All 19 Debates between Viscount Camrose and Baroness Lloyd of Effra

Cyber Security and Resilience (Network and Information Systems) Bill

Debate between Viscount Camrose and Baroness Lloyd of Effra
Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - -

My Lords, I thank the noble Lord, Lord Clement-Jones, for introducing this amendment and the noble Lord, Lord Arbuthnot of Edrom, whom I see in his place. I am sorry he was unable to attend the beginning of this debate, but we are told it was for very good reasons. I will not try to reproduce the many overwhelmingly powerful arguments that we have heard in favour of this amendment, which, on these Benches, we are also keen to support—as we support any measure on the basis that it would help organisations to protect themselves and their systems.

Penetration testing and the wonderfully named bug bounties are excellent ways to identify and address the more technically difficult vulnerabilities before they are exploited. Take one of the most widely used apps anywhere: Google Chrome, which has found that external researchers were responsible for almost a third of its patched and communicated vulnerabilities. The Government’s own consultation included respondents arguing that the Computer Misuse Act prevents cyber professionals, consumer groups and researchers undertaking this kind of legitimate public interest activity.

The amendment is wholly sensible in its design, in that it does not commit the Government to action but begins the conversation on this small but hugely important and valuable change, supported avidly, as we have heard, by everybody—more or less—within the cyber industry. It would explicitly condone good faith researchers and sanction ethical hackers to carry out their work. I cannot imagine why it would not at least be worth reviewing such a change on this basis.

I have some unsatisfied curiosity, as there are no published statistics showing how many Computer Misuse Act investigations, prosecutions or convictions involve good faith cyber security researchers, so it is hard to know how much of a dampening effect on ethical hacking the CMA is currently having. If any of the signatories to the amendment, or of course the Minister herself, could shed any statistical light on that, I would be most grateful. As I said, this amendment would allow all such considerations to be taken into account without committing the Government and, as such, I strongly support it.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I am grateful to the noble Lord for raising this topic through his amendment, and I recognise the strength of feeling on reforming the Computer Misuse Act. I agree that the UK should have the right legislative framework to allow us to tackle the threats posed by cyber criminals.

The Home Office has already carefully reviewed the Computer Misuse Act and proposes to introduce a defence to Section 1 for accredited cyber security researchers when carrying out certain cyber security activity that would currently be unlawful under Section 1 of the CMA. The Home Office has worked closely with the NCSC, law enforcement and the cyber security industry to refine these proposals. The noble Lord, Lord Clement-Jones, was briefed by Home Office officials on these proposals in February, and I hope this is able to demonstrate meaningful progress that the Government are making on this issue. The Home Office recognises that legislating in this area is a priority and will do so as parliamentary time allows. As noble Lords here are all aware, the King’s Speech in May included a commitment to a national security Bill, with measures to update the Computer Misuse Act, and work is ongoing to bring forward this legislation.

The review proposed by this particular amendment would be undesirable because it would be limited to the scope of the NIS regulations. This would be too narrow for the scope of the Computer Misuse Act; it is also unlikely to provide the Government with new information on how the Act should be reformed. I am sure that the noble Lord and others in this Room will be active in the passage of this legislation once introduced. I have read his correspondence with the Home Office, including the activities that the noble Viscount, Lord Camrose, referenced, and his expertise across all these areas will be hugely welcomed once it is introduced.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank the noble Lord, Lord Markham, for raising this important issue again. Good data hygiene and security is essential to ensuring that public bodies are resilient to cyber attacks. Through the Bill, we are better protecting data, to make our essential services safer and more secure for all those who rely on them. This includes through security and resilience requirements, which will form part of the duties placed on regulated entities and which I have mentioned at previous sittings of this Committee. In our consultation later this year, we will propose that these requirements cover data security. 

Let me emphasise that where personal data is concerned, all public bodies must already comply with the data protection principles in the UK GDPR. This includes requirements to keep personal data secure, process only the minimum amount needed to deliver their objectives, periodically review whether this data is relevant and adequate for the public body’s purposes and not to retain this data for longer than is necessary. The Information Commission regulates the data protection legislation independently of the Government. It has a range of powers at its disposal to investigate alleged breaches and require public bodies to address non-compliant practices.

Significant obligations exist under the UK GDPR. In addition, our upcoming consultation will examine measures to strengthen data security within the security and resilience regulations. A separate consultation, as proposed by the noble Lord, would not be a good route through, but it would be a good idea for us to meet and think about the most appropriate route for advice on data security in the context of the SRRs. I suggest that we focus our discussion on the SRRs in the intervening period.

As this is the last time I will speak in Committee, I want to reflect on some of the points made by noble Lords. Obviously, productivity and growing the UK economy are big themes for all of us. It is true that we have progressed through Committee faster than perhaps people anticipated, but I have heard very clearly the points that have been made very succinctly, both on fundamental structural issues—to which, as I have said, I think the approach in the Bill is right, I am just logging the fact that I have absolutely heard the motivation for that, around consistency and so on—and indeed on some of the more technical points that noble Lords have made about some of the details of the Bill, some of which I have already undertaken to come back on.

I thank the Committee for its scrutiny and noble Lords for the experience they have brought to the Committee from their practical walks of life.

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - -

In the spirit of her final remarks on the Bill overall, is the Minister able to give any update as to when the national cyber action plan might emerge?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I have nothing further to add what I have said in previous sittings.

Cyber Security and Resilience (Network and Information Systems) Bill

Debate between Viscount Camrose and Baroness Lloyd of Effra
Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - -

My Lords, I start by thanking my noble friend Lady Neville-Jones for introducing this group and setting out her stall so clearly and compellingly. I apologise that some of the amendments that have been looked at here I had in my record as being part of the next group. So, if I do not cover them all now, they will be covered by my noble friend Lord Markham as we get into the next group.

Let me begin by outlining the amendments in my name and those of my noble friends Lord Markham and Lord Holmes of Richmond. The need for action on ransomware has never been higher. The NCSC handled 204 nationally significant ransomware attacks in the year to September 2025 that we know about—up by 130% on the year prior, leading the NCSC to name ransomware as the most pressing threat to the country in its annual report. Of course, one of the challenges we face with ransomware attacks is not knowing when they happen, to whom and how often. The victims too often have strong reasons, generally associated with legal liability, not to report them. This makes it challenging, if not impossible, for any government agency seeking to identify commonalities across attacks to pursue repeat offenders and warn vulnerable organisations.

We could seek to make reporting of such attacks mandatory, but at the risk of placing hacked organisations in an impossible position where public reporting creates a legal bind that worsens the damage already done by the attack. I take on board the cogent concerns expressed by the noble Lord, Lord Clement-Jones, but the moral hazard occurs today where companies do not report ransomware attacks, thereby damaging our collective ability to defend others yet to be attacked.

Our amendment therefore seeks to find a channel that reports the facts of the hack and the metadata around it in a way that is not disclosed beyond the agency charged with cyber protection and does not become public knowledge. I do not pretend that this will be straightforward. For instance, we would have to understand how to deal with FoI requests and so on. That is why we propose a consultation. But if we were able to achieve something on this basis, we would greatly enhance our ability to protect UK PLCs from these hugely damaging attacks.

Amendment 172 seeks to require a review on the impact of the new reporting requirements introduced by the Bill. Again, this is fairly straightforward. The strengthened incident reporting requirements are being introduced to allow the regulators and the Government to help with providers and suppliers who have been attacked. Whether these requirements actually serve that purpose, and whether they do so at the expense of providers, cannot yet be known, but we must be able to form an assessment and adjust if necessary. Everyone in this Room would accept that we need statutory agility in the face of fast-moving technology, and a review on these lines could and would enable just that.

For a similar reason, I support the desire for transparency in Amendment 165 in the name of the noble Lord, Lord Clement-Jones. This may even overlap with our own amendment; we could probably think about merging the two in some way. It seems clear that both Houses of Parliament should be informed as to what the reporting regime is being used for and whether it is fulfilling its function. I hope that the Minister agrees.

I very much support Amendment 17 in the name of my noble friend Lady Neville-Jones. We are going from an incident constituting an actual adverse event on the security of network and information systems to it being capable of having such an effect. Arguably—the noble Lord, Lord Clement-Jones, made this point very well—almost any incident would meet this condition. We need language that expresses genuine risk to avoid all incidents being caught in the net. This seems wholly pragmatic to me and I commend it to the Minister, to whose response I look forward.

Baroness Lloyd of Effra Portrait The Parliamentary Under-Secretary of State, Department for Science, Innovation and Technology (Baroness Lloyd of Effra) (Lab)
- Hansard - - - Excerpts

I thank noble Lords for their amendments in this group; in fact, subsequent groups also speak to this question of the nature, scope and timeliness of incident reporting. What we are all trying to do, I think, is to get the right balance in reporting actionable information that can be used by regulators and the NCSC to improve the security of the United Kingdom and the entities that operate essential services within it. That is obviously what the Government have put forward. I have heard clearly the arguments made by noble Lords, some of which probe the intention and the detail, and I will attempt to clarify those as I speak.

First, I shall speak to Amendments 19, 36 and 44 in my name. Improving incident reporting under the NIS framework is a key pillar of the Bill. Without an understanding of incidents, our regulators and the NCSC cannot assist in recovery, assess risk and bolster resilience. The amendments that I have tabled will ensure that the incident reporting measures for regulated entities reflect what we are trying to achieve.

The Bill already requires relevant regulated entities to consider a list of factors when determining whether an incident is likely to have a significant impact and be reportable. This includes whether data relating to users is, or is likely to be, compromised. Government Amendments 19, 36 and 44 remove the reference to “users”, meaning that all data compromises relating to the relevant network and information system are in scope of incident reporting. This will enable key incidents to be reported, including the compromise of commercially sensitive information or the exposure of access details or usernames of the regulated service.

These incidents will need to be reported to the NCSC and the relevant regulator. I say in response to the noble Lord, Lord Clement-Jones, that that is the motivation behind the change to that categorisation. This will ensure that the regulators have full oversight of significant security compromises, supporting them to keep the UK safe and secure. We will shortly consult on what constitutes a significant impact and put further detail in secondary legislation and guidance.

I turn now to the amendments tabled by—

--- Later in debate ---
Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - -

My Lords, I, too, thank my noble friend Lady Harding of Winscombe for tabling this important set of amendments, which we welcome, and for clarifying the refinements of the grouping process, which had slightly eluded me up to that point. As with the previous group, this would amend four key areas of, on this occasion, customer reporting. It would tighten the timing to notify customers; widen the incidents expected to be reported by removing the adverse impact criterion; add extra reporting triggers; and add an “advice on remedies” duty.

Of course, businesses should be supported in the case of cyber attacks and our priority must be preventing, containing and controlling such incidents, but this cannot come at the expense of the customers that businesses serve and depend on. Customers deserve to know when a firm they depend on is targeted, even if such an attack does not necessarily directly adversely affect them. They deserve to be informed promptly and they deserve to be informed of potential remedies.

It is worth saying that there is a welcome side effect to doing so, based on the premise that behaviours are the best guard against cyber attack. Constantly being aware that cyber attacks are going on will improve behaviours. As was said earlier, the goal is not to create panic but, on a continuum between insouciance and panic, we must imbue a point closer to concern more widely in the population to keep people aware that we are constantly at risk of being hacked. On these Benches we feel these are wise, pragmatic and helpful changes. I certainly hope the Minister agrees.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank the noble Baroness for raising important points around customer communication. As set out in the Bill, it takes forward the current duties to notify customers that the Bill places on data centres, OESs, RDSPs and RMSPs. That duty was designed to ensure that providers of key digital and data infrastructure services consider whether their customers are likely to have been adversely affected by a reported incident—whether through disruption of service, compromise of their data or exposure of their systems to cyber threats—and to notify them.

I will explain the logic in response to the point of the noble Lord, Lord Clement-Jones, about the importance of meaningful communication with customers. The reason we have drafted the Bill so that customer notification follows the 72-hour incident report is to ensure that regulated entities can focus on understanding the nature of the incident and contact customers when they are more likely to understand its potential impacts.

We have discussed the question of what an organisation might reasonably be expected to know within 24 hours of identifying an incident. The point is that customers should be communicated with in a timely manner, with sufficient information, so that they can take the necessary action. On that point, the rationale for 72 hours was to time it, for simplicity, with the 72-hour report. I am happy to consult further with the noble Baroness to explain the logic of the 72-hour and 42-hour requirement to communicate with customers, because the motivation is exactly the same: to have actionable and meaningful communication with customers.

I turn to the degree of depth of communication, the advice that can reasonably be put on regulated entities on technical measures, and what technical mitigations customers should take on their own. It is reasonable that the regulated entity should share what they know about the nature of the incident. The question about whether the regulated entity is in the right position to provide advice to customers on what mitigations they should take is both practical and technical. Would they have enough insight to have an effective understanding of the situation of the customers and a detailed understanding of the customers and their businesses in order to give effective meaningful advice in that way—or would that just be a requirement on the entities that would not have the intended impact? On that point, I am not quite persuaded that the line is drawn in the right position.

On keeping in touch, mentioned by the noble Baronesses, Lady Kidron and Lady Harding, I am happy to come back to that on Report to make sure that we have the right balance between the initial notification and the right type of customer communication.

--- Later in debate ---
Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - -

My Lords, I thank the noble Baroness, Lady Kidron, for opening this debate on behalf of my noble friend Lady Morgan of Cotes. I will come to her amendment in a moment, after I touch on Amendment 167, tabled by the noble Baroness, Lady Ludford. Her comments, particularly about board ownership of cyber risk, were well founded and an extremely important foundation for the debate—as indeed were those of the noble Baroness, Lady Berger, who pointed out the difficulty of accelerating from zero cyber knowledge to sufficient. That is a non-trivial undertaking.

Amendment 167 is absolutely in line with the principle that we raised on the first day of this Committee in the form of Amendment 92B. It is the idea that executives should be held accountable for cyber security and resilience plans by their board and their shareholders, by reporting consistently on protections. This amendment, perhaps a little more explicitly, would require the same thing and I am very happy to support it.

I think Amendment 74 largely follows the same sentiment: that companies should and must be held accountable for their own cyber security. On this one, however, I need a little more persuasion. I am going to tread a little tentatively here, because I very much take on board the comments of my noble friend Lord Arbuthnot that we have not solved this problem yet and that carrying on as we are is probably not that sensible.

However, I do have some inner alarm bells ringing about this one. So, while we support the goal of making companies self-sufficient and accountable to their shareholders, this amendment would give the Information Commissioner powers to enforce compliance and sanction individual negligence. The concern here is that, as a matter of principle, the inner working of companies—who is accountable internally, to whom and for what—should be placed in a different category from the requirements placed upon them.

We should encourage companies to figure out internal issues themselves. By all means require board oversight of cybersecurity plans, as we have attempted to do, but my understanding is that this amendment would make it the Information Commissioner’s job to decide which individual is responsible when cyber attacks take place and are not adequately defended. I find this quite a tricky path forward, but I am clearly willing to keep talking and to be persuaded.

I am also concerned about the disincentives to become a director that this might put in place, because of what feels to me like the inherent uncertainties of the liabilities that may hang over board directors as they undertake these responsibilities. That being said, I, of course, completely agree with the underlying principle and look forward to hearing the Minister’s response.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank the noble Baronesses who introduced their amendments, including the noble Baroness, Lady Kidron, who did so on behalf of the noble Baroness, Lady Morgan, for raising the incredibly important topic of board accountability and senior management oversight. It is absolutely right that organisations, especially those delivering our essential services, are held properly accountable for their activities. That is why the Bill creates a more meaningful enforcement regime in terms of the maximum fines that can be levied—up to £17 million or 4% of turnover, whichever is higher—alongside a simpler process for taking that forward.

I also agree with the points made by the noble Baronesses, Lady Ludford and Lady Neville-Jones, and by my noble friend Lady Berger, on the extent of this being within the regulatory perimeter as well as the non-regulatory perimeter. Boards upskilling themselves and taking training seriously is absolutely imperative. That is why we have our Cyber Governance Code of Practice, which is at the heart of our approach to board and executive accountability. I personally feel that I am an extremely active proponent of this. For those who feel that we are not doing enough, I request their support in continuing to highlight that important code of practice in their own organisations, and on all the numerous boards they sit on, to make sure that we are governing cyber risk appropriately—and that many of the board directors they sit alongside are aware of it.

That is obviously not the limit of the approach that we are taking. We are going to introduce new security and resilience requirements in our secondary legislation. Our proposals will include a dedicated requirement on board-level governance, which will be consistent with the NCSC’s cyber assessment framework. It will cover issues such as organisational capability, senior responsibility, accountability for security and resilience, and effective risk escalation. In that way, we will connect the clarity on what is expected of boards with accountability through the enforcement regime.

I will touch on the point alluded to by the noble Lord, Lord Clement-Jones, on the EU’s regime. Individual liability for board-level members is not mandatory under NIS2. Different EU member states have taken different approaches to implementing the directive in this respect, so there is not a single model of implementation that the EU is following.

To conclude, I would also concur with the point that the noble Viscount, Lord Camrose, made on the importance of attracting those with cyber expertise to take on board-level roles and be able to contribute as part of the board accountable to shareholders in that way. We do not want to introduce anything that might disincentivise either senior executives with cyber expertise or those at board level from taking these very important roles.

I believe that, together with the enforcement regime and the security and resilience requirements, those two things will cement the importance of board and executive accountability firmly into the regime, in the way that noble Lords have highlighted today. That is the right approach.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

It is not the same. I wish to stress that the importance of strengthening cyber resilience can happen outside of legislation being put in place. There are many efforts that can go on to improve cyber resilience.

Moving on to the amendment of the noble Baroness, Lady Ludford, and her question about the scope, as well as the questions of the noble Lord, Lord Russell of Liverpool, about CRMs and so on, I do not know the specifics of this CRM. I am very happy to write after hearing of the attributes that were enumerated for its characteristics. Businesses that offer software as a service are in scope of the NIS regulations as cloud computing services, under the RDSP definition, if they meet the definitions in the Bill. In the case of the particular company that was mentioned, I do not know whether that would meet any definitions in the Bill.

Data protection legislation is obviously in place already, and processors are meant to have the systems in place for regularly testing, assessing and evaluating the effectiveness of their measures for ensuring the security of that processing. That legislation is already in place.

Moving on to the public sector, I will respond to the questions from the noble Lords, Lord Birt and Lord Clement-Jones. The Government are already taking equivalent steps to secure their own essential activities through the Government Cyber Action Plan, published in January this year. That plan applies to government departments, arm’s-length bodies and wider public sector organisations. It sets out clear expectations, targets and milestones at all levels to transform cyber security and resilience in the public sector. The outcomes of the plan are aligned with those of the Bill; there will be a consistent approach to strengthening cyber resilience across the public sector. Government departments are accountable for setting expectations and overseeing resilience across the sectors and organisations within their purview, while individual organisations remain responsible for managing their own cyber security and resilience.

This brings me on to Amendment 81A—

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - -

I thank the Minister for her point about the Government Cyber Action Plan, but do the strength of her arguments there not completely reinforce the urgent need to have the national cyber action plan, so that we can assess overall the cyber strategy of the nation and the role of the Bill within that strategy?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

The cyber action plan is a very thorough document. It sets out a plan over many years to improve the cyber resilience of the Government and the public sector, which I think we all agree is absolutely needed. The fact that incidents are still occurring in the public sector reinforces the need to act. We will publish the cyber action plan and, as I mentioned two days ago, I will keep the Committee and the House updated on progress on that.

Education is an incredibly important sector, and the Department for Education takes an active approach to supporting the sector. This includes the Cyber Security Hub, providing schools in England with guidance, while the standards for schools and colleges help institutions to understand their cyber security requirements. Colleges have been required to meet cyber essentials since 2024, with more than 80% of colleges now meeting this requirement.

I come to the question of MHCLG and local government. The department is also taking meaningful steps and working with local authorities to increase their cyber defences. This includes the rollout of the cyber assessment framework for local government, which would be the equivalent to what is required in the cyber Bill, and the recently proposed revisions to the best value statutory guidance to set new expectations for local authorities on cyber resilience. That best-value duty provides an immediate and proportionate route to improving through existing governance and accountability mechanisms. In addition, MHCLG is supporting councils directly.

The question of electoral infrastructure and political parties, raised in Amendments 79 and 81D, is also incredibly important, as noble Lords have set out. The Government work with the NCSC to mitigate risks there. MHCLG specifically works with local authorities to strengthen their electoral cyber resilience and ensure electoral data is adequately protected. The Joint Election Security and Preparedness Unit has responsibility for co-ordinating election security. The MHCLG digital electoral services team maintains robust incident response arrangements to protect electoral systems and citizen data. As the noble Baroness, Lady Ludford, mentioned, the NCSC also has a broad package of support for political parties, candidates and elected representatives. This includes regular engagement with parties, which can access the NCSC’s active cyber defence services, as well as NCSC providing tailored advice to parties and candidates.

I have set all that out because the motivation behind bringing these matters into scope is to engender further action. I want to emphasise that further action is happening, whether or not it is within the scope of the regulatory perimeter.

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - -

My Lords, I thank the noble Baroness the Minister for introducing this debate and for her helpful advance briefings on these amendments. I also welcome all noble Lords back for what, I am sure, will be a productive Committee stage. It is worth noting at the start of Committee that, sadly, our cyber adversaries did not take the summer off. In July, a small power generator was attacked and, in August, an attack on Manchester Airports Group compromised the data of 8.7 million of its customers.

That said, I begin by saying that we on these Benches support the intention behind the Government’s amendments. I absolutely recognise the concerns expressed by all the other speakers thus far; procedurally, this is a very unusual way to go about it, but we support the intention. We have been calling for an increase in the scope of the Bill and for cyber security measures to be undertaken by businesses and individuals, rather than the Government, where possible. We feel that these new amendments go some way to achieving that.

However, while we support the intentions, the context around them remains challenging. The difficulty that we face when trying to scrutinise and improve this Bill—and I am sure that we will return to this—is that it essentially exists, at least for now, in a vacuum. The Government’s goals are the right ones and their intentions seem to be clear, but we lack the overall holistic framework that is so important for systemic, strategic approaches to cyber security. Perhaps when the Minister stands up she can provide an update on the publication date of the national cyber action plan because, as I said at Second Reading, a cyber Bill can stand or fall only in the context of an overall cyber defence strategy, and we need to see it.

Most evident is that this currently seems to be a Bill without a department. The amendments delegating and separating powers between the Secretary of State and the Chancellor of the Duchy of Lancaster reflect this. I am really concerned—I would appreciate some reassurance from the Minister on this—that the decision to scrap DSIT, the Department for Science, Innovation and Technology, has left this Bill in limbo. A minimum of 30 teams are being split across at least three departments, and this seriously important Bill, which we are all counting on to protect us from enemies known and unknown, is adrift between departments. At the very least, the Government should set out as soon as possible who will have lead responsibility when this Bill is passed.

I thank the Minister for her clarifying remarks on the referral schemes that her amendments introduce. As I have noted, we support the attempt to expand the scope of this Bill and give businesses the ability to be self-sufficient. That support extends to the establishment of a voluntary referral scheme. However, this new voluntary scheme needs to have a clear and accessible framework and a timeline for implementation. If it is to act as an extra layer of security outside the Government’s immediate remit, vendors must know what they are expected to report and the mechanisms for doing so. There is little use setting it up if these are not made explicit at the earliest opportunity. The consultation is welcome, but some idea as to the form the Government intend this scheme to take would be helpful, alongside an indication on timing. I hope the Minister can give more clarity in her closing remarks. If not, I hope she will be able to write to me and all Members of this Committee.

I was originally going to make the point that the mandatory referral of a vendor outside current NIS regulations will necessarily be ad hoc and that, as such, defining “qualifying transactions” would not be proper. Instead, Amendment 153 was an attempt to provide clarity for decision-making without inhibiting the Government’s ability to act. However, given that the Minister said in opening that the Government have no intention of setting up a mandatory referral scheme, we must question why they feel the need to give themselves the powers to do so. Powers should not be granted and come into existence if they are never to be used. At the very least, given that the Minister has now said that the Government would consult on the definition of a qualifying transaction before any scheme is established, the amendment should ensure as much. The Government will now have the opportunity to bring these amendments back on Report. The mandatory referral scheme should be redrafted to reflect the Minister’s statement and be conditional on the defining of qualifying transactions. I hope the Minister will agree to this.

Finally, let me make a general point about the definitions used in these amendments and throughout the Bill. The proposed criterion of being “essential to the economy” is unworkably vague. It is not an adequate representation of the different types and scales of risks. I suggest, for example, the Cyber Monitoring Centre’s five-level severity scale as a model more reflective of the grades of threats facing the United Kingdom. I am not arguing that it is necessarily the right model, but it is at least tested and quantifiable. I look forward to the Minister’s response.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank noble Lords for their comments, views and questions, and I will endeavour to respond to them.

In respect of why the power is being granted to the Secretary of State or the Chancellor of the Duchy of Lancaster, it is to anticipate any unforeseen machinery of government changes. It is nothing more than that—to avoid future changes that would be needed when government departments change. On the skilled persons list, I am advised that that is currently available on the NCSC website, so it is accessible to all.

I come back to the heart of the questions: why is this power needed? It is needed because, even though we are taking powers on critical suppliers, it can be the case that vendors have the capability and intent to cause harm, particularly where they have a link to a third country. That is the element I would highlight today. It is through such vendors that a third country can gain access to or control of critical systems, enabling disruption to UK national infrastructure, surveillance through access to data at scale or espionage through access to sensitive information. The risk landscape is evolving quickly, which is why we are taking action now. On the questions posed by the noble Viscount, Lord Camrose, this is very much in the context of all the other things we are doing—all the other powers in the Bill, the scope of the Bill and the Government’s cyber action plan. This is an additional power focused in particular on being able to act earlier in a preventive manner.

On the definition of “qualifying transactions”, the amendment contains a power to create a statutory referral system. This system would need to state which procurements or transactions were in its scope, but, as the noble Viscount mentioned, we do not anticipate needing to do that now. The process of the Bill is such that we will enact both the mechanisms in the Bill and the voluntary referral mechanism. We will then be able, in the period of assessing the effectiveness of the Bill, to look at the effectiveness of the voluntary referral route. Should we need to introduce a mandatory route—obviously, we have done this in different areas of national security—we will be able to do so.

On scrutiny by Parliament, I appreciate that the fact that we tabled these amendments over the summer has meant that not everybody has been able to familiarise themselves with them and we have not been able to have as many in-depth discussions as we would normally when Parliament is sitting. I would be extremely happy to meet noble Lords with officials so that, after Committee, we can go through all the questions and points of detail that have been raised in this session on how these powers will be enacted, parliamentary scrutiny, the consultation process and all the elements that we have set out in our amendments.

A few noble Lords focused on AI. The power could be extended to high-risk AI models that are procured by operators of essential services. The test for using the vendor power direction does not specify or distinguish particular types of goods or services, in keeping with the technology-agnostic approach of the Bill. If an operator of an essential service were using a vendor-supplied AI model in connection with its network and information services, and this would give rise to a national security risk, it could be in scope of the power. That is very much in keeping with what I believe I said at Second Reading about other areas of connection with network and information services in the rest of the Bill and where that may apply to AI.

With that, I beg leave to withdraw—

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - -

Before the Minister sits down, I note that there are a lot of “just in case” elements of the Bill; to me, it feels that there are rather too many. For example, I refer the Minister back to the Chancellor of the Duchy of Lancaster v the Secretary of State. Any department is, at any time, subject to machinery of government changes, but never in any Bill that I have seen—admittedly, I have not seen that many—have both been specified, so why is it so in this Bill? Why do this now? Why not simply make a choice and amend later if necessary?

--- Later in debate ---
Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - -

My Lords, I thank the noble Lord, Lord Birt, for introducing this debate and all noble Lords who have spoken. I appreciate the rigorous strategic thinking that the noble Lords, Lord Birt and Lord Londesborough, have put into the proposal for an office for cyber resilience, but I will try to keep my remarks to the principle of a single regulator.

As others have set out very powerfully, I see the appeal of having a single regulator: it is easy to issue directives, to store data and information centrally, to take a systemic approach overall and to better manage the hiring of scarce, skilled resources. That said, as my noble friend Lady Neville-Jones pointed out, it is important to see the value of sectoral regulators supported by a centre-of-excellence model. More sector-specific expertise, more direct communication with the industry and more flexible approaches are all easier to achieve with smaller, more specific regulators. At a sufficient level of abstraction, it almost does not matter which of those models you go for; it is about having resourced, skilled and empowered people performing monitoring and enforcement activities, regardless of the body under which they sit.

More broadly, the point is that, while differences between a more centralised or more sectoral approach are worthy of debate—I do not think we would ever hit the extremes of either of those—what actually matters is ensuring that, whichever route the Government choose to take us, they make certain that the regulators are adequately resourced and that they exist within a wider strategy.

I am not sure, and look forward to finding out, whether the first of those is the case. The Government have chosen the more sectoral approach, but we do not yet know how the regulators are going to be resourced and what additional resourcing needs will be needed to cope with the increased responsibilities that will be laid at their door. I look forward to hearing from the Minister on how the regulators are going to be funded, how the funding needs will be calculated and how they are going to be supported in this significant expansion of their role.

The second point is that the regulators should exist as a part of a wider strategy, which is not currently the case. I apologise to noble Lords for banging on about this, but it is very difficult to get the past the hole in the Bill in the shape of a wider national cyber strategy. Whether the regulators are many or one matters little without the bigger picture into which they fit. In an ideal world, we would review the overall cyber strategy and then debate what regulatory structures might be appropriate to deliver it but, for now, sadly, that is not the world that we are in.

The Secretary of State—or, indeed, the Chancellor of the Duchy of Lancaster; it is not reassuring that we still do not know which one—must commit to publishing the national plan, after which we can assess the efficacy of its many parts.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank the noble Lords, Lord Birt and Lord Clement-Jones, for their introduction to this section and for setting out the motivation behind a single cyber regulator.

As others have pointed out, this is a question of sectoral expertise and cyber expertise. It is my view that, given the complex cyber landscape, establishing a single regulator would not be as effective as the approach that we are pursuing. Different sectors have different risks, technologies, operational environments, market structures and resilience challenges within their industries. To take an example, the energy sector has a greater reliance on operational technology—such as turbines, substations and gas pipes—as compared to the digital services sector, which is predominantly information technology-based. Noble Lords will see that the guidance on quantum, for example, differs in that respect. This is why expert regulators are needed to ensure compliance in a manner that reflects the realities of their sectors.

I do not recognise the assertion that there is a single internationally recognised model of best practice. There are very near neighbours who have the model that we are pursuing, which keeps the sectoral expertise. Additionally, I do not believe that it would be an effective use of resources to establish a new regulator, and the proposed 12-month establishment period would delay the implementation of this regime.

Finally, cyber would continue to exist within a multi-regulator landscape as there are separate regulatory approaches for telecommunications and financial services. I agree with the point made by many noble Lords—highlighted in particular by the noble Lord, Lord Holmes, both at Second Reading and now—that a consistent approach to implementing and enforcing the regime is crucial. The Bill will drive this through by establishing common security and resilience requirements and secondary legislation for all regulated entities, clear guidance for regulators, and a statement of strategic priorities setting common objectives that regulators must seek to achieve. These will cover issues such as governance, skills, risk management, business continuity, supply chains, incident response, and appropriate testing and exercising. They will be consulted on, and any relevant secondary legislation will be subject to the affirmative procedure.

Regulators will supervise and enforce the common requirements while providing guidance that is tailored to the risks and operational realities of their sectors. Crucially, information-sharing gateways and cost-recovery mechanisms will bolster the well-resourced, experienced regulators who stand ready to collaborate while best supporting their respective sectors. I believe that the Bill’s approach gets the right balance between sectoral expertise and a common approach.

On Amendment 91, which would require specific organisations to conduct an annual independent audit, I agree that independent assessments play an important role in providing assurance and leveraging external expertise; that is why the current framework already enables regulators to require independent audits or inspections. However, it is for the sectoral regulators to set the frequency and nature of audits, bearing in mind proportionality and their expertise in the risks and operational realities of their sectors. We will continue to drive uptake of assured independent audits across sectors, using the range of levers that the Bill provides. That is what the current framework provides for and what the implementation of the Bill will ensure.

I turn to Amendment 90, which would require the proposed OCR to work with the UK Cyber Security Council in order to ensure sufficiently qualified cyber security professionals among regulated entities; I note that the amendment laid by the noble Baroness, Lady Northover, on this topic will be debated later. The Government strongly support the need for the professionalisation of the cyber sector. We already work with the UK Cyber Security Council and regulators to encourage cyber professionalisation across NIS sectors. We also intend to set further expectations for regulators to encourage cyber professionalism through the Bill’s security and resilience requirements, which, as I just mentioned, will be set out in secondary legislation. They will address relevant training, skills and professional standards, and the Bill’s regulators must publish guidance on these requirements.

Artificial Intelligence: Legislation

Debate between Viscount Camrose and Baroness Lloyd of Effra
Thursday 16th July 2026

(2 months, 2 weeks ago)

Lords Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

My noble friend is absolutely right to highlight the fact that AI technology is with us today. It is absolutely right that, as he mentioned, we support all parts of society—children, students, workers—to understand this, discern it and use it wisely. That is why we are also developing our digital skills programme and ensuring that everybody can benefit from this transformative technology.

Viscount Camrose Portrait Viscount Camrose (Con)
- View Speech - Hansard - -

My Lords, we understand the Government’s policy of placing most of the burden of AI regulation on to existing sectoral regulators, but the cyber security and resilience Bill will create new burdens for those regulators. The Minister will accept that this is collectively an extremely significant expansion of those regulators’ powers and workload. First, are any further additions planned? Secondly, are the Government taking steps to ensure those regulators have the necessary skills and resources? Thirdly, is the new Prime Minister aware of and supportive of this approach?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

The noble Viscount is right that the cyber security and resilience Bill will indeed place new obligations on regulators, but that goes hand in hand with the support and the changes in funding and fee recovery that they will be able, after consultation, to enact. They are also supported by the technical authority of the NCSC, which provides them with advice on this. It is obviously the nature of all regulatory activities that they must take into account developments in society and the economy, and the transformative impact of AI. The Regulatory Innovation Office supports regulators to look at how they can adopt AI themselves to improve their regulatory efficiency, as well as looking at developments in their own sectors.

Employment: Artificial Intelligence

Debate between Viscount Camrose and Baroness Lloyd of Effra
Monday 13th July 2026

(2 months, 2 weeks ago)

Lords Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

We are supporting young people to get into work. We are supporting youth employment through the changes to the youth guarantee and to the growth and skills levy, so that we can provide work and training places in jobs. We can support businesses hiring those young people, so that they get the opportunity of the experience of work and of the changing labour force, and can be supported through that.

Viscount Camrose Portrait Viscount Camrose (Con)
- View Speech - Hansard - -

I welcome the Government providing a great deal of skills education, but I do not see how the Government know what skills the marketplace is looking for in AI, particularly in the situation in which we find ourselves, where the recruitment marketplace has been so badly damaged by the misapplication of AI that the market signals on what skills are actually required are not getting through. What does the AI Economics Institute think about this and how will the incoming Prime Minister take this forward?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

The Government have set up the future of work unit and have built on that with the AI Economics Institute precisely to examine the changes in the labour market and the changes to jobs—whether that is sector-specific changes or changes to particular cohorts, such as if women are particularly affected—and to then determine what action should be taken in that resolve. That is exactly what we are doing; we are being very active in understanding the technological change coming.

Wireless Telegraphy Act 2006 (Directions to OFCOM) (Revocation) Order 2026

Debate between Viscount Camrose and Baroness Lloyd of Effra
Tuesday 7th July 2026

(2 months, 3 weeks ago)

Grand Committee
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - -

My Lords, I too thank the Minister for her introduction. This is indeed a short and straightforward instrument, but certainly one worth a little bit of careful thought because of its real strategic importance. As we have heard, the Government propose to revoke the 2010 directions to Ofcom. The directions were originally issued to support the release of additional spectrum for next-gen mobile broadband. The directions have now served their purpose, and the Government, completely plausibly, argue that they are redundant.

Certainly, on the face of it, this revocation is sensible. The 2010 framework was designed for a very specific moment in the evolution of mobile networks. The market has moved on, Ofcom’s regulatory toolkit has matured, and spectrum management now operates under a more flexible and market-driven regime. Removing obsolete directions is, in principle, good housekeeping.

However, it is worth briefly pausing to consider and to put a couple of questions. Spectrum is a national strategic asset. The stability and predictability of the regulatory environment underpinned billions of pounds of private investment, and the balance of responsibility between Ministers and Ofcom must, of course, be handled with care.

I will put two questions to the Minister. First, how does this revocation sit within the Government’s wider spectrum strategy? The questions posed by the noble Lord, Lord Clement-Jones, were absolutely right in this respect. The UK faces increasing pressure on spectrum availability, from 5G and 6G deployment, satellite services, defence requirements and emerging industrial uses. Removing a set of directions is tidy, but more broadly, do the Government have a long-term strategic plan for spectrum allocation, resilience and competitiveness? If so, how does the instrument fit into that strategic plan?

Secondly, what assurances can the Minister give that revocation will not inadvertently reduce investment certainty? The 2010 directions were introduced precisely to give operators confidence during a period of rapid technological transition. We must ensure that today’s decision does not create ambiguity at a time when the UK needs sustained private investment in digital infrastructure.

Of course, we do not oppose the instrument, but we ask the Government to demonstrate that revocation is part of a coherent strategy, not simply administrative pruning. Ofcom must have the clarity it needs, operators must have the certainty they expect, and Parliament must have confidence that spectrum policy is being managed with foresight rather than drift. I look forward to the Minister’s response.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank noble Lords and the Committee for their support for this housekeeping measure to remove an obsolete direction. The direction was fully implemented and cast for its time. As noble Lords have indicated, technology has moved forward, as indeed has the state of mobile coverage and other investment.

The noble Lord, Lord Clement-Jones, specifically asked, “Why now?” We want to ensure that obsolete regulations are not in place. We have heard from the market that there is a possibility that having active obsolete regulations could provide a lack of clarity and could potentially lead to legal challenge. That is why we want to make this move now. Ofcom last revised annual fees last year and new ones are envisaged in the next year, so we are doing it now to provide clarity before then.

On the framework for spectrum, I heartily agree with the points that the noble Viscount, Lord Camrose, and the noble Lord, Lord Clement-Jones, made about the importance of spectrum. We designated an updated statement of strategic priorities in April this year; it set out our priorities across telecoms, the Post Office and, of course, spectrum, including the Government’s policy direction to Ofcom for spectrum. It touched on a number of the important matters that noble Lords have raised, including the importance of growth, innovation and the multiple uses of spectrum. This is very much a housekeeping matter in the context of that wider discussion, and it will have no impact other than that. It supports a clear and coherent framework for spectrum management, and it gives certainty to the regulators and the industry.

On certainty for investment, investment is currently at high levels. For example, the investments being made by mobile phone companies in stand-alone 5G are significant. It is being commercially led and there is committed investment in that area, such that Ofcom reports that, as of January 2026, stand-alone 5G was available outside 93% of premises across the UK—an increase of 10 percentage points since July 2025. The stability and certainty of that regulatory framework is indeed important. With that, I commend the instrument to the Committee.

Social Media: Substances Unfit for Human Consumption

Debate between Viscount Camrose and Baroness Lloyd of Effra
Wednesday 17th June 2026

(3 months, 2 weeks ago)

Lords Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

The noble Lord is right that the Online Safety Act already covers illegal content and child safety duties. Those duties are in force. Ofcom is now turning its focus to the additional duties for categorised services, which will include protections against fraudulent advertising. We are expecting Ofcom’s consultation on the additional duties next month, which should cover a number of the issues that the noble Lord raises.

Viscount Camrose Portrait Viscount Camrose (Con)
- View Speech - Hansard - -

My Lords, to pick up on the point that was well made by the noble Baroness, Lady Bull, sellers of unapproved SARMs routinely use labels in their advertising such as “not for human consumption”, while simultaneously promoting their physique-enhancing effects elsewhere on social media. Since sophisticated AI advertising tools allow sellers to target consumers with almost perfect precision, these tricks are actually no less effective than openly advertising illegal products. Can the Minister tell us who is responsible for enforcing against this and what progress they are making?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

Where it is claimed that products are sold for research purposes only, that does not prevent regulatory action where the available evidence suggests that they are in fact unauthorised medicines intended for human use. If the product is classified as a medicine and is not appropriately authorised, the MHRA can take compliance and enforcement action.

Artificial Intelligence: National Security Implications

Debate between Viscount Camrose and Baroness Lloyd of Effra
Tuesday 16th June 2026

(3 months, 2 weeks ago)

Lords Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Viscount Camrose Portrait Viscount Camrose (Con)
- View Speech - Hansard - -

My Lords, I very much welcome the proposal of the noble Lord, Lord Tarassenko, for sovereign AI capability here. But I would welcome a great deal more clarity from the Government on what exactly they mean by sovereign AI. Does it mean a complete sovereign stack of hardware, software and data? Does it mean AI capability being sovereign, as the Tony Blair Institute suggested, or some variation of that? Until there is a clear definition, it will be very difficult to understand the way forward.

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

Sovereignty is not just about controlling AI models. It is about building leverage over key parts of the value chain and bringing to the table technologies that no one else can live without. It is about looking at where the UK has competitive strengths and where we can support our most promising sectors and start-ups, whether through financial investment, support for R&D or support with visas and so on. We have identified five priority areas: compute efficiency and sovereign architecture; next generation AI labs and model development; AI for health and life sciences; AI for scientific discovery; and AI trust, integrity and assurance. Those are the areas in which we think the UK has a competitive advantage.

Online Hate Speech

Debate between Viscount Camrose and Baroness Lloyd of Effra
Tuesday 16th June 2026

(3 months, 2 weeks ago)

Lords Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

The importance of accurate, trusted news is essential. The noble Baroness touched on many different matters in her question. In respect of young people and their access to social media, as I will be talking about shortly, we have put down proposals that will restrict social media platforms in providing content to under-16s. Providing accurate news is hugely important more generally and, as I mentioned on the previous question, we are looking at the role that algorithms play in social cohesion and the spread of online hate. The noble Baroness raises the very important point of media literacy, and we are working with young people and more generally through our media literacy plan to improve the ability of all people, whether young or old, to discern misinformation and disinformation in this important area.

Viscount Camrose Portrait Viscount Camrose (Con)
- View Speech - Hansard - -

My Lords, online hate speech is not solely created by individual users. It is also generated and amplified by malicious state actors using algorithmic methods to inflame tensions and to undermine our social cohesion. So as the Government prepare to strengthen the Online Safety Act to require platforms to act more quickly during a crisis, can the Minister give us some idea of what might constitute such a crisis? In particular, do the criteria include evidence of co-ordinated algorithmic attacks, increasingly referred to as “cognitive warfare”?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

The noble Lord raises the importance of being attentive and aware of the potential for foreign states to spread disinformation online, and through the Online Safety Act we have made the foreign interference offence from the National Security Act a priority offence that places clear legal duties on services to proactively assess risks, prevent users encountering foreign interference content and remove it swiftly where it appears. Ofcom set out in its publication last week some of the answers to the specific questions about definitions that the noble Viscount raises, but I am happy to write to him afterwards if that does not fully complete the answer to his question.

Artificial Intelligence: Impact on Employment

Debate between Viscount Camrose and Baroness Lloyd of Effra
Monday 13th April 2026

(5 months, 2 weeks ago)

Lords Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

My noble friend is right that there may be differential impacts throughout the labour market. ONS analysis suggests that administrative roles may see greater transformation from AI, while our AI adoption research shows that marketing, administration and IT are the most common areas of current or planned use. The AI and the Future of Work Unit is monitoring sectoral and distributional impacts, including on gender and region. We will support those through the commitment to upskill 10 million people by 2030 and, alongside the Women in Tech Taskforce, to champion diversity in the UK tech sector.

Viscount Camrose Portrait Viscount Camrose (Con)
- View Speech - Hansard - -

My Lords, I declare my technology interests as set out in the register. We should be cautious about the assumption that improved AI skills alone will enable job seekers to adapt to a changing labour market. The misapplication of AI in recruitment often generates unmanageable volumes of synthetic job applications, making it impossible to identify genuinely qualified candidates. Without an efficiently functioning recruitment market, the Government’s efforts to boost employment will be even less effective than they currently are, so will the Minister please encourage the future of work unit to look into the matter urgently?

EU Digital Services Act and Regulation

Debate between Viscount Camrose and Baroness Lloyd of Effra
Wednesday 11th March 2026

(6 months, 3 weeks ago)

Lords Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

Our approach is to have regulators who are sector-specific and have the expertise to look at how AI is affecting the companies they regulate and its impact.

Viscount Camrose Portrait Viscount Camrose (Con)
- View Speech - Hansard - -

My Lords, many digital harms such as disinformation and illegal or fraudulent content operate across borders. In that light, can the Minister enlarge on the practical measures the Government are pursuing with the European Union to assure effective cross-border enforcement of our respective digital regulations, particularly with respect to Ofcom’s work with those responsible for enforcing the Digital Services Act?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

Ofcom and the EU have an agreement and talk frequently about regulatory co-operation. Ofcom is also a member of a global network of regulators, so it can share best practice and welcome further co-operation.

UK Space Economy

Debate between Viscount Camrose and Baroness Lloyd of Effra
Wednesday 11th March 2026

(6 months, 3 weeks ago)

Lords Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

Absolutely. One of the great pleasures of covering civil space is the enormity of expertise in our universities and companies. Almost everybody you meet is doing something ground-breaking and impressive. I would be very happy to meet the people suggested by my noble friend.

Viscount Camrose Portrait Viscount Camrose (Con)
- View Speech - Hansard - -

My Lords, events in Ukraine and Iran are showing the growing military defence importance of satellite communication, navigation and earth observation systems. Given our strengths here in the UK in satellite manufacture and space data services, does the Minister agree that the UK space sector is particularly well suited to dual-use applications that support both economic growth and defensive capability? If so, is now the moment for the Government to look for further ways to promote investment in our satellite manufacturing sector?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

The noble Viscount makes an important point. The two priorities of our space policy are economic growth and national security; they are priorities for the whole of government and are central to our approach to space. I co-chair the Space Ministerial Forum with my colleague from the Ministry of Defence, bringing that whole-of-government approach to this important issue. In the speech I made last week on our four priorities, satellite communication was one of them; it is a real priority for the Government.

Superintelligent AI

Debate between Viscount Camrose and Baroness Lloyd of Effra
Monday 26th January 2026

(8 months, 1 week ago)

Lords Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

As I mentioned at the start, there is a lot of debate about the pathway that AI development will take and the pace at which it is developing. The AI Security Institute has reported a sharp rise in AI capabilities over the past 18 months, with continued growth almost certain, and it is looking at the implications of this. For example, one of its research focuses is tracking the development of AI capabilities that would test the limits of human control, which is one of the most pertinent questions for anybody thinking about the implications of superintelligence.

Viscount Camrose Portrait Viscount Camrose (Con)
- View Speech - Hansard - -

My Lords, I want to build on the very important point raised by the noble Lord, Lord Hunt. Given that AI research and development can be conducted, in effect, anywhere, regulation of the development of superintelligent AI is going to have to be global. Does the Minister feel that the UK is genuinely taking full advantage of our considerable convening power in this space to drive forward the global AI safety agenda? Further, might there be grounds for concern that our convening power may be diminished over time by the emerging political uncertainty that came to the fore over the weekend?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

The Government have forged many extremely successful relationships; as evidenced, for example, by the number of trade deals secured over the past 18 months or so. These relationships with the EU, the US, India, France and many other countries include discussions on AI. In addition, the UK is the co-ordinator on related questions for the International Network for Advanced AI Measurement, Evaluation and Science, which aims to shape and advance the science of AI evaluations globally. Our engagement is on all levels, and specifically on the technical level. The noble Viscount makes an extremely important point. This is an effort of global development, so it is important that we engage with developers globally and with other countries.

Technology Adoption Review

Debate between Viscount Camrose and Baroness Lloyd of Effra
Monday 15th December 2025

(9 months, 2 weeks ago)

Lords Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

In many areas—in fact, the entire industrial strategy and particularly the Technology Adoption Review—that has been done in concert with the private sector. It is an incredibly important part of the approach. To take one example, the skills package in construction takes that approach forward; both the private and public sectors are putting themselves forward together to provide more opportunities for young people. That is the approach that we will take across digital and AI skills, as I mentioned.

Viscount Camrose Portrait Viscount Camrose (Con)
- View Speech - Hansard - -

I draw noble Lords’ attention to my technology interests, as set out in the register. What assessment have the Government made of the critique of the CBI and others that their technology adoption plans are too fragmented? Does the Minister agree that, without strong co-ordination across different technology adoption initiatives, we will be unable either to assess their collective impacts or to learn their individual lessons?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

The technology review and many others have identified that there is no silver bullet in respect of technology adoption. What is needed in the creative industries is perhaps completely different from what is needed in the energy sector, for example. The review’s approach and its adoption into the industrial strategy is to match the needs of a particular sector with a set of technological or digital approaches. Beneath that are some common themes—for example, on skills, connectivity or infrastructure. We have to look at it in that way: measures cut across the economy and specific measures are suited to subsectors.

Children: Social Media

Debate between Viscount Camrose and Baroness Lloyd of Effra
Wednesday 10th December 2025

(9 months, 3 weeks ago)

Lords Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

The noble Lord cites some important evidence which, along with other evidence about the links between social media use and different cohorts of young people, young adults and so on, is very important. The Government and Ofcom are looking at that carefully. As I said before, we continue to keep open all the issues here to protect children from unsafe content, while allowing them to participate actively in the digital world, which can provide many opportunities to young people and much education.

Viscount Camrose Portrait Viscount Camrose (Con)
- View Speech - Hansard - -

My Lords, screen addiction is a growing problem for all ages, but far more so for children. In July, Peter Kyle, the former Secretary of State for DSIT, committed to bringing forward proposals in the autumn to restrict children’s screen time. Since the reshuffles, we have heard no more about those proposals. Can the Minister clarify this point today? Will the Government be bringing forward a package along the lines set out by the former Secretary of State?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

We are focusing on implementation of the Online Safety Act: protecting children from harmful content, backing Ofcom as it goes through the children’s risk assessments of the platform operators, and ensuring that the duties that came in in July are effective. That is the priority for the time being. As I said, we are looking at the evidence and assessing what other measures may be needed. If we need to do so in due course, we will do so.

Mobile Phone and Broadband Prices

Debate between Viscount Camrose and Baroness Lloyd of Effra
Tuesday 9th December 2025

(9 months, 3 weeks ago)

Lords Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

There are very important roles for our regulators. There are also very important governance systems in place that govern how regulators work and how they are accountable to Parliament. I do not think there is any case at present to take the action my noble friend suggests.

Viscount Camrose Portrait Viscount Camrose (Con)
- View Speech - Hansard - -

My Lords, in May, the Vodafone-Three merger was completed, reducing the number of mobile operators in the country from four to three. Building on the question from my noble friend Lord Vaizey, six months on from the merger, what is the Government’s assessment of its impact, first on consumer prices and secondly on investment in the infrastructure that improves both the digital economy and rural connectivity?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- View Speech - Hansard - - - Excerpts

As part of that merger, there was a commitment to invest £11 billion in infrastructure. That is a very important part of the continued rollout of our digital infrastructure, and it is monitored through Ofcom’s Connected Nations report, which is published regularly.

Online Safety Act 2023 (Priority Offences) (Amendment) Regulations 2025

Debate between Viscount Camrose and Baroness Lloyd of Effra
Thursday 4th December 2025

(9 months, 4 weeks ago)

Grand Committee
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

My Lords, I thank noble Lords for their broad support for adding these offences to the priority offences list. This is an important step in improving the online safety regime and improving the environment in which we all use the internet, particularly children and vulnerable people. This will help fulfil the Government’s commitment to improving online safety and strengthening protections for women and girls.

On the points made by the noble Lord, Lord Addington, about tone and proactivity, it is really important that we communicate what we are doing, both in the online world and in terms of violence against women and girls in the physical world. We know that we must all do more to tackle misogynistic abuse, pile-ons, harassment and stalking, and the Government’s whole approach to tackling violence against women and girls is an active one and is something that we have real, serious goals on. We welcome everyone supporting that move forward. For example, the publication of Ofcom’s guidance, A Safer Life Online for Women and Girls, sets out the steps that services can take to create safer online spaces, and the Government will be setting out our strategy for tackling violence against women and girls in due course as part of that. I think that the publication of Ofcom’s report this morning, which sets out the activity that it has taken and will take, will help raise the profile, as the noble Lord says, about what is expected of services in terms of the urgency and the rigour with which these changes are made.

On the question of VPNs, which we talked about a little earlier, we do not have a huge amount of information or research about their use, particularly by young people to circumvent age assurance. We know that there are legitimate reasons to use VPNs, and we do not have a huge amount of evidence about their use by young people, either very young people or older teenagers. Ofcom and the Government are committed to increasing the research and evidence for how VPNs are being used and whether this is indeed a way that age assurance is being circumvented, or whether it is for what might be legitimate reasons, such as security or privacy reasons. That is an important piece of the evidence puzzle to know exactly what measures to take subsequently.

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - -

I am particularly interested in whether it is a legitimate defence for a platform to say, “We could not have prevented this access because a VPN was in use”, and therefore whether it falls to the platforms themselves to figure out how to prevent abuse via VPNs.

Artificial Intelligence Legislation

Debate between Viscount Camrose and Baroness Lloyd of Effra
Monday 17th November 2025

(10 months, 2 weeks ago)

Lords Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

The noble Lord asks a very good question about our sovereign capabilities. The Sovereign AI Unit’s remit spans the full AI stack, including large language models. Our priority is to secure UK access to the best models, including by deepening strategic partnerships and remaining open to backing UK companies to compete. However, we are focusing our efforts where there is greater opportunity for the UK to advance its strategic position in AI, looking across the value chain. This could mean supporting companies developing narrow models in high-impact sectors in which the UK has strengths, such as defence or drug discovery, or backing paradigm-shifting approaches in computing that can outperform incumbents.

Viscount Camrose Portrait Viscount Camrose (Con)
- Hansard - -

My Lords, in September the Government announced plans for a national digital identity system—a policy that will have very profound implications for the safe use of AI, particularly agentic AI. Can the Minister confirm that the interaction between the Government’s digital identity scheme and AI systems will be explicitly included within the scope of the consultation? If not, can the Minister commit to ensuring that it is?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

The noble Viscount asks about digital ID, as he highlights a proposal which was announced a few months ago. Digital ID will help make it easier for people to access the services they are entitled to and prevent illegal working. It will streamline interactions with the state, saving time and cutting frustrating paperwork. A public consultation on the digital ID will launch in the coming few weeks, to ensure the system is secure, trusted and inclusive. I will take back his specific question on the coverage of the consultation coming up.

Protection of Children Codes of Practice

Debate between Viscount Camrose and Baroness Lloyd of Effra
Thursday 30th October 2025

(11 months ago)

Lords Chamber
Read Full debate Read Hansard Text Read Debate Ministerial Extracts
Viscount Camrose Portrait Viscount Camrose (Con)
- View Speech - Hansard - -

My Lords, not much we debate in your Lordships’ House unites us so thoroughly as our shared recognition that children must be protected from harmful online content and behaviours. I am delighted that we are as one when it comes to the importance of shielding young people from extreme pornography, content promoting self-harm or suicide, or other serious risks.

This makes it all the more important to scrutinise how the Government and Ofcom have chosen to implement these protections. The role of the draft codes of practice, laid in April this year and brought into effect in July, is to translate Parliament’s intentions into practical rules for service providers. As the noble Lord, Lord Russell, set out so clearly, there are some serious concerns about whether these codes are achieving their stated objectives, and I thank the noble Lord, Lord Clement-Jones, for bringing this important Motion to the House today and for giving us the chance to air our views.

There is some evidence that the codes are being applied in a way that risks overreach and unintended consequences. Some platforms, such as X and Reddit, in attempting to comply, blocked wide-ranging content, including parliamentary debates on grooming gangs and posts relating to the wars in Ukraine and Gaza. Several experts have warned that such overapplication risks stifling legitimate public debate. It has even been suggested that some platforms deliberately overapply some rules as a way to influence government towards weakening them.

The Act was always designed to respect freedom of expression—political and otherwise—while protecting internet users, especially children, from harm. The Government’s own guidance confirms this, but clearly the practical effect has not always to date reflected that intent.

There also exist concerns about the complexity and accessibility of the codes. Platforms, parents and of course children themselves in some instances may struggle to understand what duties are required and how to enforce them. The guidance is hundreds of pages long and, while Ofcom has issued advice on risk assessments and age-verification measures, there is a real danger that the practical realities of compliance, particularly for smaller providers, leave gaps in protection. Complexity should not become a barrier to the very protections these codes are meant to provide.

We have also been discussing the iterative approach taken by Ofcom. Presenting the codes as a first step, to be refined over time, is in principle essential, for two reasons. The first is that, as we know, this is a pioneering piece of legislation and we must remain open to adapting it. The second is that I am afraid that the people we are up against are inventive users of fast-moving technology.

However, the iterative approach is also clearly creating uncertainty. Civil society organisations have reported that their concerns were not fully addressed during consultation. Children face immediate risks and it is imperative that the Government ensure that these gaps are closed without delay. The noble Lord, Lord Clement-Jones, cited the statistic that a young life aged between 10 and 19 is lost to suicide every week where technology has been a factor. The codes should not act or be viewed as a ceiling for safety standards. Rather, they must set a floor for safety standards and be subject to firm and measurable enforcement.

Enforcement and proportionality are, of course, critical. The Act grants Ofcom significant powers, including fines, criminal liability and restrictions on financial and commercial arrangements. Yet there are practical challenges to ensuring that these powers are applied in a proportionate and evidence-based way. The critical challenge facing the Government as they operate the Act’s machinery is to protect children while avoiding excessive interference with legitimate content and adult access to lawful material.

All that said, we on these Benches do have questions over the Government’s handling of these codes. Our purpose is to challenge the Government to deliver children’s online safety effectively and proportionately. While I welcome the Minister to her place and wish her the very best for her very important role, particularly in this respect, I ask her for some greater clarity, if she is able to provide it, on three strands of Ofcom’s work. First, how will Ofcom monitor implementation by platforms? Secondly, how will it ensure that civil society is genuinely incorporated, and of course that consultees recognise that they have been listened to? Thirdly, how will it address current gaps in coverage without delay?

I am delighted to be participating in this important debate and to have the opportunity to seek these assurances from the Government. We must see rapid action to ensure that the codes protect children in practice, do not inadvertently suppress legitimate debate, and are accessible and enforceable in the real world. I support the scrutiny behind this regret Motion and hope that, when the Minister rises, she will provide answers that reassure us all that the protection of children online is being delivered with both effectiveness and proportionality.

Baroness Lloyd of Effra Portrait The Parliamentary Under-Secretary of State, Department for Business and Trade and Department for Science, Information and Technology (Baroness Lloyd of Effra) (Lab)
- View Speech - Hansard - - - Excerpts

My Lords, I thank noble Lords for their valuable contributions today, and I thank the noble Lord, Lord Clement-Jones, for initiating the debate. I absolutely acknowledge the huge expertise in the Room today. I thank the noble Lord, Lord Russell, for his suggestion of further discussions with individual Members.

I found reading the Secondary Legislation Scrutiny Committee’s report an excellent basis for this discussion. That committee plays a very important role, as do other committees, such as the House of Lords Communications and Digital Committee and the House of Commons Science, Innovation and Technology Committee. The role of ongoing scrutiny by all these bodies is absolutely essential. On the matter of the specific committee that the noble Lord, Lord Russell, mentioned, it would be for the House to decide whether that would be set up to monitor this legislation and the codes.

As others have mentioned, we are working closely with Ofcom to monitor the effectiveness of the Online Safety Act. While the early signs are encouraging, the true test will be whether adults and children are having a safer online experience. Ofcom has put in place a robust monitoring and evaluation program, tracking changes firms are making in response to regulation, gathering data from the supervised services and commissioning research to measure impact. Some of that research has been mentioned in the course of the debate. It is quite extensive and provides a lot of information to civil society organisations, Members of this House and others.

What binds us together is the determination to do everything we need to do to keep children safe online, as built on the evidence. That is a priority. The previous Secretary of State, in issuing his statement of strategic priorities, made it clear that the first priority was safety by design. That builds on the safety by design measures within the codes, such as the safer design of algorithms to filter out harmful content from children’s feeds. On 25 July, Ofcom published its statement, setting out what it proposes to do in consequence of that statement of strategic priorities. Under the Act, it must publish further annual reviews of what action it has taken as a result of the statement of strategic priorities, including on safety by design.

We have taken action to strengthen the regulatory framework by making further offences priority offences under the Online Safety Act, reflecting the most serious and prevalent illegal content and online activity—for example, laying an SI to make cyberflashing, encouraging self-harm and the sharing of intimate images without consent priority offences under the Act.

Others have mentioned the importance of basing our decisions on good evidence of what is happening. Recognising that further research was required to improve the evidence base, the Government have commissioned a feasibility study to explore the impact of smartphones and social media use on children.