(1 week, 4 days ago)
Lords ChamberTo ask His Majesty’s Government whether, and if so when, they expect to bring forward legislation on the development and use of artificial intelligence in the United Kingdom.
The Parliamentary Under-Secretary of State, Department for Science, Innovation and Technology (Baroness Lloyd of Effra) (Lab)
My Lords, AI has the potential for significant advances in science, productivity and living standards if adopted securely. While we are taking steps to develop our sovereign capability, we are also bringing forward the regulation for growth Bill to ensure that our regulatory environment drives the growth we need to seize the opportunities brought by AI. Through our world-leading AI Security Institute, we are supporting international safeguard developments and ensuring that the Government have the best understanding of model capabilities as they advance.
My Lords, I thank the Minister for that Answer, but I also say well done to the England football team for reaching the semi-finals of the World Cup. In doing so, they demonstrated AI—actual intelligence.
The stone age did not end because we ran out of stone. AI technology has given us amazing ways of solving everyday problems. The Minister mentioned the AI Security Institute. It plays an important role, especially concerning research, but it does not have powers to compel companies to engage with or to protect us against serious risks from AI. We know that AI can bring great benefits, from health to wealth, but it can also bring problems. Can the Minister therefore tell us when we will have AI regulation? The Government seem to have a “wait and see” attitude. AI also sees, but it does not wait.
Baroness Lloyd of Effra (Lab)
The Government are acting to ensure that the UK can grasp the transformative potential of AI. That includes developing our sovereign capability and, as the noble Lord mentioned, relying on the advice of the AI Security Institute. Our approach is that we will legislate where we need to. We have done so through the Online Safety Act and we are doing so in other areas where we see the need. We believe that the best way of regulating is through context-specific regulation, which will take into account the specific issues that arise when AI is adopted by particular sectors.
(1 week, 6 days ago)
Lords ChamberMy Lords, I thank the Minister for introducing this important Bill. Cyber security is clearly vital to the protection and prosperity of our nation. But if we fail to plan, we plan to fail, and this Bill is at the heart of the Government’s cyber security plan.
I was born and raised in a part of the world that many think of as paradise, bliss, utopia. It is called Birmingham, just off the M6 by the gasworks. I can see there is some accord in the Chamber—or maybe it should go to VAR. I was a district councillor in that region. One of the largest employers there is Jaguar Land Rover. This giant motor vehicle manufacturer is the head of a supply chain of over 4,000 companies. JLR was the victim, as we all know, of a cyber attack last year and was bailed out by this Government to the tune of a £1.5 billion loan guarantee. The Government believed they had no choice because if they had let JLR fall, thousands of workers would have lost their jobs. I have some sympathy with that rationale, but it did set a dangerous precedent. It is also worth noting, surely, that the company had not completed taking out an insurance policy against cyber attacks.
So the first point I want to make to the Minister is that there is no mention in the Bill of the role of the insurance industry. Surely the issue of essential and compulsory cyber insurance needs to be looked at; otherwise, we will have another situation where we have to bail out another huge company.
The retail chain Marks & Spencer lost 99% of its profits due to a ransomware attack which disrupted services and stole customer data last year. Harrods and the Co-op also experienced cyber breaches over recent months. Surely, then, there is a glaring weakness in the Bill in that it will have no impact on private companies such as these. Can the Minister explain why the scope of the Bill cannot be extended—not in the future but now—to include large private retailers, at least those over a certain defined size or turnover? I understand there is potential in the Bill for improving things in the future, but why not do it now?
One of the lessons of history is that we must learn lessons from history, and surely a vital lesson is to take into account the changes in the world around us. In the Bill, the Government recognise that the artificial intelligence revolution has increased the need for more effective cyber security. Yet there is still no UK AI regulation, no cyber strategy, no mention at all of quantum computing or encryption. These matters need to be discussed and looked at now, not some time in the future, when you consider how fast AI is progressing.
We also have a cyber security skills shortage, with 49% of UK companies admitting a lack of cyber foundational skills. As well as protecting the nation, in this AI age it is skills that will pay the bills and grow the economy. It is right that the Government have announced initiatives to attempt to fill vacancies in the cyber security industry, but there is no definition in the Bill of what is required to be a “skilled person” in this context. I just ask the question: why not? Why not look at it now?
We are living longer, and the demands on the public sector are growing, but there is a lack of focus in the Bill on the public sector, particularly the risk to NHS data. For example, Synnovis, which has been mentioned, is a company which provides pathology services to the NHS. A couple of years ago, a ransomware attack on Synnovis cost £32.7 million and resulted in delays to more than 11,000 appointments and even, allegedly, one death. Surely all companies, private and public, that hold personal data should demonstrate that they have effective defences against cyber attacks. I have tried to find out whether Synnovis or its suppliers would be covered by the Bill; there is some ambiguity over that, and that ambiguity at this stage is not helpful.
I welcome that the expanded scope of the Bill now includes data centres, managed service providers, electrical load controls and critical suppliers. But the Bill does not go far enough to protect the UK economy. The current structure of the Bill allows the Secretary of State, in principle, to expand the number of sectors in the scope of the regulations. But even to implement secondary legislation will require the Government to meet a number of conditions. The Minister has referred to emergency powers, but that is still a process rather than an event. Surely the principle of the Secretary of State reporting back to Parliament every five years is not good enough in this fast AI world that we are living in.
The Government also need to recognise that many companies operate across borders, including in the EU, where they have to comply with European directives on cyber security that do not apply in the UK. Over- regulation must not stifle innovation. With 12 regulators enforcing this Bill, there is a danger of regulatory duplication. This is especially so for organisations covered by more than one regulator. Where appropriate, the Government should seek to ensure that UK cyber security regulations align across each regulated sector and across borders with other jurisdictions such as the EU. For example, the Government could ensure that all regulators accept common forms of evidence demonstrating compliance.
There needs to be the adoption of a common baseline security standard, alongside ongoing evidence of security requirements across regulated sectors. This should also recognise that different sectors have their own particular needs: farming is different from fashion, which is different from football. The standard could be the National Cyber Security Centre’s cyber assessment framework. An example of co-ordinating regulators already exists in the Digital Regulation Cooperation Forum, which helps deliver a coherent approach to digital regulation.
Some 43% of all UK companies experienced a cyber breach in the past 12 months. The Department for Science, Innovation and Technology reports that cyber attacks cost the UK economy £14.7 billion a year, and the problem is increasing. For 10 years, I had the privilege of being vice-president of the British Board of Film Classification. Hollywood sometimes produces entertaining films that see the future; for example, Steven Spielberg’s movie “A.I.” was made 25 years ago—an incredible thought. There was a consistent theme in many of the more positive films that we regulated, in that good overcame evil. With a stronger version of this Bill, we can defeat the cyber monsters. In the more positive and hopeful movies we regulated, RoboCop prevailed over the Terminator and Luke Skywalker overcame Darth Vader.
(1 year, 8 months ago)
Lords ChamberMy Lords, I too thank the noble Viscount, Lord Stansgate, for introducing this important debate today, and congratulate the noble Baroness, Lady Freeman of Steventon, on an excellent maiden speech. This is a wide-ranging topic, but since I am delighted to be an officer of the All-Party Group on Artificial Intelligence, most of my comments will be in the context of AI.
The Stone Age did not end because we ran out of stones. It is simply a fact that mankind has always found a new and improved way of doing things. The catalyst for this change is science and technology. Although this debate relates science and technology mainly to the economy, we must not forget the effect that it has on peoples’ personal lives. My mother was a fit and healthy 79 year-old, even swimming most days. Suddenly, a major heart attack reduced her to paralysis. She was unable to speak. Within a year, she was back at the same hospital, this time as a volunteer counsellor to some of the stroke patients. It was explained to me by the consultant leading her care that their pioneering heart valve AI technology had saved her life—which would probably have been lost had the attack happened just a few years earlier. Science and technology is about people as well as the pound.
However, every industrial revolution has been met with some who resist change. In relation to AI, some say that this is a new error, not a new era. One of the lessons of history is that we do not learn lessons from history. During my time as chancellor of Bournemouth University, I emphasised to the students that this AI revolution requires new skills. Yes, some jobs will be lost, but even more jobs will be created. Increasingly, it will be skills that pay the bills. Yet a number of commentators including, in June 2024, the Council on Geostrategy, highlighted that Britain’s current visa system is one of the barriers to attracting top international talent and risks making the country a less competitive environment. How do the Government intend to address the skills gap in science and technology?
There is also the issue of regulation. I was a barrister and judge for some years and am aware of the need for some regulatory framework for AI. A few years ago, I had the privilege of meeting Sir Tim Berners-Lee, the creator of the world wide web. It was just me and Sir Tim in the room—and 200 other people—but I had a tremendous conversation with him. He told me that he has been warning for years about too much power being accumulated by just a few giant social media platforms. I understand that too much regulation could stifle innovation, but what plans do the Government have concerning future regulation?
Science and technology, including AI, are driven by data. Data is an increasingly powerful source of information. In fact, data is so important that instead of a baby’s first word being “Dada”, one day it might be “data”. The need to protect personal data, especially that of children, the elderly and other vulnerable groups, is paramount. For 10 years, I was vice-president of the British Board of Film Classification. Our main remit was to protect vulnerable groups. What extra safeguards will there be to ensure the protection of, for example, patients’ records in the NHS?
I see science and technology as providing solutions to people’s everyday lives. It should be reducing the gap between the have-nots and the have-yachts, so let us embrace this industrial revolution with faith, not fear.