She asked the Minister to say how he intended to assess a threat that the Government were not measuring. I confess that I have not recorded the answer from the Minister but, even if I cannot get an answer on that particular second-hand question now, we on these Benches share, along with the noble Baroness, Lady Kidron, the deep concern at our vulnerability to external shocks. We need a bit of reassurance that the Government are thinking about how we can better protect ourselves against all these external events. On Amendments 83 or 166, it would be good to hear a positive response from the Minister.
Lord Tarassenko Portrait Lord Tarassenko (CB)
- Hansard - -

My Lords, I shall speak in support of Amendment 83 in the name of the noble Baroness, Lady Kidron, to which I have added my name. In my speech, I will focus just on the aspects of the digital sovereign strategy that are relevant to the NHS. I speak as someone who held an honorary contract with the Oxford University Hospitals NHS Foundation Trust until November 2025, enabling me to be a co-investigator on research projects involving patient data.

Cyber attacks against NHS trusts and their supply chains occur with very high frequency, from regular automated phishing attempts, which are blocked daily, to major incidents causing significant clinical disruption. Health and social care consistently rank among the top sectors reported for cyber incidents and data breaches to the ICO. I am sure that we all remember the WannaCry cyber attack in May 2017, which affected 81 of our 236 NHS trusts at the time, causing nearly 20,000 appointments to be cancelled in a week.

Less than two years ago, in November 2024, there was a major cyber attack against the Wirral University Teaching Hospital NHS Foundation Trust, which compromised the trust’s electronic patient record. I know that EPR well as we have the same EPR in Oxford: Cerner Millennium. As a result of the cyber attack, staff in the Wirral hospitals lost all access to patient records, electronic prescribing tools and diagnostic results. All elective surgeries and outpatient appointments across the trust had to be cancelled, and members of the public were told not to use the emergency department at one of the hospitals in the trust. All clinical systems remained completely offline for nine days.

I mentioned the EPR Cerner Millennium. Cerner is now part of Oracle Health. Together, Oracle and Epic, both of which are US companies, account for about 40% of hospital EPR contracts in England and Wales. In primary care, EMIS software manages just under 60% of the patient records—the records of 35 to 40 million patients across England and Wales. EMIS was bought by Optum, part of the UnitedHealth Group, in 2023, but, in March this year, the UnitedHealth Group sold Optum to a US private equity firm, TPG, for just under £300 million. I will come back to that briefly later.

In 2023, NHS England and the Department of Health and Social Care launched a 2030 cyber security strategy. The noble Lord, Lord Markham, when he was a Health Minister, wrote the foreword—he will remember this, I am sure—to the strategy document. In it, he wrote—we all agree with him, I am sure—that

“the cyber security of our health and social care … underwrites patient safety”.

The group director for cyber security for the DHSC has recently written to all NHS trust boards informing them that, from this month, September 2026, new cyber policies will be included in the next data security and protection toolkit, covering issues such as multi-factor authentication, high-severity alerts and endpoint detection. There is nothing about AI, which is perhaps the subtitle of this Bill—something that will, I hope, have been removed by Report. Yet we know from Tuesday’s debate and last week’s open letter from 100 companies, including large tech firms, that AI-enabled cyber attacks are about to become more widespread and more sophisticated within months.

This prompts three questions. First, are officials from the Minister’s department, which has overall responsibility for cyber security, co-ordinating with the cyber security group in the DHSC—especially with respect to the latest threats from AI agents?

Secondly, have the recent reports from the AISI been communicated to the cyber security group in the DHSC, and have their implications for the NHS been discussed with them? I note here that the new Minister for Science and Innovation, Chris McDonald MP, is a Minister in both the DBIST and the DHSC, so I am hopeful that the answer to these two questions might be yes.

Thirdly, given the high prevalence of foreign ownership of companies, such as Epic and TPG, that are responsible for managing patient data within the NHS—notwithstanding the single-supplier agreement with Palantir, another US company, for the Federated Data Platform—has the Minister’s department assessed the risk to relevant network and information systems as a result of our technological dependence on these companies?

What I have described for the NHS also applies to other sovereign data assets such as those held by the BBC or the Met Office. If the full value to the UK of these sovereign data assets is to be realised as part of the Government’s growth strategy, we need to be optimally protected against cyber attacks, including AI-enabled attacks. For that to happen, we need a coherent digital sovereign strategy across government departments, led by the Minister’s department.

Lord Russell of Liverpool Portrait Lord Russell of Liverpool (CB)
- Hansard - - - Excerpts

My Lords, I echo the words of the noble Baroness, Lady Kidron: in the previous group, we probably would not have had anything like that debate if a clear strategy were indeed in place.

I will speak very briefly and in the context of other countries’ views of the safety and security of doing business with the UK and UK entities. Part of the backdrop is an attempt by His Majesty’s Government to try to do a reset with the EU, not least because of the problems we are having with our erstwhile colonial possessions across the Atlantic. We need to be viewed as a safe haven for the security of our business and data. If we look at what the EU, for all its bureaucratic idiosyncrasies, has been doing with NIS2, in many instances that is an extremely good model for us when looking comprehensively at the different sectors that need to be involved. NIS2 covers energy, transport, banking, financial market infrastructures, health, drinking water, wastewater, digital infrastructure, ISP services, public administration, space, postal services, waste management, chemicals, food, manufacturing, research and other critical parts of the economy. The EU is ahead of us and has done a great deal of groundwork; if we were to talk to the EU, we could benefit hugely without reinventing the wheel.

It is imperative not only that we give noble Lords and parliamentarians a feeling that we know what we are doing and where we are going but that other countries currently doing, or thinking of doing, business or more business with us have faith in the security of our data and cyber security infrastructure. If I were looking to invest in a company, that is an area I would look at very carefully—but, frankly, at the moment, I would not feel very confident.

Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - - - Excerpts

My Lords, in moving this amendment, I shall speak also to Amendment 75 in my name; I thank those noble Lords who have added their names in support. I was glad to add my name to Amendments 12, 85 and 86 in the name of the noble Lord, Lord Tarassenko, and Amendment 84 in the name of the noble Lord, Lord Clement-Jones.

At the heart of these amendments is the place of artificial intelligence in the Bill. This concern was powerfully raised by noble Lords at Second Reading and repeatedly raised by colleagues from all sides in the other place—as well as, I rather suspect, earlier in this Session. Amendment 6 is a probing amendment. It seeks to understand whether AI products and services are categorised as relevant digital services and, therefore, whether providers of AI products and services will be subject to the same duties in the Bill as other providers of relevant digital services, such as online marketplaces and search engines.

The reason I raise this and wish to have clarification is that, in the NIS regulations, the definition of an online search engine is

“a digital service that allows users to perform searches of, in principle, all websites or websites in a particular language on the basis of a query on any subject in the form of a keyword, phrase or other input, and returns links in which information related to the requested content can be found”.

This sounds a lot like a definition that could cover many of the LLMs and AI agents, so I ask the Minister whether AI services are already covered under the categorisation of online search engines or absolutely not. I would also like her to confirm whether, if an AI service did not offer links or was restricted to a particular subject matter but had all these other features, it would automatically fall out of the regime—that is, whether some are covered and some are not.

At Second Reading in the other place, the Minister said—the Minister here just gave this answer, I believe—that the Bill enables the Secretary of State to require an organisation using AI

“to cease using and isolate an AI model”—[Official Report, Commons, 16/6/26; col. 779.]

but suggested that those powers are “a backstop” and do not focus on the safety of AI products systematically. I find myself confused because, on the one hand, it seems that the definition could include them but, on the other, it seems that there may be reasons why some might be out of scope. It appears that AI is not properly considered proactively but, if there is a disaster, the Secretary of State can do something. When the Minister speaks, I would be grateful if she could answer those two questions directly. This is a probing amendment, as I say, and it would be helpful, in the course of considering the Bill, to understand that categorically.

Amendment 75 would establish a series of red lines for AI products and services classified as relevant digital services. These red lines have excellent parentage; they reflect the work of Professor Stuart Russell and are signed up to by some of the most eminent AI founders and professionals around the globe. They also reflect the global call for AI red lines launched during the United Nations General Assembly.

In short, they provide that AI services must not be capable of evading human oversight, shutdown or control, nor be able to autonomously self-replicate, self-improve or acquire compute. They provide that AI providers would be prohibited from creating systems capable of autonomously conducting sophisticated attacks on critical infrastructure, that support terrorists and hostile states in attacks on such critical infrastructure, or that can deceive or manipulate populations at scale. They also prevent capabilities that relate to the availability, authenticity, integrity or confidentiality of stored or processed data, which follows the exact language of the Bill. Proposed new subsection (3) of the amendment would require AISI to ensure that these red lines are adhered to. This is an essential amendment and I believe the UK is singularly well placed to introduce it. There is increasing evidence and understanding of the risks, and both the public and experts are calling for action.

I was going to quote many people, but will say just that, a couple of weeks ago, I spoke to Jonathan Hall KC, the Independent Reviewer of Terrorism Legislation and the Independent Reviewer of State Threats Legislation. He is among the many people who have warned publicly about the risk of AI used to support terrorist action and subvert information in the public domain. Recent polling has found that 85% of the UK public would like this to happen; they would like red lines.

I fully support Amendments 12, 85 and 86 in the name of noble Lord, Lord Tarassenko, which seek to establish a greater role for AISI in these regulations and to give it statutory powers. I leave it to the noble Lord to explain the amendments in full, which I am sure he will do much better than me, except to say that, in July, some other noble Lords and I were briefed by one of the frontier companies, which gleefully said that it worked to a set of ethical standards. However, when pressed—repeatedly, by noble Lords—the company admitted that it wrote, interpreted and managed those standards itself and was free to abandon them in an instant. Have we not learned from countless experiences before, in online safety, privacy and AI itself, that allowing tech companies to set and mark their own homework endangers the public and our national security?

Amendment 92 from the noble Lord, Lord Clement-Jones, has a similar aim to that of the noble Lord, Lord Tarassenko. I hope that, during the passage of the Bill, the Government find a unifying approach with both noble Lords to back AISI in its functions and separate it from political control. The AISI organisation is the envy of the world, with the capability to oversee a regime for robustly and fairly ensuring that AI is trusted. I beg to move.

Lord Tarassenko Portrait Lord Tarassenko (CB)
- Hansard - -

My Lords, I will speak to Amendments 12, 85 and 86 in my name, and in support of Amendment 6 in the name of the noble Baroness, Lady Kidron, to which I have also added my name.

At Second Reading, several noble Lords spoke about the AI-shaped hole in the Bill. I shall not repeat their arguments but will present other evidence, including incidents that have been reported since Second Reading in mid-July, on why this AI-shaped hole needs to be filled. Three serious incidents have been reported since just mid-July: one involving OpenAI’s GPT-5.6 Sol and an unreleased model, one involving Anthropic’s Claude models and one involving multiple AI agents during a cyber evaluation by the AI Security Institute—AISI.

AI models, within an appropriate harness, are now capable of operating as autonomous agents. They can break a complex command—for example, “Find a vulnerability in this network”—into sequential tasks, adjust strategy dynamically and execute without further human intervention. These AI agents are built with tool-use capabilities, enabling them to plan but also execute and adapt multistep workflows autonomously.

More details have emerged of the Hugging Face hack which occurred on 11 July, just before the Second Reading debate. A report published last week by three researchers from METR and Redwood Research reveals the scale of the incident. Around 1,200 agents in separate sandboxes collaborated on a message board in an attempt to cheat on a task on which they were being evaluated, with around 700 participating in the actual cyber attack on the open source AI platform Hugging Face. As we know, this is the incident that prompted Anthropic to check whether its own AI agents with Claude models at the core of the harness had carried out similar cyber attacks; this check uncovered three cases that were then reported to the affected companies.

Finally, at the beginning of August, AISI published an incident report detailing unsanctioned online actions by AI agents doing cyber capability evaluation tests conducted at the end of July. Out of 122 evaluation runs carried out by AISI across seven frontier models, 10 runs produced 19 distinct unsanctioned actions on the live internet. The report highlighted behaviours such as cross-agent co-ordination and out-of-bounds target pursuit.

However, it is not just frontier AI models that we should worry about. The cyber capabilities of leading open-weight models, such as GLM-5.2 and DeepSeek V4 Pro, are now reckoned to be only four to seven months behind those of the closed-source frontier models of US big tech. In many ways, these open-weight models carry even greater risks. Once the models have been released, safeguards can be removed and copies can be run on private systems beyond monitoring. Cyber attackers can then fine-tune the weights for malicious purposes, perform ablation on safety refusal directions within the model’s neural network and strip out any safety layers. The open-weight model then becomes an uncensored agent engine that will execute malicious instructions without refusal. It will process malicious requests as neutrally as if they were standard requests. We are not far away from cyber attacks from unknown AI agents based on modified open-weight models.

It is now beyond any doubt that autonomous AI agents running frontier AI models, both closed source and open weight, are or will soon be capable of co-ordinating complex cyber attacks. It is therefore not surprising that a group of 100 companies, including Google, Microsoft, Anthropic and OpenAI, as well as UK-based companies such as Arm, BT, PwC and KPMG, signed an open letter last week warning that cyber attacks orchestrated by frontier AI models will become more widespread and more sophisticated in a matter of months. The letter outlines three main principles or actions.

The Minister conceded at the end of Second Reading that

“AI capabilities are moving very fast”,


but asserted that

“strong cyber fundamentals still work”.—[Official Report, 14/7/26; col. 620.]

This is true, but the first principle listed in the letter is that existing security practices will no longer be sufficient to protect against cyber attacks orchestrated by frontier AI agents. Amendment 6 would therefore require the definition of “relevant digital service” being inserted into the NIS regulations by this Bill to include generative AI models, including large language models and AI agents. They are fast becoming the main factor in the cyber security arms race.

--- Later in debate ---
Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - - - Excerpts

If I have understood what the Minister said, the NHS must protect itself, but the AI that is attacking it has no duties or obligations under the Bill to check itself before it is used in those ways. That is what I think is the Government’s position, and I would be grateful, when she responds, if she could answer that.

I also want to say two other things. One is that I think these issues will come back on Report, so I would be grateful for some proper discussion before then, so that we can see whether we come to a certain place. I do not have it at my fingertips—I may be helped by one of my colleagues—the amount of search that now happens through AI, but it is almost ludicrous to suggest that LLMs are not search. It is deliberate that I got that answer.

Lord Tarassenko Portrait Lord Tarassenko (CB)
- Hansard - -

It is 5 trillion a year.

Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - - - Excerpts

Five trillion, a year. I am grateful to the Minister for answering my question because, very often, that does not happen. That really points at a problem.