(4 days, 14 hours ago)
Lords ChamberMy Lords, we stand today at a moment of profound vulnerability for the United Kingdom. Our economic security, our national safety and even our long-term sovereignty are at massive risk because we do not yet host or own enough of our own computing infrastructure, our own cloud services or our own advanced AI capabilities. By relying so heavily on foreign businesses and Governments far from our shores, we leave ourselves exposed to the possibility of remote disablement, restriction or withdrawal of the very systems that our society, our public services and our businesses increasingly depend on.
Today, the UK relies almost entirely on American and Chinese companies for the most capable AI models. Recent events, including the United States restricting access to one of Anthropic’s most advanced systems, show how fragile that dependence is. In a world where AI increasingly underpins economic growth and national security, Britain must develop homegrown capabilities. Yes, we have a sovereign AI fund, but it is just a fraction of what our neighbours are pursuing. Other nations are already building sovereign AI systems at scale. The United States, China and the European Union are investing billions into domestic computing infrastructure, national-level model development and secure AI infrastructure. France has launched a sovereign AI initiative centred on national cloud and compute capacity, the UAE is developing its own frontier-led models, and countries such as Japan, South Korea and India are rapidly expanding state-backed AI ecosystems.
Here in the UK, we have one of the largest and richest bodies of public data anywhere in the world, not least from our NHS. As the cost of building capable AI systems continues to fall, we have a genuine opportunity to harness that data for ourselves, to help clinicians reach diagnoses faster, and to build public services that reflect our own standards and accountability, rather than simply adopting whatever the market happens to offer us.
But we must also confront the elephant in the room: leading AI companies are racing towards superintelligence, despite acknowledging that it could pose an existential threat to humanity. Sovereign AI is absolutely critical, but it is worth investing in only if other AI models can be kept under control. As we welcome our new Prime Minister, there is a danger that could overshadow all his important goals: the real possibility that advanced AI systems become uncontrollable. How the incoming leadership chooses to approach AI risk will shape our entire future.
Over 120 parliamentarians so far have called for superintelligent AI to be formally recognised as a national and global security threat. I am one of them. Simply put, the UK must lead an international agreement to prohibit the development of superintelligence until it can be proven safe. If we fail, every other ambition for our country risks being swept aside. The clock is ticking. Some AI systems already exceed human abilities in narrow domains, such as Google DeepMind’s AlphaFold. In June, the director of the US National Security Agency revealed that Anthropic’s Mythos model identified vulnerabilities in classified systems. This should be a wake-up call for every Government, including ours.
We are only just beginning to see a shift in the West towards an appetite for government action. At the recent G7 summit, Sam Altman of OpenAI and Sir Demis Hassabis of Google DeepMind both called for a US-led standards body to test the cutting-edge frontier AI models for national security threats. But there is no indication that this is actually coming—and there are agitators that we should all be aware of. It was only this week on X that President Trump’s former AI adviser, David Sacks, called for “permissionless innovation”.
Building more of our AI at home is vital to our security and our economy, but none of it will count for anything unless humans stay in charge. The day that someone builds a true superintelligence or we lose our grip on a powerful AI system, that sovereignty is gone. This week—in fact, just the other day—we witnessed a taste of what happens when humans lose control: the unintended and unprecedented accidental cyber attack by the new GPT-5.6 Sol and other models on the very platform that was hosting a test. Perhaps it should concern us all that that did not make some of the front pages of our newspapers.
This debate shines a spotlight on something vital for our country: that building sovereign AI capacity is absolutely essential. But, if any nation or company builds a true superintelligence without guardrails, that sovereignty disappears everywhere. We need urgent action to develop our own models to ensure that we have rapid investment in our own AI infrastructure for our economy, for our security and for our resilience. But we also need urgent action to prohibit the development of superintelligent AI until scientific consensus shows us that it can be made safe. The time to act is now.
(5 days, 14 hours ago)
Lords ChamberMy Lords, we will hear from the Labour and then the Conservative Benches.
Baroness Lloyd of Effra (Lab)
We set out yesterday in our Written Ministerial Statement the allocation of responsibilities under the Government going forward. The strategy will be looked after by the Cabinet Office, which is taking the lead for AI strategy and public sector AI adoption. The Department for Business, Innovation, Science and Trade will take on responsibility for the science and innovation portfolio. As I mentioned at the beginning, it is a whole of government approach. You will find discussion of AI policy implications in every sectoral dimension, from financial services to maritime, because it is a technology that affects all areas. That is another reason why we need to look at regulation with a sector by sector approach, because it affects different sectors differently.
My Lords, there can be no greater motivation for extensive international co-operation on AI than when it comes to safety. Other noble Lords have referred to this, but it is worth reiterating in detail that, last night, the co-founder of OpenAI, Sam Altman, announced to the world that its latest next-generation version GPT-5.6 Sol, and an even more capable pre-release model were involved in an unprecedented cyber incident and independently executed a complex cyber attack. Surely the time for giving advice to the tech companies is over. I welcome the Government’s Bill on cyber security and resilience, but it does not extend to AI. Will the UK lead the way and co-ordinate a global agreement on the transparency, oversight and regulation of AI?
Baroness Lloyd of Effra (Lab)
We will continue to build on the work of discussing AI safety, adoption and governance through existing multilateral and multi-stakeholder initiatives, such as those I referred to before, including the G7, the OECD Global Partnership on AI and the Council of Europe, among others. That is the approach we will be taking forward. My noble friend raises very important questions, and in respect of online safety, our online safety regulator co-operates closely with other regulators to look at the implications of AI for online safety and will continue to do so.
(1 week, 6 days ago)
Lords ChamberMy Lords, I strongly welcome the intention of the Bill to strengthen the United Kingdom’s defences by updating our cyber security legislation as it applies to critical national infrastructure. That is good and overdue. As my noble friend Lady Gill pointed to, there is barely a week, if not a day, that passes without a significant business, hospital, local authority or supplier to government reporting a serious cyber incident. Every part of our infrastructure is vulnerable, and a legislative update to reflect that reality is one that this House should have absolutely no hesitation in supporting.
Noble Lords have already raised concerns about a number of things relating to what is or is not in the Bill, and things that perhaps need to be tweaked—how we should consider the economic impact of cyber attacks, as well as issues around insurance, reporting, workforce development and training, making AISI a statutory body and the lack of joined-up work across 12 different regulators. These are all concerns that I share.
I want to use the time I have available to add some details on the significant gap that has already been shared by others: the Bill currently makes no provision at all for artificial intelligence or, connected to that, for cyber sovereignty. This is not a hypothetical concern. Our allies have already grasped that, if their critical systems, their public services and their citizens’ data will depend increasingly on AI, relying entirely on foreign-built, foreign-hosted models is itself a national security question and diminishes those countries’ resilience. This is now the direction of travel right across Europe, and we should not assume that we can simply stand outside it.
The Netherlands has built GPT-NL, a sovereign open language model developed by a consortium led by the research institute TNO alongside SURF and the Netherlands Forensic Institute and funded by the Dutch Government. It exists explicitly so that Dutch public bodies are not routing sensitive data through services they do not control, governed by laws they did not write and using models they did not develop or test. Germany has gone further still with Soofi—Sovereign Open Source Foundation Models—a government-backed initiative bringing together German research institutions and industry to build an open foundation model of around 100 billion parameters intended to underpin domestic industry and to handle complex technical and analytical tasks. These are not vanity projects; they are deliberate decisions by Governments to secure and keep control of the systems their public services are increasingly relying on.
The strategic logic is plain. A handful of foreign providers now sit upstream of much of the world’s AI capability, and a dependency that concentrated is a single point of failure that no Government should accept for their critical national infrastructure. Sovereignty over the AI that runs our critical systems cannot be an optional extra; it should be treated as part of our national cyber security and national resilience decisions. The Bill as currently presented is entirely silent on that question.
I will raise two specific areas where this absence should concern your Lordships. The first is education infrastructure, specifically exams and marking, which are increasingly stored and processed online. I understand that awarding bodies in this country are already exploring AI-assisted marking. If AI becomes embedded in that process, the accuracy of a child’s marks will depend partly on how that AI model behaves, and yet it will sit outside the Bill’s jurisdiction. We are creating a critical dependency for the life chances of every child in this country, resting on a model we may neither own nor be able to scrutinise, with no corresponding legislative safeguard. We would have all the risk of a critical dependency with none of the legal guardrails that the Bill is designed to provide.
The second area is electoral services and the data held on the electoral register. I do not think I need to labour the point about why the integrity, security and sovereignty of electoral roll datasets matter. If AI systems come to play any role in how our electoral registers are compiled, verified or protected—we should assume that they will—we must be able to answer three questions: who controls the model, where does the data go, and what happens if that dependency is disrupted or compromised? A register we cannot fully account for is a register that we all cannot fully trust. The Bill should be equipping us to answer those questions.
None of these points is an argument against the Bill; they are an argument for finishing it. As many noble Lords have already alluded to, technology is moving faster than any Bill can be introduced. There are many stats on the speed of tech evolution; the one that consumes me the most is that the maximum length of tasks that AI models can successfully complete is now doubling roughly every four months. We owe it to the public to build in adaptability from the start, rather than returning to primary legislation each time the landscape shifts.
We have here in the United Kingdom one of the largest and richest bodies of public data anywhere in the world, not least from our NHS and our public service broadcasters. As the cost of building capable AI systems continues to fall, we have a genuine opportunity to harness that data ourselves; to help clinicians reach diagnoses faster; to ease the administrative burden that weighs so heavily on our public servants; and to build public services that reflect our own standards, accountability and values, rather than simply adopting whatever the market happens to offer.
Building this capability at home is also how we ensure that the guardrails and safety measures that we believe are necessary are actually built in to bolster the opportunity for full cyber security, rather than inheriting it from systems designed to other standards and other priorities without any concern for real safety and security. This is something for which I will continue to advocate and which, I believe, will supercharge the realisation of the aims of the Bill. I therefore welcome my noble friend the Minister’s reflections on whether AI and cyber sovereignty might yet find a place in this legislation.
I look forward to the rest of this debate and to playing my part in scrutinising and enhancing this legislation.