(3 weeks, 5 days ago)
Lords ChamberThe Government are clear that all parties involved in the development of AI need to be in agreement about a way forward.
My Lords, we will hear from the Conservative Benches.
My Lords, the tech companies, particularly the social media companies, have argued for a decade that their technology is global and, therefore, that local regulation is not the way to do it. Yet Australia, and now, I believe, this House have realised that local regulation is the only way you get global regulation in the end. Why do we think AI is any different?
I apologise if I gave the impression that we do not think we should have any regulation relating to AI. What I was trying to get across was that we are taking an agile and context-based approach to AI regulation, which seeks to get a balance. The Government have put through a number of pieces of legislation that have AI-related elements. I will be very happy to write to the noble Baroness to outline what these are.
(1 month ago)
Grand CommitteeMy Lords, the campaign to reform the Computer Misuse Act is at least 10 years old, not just five. We—including me—have been working to try to get the provision that is contained in the amendment before us from the noble Lord, Lord Clement-Jones. I endorse every single word that he said; he put the case precisely as it needed to be set out. It is absolutely anomalous that we still have this legislation on the statute book, and we need an update to it.
We need to put our researchers, and those who help to protect us and keep us safe, in a safe position themselves, which they are not at the moment. They are subject to potential criminal prosecution, which is stupid and a great disincentive to doing what needs to be done. I very much hope that the Minister will be persuaded to take this opportunity—not to reject it—to put a clause, even if it needs modification to a form that the Government approve of, in this legislation.
My Lords, I will speak briefly in support of the amendment from the noble Lord, Lord Clement-Jones, which he so comprehensively set out. I did not mention this at Second Reading because I thought it was so self-evidently sensible that this needed to be fixed. I should know better, having been in this place for a decade, than to assume that something will happen just because it is self-evidently sensible.
The last three days in Committee have been rather depressing—my noble friend Lord Vaizey is lucky he was not here last week, although he managed to give an excellent speech that suggested he had at least been following us in Hansard or on TV—because it has been so clear that the most important issues are not being addressed in the Bill. This seems like something simple to fix. There are much bigger issues, such as the complete gaping hole of the absence of AI and the huge complexity of all the different regimes that the noble Lord, Lord Birt, set out. I am of the view that you cannot wait for the perfect, and there is a real risk that we are letting perfect be the enemy of the good. This is a straightforward and sensible proposal that I think the Government previously agreed with, but it was just not the right time. Surely, now is the time for us to do things rather than keep kicking the can down the road.
Lord Tarassenko (CB)
My Lords, one of the advantages of being in this Committee Room for these debates in Committee is that I can use Claude—I hope that is allowed—to answer the question of what the cyber security community thinks about the Computer Misuse Act. The answer comes back in bold. I will read just the paragraph in bold: “The UK cyber security community’s view is that the Computer Misuse Act 1990 is dangerously out of date and reform efforts so far do not go far enough”. I rest my case.
(1 month, 1 week ago)
Grand CommitteeMy Lords, I rise to introduce a large number of amendments, for which I apologise: Amendments 18 to 23, 25 to 31, 33 to 39, 41 to 47 and 49 and 50.
Full house. Fear not—it is not as complex as it seems. These amendments, which I have introduced, and I am grateful for the support of the noble Baroness, Lady Kidron, and my noble friend Lord Holmes of Richmond, seek to strengthen the staged reporting requirements of the four different groups of entities, so each change must be repeated four times. Because of the way in which the Bill is drafted, I was unable to introduce the change just once; I had to put in each micro phrase, hence so many amendments. The aim is to strengthen the staged reporting requirements for operators of essential services, data centres, relevant digital service providers and relevant managed service providers, so everything is multiplied by four.
The Bill, as it stands, requires only an initial report within 24 hours and a full notification within 72 hours of an incident. My amendments would add two further stages: an intermediate report which is capped at 14 days after the incident has first been notified, or sooner if the relevant regulator requires, and a final report within one month. In all four cases, the reports must be given without undue delay, so that regulated entities cannot use the timeframes as an excuse to delay until the end of the time period.
These amendments are in line with the EU’s NIS2 directive. The reason why I have introduced them, as I said at Second Reading, is that I have lived this. I absolutely understand what the fog feels like. In the first moment when you have been attacked, you do not understand what has happened: you do not know who is attacking you, you do not know what they could have stolen, you do not know where they have gone, but you do know that it is serious. That is your first report. You start to understand, 72 hours later, quite how awful it could be. That is your second report, where you start to get real data, because your teams have worked all night, usually all around the world, to try to work out where the malign actors have gone. But it is really only after a couple of weeks that you have a proper sense of what has happened.
I recognise that my experience is, obviously, 10 years old, but quite recently I had a long conversation with some of the leaders at Marks & Spencer. The thing that scared me most was that it seemed so similar to my experience 10 years ago and that this basic process is likely to be the same. So we need the requirement to properly update whatever you learn two weeks on, and then a month later the fog starts to clear and you have a proper sense of the real scale of the problem.
The reason why we need to put this in legislation is that, throughout that entire period, all the incentives for you, as a corporate leader, are not to say anything. This is the biggest corporate taboo. Your board will be encouraging you not to tell everyone, the public will be telling you not to tell everyone and there is a real risk, unless you are forced to, that you just make it easier for the blackmailers to do their work. My personal experience was of being blackmailed during this process. Obviously, at the time, there were none of these regulations. I can tell your Lordships that there were so many voices saying, “Why don’t you just shut up? You don’t know what’s going on yet. Keep quiet”. Yet if, in the fog, you share this information with regulators and with law enforcement agencies, that is how the law can prevail. It is how regulators can work out what is happening and how they can warn others who might be affected. It is how the law enforcement agencies can do their work to try to find the bad guys.
This really matters if we want the rule of law to exist in the digital world, because the incentives, even for entirely well-meaning and upstanding leaders of corporations—and government departments, dare I say—are to keep quiet. We need to put these reporting requirements in the Bill. All the amendments would do is bring our own legislation in line with the NIS2 framework. To be honest, many of these companies and these incidents are likely to need to be reported in Europe at the same time as they are in the UK. As my noble friend Lady Neville-Jones said, there is a real primacy on keeping things simple. The more we can mirror and have exactly the same reporting requirements, the easier it will be when you are in that terrifying moment when you realise that you have a serious incident. I beg to move.
Baroness Lloyd of Effra (Lab)
I think we all agree that we want a proportionate and clear regime. The noble Lord supports further incident reporting here—additional stages of incident reporting. In our impact assessment, we clearly set out the implications of that in its cost to business and so on. We will come on shortly to discuss potentially broadening the scope of incidents that would be reported. We have not been able to quantify that potential impact, as a sort of counterfactual, because we are only just discussing that.
My Lords, I have listened really carefully to the Minister and thank her for her response, but I feel that we just had a completely black and white no, which is extremely disappointing. We have had something almost worse than a black and white no, because if I heard her correctly—I will need to go back and read it again—I think she has added uncertainty, because suggesting that it is okay because regulators have the ability to ask for extra reporting is a company’s worst nightmare. What you want is really clear black and white guardrails, as we have been trying to introduce in these amendments.
I had hoped that we could have follow-up discussions between now and Report, but I feel like the door has been rather slammed in my face. I would be very keen to understand, as the noble Lord, Lord Clement-Jones, has just said, what consultation has really happened and to have a recognition that you need to consult organisations that have experienced a substantial cyber attack. If an organisation has not, then I am afraid it will want to keep quiet and will not want to report anything. It is easy to ask broad groups of organisations, “Would you like more reporting?” We all know what the answer to that would be. That is an easy consultation.
I would really value more detailed discussions with the Minister and her officials between now and Report, because I feel that we will come back to this, particularly given the support that my amendments have received from across the Committee, for which I am extremely grateful. I beg leave to withdraw the amendment.
I apologise, I stand to speak to a whole other group of amendments that suffer from the same challenge of needing to be repeated four times, which is why I suggested to the clerks that we degroup them, otherwise we would have got into a real muddle.
This group seeks to address the obligation to report incidents to customers, as the Minister referenced in her remarks earlier. Currently, the Bill requires notification only where a customer is,
“likely to be adversely affected”.
The obligation is to explain the nature of the incident and why the customer is affected. My amendments seek to broaden and deepen that duty. Customers must be notified where an incident has caused or has the potential to cause severe operational damage or financial loss, where I hope my drafting has not fallen prey to the issue that my noble friend Lady Neville-Jones, addressed in Amendment 17. If it has done so, we obviously need to address that.
The duty is extended to cover related natural or legal persons who could suffer considerable damage as a result. The regulated entities must also advise customers on what measures to take in response. Probably most importantly in this group of amendments, the entities must keep customers updated until the incident is resolved, whereas at the moment the Bill only requires them to notify customers once and then leave them hanging, waiting to find out what is going on. Together these amendments would ensure that customers are told promptly what to do and are kept informed throughout the incident until it is resolved. They also follow the NIS2 directive in requiring advice on protective measures and go a little further by making it a requirement to communicate to related persons as well.
Sadly, I have personal experience in this, not from my TalkTalk times but much more recently. I suspect anybody who is on a board or who has chaired a business has experienced this. An organisation that I chair is the customer of a managed service provider that recently experienced an incident. It did not tell us. The incident was to do with some of our staff payroll information, so it was sensitive and important. When it did tell us, it then did not keep us informed about what was going on. So I feel that pain.
I know that some noble Lords may have concerns that we do not want to create panic by endless notification. I absolutely agree. Hence my attempt to define this as severe operational damage. I would very much welcome input between now and Report if we can tighten that wording to make sure that this does not represent lots of unnecessary email alerts telling you that a system three stages back in the tech stack might have been affected. But when your customers’ data has been exposed in a cyber attack through a managed service provider, data centre or digital service that you use, it is entirely reasonable that those companies have a requirement to inform and keep you updated during the incident. That is all that these amendments seek to do. I beg to move.
My Lords, for reasons that I do not understand, I do not have my name on these amendments, given all the others from the noble Baroness that I do, but I support them. It is funny, because when I came back from holiday in August, I had no fewer than five emails from companies saying that there had been data breaches in which I was involved, and I had that exact thought—“What now? What do I do? What’s next? How serious?”—and did nothing.
Baroness Lloyd of Effra (Lab)
I thank the noble Baroness for raising important points around customer communication. As set out in the Bill, it takes forward the current duties to notify customers that the Bill places on data centres, OESs, RDSPs and RMSPs. That duty was designed to ensure that providers of key digital and data infrastructure services consider whether their customers are likely to have been adversely affected by a reported incident—whether through disruption of service, compromise of their data or exposure of their systems to cyber threats—and to notify them.
I will explain the logic in response to the point of the noble Lord, Lord Clement-Jones, about the importance of meaningful communication with customers. The reason we have drafted the Bill so that customer notification follows the 72-hour incident report is to ensure that regulated entities can focus on understanding the nature of the incident and contact customers when they are more likely to understand its potential impacts.
We have discussed the question of what an organisation might reasonably be expected to know within 24 hours of identifying an incident. The point is that customers should be communicated with in a timely manner, with sufficient information, so that they can take the necessary action. On that point, the rationale for 72 hours was to time it, for simplicity, with the 72-hour report. I am happy to consult further with the noble Baroness to explain the logic of the 72-hour and 42-hour requirement to communicate with customers, because the motivation is exactly the same: to have actionable and meaningful communication with customers.
I turn to the degree of depth of communication, the advice that can reasonably be put on regulated entities on technical measures, and what technical mitigations customers should take on their own. It is reasonable that the regulated entity should share what they know about the nature of the incident. The question about whether the regulated entity is in the right position to provide advice to customers on what mitigations they should take is both practical and technical. Would they have enough insight to have an effective understanding of the situation of the customers and a detailed understanding of the customers and their businesses in order to give effective meaningful advice in that way—or would that just be a requirement on the entities that would not have the intended impact? On that point, I am not quite persuaded that the line is drawn in the right position.
On keeping in touch, mentioned by the noble Baronesses, Lady Kidron and Lady Harding, I am happy to come back to that on Report to make sure that we have the right balance between the initial notification and the right type of customer communication.
I thank all the noble Lords who, again, have supported my long list of amendments and I thank them for their excellent contributions. It feels as if we made a very small breakthrough, for which I am extremely grateful, and I thank the Minister. I will not delay anyone any longer as we have another group of my amendments to come, but I look forward to some detailed discussions between now and Report to see if we can bring this back in a form that we are all able to support. I beg leave to withdraw the amendment.
I am sorry, it is me again. In a break with tradition, we have only one amendment in this group. That is because this amendment would insert a proposed new clause, as opposed to lots of small changes to existing clauses. Amendment 72 is in my name and, once again, I thank the noble Baroness, Lady Kidron, for adding her name.
This proposed new clause seeks to ensure that organisations regulated under the Bill must report any near misses, cyber threats or incidents currently under the thresholds as set out in the Bill that could affect their network and information systems. I am, again, mindful that it is important that this is consistent with the extremely well-made points of my noble friend Lady Neville-Jones in Amendment 17. It is welcome to have discussions on whether the wording is right, because the purpose is to get the near miss, rather than a huge deluge of meaningless reporting.
As it stands, the Bill requires regulated entities to report only what has happened, and only if it crosses a threshold based on factors such as scale, duration and the number of people affected. However, my amendments look to close the gaps in the event of, for example, an attack an organisation has stopped before it has caused major damage, but had the attack had been successful, it would have had a substantial effect across the whole industry. Other examples are where there are very credible warnings of an expected attack that does not occur, or where there is an incident that falls just below the thresholds that could still be significant.
The intention of this amendment—unlike in my other two groups, it is quite a probing amendment to see if we can work together to capture the spirit of this—is to close a reporting gap where significant incidents may not be reported simply because of the way we have drawn up the definitions in the Bill.
As in the other two groups that I have led, this follows the EU NIS2 directive, although the NIS2 directive creates a voluntary rather than a mandatory reporting provision for this. My view is that the taboo for going public on cyber attacks is so great that voluntary reporting is not the way to do this. It is better for all organisations to know the black and white of what they can do, what they should do and what they do not have to do. In some sectors, certainly the one I worked in—telecoms—there is a fair amount of voluntary sharing. But even there, there is such a taboo about speaking to your regulator about a problem that this needs to be made this mandatory rather than voluntary. Other than that, this seeks to replicate what is in the EU NIS2 directives. With that—I think noble Lords have probably heard enough of me—I beg to move.
My Lords, I support Amendment 72 and I have signed it. I recognise the probing nature of this, but I also recognise the problem it seeks to address. The knowledge that a cyber threat or cyber attack has failed may be incredibly important intelligence because, on the whole, someone trying to create a cyber threat will not retire after the first time that it did not work out; they will try somewhere else, so the intelligence element of this is so crucial.
Some of the people in cyber security talk about seven stages of cyber attack. The first stage is reconnaissance: you are just having a look round and trying to identify vulnerabilities. The second stage is weaponisation: you are developing the means to target that weakness, which can be as simple as an email. It is not until the third stage that the attack begins. But there are still three or four more stages, each of which can provide a barrier and each of which can be the place at which the attack stops. It is not uncommon for attackers to carry out multiple attempts to find or exploit a vulnerability, or indeed to do a small-scale attack in order to then do something larger down the line. In all these cases, there is something absolutely critical for the regulator and possibly the enforcement community to know.
Baroness Lloyd of Effra (Lab)
My Lords, I thank the noble Baroness for raising this question about the requirement for regulated entities to report cyber threats, near misses and sub-threshold incidents within a 72-hour deadline.
I turn first to the question of voluntary reporting, which we touched on a little in the context of discussing the industry groupings on Tuesday and the trust groups that exist and are often facilitated by the NCSC. These are incredibly valuable groups. We absolutely encourage voluntary reporting, whether through those groups or other industry bodies. There is a question about whether putting such groups and mechanisms on a statutory footing helps or hinders that objective, because we need to engender the confidence to share information, as the noble Baroness and others mentioned. There is a question about whether that is within the regulatory perimeter, as it were, and whether it encourages that or not. I am happy to come back to that on Report.
I turn to the question of reporting sub-threshold incidents. The amendment concerns incidents that have been successfully contained or have proved ineffective, incidents that fall somewhere below the current reporting thresholds and any potential circumstance or event that could, if it occurred, affect a regulated entity’s systems or the users of a service provided through these systems. We discussed that in the context of data centres. Let me answer the question from the noble Baroness, Lady Kidron. In the discussion on data centres, I was speaking about near misses. We made the point highlighted by the noble Baroness, Lady Neville-Jones: near misses and those types of incidents would be captured for data centres, given the particular role they play in our digital infrastructure.
The extension of similar requirements—although, as we read it, they are much broader requirements—to all regulated entities would increase regulatory reporting very significantly. The noble Baroness, Lady Neville-Jones, made the point right at the beginning—although it could have possibly been someone else—about the ability of our regulators to effectively utilise the threat intelligence and manage it so that it can be conveyed into actionable advice and trend data. These are the considerations that we take.
Another consideration is that the entities that have more sophisticated surveillance and mitigations may be able to identify attacks more effectively. We would not want to set up a situation where there were any perverse incentives in the system for those who have very adept surveillance and assessments away from reporting or developing that.
Even though I heard very clearly that the motivation is that the amendment is just to catch to those incidents that just fall below, our reading of it is that it would be much wider, and it may indeed have some other effects. At this stage, I would not support the amendment as drafted.
It was my suggestion to break up these amendments into different groups, otherwise we would have had about 100 amendments in one group. There is an awful lot of overlap in the discussion on this group in particular and Amendment 17 in the name of my noble friend Lady Neville-Jones. Would the Minister commit to having a joint meeting, where we could try to work this through together? I think we share a common goal of wanting to give as much relevant, immediate and up-to-date intelligence to the network as possible, without overwhelming, and recognising that, as the noble Lord, Lord Clement-Jones, said, time is absolutely everything in these cyber attacks. If we could discuss that together rather than separately, that would be extremely valuable.
Baroness Lloyd of Effra (Lab)
That would indeed be very valuable to discuss the questions around definition, scope, coverage, timeliness and impact on potential entities—sorry, I have just expanded our agenda.
I have heard very clearly the willingness to discuss and collaborate from the Minister, which is extremely welcome, as were the contributions from all noble Lords. If the last hour and half has shown anything, it is that there is a genuine cross-Committee desire to work—this is what the House does at its best—to genuinely improve, with a shared goal of a piece of legislation that the country will benefit from if we can get it right. I beg leave to withdraw the amendment.
My Lords, I also support Amendments 74 and 167. My experience is that boards that tell you that their cyber security is really good are the ones you should be most worried about. Boards that are really worried about it and can tell you where they think they are exposed might be in a slightly better place. There are too many organisations that will tell you that they are fine. Boards that are not doing what is set out in Amendment 167 are in trouble. It is entirely appropriate, and I fully support that amendment.
On Amendment 74, I would just like to draw a thread between the financial services senior management regime, what we have learned in the Online Safety Act and Tuesday’s debate about whether frontier AI models are included in the scope of the Bill. We have learned from the financial services senior management regime that when you make individual human beings accountable, they change. There is no doubt that the senior management regime in financial services has served to move the dial on the culture in financial services, and all previous attempts have failed.
Through the Online Safety Act, we have learned that various companies—not ones regulated by this Bill—have not taken seriously fines from Ofcom and simply refused to obey. We are living through an era when the tech sector wants to believe that it is exceptional and that laws from individual countries do not apply to it. It is therefore very important that we put into the Bill liability for senior executives, precisely because of what we have learned: in a sector that is doing it, you get culture change. In other digital legislation, where we do not have this, regulators’ decisions have actively been flouted. This is even more important if the Minister were to accept the amendments we debated on Tuesday—the noble Lord, Lord Tarassenko, has arrived just in time—because I firmly believe that the single most important part of regulating AI is holding the creators of the model accountable for their actions. Given that the biggest cyber security threats we face are the actions of agentic AI, I want to be able to build the framework that enables us to hold the managers and leaders developing those models, who currently say that this has nothing to do with them, accountable for their actions. I may be stretching it a bit, but I hope that Amendment 74 would be the beginnings of a framework that would enable us to hold senior tech titans to account.
My Lords, I will speak quickly. I was just checking my records, particularly on Amendment 167. It was just under a year ago that I completed the FT board director programme, which was specifically around cyber risk for boards. In a room of around 50 people, we had a tabletop exercise on a real-life scenario about what one should do in the event of a very serious cyber crisis and cyber risk. I was struck by a number of things. In the room were people with vast waves of expertise and experience, none of whom was a technology expert. All said that no other members of their board had attended training like this. They were there because, having completed a board director programme, it piqued their interest, as it did mine, it was freely on offer and they decided to attend.
Having gone through that session, we covered things such as the regulatory experience, issues around how to challenge management in the event of one of these incidents, how you need to test organisational resilience, how you need to look at the risks involved, and how to respond decisively and to have the expertise and understanding to do so. It was very clear to me, even during that half-day exercise, that that training was not sufficient for me as a board director and member to be able to fulfil that role.
Having gone through that experience, I think for many reasons that this amendment is so important to ensure that boards across this country—be they private boards, FTSE boards or boards of regulated companies—can do their jobs effectively. In this world, which is extending—I echo the points made about AI—it is even more imperative that we have this amendment to ensure that boards are able to fulfil their roles effectively.
(1 month, 1 week ago)
Grand CommitteeMy Lords, I think that this is profoundly unsatisfactory. It is not good parliamentary procedure to table so many amendments radically different from anything that we have seen before, which I, for one, have seen only at the last minute, so to speak—I have read them, but I will not claim to have studied them. I do not altogether know what I think, but I readily accept that the noble Lord, Lord Clement-Jones, has had a chance to scrutinise them in a lot more detail than I have.
I do not have anything substantial to say, but I would like to ask the Minister a question. Manifestly, there is a national security risk, which we would all recognise, and we all recognise that something needs to be done about it. But, if this is a national security issue, perhaps the Minister could explain to us why it cannot be dealt with under existing national security procedures. I have had time to go on to the GCHQ website, where one finds an impressive and considered approach to handling different security issues of this kind called the “equities process”—I did not know about it until the weekend, but it is impressive to read. I just do not understand why you would lodge such a set of issues with DCMS rather than the Cabinet Office. DCMS seems to me completely the wrong home for identifying, weighing and working out what to do about things that have such profound ramifications. Perhaps the Minister could explain to us why existing procedures, which are well tested and, by and large, involve GCHQ with a lot of consent in other areas of government activity, cannot be applied here with the same sensitivity that GCHQ has shown on other occasions. We cannot have a meaningful discussion about this today, but I think that the Minister has to think about how we can have a meaningful discussion before we reach the next stage of the Bill.
My Lords, if I may, I will reiterate points that the noble Lord, Lord Birt, has made. A number of us are struggling to keep up. Much of what the noble Lord, Lord Clement-Jones, said made a lot of sense, but I certainly do not feel sufficiently sighted on the amendments and I would like to request from the Minister a proper briefing as soon as we possibly can. We have multiple days in Committee and I feel that we will keep going round the issue of how AI is being addressed in the Bill. At the core, we are all trying to stand on both sides of the fence: we are very nervous of these powers, which appear to have been snuck in without much scrutiny, but, on the other hand, at Second Reading many of us were clear that we want to see AI captured in the Bill. I am very much in two minds and would welcome a proper briefing from the experts.
My Lords, I thank the noble Baroness the Minister for introducing this debate and for her helpful advance briefings on these amendments. I also welcome all noble Lords back for what, I am sure, will be a productive Committee stage. It is worth noting at the start of Committee that, sadly, our cyber adversaries did not take the summer off. In July, a small power generator was attacked and, in August, an attack on Manchester Airports Group compromised the data of 8.7 million of its customers.
That said, I begin by saying that we on these Benches support the intention behind the Government’s amendments. I absolutely recognise the concerns expressed by all the other speakers thus far; procedurally, this is a very unusual way to go about it, but we support the intention. We have been calling for an increase in the scope of the Bill and for cyber security measures to be undertaken by businesses and individuals, rather than the Government, where possible. We feel that these new amendments go some way to achieving that.
However, while we support the intentions, the context around them remains challenging. The difficulty that we face when trying to scrutinise and improve this Bill—and I am sure that we will return to this—is that it essentially exists, at least for now, in a vacuum. The Government’s goals are the right ones and their intentions seem to be clear, but we lack the overall holistic framework that is so important for systemic, strategic approaches to cyber security. Perhaps when the Minister stands up she can provide an update on the publication date of the national cyber action plan because, as I said at Second Reading, a cyber Bill can stand or fall only in the context of an overall cyber defence strategy, and we need to see it.
Most evident is that this currently seems to be a Bill without a department. The amendments delegating and separating powers between the Secretary of State and the Chancellor of the Duchy of Lancaster reflect this. I am really concerned—I would appreciate some reassurance from the Minister on this—that the decision to scrap DSIT, the Department for Science, Innovation and Technology, has left this Bill in limbo. A minimum of 30 teams are being split across at least three departments, and this seriously important Bill, which we are all counting on to protect us from enemies known and unknown, is adrift between departments. At the very least, the Government should set out as soon as possible who will have lead responsibility when this Bill is passed.
I thank the Minister for her clarifying remarks on the referral schemes that her amendments introduce. As I have noted, we support the attempt to expand the scope of this Bill and give businesses the ability to be self-sufficient. That support extends to the establishment of a voluntary referral scheme. However, this new voluntary scheme needs to have a clear and accessible framework and a timeline for implementation. If it is to act as an extra layer of security outside the Government’s immediate remit, vendors must know what they are expected to report and the mechanisms for doing so. There is little use setting it up if these are not made explicit at the earliest opportunity. The consultation is welcome, but some idea as to the form the Government intend this scheme to take would be helpful, alongside an indication on timing. I hope the Minister can give more clarity in her closing remarks. If not, I hope she will be able to write to me and all Members of this Committee.
I was originally going to make the point that the mandatory referral of a vendor outside current NIS regulations will necessarily be ad hoc and that, as such, defining “qualifying transactions” would not be proper. Instead, Amendment 153 was an attempt to provide clarity for decision-making without inhibiting the Government’s ability to act. However, given that the Minister said in opening that the Government have no intention of setting up a mandatory referral scheme, we must question why they feel the need to give themselves the powers to do so. Powers should not be granted and come into existence if they are never to be used. At the very least, given that the Minister has now said that the Government would consult on the definition of a qualifying transaction before any scheme is established, the amendment should ensure as much. The Government will now have the opportunity to bring these amendments back on Report. The mandatory referral scheme should be redrafted to reflect the Minister’s statement and be conditional on the defining of qualifying transactions. I hope the Minister will agree to this.
Finally, let me make a general point about the definitions used in these amendments and throughout the Bill. The proposed criterion of being “essential to the economy” is unworkably vague. It is not an adequate representation of the different types and scales of risks. I suggest, for example, the Cyber Monitoring Centre’s five-level severity scale as a model more reflective of the grades of threats facing the United Kingdom. I am not arguing that it is necessarily the right model, but it is at least tested and quantifiable. I look forward to the Minister’s response.
My Lords, I am very sorry that I missed the early part of that debate because I feel it might impact on some of the things I say. However, when I read the government amendments, I could not see anything in them that made the amendments unnecessary, so I will read carefully all aspects of the first group but I intend to progress with the amendments that I have tabled. I will speak to Amendments 3, 8 and 13 in my name and in the names of the noble Baronesses, Lady Harding, Lady Berger and Lady Morgan. Together, they would expand the scope of services in the Bill so that so-called “small but risky” services were included.
Amendment 3 stipulates that smaller data centres could be included if Ofcom considers that an incident affecting the data centre would have a significant impact on the economy or on the day-to-day functioning of society in the UK, taking into account the data centre’s customer base and its role supporting other essential services. Currently, data centres that are for an enterprise purpose only are covered in the Bill only if the rated IT load is 10 megawatts or greater. This is a mid-size data centre. However, there are commercial data centres that can be much smaller than this and are threatening. Perhaps most notable is a recent example from Denmark where the small cloud hosting providers, CloudNordic and AzeroCloud, suffered a ransomware attack that resulted in the paralysing of all company systems and the servers being shut down. Their hundreds of customers lost all their data, and it was unrecoverable. “Customers” is a bland word, but imagine that you are a hospital treating patients, a university conducting years of scientific research or a small business with its entire operation at stake: the loss of your data risks lost livelihoods, and possibly even lives.
Meanwhile, many experts are calling for an expansion of smaller data centres. They are less taxing on the natural and local environment, more embedded in local communities and are in contrast to mid and large centres, whose environmental costs hit local communities, use up water, increase the strain on the grid, are possibly noisy and ugly and favour the hyperscale business models of big tech. If smaller data centres are an attractive alternative to unpopular larger ones, it is even more essential that they are in scope of these regulations.
Amendment 8 stipulates that a relevant digital service provider would be included if the ICO or AISI determines that the provision of a service poses a risk to public safety, national security or the security of network and information systems. Amendment 3 would do something similar for relevant managed service providers, with the ICO establishing whether a managed service provider poses a risk. Currently, services are excluded if they have fewer than 50 employees and a turnover equivalent to below £8.5 million—it is actually given in euros. I anticipate that the reasoning is not wanting to impose unnecessary burdens on small and micro-sized businesses with fewer employees and resources. I recognise that that is as a concern, but it is equally important to understand that small businesses of all kinds, including those that host critical services and infrastructure in the UK, are regularly victims of cyber attacks. The Government’s own Cyber Security Breaches Survey for 2025-26 records that 42% of micro-sized business and 46% of small businesses in the UK have been the target of cyber attacks. It is simply not the case that small means that risks are contained. The Government’s own figures show that, of the more than 100,000 UK tech companies, 95% have fewer than 50 employees.
These amendments would replicate the rationale of amendments to the then Online Safety Bill from the noble Baroness, Lady Morgan, on Report. I know that she would have liked to be here to speak to them, but she is unable to be here today. Her amendments stipulated that services under the Online Safety Bill should be categorised by risk or size. I will not rehearse what noble Lords have heard many times, but the lesson of that Bill is that the Government of the day got it wrong, as did the regulator. In the connected world, a small component of a global system can cause havoc.
When this Bill first entered the other place, I went to a briefing by Politico where its four experts spoke repeatedly about how narrow the Bill was and how focused it was on providing for a small subset of issues relating to cyber security and safety with a vision of hyperscale vendors. They were a combination of exasperated and incredulous that, even as we saw the increasing cost to the economy, the damage to businesses caught up in it and the devastation to individuals, as well as what all agreed was a national security threat, the Government had not sought to offer a vision for how all these might be protected. When it came to questions, the first was to ask why the experts thought the Government had been so unambitious. The answer was unedifying: to prevent the Lords hijacking the Bill.
I hope that the new Administration who start today have moved on and that we will have a more collegiate approach. I have read all the amendments currently laid, including the ones in this group, and in almost all cases they seek to do what is the stated intention of the Bill: to make the country more resilient. In the world of cyber security, size is not a proxy for risk; it is much more complex than that. The amendments in my name and those of others seek to ensure that we learn lessons from the Online Safety Act. I beg to move.
My Lords, I support Amendments 3, 8 and 13 in the name of the noble Baroness, Lady Kidron, to which I have added my name. I will not repeat too much all her comments on our learning from the Online Safety Act that small does not mean low risk. However, it should not be a surprise that those of us who championed that amendment to the then Online Safety Bill have again put our names to it. We have learned the hard way that, in online safety, risk can come from the smallest providers.
I have learned it personally. I retired from TalkTalk 10 years ago and I remember, what must have been 11 years ago—I promise this is not a cyber attack story—a mapping exercise across all the telcos, mobile and fixed, looking at our even then incredibly complex data centre networks across Europe. I am sure this has all changed and is much more complex, but I remember discovering, as a result of that exercise, that all of us were routing traffic through the same small data centre in central Europe and none of us was aware that we were doing so. These networks are expanding so fast and data centres and managed service providers are growing so fast that it is impossible for people to retain perfect knowledge 100% of the time, so a small provider really can be a node that brings down the whole network. It is not just in child safety that we have learned that small can mean very risky; it is also the case in the world of physical digital infrastructure, which we have known for some time in telecoms. That is why these amendments are so important.
My Lords, these amendments confront us immediately with some of the Bill’s most fundamental potential structural weaknesses—the danger of a static, arbitrary and pre-digital scope. The Government appear to have conceded this point already by tabling those infamous 65 high-risk vendor amendments in the previous group. Let us look first at Amendment 3 in the name of the noble Baroness, Lady Kidron, which I would have signed if there had been room.
As drafted, the Bill brings data centres into scope, relying entirely on rigid physical megawatt thresholds—specifically a rated IT load of 1 megawatt, or 10 megawatts for enterprise facilities. In the modern cloud ecosystem, physical power load is a crude and unreliable proxy for risk. A highly dense, interconnected facility drawing under 1 megawatt can host the critical patient records of multiple NHS trusts, emergency dispatch telemetry or core local government routing directories. If that facility is compromised, the societal and economic devastation will be catastrophic, regardless of how much electricity it pulls from the grid—the noble Baroness drew the parallels with NHS data centres.
Amendment 3 would provide the essential statutory fix. It would empower Ofcom to apply a risk-based designation that looks beyond physical power to evaluate the customer base, data sensitivity and critical interconnectivity. I listened with considerable interest and sympathy to what the noble Baronesses, Lady Kidron and Lady Harding, had to say about parallels with the Online Safety Act, which is engraved on our hearts.
My Lords, I support Amendment 75 from the noble Baroness, Lady Kidron, and Amendment 84 in the name of the noble Lord, Lord Clement-Jones, both of which I have added my name to, but I also support all the amendments in the name of the noble Lord, Lord Tarassenko, that I was not smart enough to get my name to last week.
This group of amendments demonstrates not just the AI-shaped hole in the Bill but the complete absence of an AI Bill. It worries me that in one group, of a Tuesday afternoon, no more than 25 Peers are discussing such really big and important issues. We are really letting our country down and not building on the strengths that the noble Lord, Lord Tarassenko, set out that we have in this space by not debating this properly.
The Governor of the Bank of England also sent an open letter at the weekend, from the G20 Finance Ministers’ meeting:
“Recent developments have also highlighted to me that many jurisdictions do not have the protocols in place to manage the development, release, and deployment of advanced frontier AI models, heightening risks for the financial sector and beyond”.
He was speaking as the chair of the Financial Stability Board, the global financial stability regulator. He continued:
“Taking appropriate steps to support safe and responsible model release and deployment on a global basis should in my view be a priority and would benefit all sectors of the economy”.
We should not try to shoehorn this into a cyber security Bill but we have no other choice, which is why I have added my name to these two substantial amendments. I think that both the “red line” amendment, Amendment 75, and the “last resort” amendment, Amendment 84, provide two fundamental elements of regulating AI. I expect that we will hear that it is not appropriate to do it yet, to which the question is, “When?”
In the physical world, we know that just because you can do something, it does not mean that you should. We do not allow people to design new automatic weapons and carry them around on the streets, but it really worries me that, in the AI space, we are quite happy to let people launch things and then have a cyber security Bill to deal with the consequences after the event, whereas it seems entirely logical and just basic common sense to establish what should not be allowed, which is what Amendment 75 aims to do. And if someone launches something that is causing considerable harm, we need to be able to stop it, which is what Amendment 84 would do.
The amendments from the noble Lord, Lord Tarassenko, are great amendments because they are not creating a new regulator; they would give one that is not yet an official regulator but is doing outstanding global work the legal footing and legitimacy to build on that. I view all these, individually, as very substantive improvements in our nascent approach to AI regulation, and I fear that we and our successors will look back in sorrow at our inability to grasp this particular nettle now, because I do not know who else is going to. I think we actually have an opportunity in this country to do it, and it is set out in the scope of these amendments.
My Lords, it is a pleasure to support all the amendments in this group. In one set of amendments in Committee, we have more on AI than in not just the cyber Bill but across most government legislation—past, present and, tragically, probably largely future.
As has already been mentioned and was covered, widely and rightly, at Second Reading, there is a huge gaping hole at the centre of this Bill, a silence that booms around the entire Bill, and that is all things AI. It seems unfortunate that we were told at Second Reading, and probably will be today, that the Bill is not the place for AI. Well, maybe it is not, but it certainly is in that no previous opportunities have been taken. As was mentioned, there was one line in the 2024 King’s Speech: something around frontier models with AI. There have been various other nods and winks. There was a Bill potentially ready to go at the end of autumn 2024; nothing came, and still we have nothing. So now we have a cyber Bill. It would be extraordinary if the Bill did not not only consider AI but have the thread of AI running right through it. What is behind so many of the difficulties, the clear, present and real dangers that the Minister has set out? Well, it may be said to be cyber at the front end, but AI is the grunt, brute force driving so much of this, and that is what all the amendments in this group speak to.
The noble Lord, Lord Tarassenko, was right to highlight the excellent work of AISI, but again, as we have seen with previous regulators, for want of proper action when it comes to AI, and indeed other technologies, numerous Governments have just piled on more and more requirements and obligations on various regulators, as if somehow they are going to be able to manage this. This is what we are already seeing with AISI. AISI is world-renowned and rightly respected, but it is already being asked to do an increasing number of tasks without the statutory footing or the resourcing to enable it to continue to do that at world class and at the leading edge. When the Minister comes to respond, I would be very interested if she would update the Committee on how she sees the role of AISI going forward. It is in the right position and is perfectly formed for the task, but statutory underpinning and resourcing would make such a significant difference.
If the Government fail to accept these amendments, or indeed, if they so prefer, fail to bring forward amendments of their own, we will have a very narrow and specific piece of cyber legislation. It will be good in that it is the first piece of legislation to have “Cyber” in its title—good in so far as that goes—but it is unfortunate that the legislation sees not only cyber but technology through the view, which has largely washed across from the United States, that it is all about big players, as if AI were only about these LLMs, or frontier models or whatever nomenclature one chooses. “The journey of AI has been up to this point; this is the zenith and the focus should be on these large so-called AI models.” Not a bit of it—they are but one element of a far more complex constellation.
Taking a broader view would enable the Government not only to have the right thread of AI running through the Bill but to be far more UK-focused and context rich, and it would put AI in the Bill in a way which would enable adaptability and agility going forward, rather than potentially trapping ourselves with one specific view of AI or leaving ourselves at the will of all these organisations, individuals and entities that use various AI to attack us. With no or little AI, or only euphemistic nods and winks to it, throughout the Bill, I believe we need to have a rewrite of the entire Bill. This group of amendments is a very good start in that direction.