(2 days, 9 hours ago)
Grand CommitteeMy Lords, in moving this amendment, I shall speak also to Amendment 75 in my name; I thank those noble Lords who have added their names in support. I was glad to add my name to Amendments 12, 85 and 86 in the name of the noble Lord, Lord Tarassenko, and Amendment 84 in the name of the noble Lord, Lord Clement-Jones.
At the heart of these amendments is the place of artificial intelligence in the Bill. This concern was powerfully raised by noble Lords at Second Reading and repeatedly raised by colleagues from all sides in the other place—as well as, I rather suspect, earlier in this Session. Amendment 6 is a probing amendment. It seeks to understand whether AI products and services are categorised as relevant digital services and, therefore, whether providers of AI products and services will be subject to the same duties in the Bill as other providers of relevant digital services, such as online marketplaces and search engines.
The reason I raise this and wish to have clarification is that, in the NIS regulations, the definition of an online search engine is
“a digital service that allows users to perform searches of, in principle, all websites or websites in a particular language on the basis of a query on any subject in the form of a keyword, phrase or other input, and returns links in which information related to the requested content can be found”.
This sounds a lot like a definition that could cover many of the LLMs and AI agents, so I ask the Minister whether AI services are already covered under the categorisation of online search engines or absolutely not. I would also like her to confirm whether, if an AI service did not offer links or was restricted to a particular subject matter but had all these other features, it would automatically fall out of the regime—that is, whether some are covered and some are not.
At Second Reading in the other place, the Minister said—the Minister here just gave this answer, I believe—that the Bill enables the Secretary of State to require an organisation using AI
“to cease using and isolate an AI model”—[Official Report, Commons, 16/6/26; col. 779.]
but suggested that those powers are “a backstop” and do not focus on the safety of AI products systematically. I find myself confused because, on the one hand, it seems that the definition could include them but, on the other, it seems that there may be reasons why some might be out of scope. It appears that AI is not properly considered proactively but, if there is a disaster, the Secretary of State can do something. When the Minister speaks, I would be grateful if she could answer those two questions directly. This is a probing amendment, as I say, and it would be helpful, in the course of considering the Bill, to understand that categorically.
Amendment 75 would establish a series of red lines for AI products and services classified as relevant digital services. These red lines have excellent parentage; they reflect the work of Professor Stuart Russell and are signed up to by some of the most eminent AI founders and professionals around the globe. They also reflect the global call for AI red lines launched during the United Nations General Assembly.
In short, they provide that AI services must not be capable of evading human oversight, shutdown or control, nor be able to autonomously self-replicate, self-improve or acquire compute. They provide that AI providers would be prohibited from creating systems capable of autonomously conducting sophisticated attacks on critical infrastructure, that support terrorists and hostile states in attacks on such critical infrastructure, or that can deceive or manipulate populations at scale. They also prevent capabilities that relate to the availability, authenticity, integrity or confidentiality of stored or processed data, which follows the exact language of the Bill. Proposed new subsection (3) of the amendment would require AISI to ensure that these red lines are adhered to. This is an essential amendment and I believe the UK is singularly well placed to introduce it. There is increasing evidence and understanding of the risks, and both the public and experts are calling for action.
I was going to quote many people, but will say just that, a couple of weeks ago, I spoke to Jonathan Hall KC, the Independent Reviewer of Terrorism Legislation and the Independent Reviewer of State Threats Legislation. He is among the many people who have warned publicly about the risk of AI used to support terrorist action and subvert information in the public domain. Recent polling has found that 85% of the UK public would like this to happen; they would like red lines.
I fully support Amendments 12, 85 and 86 in the name of noble Lord, Lord Tarassenko, which seek to establish a greater role for AISI in these regulations and to give it statutory powers. I leave it to the noble Lord to explain the amendments in full, which I am sure he will do much better than me, except to say that, in July, some other noble Lords and I were briefed by one of the frontier companies, which gleefully said that it worked to a set of ethical standards. However, when pressed—repeatedly, by noble Lords—the company admitted that it wrote, interpreted and managed those standards itself and was free to abandon them in an instant. Have we not learned from countless experiences before, in online safety, privacy and AI itself, that allowing tech companies to set and mark their own homework endangers the public and our national security?
Amendment 92 from the noble Lord, Lord Clement-Jones, has a similar aim to that of the noble Lord, Lord Tarassenko. I hope that, during the passage of the Bill, the Government find a unifying approach with both noble Lords to back AISI in its functions and separate it from political control. The AISI organisation is the envy of the world, with the capability to oversee a regime for robustly and fairly ensuring that AI is trusted. I beg to move.
Lord Tarassenko (CB)
My Lords, I will speak to Amendments 12, 85 and 86 in my name, and in support of Amendment 6 in the name of the noble Baroness, Lady Kidron, to which I have also added my name.
At Second Reading, several noble Lords spoke about the AI-shaped hole in the Bill. I shall not repeat their arguments but will present other evidence, including incidents that have been reported since Second Reading in mid-July, on why this AI-shaped hole needs to be filled. Three serious incidents have been reported since just mid-July: one involving OpenAI’s GPT-5.6 Sol and an unreleased model, one involving Anthropic’s Claude models and one involving multiple AI agents during a cyber evaluation by the AI Security Institute—AISI.
AI models, within an appropriate harness, are now capable of operating as autonomous agents. They can break a complex command—for example, “Find a vulnerability in this network”—into sequential tasks, adjust strategy dynamically and execute without further human intervention. These AI agents are built with tool-use capabilities, enabling them to plan but also execute and adapt multistep workflows autonomously.
More details have emerged of the Hugging Face hack which occurred on 11 July, just before the Second Reading debate. A report published last week by three researchers from METR and Redwood Research reveals the scale of the incident. Around 1,200 agents in separate sandboxes collaborated on a message board in an attempt to cheat on a task on which they were being evaluated, with around 700 participating in the actual cyber attack on the open source AI platform Hugging Face. As we know, this is the incident that prompted Anthropic to check whether its own AI agents with Claude models at the core of the harness had carried out similar cyber attacks; this check uncovered three cases that were then reported to the affected companies.
Finally, at the beginning of August, AISI published an incident report detailing unsanctioned online actions by AI agents doing cyber capability evaluation tests conducted at the end of July. Out of 122 evaluation runs carried out by AISI across seven frontier models, 10 runs produced 19 distinct unsanctioned actions on the live internet. The report highlighted behaviours such as cross-agent co-ordination and out-of-bounds target pursuit.
However, it is not just frontier AI models that we should worry about. The cyber capabilities of leading open-weight models, such as GLM-5.2 and DeepSeek V4 Pro, are now reckoned to be only four to seven months behind those of the closed-source frontier models of US big tech. In many ways, these open-weight models carry even greater risks. Once the models have been released, safeguards can be removed and copies can be run on private systems beyond monitoring. Cyber attackers can then fine-tune the weights for malicious purposes, perform ablation on safety refusal directions within the model’s neural network and strip out any safety layers. The open-weight model then becomes an uncensored agent engine that will execute malicious instructions without refusal. It will process malicious requests as neutrally as if they were standard requests. We are not far away from cyber attacks from unknown AI agents based on modified open-weight models.
It is now beyond any doubt that autonomous AI agents running frontier AI models, both closed source and open weight, are or will soon be capable of co-ordinating complex cyber attacks. It is therefore not surprising that a group of 100 companies, including Google, Microsoft, Anthropic and OpenAI, as well as UK-based companies such as Arm, BT, PwC and KPMG, signed an open letter last week warning that cyber attacks orchestrated by frontier AI models will become more widespread and more sophisticated in a matter of months. The letter outlines three main principles or actions.
The Minister conceded at the end of Second Reading that
“AI capabilities are moving very fast”,
but asserted that
“strong cyber fundamentals still work”.—[Official Report, 14/7/26; col. 620.]
This is true, but the first principle listed in the letter is that existing security practices will no longer be sufficient to protect against cyber attacks orchestrated by frontier AI agents. Amendment 6 would therefore require the definition of “relevant digital service” being inserted into the NIS regulations by this Bill to include generative AI models, including large language models and AI agents. They are fast becoming the main factor in the cyber security arms race.
If I have understood what the Minister said, the NHS must protect itself, but the AI that is attacking it has no duties or obligations under the Bill to check itself before it is used in those ways. That is what I think is the Government’s position, and I would be grateful, when she responds, if she could answer that.
I also want to say two other things. One is that I think these issues will come back on Report, so I would be grateful for some proper discussion before then, so that we can see whether we come to a certain place. I do not have it at my fingertips—I may be helped by one of my colleagues—the amount of search that now happens through AI, but it is almost ludicrous to suggest that LLMs are not search. It is deliberate that I got that answer.
Five trillion, a year. I am grateful to the Minister for answering my question because, very often, that does not happen. That really points at a problem.
(7 months ago)
Lords Chamber
Lord Tarassenko (CB)
My Lords, Amendment 227 is in my name and that of the noble Baroness, Lady Kidron. We started with AI during Oral Questions what is now yesterday afternoon. We considered the use of AAI in the debate on Amendment 209 yesterday evening. We are now back with AI within edtech. Amendment 227 is about ensuring that a minimum level of provision of software tools, including websites, is available to every pupil in England, regardless of the school they attend.
Over the last six months, I have worked with Professor Peyton Jones from the University of Cambridge and the Raspberry Pi Foundation to develop proposals for a level 3 qualification in data science and AI. This is being done in consultation with the relevant team in the Department for Education.
Importantly, this level 3 qualification would not be just for those sixth-formers who will go on to read computer science at university but, first and foremost, for the professionals of the future, such as lawyers, economists and doctors. The aim is to give those pupils in the final two years of school sufficient knowledge and experience of up-to-date AI to enable them to use it properly in their time at university and at the start of their professional careers.
If the UK is to have a workforce ready to take advantage of the opportunities that AI offers, AI education needs to begin at school. I know that His Majesty’s Government recognise this. They have just published a set of standards which generative AI products should meet to be considered safe for users in educational settings. However, these are intended mainly for edtech developers and suppliers to schools and colleges, not schoolteachers and administrators.
During a workshop organised by the Raspberry Pi Foundation last November, I met teachers from all types of schools who were keen to learn more about a level 3 qualification in data science and AI. I soon discovered that IT departments in many schools today have a strict, if misguided, interpretation of the Online Safety Act. As far as they are concerned, the safest way to prevent pupils accessing harmful or inappropriate material while on school premises is to bar them from accessing any website, even and especially OpenAI’s. There are other schools, of course, where the staff in the IT department operate a more nuanced firewall policy.
This amendment seeks to ensure that there is an irreducible minimum set of software tools, including websites, which every pupil in any school in England will be able to access during the school day. Pupils should be prevented from accessing websites which may lead to harm, but they should instead have access to websites with strong educational missions; for example, Code.org or MathsWatch. These would be included in a register of software tools permitted in schools and whitelisted by the school network firewall system.
Schools would be free to add other websites if they wished to do so, but the amendment would ensure that all pupils in England had access to a minimum set of whitelisted software tools, enabling them to learn about data science and AI as part of their school education. I beg to move.
My Lords, Amendments 238 to 240 are in my name and those of my noble friends Lady Cass and Lord Russell. I support Amendment 227 in the name of my noble friend Lord Tarassenko. I start by thanking the Minister and her officials for the engagement that we have had since Committee. These amendments, unlike in the previous grouping, are all about a single thing: the uses of technology in our schools. I feel that they are long overdue; we have seen many of them before in our deliberations on the Data (Use and Access) Bill, as well as earlier in this Bill.
Less than a fortnight ago, the Secretary of State delivered a speech in which she said that we are in the middle of a technology revolution in education and that technology is moving so quickly that:
“The world of even 5 years ago is gone forever—already a lost, obsolete age”.
We are in a time of change, but I am very concerned that this uncritical view of tech is difficult for schools. The Secretary of State is dismissing long-standing educational practices, honed by experience and research, in favour of technology, some of which is proven to be unsafe and to invade privacy, and much of which has yet to be tested.
I will go through the amendments quickly. Amendment 238 would require the Secretary of State to prepare a statutory code of practice on the efficacy of educational technology within 18 months of the Act’s passing, and a certification scheme for minimum pedagogical standards for edtech procurement in schools. In December, the Minister wrote to me to say that the Government were developing a new approach to certify edtech products to make certain that they are safe and fit for purpose, through an accreditation service and statutory guidance. It seemed from the letter that she was referring to filtering and monitoring, which I will come to, but I would be grateful if she would clarify that when she responds.
The problem is that the process by which we are interrogating edtech is far slower than the process by which we are introducing it into our schools. Although I welcome the idea that the Government will test novel products and consult a wide group of people, unless I am mistaken, the regime does not offer a certification scheme that guarantees the learning outcomes of edtech.
It is for that reason that I also support my noble friend Lord Tarassenko’s Amendment 227. He and I have worked on a number of issues that seek to apply existing rules to technology to ensure that those who develop it consider the needs of individuals and communities into which it is deployed. Given that my noble friend has given a detailed explanation of his whitelist amendment, I will not reiterate it now, but I commend this amendment to the Government, because it is a model for how we should deal with edtech more broadly: insist on existing standards, make adherence visible and, in doing so, make a well-designed, private, positive use case for tech in schools. Without the existing standards, we cannot see what the edtech is doing.
Amendment 239 requires the Government to set statutory standards for filtering and monitoring systems used in schools. This amendment is marginally different from the one that I tabled in Committee, in that it clarifies adherence to data collection practices, that there is nothing in them that prevents staff carrying out their safeguarding duties, and that the standards would be checked with real-time tests established through a certification scheme with which Ofsted would check that schools complied.
I have been pressing this issue for over five years and yet we have failed to solve the problem. The introduction of generative AI means that we are going backwards and I believe that the Government have turned to guidance again: they have updated their filtering and monitoring standards only this month. I am pleased to see that that guidance now clarifies that barriers to illegal content must be switched on at all times and I believe that the Minister will also commit to consultation.
However, experts at the UK Safer Internet Centre suggest that seven of the 24 filtering and monitoring systems used in the UK do not currently meet the standards that filter for illegal content and only three of them currently provide clear evidence that they can analyse and block generative AI content in real time, as the new standards require. The same experts say that market compliance is uneven, that schools are dependent on providers’ self-assessments and that there is a serious gap between policy intent and consistent implementation. We need to remove the inconsistency, meet basic safety requirements and insist that they are routinely checked. It is not right that schools are left with the burden of working out what the system they have paid for does or does not do. I understand that many school leaders believe they comply with filtering and monitoring standards, but do not. I worry that the Government are overestimating compliance overall.
It is a tragedy that we are discussing this at midnight. This amendment should have been put in front of the House. I remind noble Lords who are in the Chamber or reading this in Hansard that Frankie Thomas lost her life, and her parents, who campaigned fiercely for these amendments, have for five years been told by Minister after Minister that this would be put right, and it still has not been. I ask the Minister to give me some hope that this will be put right in statute at the basic level we require and that experts are asking for. Obviously, there will be no vote this evening.
Finally, Amendment 240 would require the ICO to issue a code of practice for educational settings. On Report of the data Bill, the then Minister, the noble Lord, Lord Vallance, gave firm commitments that the Government would use their powers to require the ICO to publish a new code of practice. In Committee of this Bill, the Minister said the ICO was under a commitment to produce an edtech code of practice, but the Minister’s letter to me of 16 December said the Government will lay regulations in the second half of 2026 requiring the ICO to begin work on the edtech code. This is political snakes and ladders. I am back at the beginning. In the old world—which is gone for ever and obsolete—it was not doable that every movement, emotion and learning outcome of a child could be taken by a commercial company from school and pushed into the commercial world to be exploited.
Amendment 240—which I have been promised twice by two different Ministers—would set a clear time limit of six months after the Act’s passing within which an ICO code of practice for education must be established. As set out in the Minister’s letter, it will be more than 18 months from when Ministers first committed to it that it would be started. Can she speed that promise right up?
Each of these amendments asks the Government to set the standards so that tech can do the technology, the teachers can do the teaching and the children can flourish. Anything less is putting big tech ahead of children.