Viscount, Lord Camrose, says, prepare to vote at 16—and to learn, connect and grow while properly dismantling the addictive profit-driven architecture that is doing them such harm.
The Parliamentary Under-Secretary of State, Department for Business and Trade and Department for Science, Innovation and Technology (Baroness Lloyd of Effra) (Lab)
I thank the noble Lord, Lord Clement-Jones, and the noble Viscount, Lord Camrose, for their contributions. They have been at the forefront of calls to engage on how to make our online world safe for children growing up for many years, and I join them in paying tribute to the bereaved families who have also been tirelessly campaigning on this issue.
The Government set out earlier this year our intention to consult parents, children and young people on what more needs to be done. We also committed to act swiftly following that consultation. We repeatedly said, “The question is how we act, not if we act”. The two noble Lords have expressed concern about the Government’s consultative approach. Perhaps they have questioned whether it was needed. We feel that the approach has been both swift and responsible. A short, focused consultation was necessary so that we could hear that input. We received over 116,000 responses from parents, civil society, industry and, crucially, children and young people themselves. The magnitude of that engagement demonstrates the range of strong views. We felt that it was critical to listen to those children and families and to have a national conversation.
This week we have set out plans to ban social media platforms from allowing those under 16 to access them. On the point made by the noble Lord, Lord Clement-Jones, we have also announced our intention to restrict under-16s from accessing some harmful functionality, such as livestreaming and features that enable the discoverability of children and facilitate unrestricted communications with strangers. It is by doing those two things together that we build a safer future. Those features will also be off by default for 16 and 17 year- olds, and we have made it clear that we will age-gate features on AI chatbots that enable sexually explicit interactions to over-18s. We believe that will deliver graduated, age-appropriate experiences and address concerns about the issue of cliff edges, as highlighted by the noble Lord, Lord Clement-Jones.
On the question of speed and when we are going to act, we have committed to moving as quickly as possible to lay these regulations on social media by the end of the year, to vote as quickly as we can on those, and to implement them by spring 2027. By taking the powers in the Children’s Wellbeing and Schools Act, we can move at this speed.
Noble Lords also asked about the digital age of consent. We have said we will come back to some other questions that were raised in the consultation—for example, the digital age of consent and the risk of circumvention through virtual private networks—in July, when we will come back on further details.
On the question of different ages, it is indeed the case that there are many different ages in our legislation for access to alcohol and access to gambling. That is a feature of our legislation. We feel these are the right ages to restrict social media companies from providing services to under 16 year-olds—and, as I mentioned, setting the default features for 16 and 17 year-olds.
In terms of the scope, this is indeed based on the Australian criteria. We will set out, with the regulations later this year, exactly the criteria that we choose in our regulations. In respect of age verification, currently the Ofcom guidance recommends the following age-assurance methods for over-18s: passports, driving licences, credit cards, facial scanning, mobile network operator checks, open banking checks, or email-based age estimation. Some of these will not work for the 16-plus category. That is why the Secretary of State has asked Ofcom to look at options for highly effective age assurance for 16 year-olds. We have asked that it publishes its findings in October, so that Members of this House can consider them before voting on the regulations. So, to answer the question of the noble Viscount, Lord Camrose, on age verification, there are a variety of models.
On the question of evidence gaps, we are aware, obviously, that social media moves quickly and that new services may be provided. We think that this can provide some opportunities. The current legislation is set in a certain way. Once the legislation and the regulations are changed, this will provide the opportunity for providers to provide services that they do not today—for example, to access the news or other services. This may provide our children and young people with better opportunities than they have today.
We also recognise that some children may attempt to circumvent age restrictions. What we are setting out in this set of proposals is a new societal norm. We are resetting what is expected. This will benefit children today and, importantly, it will benefit children growing up today who have not yet reached the age of 13, 16 or 18—the generation of tomorrow.
On the question of enforcement powers, obviously this is an incredibly important point. We need the new regime to be effectively enforced. That is why the Secretary of State wrote to the chair and CEO of Ofcom to reinforce this and to ask that they ensure that there is robust and effective enforcement of the ban, and to submit to Parliament and make publicly available an update on their wider enforcement strategy, noting the legitimate interest of Members in the other place and of noble Peers here. We will ensure that Ofcom has the resources to properly enforce these new measures and to take strong enforcement action and protect all users more widely.
We recognise the importance of parliamentary scrutiny in this process, and I welcome the offers to collaborate and engage on the proposals we bring forward with the appropriate scrutiny—and, it seems, some extra scrutiny and critique from the noble Lord, Lord Clement-Jones. We all want to protect children online and ensure that their online life is as fulfilling as their offline life. It is a responsibility we take very seriously. We do not want children to have to navigate unsafe digital spaces. We believe that our statement of intent here will do that and will deliver to make sure that we give children the childhood they deserve.
(3 months, 2 weeks ago)
Lords Chamber
Baroness Lloyd of Effra (Lab)
The noble Lord raises very important points, including the fact that Mythos and Fable are unavailable worldwide, including in the US. He rightly stresses the importance of the AI Security Institute—its establishment, its ongoing support and funding by this Government, and the fact that it was able to test both Mythos 5 and Fable 5. We are in touch with the US Government and are monitoring the situation closely.
My Lords, the Minister has mentioned the AI Security Institute. It identified ways to circumvent the safety guardrails of Fable 5 and Mythos before their public launch, including vulnerabilities that could allow the extraction of instructions for producing dangerous substances, yet the model was released by Anthropic regardless. Will the Minister now accept that voluntary co-operation with safety institutes is wholly insufficient at this level of capability and bring forward legislation giving the AI Security Institute the statutory power, where necessary, to delay or prevent the launch of dangerous frontier AI models in the UK?
Baroness Lloyd of Effra (Lab)
The AI Security Institute did test Mythos and Fable before they were launched. In light of the risks that they potentially posed—Mythos in particular—we also gave advice to our companies. We worked carefully with the National Cyber Security Centre to provide advice to companies and regulators on what needed to be done because, generally speaking, what we find with these potential new capabilities is that many of the basic mitigants that you need to take will inhibit the effectiveness of these new models. In respect of regulation, as I mentioned a moment ago, we continue to support the effectiveness of sector-based regulators regulating AI risks as they approach their sectors. They are best placed to know what those risks are and what the mitigants will be.
(3 months, 3 weeks ago)
Lords Chamber
The Parliamentary Under-Secretary of State, Department for Business and Trade and Department for Science, Innovation and Technology (Baroness Lloyd of Effra) (Lab)
I agree with the noble Lord that there is unanimity on the importance of tackling child sexual abuse online and taking measures to further restrict that and make it harder. As my noble friend Lord Hanson made clear during the passage of the Act, device-level nudity detection can play an important role in preventing children taking, sharing or viewing nude imagery.
This measure really looks at how to prevent those images getting online. That is a very important part of the strategy; it stops harm before it happens, in addition to the law enforcement activity that must happen in parallel. It applies to both old and new smartphones and tablets, and we expect tech companies to set up controls so that, if a parent hands down a phone, for example, all they have to do is reset it to enact this operating-level facility.
In respect of making sure that legislation is ready, as the Minister for Online Safety said in the other place yesterday, he is working carefully and closely in parallel with the Home Office to draw up legislation should that be needed, should the protections not be put in place at scale as expected.
My Lords, I congratulate my honourable friend Munira Wilson on trying to extract some clarity from the Government after the Prime Minister’s speech yesterday before almost any of us arrived at London Tech Week. Sadly, it did not contain all of what was in the weekend media briefings. On these Benches, the Liberal Democrats have long called for a film-style harms-based age-rating system, with addictiveness as a central criterion, rather than a blanket ban on user-to-user services. Minister Narayan in the Commons subsequently indicated yesterday that addictiveness is
“very much on our minds”.—[Official Report, Commons, 8/6/26; col. 31.]
Can the Minister confirm that the forthcoming consultation response will explicitly adopt addictive design, including infinite scroll, autoplay and recommender algorithms as a harm category, triggering age-based platform restrictions, rather than relying solely on content type or constituting a blanket ban? Can she confirm that this will be enshrined in legislation, rather than a voluntary expectation of tech platforms?
Baroness Lloyd of Effra (Lab)
The consultation to which the noble Lord refers includes looking at features and functionalities; it looks at addictive algorithms, screen time and the impact on children’s health. The consultation has closed. There were many responses, and we are taking time to make sure that we have looked carefully at them—and, in addition to those responses, at the conversations that have gone on. I cannot pre-empt the Government’s response, which will come soon, but all the matters I have just mentioned were within the consultation for discussion.
(4 months ago)
Lords ChamberTo ask His Majesty’s Government what strategy they have to ensure that the Sovereign AI Fund will support sovereign AI infrastructure and reduce public sector dependence on foreign hyperscale cloud providers.
The Parliamentary Under-Secretary of State, Department for Business and Trade and Department for Science, Innovation and Technology (Baroness Lloyd of Effra) (Lab)
The sovereign AI fund will support early-stage British start-ups at strategically important parts of the AI value chain, including AI infrastructure and compute. It is not designed to replace foreign cloud providers or achieve total UK self-sufficiency. Instead, the fund seeks to reduce our strategic dependence and ensure that the UK has a stake in a world economy transformed by AI.
My Lords, the Secretary of State has said that Britain
“must be an AI maker, not an AI taker”,—[Official Report, Commons, 18/3/26; col. 55WS.]
and the sovereign AI unit’s own chair has promised British start-ups a guaranteed route to government contracts. But even the AI Minister, Mr Narayan, has admitted that procurement is too hard for British start-ups across government. So when will public procurement, in particular the G-Cloud framework, be reformed to match that promise? Will “sovereign AI” not remain just a slogan without that?
(5 months, 3 weeks ago)
Lords Chamber
Baroness Lloyd of Effra (Lab)
Reducing the AI skills gap and understanding the impact of the labour market’s change due to AI is indeed something that we are looking at closely. DSIT regularly reviews the AI labour market and skills gap, and we are working with Skills England to fully understand the needs. I will need to update the noble Lord on the role of the regional centres he mentions after this session.
My Lords, the Government have cited their own Ipsos research that 84% of people at work have not undertaken any AI training in the past 12 months. The Government’s AI skills boost programme is welcome, but it is not enough. Will the Minister commit to personal learning accounts, giving individuals genuine choice over their upskilling, and to prioritising putting the creativity and critical reasoning at the heart of the national curriculum that AI cannot replicate?
Baroness Lloyd of Effra (Lab)
The noble Lord is right that AI poses challenges and opportunities to those in the labour market. The AI skills boost programme that the Government have announced is extremely ambitious in its reach. It will see a major expansion to upskill 10 million workers, which is a huge endeavour and will see the UK fit to grab the opportunities of the AI technology that is coming today.
(6 months, 3 weeks ago)
Lords Chamber
Baroness Lloyd of Effra (Lab)
We have the Online Safety Act, which is enforced by Ofcom and other regulators and, as the noble Lord will know, we announced a consultation just recently on areas that we may seek to expand or take further measures on to enhance children’s well-being.
My Lords, does the Minister accept that, as part of this dialogue, close co-operation on robust competition enforcement is essential to resist growing US pressure to weaken digital rules? As the EU actively enforces its Digital Markets Act, will the Government commit to aligning in practice with strong EU enforcement standards rather than allowing US corporate lobbying to dilute the UK’s digital markets competition regime?
Baroness Lloyd of Effra (Lab)
The UK has taken decisive action to strengthen competition and fairness in digital markets. In January 2025, Parliament equipped the CMA with new powers to boost competition and innovation in digital markets. In May, the Government issued a clear steer to the CMA to prioritise this work and align action with international jurisdictions, including the EU. The UK and CMA engage regularly with EU counterparts as both regimes begin operation to help maintain close alignment on emerging issues.
(6 months, 3 weeks ago)
Lords Chamber
Baroness Lloyd of Effra (Lab)
I share the enthusiasm of my noble friend, the committee and the report for the space economy. We responded in detail to the recommendations earlier this year. We are setting out our strategic priorities, which, as the committee and my noble friend highlighted, encompassed many aspects of our lives, including defence, economic growth and support for our farming communities. We will continue to focus our spend on the priorities of economic growth and national security outcomes.
My Lords, on the Government’s space plan, will they formally adopt a policy of space debris neutrality, requiring all satellites launched from the UK to have what is called a “designed to demise” commitment to prevent further orbital congestion? With an active debris removal procurement worth some £75 million, how are the Government ensuring that UK-based SMEs are not being edged out by larger international companies for these critical domestic contracts?
Baroness Lloyd of Effra (Lab)
The noble Lord raises the important issue of space debris, which creates risks to our critical national infrastructure. We are strengthening UK space surveillance and investing in debris mitigation technologies. We are seen as a leader in space sustainability, including with the international community and His Majesty the King. We are supporting important UK companies such as Astroscale to understand the risks and costs of active debris removal. In fact, there are further announcements today on this important issue of space debris removal.
(8 months, 1 week ago)
Lords Chamber
Baroness Lloyd of Effra (Lab)
The Government are aware of calls to make the data preservation process faster. These are new powers and we are actively monitoring the effectiveness of the current process, working closely with Ofcom to do this. We are carefully considering any means that could allow relevant data to be preserved in a timely manner to ensure investigations are well informed and families get the answers they need.
My Lords, the litigation alleges that TikTok’s algorithm deliberately promoted harmful content to children. That is exactly what we originally thought the Online Safety Act was going to help protect our children from, but that appears to be wrong. Will the Government, given their statement of strategic priorities, insert a statutory definition of safety by design and require Ofcom specifically to address addictive algorithms and compulsive design features?
Baroness Lloyd of Effra (Lab)
The noble Lord will be aware of the Statement that the Technology Secretary made last week to initiate a short consultation looking at further measures that could be taken, which responds to some of the questions that underlie his question about the nature of social media use and actions that could be taken in response to parental and other requests to deal with it—for example, looking at breaks to stop excessive doomscrolling, or further enforcement of the law. That consultation will take place swiftly before the summer.
(8 months, 1 week ago)
Lords Chamber
Baroness Lloyd of Effra (Lab)
My noble friend is right to mention the research of the AI Security Institute, which is advice the Government listen to and take very seriously. AI is a general-purpose technology with a wide range of applications, which is why the UK believes that the vast majority of AI should be regulated at the point of use. My noble friend is also right that collaboration with other countries is critical, and the UK’s approach is to engage with many other countries, and through the AI Security Institute with developers so that it has good insight into what is happening in development today.
My Lords, I declare an interest as a consultant to DLA Piper on AI regulation and policy. In their manifesto, the Government promised
“binding regulation on … companies developing the most powerful AI models”,
yet, 18 months later, even in light of the harmful activities of stand-alone AI bots, we have seen neither the promised consultation nor any draft legislation. How can the Government credibly claim to be taking superintelligence seriously when they cannot get round even to publishing a consultation, let alone legislating?
Baroness Lloyd of Effra (Lab)
As I mentioned earlier, most AI systems are regulated by our existing expert regulators, and they are already acting. The ICO has released guidance on AI and data protection and the MHRA is taking action to allow a sandbox for AI as a medical device product. We are working with regulators to boost their capabilities as part of the AI opportunities action plan, and where we need to take action—for example, as we have under the Online Safety Act—we will do so. We do not speculate on legislation ahead of future parliamentary Sessions, but we will keep noble Lords updated should and when we bring forward a consultation ahead of any potential legislation.
(8 months, 2 weeks ago)
Lords ChamberMy Lords, we on the Liberal Democrat Benches welcome the Secretary of State’s Statement, as well as her commitment to bring the new offence of creating or requesting non-consensual intimate images into force and to make it a priority offence. However, why has it taken this specific crisis with Grok and X to spur such urgency? The Government have had the power for months to commence this offence, so why have they waited until women and children were victimised on an industrial scale?
My Commons colleagues have called for the National Crime Agency to launch an urgent criminal investigation into X for facilitating the creation and distribution of this vile and abusive deepfake imagery. The Secretary of State is right to call X’s decision to put the creation of these images behind a paywall insulting; indeed, it is the monetisation of abuse. We welcome Ofcom’s formal investigation into sexualised imagery generated by Grok and shared on X. However, will the Minister confirm that individuals creating and sharing this content will also face criminal investigation by the police? Does the Minister not find it strange that the Prime Minister needs to be reassured that X, which is used by many parliamentarians and government departments, will comply with UK law?
While we welcome the move to criminalise nudification apps in the Crime and Policing Bill, we are still waiting for the substantive AI Bill promised in the manifesto. The Grok incident proves that voluntary agreements are not enough. I had to take a slightly deep breath when I listened to what the noble Viscount, Lord Camrose, had to say. Who knew that the Conservative Party was in favour of AI regulation? Will the Government commit to a comprehensive, risk-based regulatory framework, with mandatory safety testing, for high-risk models before they are released to the public, of the kind that we have been calling for on these Benches for some time? We need risk-proportionate, mandatory standards, not voluntary commitments that can be abandoned overnight.
Will the Government mandate the adoption of hashtagging technology that would make the removal of non-consensual images possible, as proposed by the noble Baroness, Lady Owen of Alderley Edge, in Committee on the Crime and Policing Bill—I am pleased to see that the noble Lord, Lord Hanson, is in his place—and as advocated by StopNCII.org?
The Secretary of State mentioned her commitment to the safety of children, yet she has previously resisted our calls to raise the digital age of consent to 16, in line with European standards. If the Government truly want to stop companies profiteering from children’s attention and data, why will they not adopt this evidence-based intervention?
To be absolutely clear, the creation and distribution of non-consensual intimate images has nothing whatever to do with free speech. These are serious criminal offences. There is no free speech right to sexually abuse women and children, whether offline or online. Any attempt to frame this as an issue of freedom of expression is a cynical distortion designed to shield platforms from their legal responsibilities.
Does the Minister have full confidence that Ofcom has the resources and resolve to take on these global tech giants, especially now that it is beginning to ramp up the use of its investigation and enforcement powers? Will the Government ensure that Ofcom uses the full range of enforcement powers available to it? If X continues to refuse compliance, will Ofcom deploy the business disruption measures under Part 7, Chapter 6 of the Online Safety Act? Will it seek service restriction orders under Sections 144 and 145 to require payment service providers and advertisers to withdraw their services from the non-compliant platform? The public expect swift and decisive action, not a drawn-out investigation while the abuse continues. Ofcom must use every tool Parliament has given it.
Finally, if the Government believe that X is a platform facilitating illegal content at scale, why do they continue to prioritise it for official communications? Is it not time for the Government to lead by example and reduce their dependence on a platform that seems ideologically opposed to the values of decency and even perhaps the UK rule of law, especially now that we know that the Government have withdrawn their claim that 10.8 million families use X as their main news source?
AI technologies are developing at an exponential rate. Clarity on regulation is needed urgently by developers, adopters and, most importantly, the women and children who deserve protection. The tech sector can be a force for enormous good, but only when it operates within comprehensive, risk-proportionate regulatory frameworks that put safety first. We on these Benches will support robust action to ensure that that happens.
The Parliamentary Under-Secretary of State, Department for Business and Trade and Department for Science, Innovation and Technology (Baroness Lloyd of Effra) (Lab)
I thank both noble Lords for their contributions to the debate. We all agree that the circulation of these vile, non-consensual deepfakes has been shocking. Sexually manipulating images of women and children is despicable and abhorrent. The law is clear: sharing or threatening to share a deepfake intimate image without consent, including images of people in their underwear, is a criminal offence. To the noble Lord’s point, individuals who share non-consensual sexual deepfakes should expect to face the full extent of the law. In addition, under the Online Safety Act, services have duties to prevent and swiftly remove the content. If someone has had non-consensual intimate images of themselves created or shared, they should report it to the police, as these are serious criminal offences.
I turn to some of the points that have been raised so far. The Government have been very clear on their approach in terms of both the AI action plan and the legislation that we have brought forward. We have introduced a range of new AI-related measures in this Session to tackle illegal activity; we have introduced a new criminal offence to make it illegal to create or alter an AI model to create CSAM; we are banning nudification apps; and we are introducing a new legal defence to make it possible for selected experts to safely and securely test models for CSAM and non-consensual intimate images and extreme pornography vulnerabilities.
AI is a general-purpose technology with a wide range of applications, which is why we think that the vast majority of AI systems should be regulated at the point of use. In response to the AI action plan, the Government are committed to working with regulators to boost their capabilities. We will legislate where needed and where we see evidence of the gaps. Our track record so far has shown that that is what we do, but we will not speculate, as ever, on legislation ahead of future parliamentary Sessions.
I come to the question of Ofcom enforcement action. On Ofcom’s investigation process, the Secretary of State was clear that she expects an update from Ofcom on next steps as soon as possible and expects Ofcom to use the full legal powers that Parliament has given it to investigate and take the action that is needed. If companies are found to have broken the law, Parliament has given Ofcom significant enforcement measures. These include the power to issue fines of up to 10% of a company’s qualifying worldwide revenue and, in the most serious cases, Ofcom can apply for a court order to impose serious business disruption measures. These are all tools at Ofcom’s disposal as it takes forward its investigations. On the question of whether Ofcom has the resources to investigate online safety, as I think I have mentioned in the House before, Ofcom has been given additional resources year on year to undertake its duties in respect of enforcing the Online Safety Act: that is, I think, £92 million, which is an uplift on previous years.
I come to the question of the Government’s participation in news channels and on X. We will keep our participation under review. We do not believe that withdrawing would solve the problems that we have seen. People get their news from sources such as X and it is important that they hear from a Government committed to protecting women and girls. It is important that they hear what we are doing and hear when we call out vile actions such as these. We think it is extremely important to continue to take action and continue to back Ofcom in the actions that it is taking in respect of this investigation, and in fact all of its investigations under the Online Safety Act.
The noble Lord asked whether it should be mandatory for AI developers to test whether their models can produce illegal material. Enabling AI developers to test for vulnerabilities in their models is essential for improving safeguards and ensuring that they are robust and future-proofed. At present, such testing is voluntary, but we have been clear that no option is off the table when it comes to protecting UK users, and we will act where evidence suggests that further action can be effective or necessary. We are keeping many of the areas that have been raised today under review and we are seeking further evidence. We are looking at what is happening in other jurisdictions and at what is happening here and we will continue to take action.
I also reflect on the point that the noble Lord made that the issues around enforcing illegal activity are nothing to do with free speech. These are entirely separate issues and it is incredibly important to note that this is not about restricting free speech, but about upholding the law and ensuring that the standards that we expect offline are held online. Many tech companies are acting responsibly and making strong endeavours to comply with the Online Safety Act, and we welcome their engagement on that. We need to make sure that our legislation and our enforcement is kept up to date with the great strides in technology that are happening. This means that, in some cases, we will be looking at the real-life impact and taking measures where new issues arise. That is the track record that we have shown and that is what we will continue to do.
(9 months, 2 weeks ago)
Lords Chamber
Baroness Lloyd of Effra (Lab)
The noble Lord is absolutely right that we need to take action on a number of fronts, including AI literacy and digital skills more generally. The Government are taking action on digital skills in a number of areas, including through what was the CyberFirst programme and is now the TechFirst programme, looking at both young people and students.
On AI skills, particularly for those in the workforce, the Prime Minister announced a plan to train 7.5 million workers with essential AI skills by 2030 through our industry partnership with key players. It is great to have those players collaborating with us on that.
My Lords, the Technology Adoption Review is clear that the UK’s ability to turn research excellence into productivity gains depends on skills and access to world-class talent across our innovation system. In light of Sir Paul Nurse’s recent warnings that high visa fees and restrictive rules are actively deterring early career researchers and damaging the UK’s science base, will the Government commit to aligning research visa policy with their technology adoption ambitions, say, by emulating the Canada Global Impact+ Research Talent Initiative?
Baroness Lloyd of Effra (Lab)
The noble Lord is right that attracting high-calibre talent to this country is incredibly important. We have a number of ongoing initiatives to do that, including the Global Talent Taskforce, as well as through academia, as my noble friend the Minister with responsibility for science and technology talked about. The digital skills jobs plan will also set out how we can support that aim and get the balance right between growing homegrown talent and attracting those we need to from abroad, so that we have the best chances of growing our science base and the spin-outs.
(10 months ago)
Lords Chamber
Baroness Lloyd of Effra (Lab)
I thank the noble Lord. He brings a great deal of experience over the years in many areas of data protection legislation, anti-money laundering and the security side. Since the UK and EU leaders’ summit on 19 May, we have been working with the EU to increase the safety and security of UK and EU citizens, to respond to shared threats, and to support police investigations, including through enhanced data exchange. We continue to work and meet closely with the EU on these matters.
My Lords, the Government are trying to hit a moving target, as far as I can see. The EU is adopting a new digital omnibus, which will change EU GDPR. How confident are the Government about being able to get a decision from the EU in time?
Baroness Lloyd of Effra (Lab)
To take that question in two parts, we are confident about the EU’s scrutiny of our legislation. The Commission has started its review and published the report that I mentioned in July. The European Data Protection Board published a non-legally binding opinion on its draft decision on 20 October. We are confident that a member state vote will take place ahead of the 27 December deadline. The EU’s proposals to change its data protection framework have only recently been published. We will have a look at the details of those changes as and when they become clear and are confirmed.
(10 months ago)
Lords ChamberMy Lords, the Minister says that the Government are standing right behind Ofcom. Many of us very strongly support Ofcom’s actions in fining those such as the AVS Group for not observing proper age checks on their sites. But, as the noble Lord, Lord Carlile, indicates, there is no point in having fines unless we have proper enforcement. What resource are the Government satisfied Ofcom has to pursue enforcement?
Baroness Lloyd of Effra (Lab)
We have ensured that Ofcom is resourced to implement its online safety duties and have increased the amount available to it year on year; its budget is, I think, £92 million to support all its Online Safety Act responsibilities. We believe that it has the resources it needs to effectively implement and supervise the Online Safety Act.
(10 months, 2 weeks ago)
Lords Chamber
Baroness Lloyd of Effra (Lab)
I remind the House that AI is already regulated in the UK and we regulate on a context-specific approach. Our regulators can take account of the developments in AI, which are indeed rapid, and ensure that they are tailored. In addition, as noble Lords know, we have got various regulators undertaking regulatory sandboxes and the new proposal for the AI growth lab, which will look across all sectors and allow regulators to collaborate on this quite rapidly changing technological development.
My Lords, I declare in interest as chair of the Authors’ Licensing and Collecting Society and as a consultant to DLA Piper on AI policy. The first meeting of the rather grandly named Lords’ AI and copyright parliamentary engagement group takes place tomorrow. Would it not be extraordinary if the Government did not bring forward a Bill in the face of that engagement group’s conclusions and those of the industry working groups? Would any of those discussions not be rendered meaningless without a Bill next year? If a Bill does not come forward, would that not demonstrate the influence of big tech and the major technology companies on the Government?
Baroness Lloyd of Effra (Lab)
The issues to which the noble Lord refers have, of course, been extensively debated here. One outcome of conversations during the passing of the data Act was a commitment to have these discussions. I also think it would be premature to decide the nature or timing of legislation until those discussions are completed. Like the noble Lord, I highlight the importance of the parliamentary consultations, the first of which with Peers is indeed happening tomorrow, with the two Secretaries of State.