Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Science, Innovation & Technology
Baroness Kidron Portrait Baroness Kidron (CB)
- View Speech - Hansard - -

My Lords, there is a risk of agreement breaking out at this juncture. I too very much welcome the cyber security Bill and agree with others who have raised the omissions. There is nothing for the private sector and nothing on local authorities. It focuses on the size of service provider rather than risk and, in doing so, fails to learn from the battles during the Online Safety Act which established beyond doubt that the size of the company does not equate to the risk it poses in any system. There is also no mandate for executive responsibilities, as in NIS2 in Europe. All these things feel like critical omissions but, above all, there is nothing on AI, as we have just heard. That is where I will focus my remarks.

In February, Darktrace, a cyber security firm based in Cambridge, surveyed cyber security professionals; 73% of them reported that AI-powered threats are already significantly impacting their organisations. Nine out of 10 said they needed major upgrades to their defences. Only weeks ago, the US Government instructed Anthropic to withdraw two frontier models, going from zero regulation of AI to a 100% ban within 90 minutes. This was on the understanding that it posed a national security threat, with capabilities that experts anticipate will be mirrored by other frontier models, including Chinese ones, within months. It seems extraordinarily ill advised, therefore, that AI is not front and centre of the Bill. Clearly, this is a decision rather than an omission so, when she responds, can the Minister explain why, given the scale of the cyber security threat presented by AI, the Government have chosen not to identify it and tackle it explicitly in the Bill?

The absence of AI from the Bill also means the absence of the AI Security Institute. AISI is recognised globally as world leading, yet since this Government came to power its name has been changed from “Safety” to “Security” institute. We have heard repeatedly from insiders that they have been instructed not to upset the Americans. Most recently, a decision was made to fold its societal resilience team—which dealt with things including psychological harms, child safety, environmental harms, synthetic media abuse and faults with using AI for hiring, police and credit scoring—in favour of the existential threat agenda, which frontier companies prefer to discuss because industry prefers to talk about the harms of the future rather than the ones that are here right now.

I sit on the Joint Committee on the National Security Strategy and simply cannot overstate the repeated cries from security experts for society-wide resilience and a broader definition of security, including information integrity and digital sovereignty. They understand that threats to security are structural and multifaceted and need constant oversight. Can the Minister say why we are not using this Bill to strengthen and empower AISI as an independent statutory body to ensure the safety and security of the nation and to provide a constant source of wisdom and expertise over AI across all domains, with a statutory remit that allows it to investigate the full spectrum of unsafe security risks and mandatory rules for AI safety training and reporting of security incidents directly to it?

It is easy to dismiss these issues as outside the cyber security remit, but that is not the case. I was at a conference about agentic AI last week where medical researchers showed that, in 51% of cases where a person should go to hospital, AI told them not to. This has profound consequences for the health of a nation. More chilling still, the same experts pointed out that, as AI becomes integrated with health records and prescribing systems, a malign actor or hostile state could in one fell swoop manipulate the online prescriptions of an entire nation.

Similarly, in my conversations with specialist police they have said that they are extremely worried about the way digital services are fuelling an ever-growing pipeline of extremists. Recent research by the Center for Countering Digital Hate shows that eight out of 10 chatbots are willing to plan a school shooting or an attack on a synagogue. In 2025, for the first time, automated traffic overtook human traffic online, much of it concealing its identity, leaving operators unable to distinguish benign automation from hostile traffic. This enables the mass harvesting of data used to facilitate a future cyber attack at scale. As non-human traffic climbs, our exposure to cyber attacks grows with it.

At best, the Bill is unclear how these sorts of harms impact our security and adds to the mishmash of provisions and the powers taken by the Secretary of State in several previous Bills. At worst, these issues are not covered at all. The Minister in the other place said that the Bill is “technology agnostic”. Can the Minister explain what that means in practice? AI is not simply another risk to be regulated; it changes the nature, speed and scale of cyber attacks themselves.

Two weeks ago, I and several other noble Lords received a briefing from the Institute for AI Policy and Strategy and the Centre for Long-Term Resilience. They are at the forefront of tracing emerging technologies and threats and have set out a clear strategy built around four ideas: delay, defend, detect and disrupt. They have practical proposals under each heading to improve the Bill, giving us greater oversight and transparency and narrowing and neutralising the spectrum of risk. But as it stands, the Secretary of State, as she has done on so many occasions, has taken powers herself rather than offering Parliament a coherent plan of action.

In short, the greatest omission from the Bill is that it focuses primarily on what a limited set of companies and service providers should do and too little on the resilience of the wider digital system. Over the last two years, we have seen the way in which dependencies on US tech have muted our ability to protect children and creatives and made our NHS, government data and our economy vulnerable. A truly secure cyber policy is a sovereign one which gives the Government control over key chokeholds in the system and oversight over critical infrastructure while encouraging a far greater range of providers. It is one that retains valuable data in the UK, prioritises UK tech companies and deliberately works alongside other middle powers by building relationships in which we are a rule-maker rather than a rule-taker. That, to my mind, is the real opportunity presented by this Bill. It is an opportunity yet to be realised.