Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Digital, Culture, Media & Sport
Moved by
3: Clause 4, page 3, line 18, at end insert—
“(3A) A data centre also meets the threshold requirement in this paragraph, regardless of its rated IT load, if the Office of Communications considers that an incident affecting the data centre would be likely to have a significant impact on the economy or the day-to-day functioning of society in the United Kingdom or any part of it, having regard in particular to the data centre’s customer base and level of interconnection with essential services.”Member’s explanatory statement
The amendment seeks to add a risk-based designation criterion alongside the existing megawatt thresholds for operators of essential services.
--- Later in debate ---
Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - -

My Lords, I am very sorry that I missed the early part of that debate because I feel it might impact on some of the things I say. However, when I read the government amendments, I could not see anything in them that made the amendments unnecessary, so I will read carefully all aspects of the first group but I intend to progress with the amendments that I have tabled. I will speak to Amendments 3, 8 and 13 in my name and in the names of the noble Baronesses, Lady Harding, Lady Berger and Lady Morgan. Together, they would expand the scope of services in the Bill so that so-called “small but risky” services were included.

Amendment 3 stipulates that smaller data centres could be included if Ofcom considers that an incident affecting the data centre would have a significant impact on the economy or on the day-to-day functioning of society in the UK, taking into account the data centre’s customer base and its role supporting other essential services. Currently, data centres that are for an enterprise purpose only are covered in the Bill only if the rated IT load is 10 megawatts or greater. This is a mid-size data centre. However, there are commercial data centres that can be much smaller than this and are threatening. Perhaps most notable is a recent example from Denmark where the small cloud hosting providers, CloudNordic and AzeroCloud, suffered a ransomware attack that resulted in the paralysing of all company systems and the servers being shut down. Their hundreds of customers lost all their data, and it was unrecoverable. “Customers” is a bland word, but imagine that you are a hospital treating patients, a university conducting years of scientific research or a small business with its entire operation at stake: the loss of your data risks lost livelihoods, and possibly even lives.

Meanwhile, many experts are calling for an expansion of smaller data centres. They are less taxing on the natural and local environment, more embedded in local communities and are in contrast to mid and large centres, whose environmental costs hit local communities, use up water, increase the strain on the grid, are possibly noisy and ugly and favour the hyperscale business models of big tech. If smaller data centres are an attractive alternative to unpopular larger ones, it is even more essential that they are in scope of these regulations.

Amendment 8 stipulates that a relevant digital service provider would be included if the ICO or AISI determines that the provision of a service poses a risk to public safety, national security or the security of network and information systems. Amendment 3 would do something similar for relevant managed service providers, with the ICO establishing whether a managed service provider poses a risk. Currently, services are excluded if they have fewer than 50 employees and a turnover equivalent to below £8.5 million—it is actually given in euros. I anticipate that the reasoning is not wanting to impose unnecessary burdens on small and micro-sized businesses with fewer employees and resources. I recognise that that is as a concern, but it is equally important to understand that small businesses of all kinds, including those that host critical services and infrastructure in the UK, are regularly victims of cyber attacks. The Government’s own Cyber Security Breaches Survey for 2025-26 records that 42% of micro-sized business and 46% of small businesses in the UK have been the target of cyber attacks. It is simply not the case that small means that risks are contained. The Government’s own figures show that, of the more than 100,000 UK tech companies, 95% have fewer than 50 employees.

These amendments would replicate the rationale of amendments to the then Online Safety Bill from the noble Baroness, Lady Morgan, on Report. I know that she would have liked to be here to speak to them, but she is unable to be here today. Her amendments stipulated that services under the Online Safety Bill should be categorised by risk or size. I will not rehearse what noble Lords have heard many times, but the lesson of that Bill is that the Government of the day got it wrong, as did the regulator. In the connected world, a small component of a global system can cause havoc.

When this Bill first entered the other place, I went to a briefing by Politico where its four experts spoke repeatedly about how narrow the Bill was and how focused it was on providing for a small subset of issues relating to cyber security and safety with a vision of hyperscale vendors. They were a combination of exasperated and incredulous that, even as we saw the increasing cost to the economy, the damage to businesses caught up in it and the devastation to individuals, as well as what all agreed was a national security threat, the Government had not sought to offer a vision for how all these might be protected. When it came to questions, the first was to ask why the experts thought the Government had been so unambitious. The answer was unedifying: to prevent the Lords hijacking the Bill.

I hope that the new Administration who start today have moved on and that we will have a more collegiate approach. I have read all the amendments currently laid, including the ones in this group, and in almost all cases they seek to do what is the stated intention of the Bill: to make the country more resilient. In the world of cyber security, size is not a proxy for risk; it is much more complex than that. The amendments in my name and those of others seek to ensure that we learn lessons from the Online Safety Act. I beg to move.

Baroness Harding of Winscombe Portrait Baroness Harding of Winscombe (Con)
- Hansard - - - Excerpts

My Lords, I support Amendments 3, 8 and 13 in the name of the noble Baroness, Lady Kidron, to which I have added my name. I will not repeat too much all her comments on our learning from the Online Safety Act that small does not mean low risk. However, it should not be a surprise that those of us who championed that amendment to the then Online Safety Bill have again put our names to it. We have learned the hard way that, in online safety, risk can come from the smallest providers.

I have learned it personally. I retired from TalkTalk 10 years ago and I remember, what must have been 11 years ago—I promise this is not a cyber attack story—a mapping exercise across all the telcos, mobile and fixed, looking at our even then incredibly complex data centre networks across Europe. I am sure this has all changed and is much more complex, but I remember discovering, as a result of that exercise, that all of us were routing traffic through the same small data centre in central Europe and none of us was aware that we were doing so. These networks are expanding so fast and data centres and managed service providers are growing so fast that it is impossible for people to retain perfect knowledge 100% of the time, so a small provider really can be a node that brings down the whole network. It is not just in child safety that we have learned that small can mean very risky; it is also the case in the world of physical digital infrastructure, which we have known for some time in telecoms. That is why these amendments are so important.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank the noble Baroness, Lady Kidron, for her introduction and my noble friend Lady Harding for setting out the motivation for ensuring that we have the right balance of risk and regulation here. The amendments from the noble Baroness, Lady Kidron, seek to allow for the designation of systemically important data centres, RDSPs and RMSPs which do not already meet the threshold. The Government have considered this issue in the development of the regime and have taken an approach which reflects the markets of the various digital services in scope of the regime.

In respect of data centres, the Government agree that a data centre’s significance is not determined solely by size and recognise that smaller facilities may play an important role in supporting the economy and wider society. For that reason, the Bill already provides a route for such operators to be brought into scope outside the standard threshold requirements. The competent authority, Ofcom, has powers to gather information from operators and assess whether designation is appropriate in individual cases.

However, with respect to the RDSP and RMSP measures, the existing small and micro-enterprise exclusions have been designed to be proportionate and avoid imposing undue burden on entities with limited resources and market coverage, while focusing on providers whose disruption would have significant societal impact or economic risk to the UK. Although many small and micro-enterprises operate in the digital and managed services market, large MSPs hold a disproportionate share of market value. The largest MSPs account for 86% of revenue in the UK, despite representing just 4% of all MSPs. It is the disruption of these services that is most likely to cause significant harm to the UK.

The Bill also has measures in place to bring small or micro digital or managed service providers into the scope of the Bill if they are considered to provide a critical service to a regulated entity. If these entities meet the designation criteria, they can be designated as a critical supplier and be subject to mandatory cyber security and resilience requirements. I assure the noble Baroness that I recognise the discrepancy between these two regimes and her concerns, and I am content to explore this, and the points made by the noble Lord, Lord Markham, further, and to provide a more detailed response on Report.

On the issue raised by the noble Lord, Lord Clement-Jones, for his amendment which would amend the relevant managed services definition by excluding specific services, I take seriously the importance of providing clear definitions in the Bill. That is why the definition in the Bill is designed to capture services posing a risk to the UK economy and society, both today and beyond. I reassure the noble Lord that the relevant managed services that would be excluded by this amendment are already likely to be excluded by virtue of them not meeting the definition in the Bill. However, we cannot and should not list every service not in scope or we risk providing a definition that quickly becomes outdated and fails to accommodate new trends in both technology and services—a point frequently made by noble Lords in respect of the development of technology and online services. The Bill requires a delicate balance to ensure that the definition includes the right level of detail. The regulator, the Information Commission, will provide guidance on the application of the regulations prior to commencement of the RMSP provisions, including elements of the RMSP definitions.

On the point raised by the noble Lord, Lord Clement-Jones, on privileged access, MSPs pose risks because they provide ongoing management of customers’ IT services and often have deep and broad access to the networks, infrastructure and data those customers rely on, so the Bill focuses on any connection or access to network and information systems relied on by the customer rather than only access whether privileged or administrative. That is because requiring privileged access would narrow the definition and include some firms we intend to regulate as providers composed of cyber risks through non-privileged access without holding elevated administrative rights. For that reason, I caution against adding these exclusions to the definition of a managed service.

Finally, Amendments 4 and 5 are tabled in my name. They are targeted and technical amendments that improve the clarity and consistency of the Bill by strengthening the definition of load control in Clause 6. They clarify that the relevant activity must be carried out for system balancing purposes. System balancing purposes are defined as purposes which contribute to the,

“balancing, flexibility, security or stability of the electricity system”.

The policy intention has not changed. This amendment simply provides greater clarity about the activities the regime is intended to capture. It will reduce the risk of misinterpretation, provide greater certainty for industry and regulators and support effective regulatory oversight. This will ensure that the regime captures the activities intended to fall within scope and reduces the risk of inadvertently capturing activities that are not relevant to the operation and resilience of the electricity system.

Regarding the questions about the further scope of the Bill in respect of local government and the Government’s cyber action plan, I believe we will return to that in later groups.

Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - -

I am very grateful to the Minister for suggesting that there will be some consideration of the gap, as she put it, and I look forward to that. I want to raise one thing, which is that I was very struck by her reference to a small number of companies having 86% of the market. In a sector that is dominated by the concentration of power in very small numbers of companies owning many pieces of the stack, is she not worried that making those companies protected and safe and the smaller ones not may further serve to increase the concentration of power and market concentration? Is that not a problem for the future?

Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

The purpose of the Cyber Security and Resilience (Network and information Systems) Bill is to further enhance the scope and powers we have to protect essential services connected through network and information services. The market as it exists today is as I described. What is within the scope is not the totality of our approach to supporting the further cyber resilience of the UK economy. That is why, for example, we have CRCs locally to support SMEs so that whatever size they are, they can get assistance on the best cyber protection they can take. It is why we have Cyber Essentials and why the NCSC provides advice—all that the economy needs to take appropriate action to be secure. That is one aspect. The second aspect is that small and micro digital managed service providers are in scope of the Bill if they are considered to provide a critical service to a regulated entity, so even very small entities could possibly be in scope if they are so designated.

The last point I shall make—and I am sure we will come on to this further when we come to talk about AI—is that the Government are doing a huge amount in regulation and funding through public finance institutions to support the development of UK technology companies and UK innovators and to ensure that they have the right procurement contracts with the public sector so that they can grow and so that the entirety of our companies can benefit from the best global managed service providers and the best UK managed service providers.

--- Later in debate ---
Moved by
6: Clause 7, page 6, line 31, after “engine” insert “, an AI product or service”
Member’s explanatory statement
This amendment probes whether the definition of “relevant digital service” being inserted into the NIS Regulations by this bill includes generative-AI models, including but not limited to AI agents and large language models.
Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - -

My Lords, in moving this amendment, I shall speak also to Amendment 75 in my name; I thank those noble Lords who have added their names in support. I was glad to add my name to Amendments 12, 85 and 86 in the name of the noble Lord, Lord Tarassenko, and Amendment 84 in the name of the noble Lord, Lord Clement-Jones.

At the heart of these amendments is the place of artificial intelligence in the Bill. This concern was powerfully raised by noble Lords at Second Reading and repeatedly raised by colleagues from all sides in the other place—as well as, I rather suspect, earlier in this Session. Amendment 6 is a probing amendment. It seeks to understand whether AI products and services are categorised as relevant digital services and, therefore, whether providers of AI products and services will be subject to the same duties in the Bill as other providers of relevant digital services, such as online marketplaces and search engines.

The reason I raise this and wish to have clarification is that, in the NIS regulations, the definition of an online search engine is

“a digital service that allows users to perform searches of, in principle, all websites or websites in a particular language on the basis of a query on any subject in the form of a keyword, phrase or other input, and returns links in which information related to the requested content can be found”.

This sounds a lot like a definition that could cover many of the LLMs and AI agents, so I ask the Minister whether AI services are already covered under the categorisation of online search engines or absolutely not. I would also like her to confirm whether, if an AI service did not offer links or was restricted to a particular subject matter but had all these other features, it would automatically fall out of the regime—that is, whether some are covered and some are not.

At Second Reading in the other place, the Minister said—the Minister here just gave this answer, I believe—that the Bill enables the Secretary of State to require an organisation using AI

“to cease using and isolate an AI model”—[Official Report, Commons, 16/6/26; col. 779.]

but suggested that those powers are “a backstop” and do not focus on the safety of AI products systematically. I find myself confused because, on the one hand, it seems that the definition could include them but, on the other, it seems that there may be reasons why some might be out of scope. It appears that AI is not properly considered proactively but, if there is a disaster, the Secretary of State can do something. When the Minister speaks, I would be grateful if she could answer those two questions directly. This is a probing amendment, as I say, and it would be helpful, in the course of considering the Bill, to understand that categorically.

Amendment 75 would establish a series of red lines for AI products and services classified as relevant digital services. These red lines have excellent parentage; they reflect the work of Professor Stuart Russell and are signed up to by some of the most eminent AI founders and professionals around the globe. They also reflect the global call for AI red lines launched during the United Nations General Assembly.

In short, they provide that AI services must not be capable of evading human oversight, shutdown or control, nor be able to autonomously self-replicate, self-improve or acquire compute. They provide that AI providers would be prohibited from creating systems capable of autonomously conducting sophisticated attacks on critical infrastructure, that support terrorists and hostile states in attacks on such critical infrastructure, or that can deceive or manipulate populations at scale. They also prevent capabilities that relate to the availability, authenticity, integrity or confidentiality of stored or processed data, which follows the exact language of the Bill. Proposed new subsection (3) of the amendment would require AISI to ensure that these red lines are adhered to. This is an essential amendment and I believe the UK is singularly well placed to introduce it. There is increasing evidence and understanding of the risks, and both the public and experts are calling for action.

I was going to quote many people, but will say just that, a couple of weeks ago, I spoke to Jonathan Hall KC, the Independent Reviewer of Terrorism Legislation and the Independent Reviewer of State Threats Legislation. He is among the many people who have warned publicly about the risk of AI used to support terrorist action and subvert information in the public domain. Recent polling has found that 85% of the UK public would like this to happen; they would like red lines.

I fully support Amendments 12, 85 and 86 in the name of noble Lord, Lord Tarassenko, which seek to establish a greater role for AISI in these regulations and to give it statutory powers. I leave it to the noble Lord to explain the amendments in full, which I am sure he will do much better than me, except to say that, in July, some other noble Lords and I were briefed by one of the frontier companies, which gleefully said that it worked to a set of ethical standards. However, when pressed—repeatedly, by noble Lords—the company admitted that it wrote, interpreted and managed those standards itself and was free to abandon them in an instant. Have we not learned from countless experiences before, in online safety, privacy and AI itself, that allowing tech companies to set and mark their own homework endangers the public and our national security?

Amendment 92 from the noble Lord, Lord Clement-Jones, has a similar aim to that of the noble Lord, Lord Tarassenko. I hope that, during the passage of the Bill, the Government find a unifying approach with both noble Lords to back AISI in its functions and separate it from political control. The AISI organisation is the envy of the world, with the capability to oversee a regime for robustly and fairly ensuring that AI is trusted. I beg to move.

Lord Tarassenko Portrait Lord Tarassenko (CB)
- Hansard - - - Excerpts

My Lords, I will speak to Amendments 12, 85 and 86 in my name, and in support of Amendment 6 in the name of the noble Baroness, Lady Kidron, to which I have also added my name.

At Second Reading, several noble Lords spoke about the AI-shaped hole in the Bill. I shall not repeat their arguments but will present other evidence, including incidents that have been reported since Second Reading in mid-July, on why this AI-shaped hole needs to be filled. Three serious incidents have been reported since just mid-July: one involving OpenAI’s GPT-5.6 Sol and an unreleased model, one involving Anthropic’s Claude models and one involving multiple AI agents during a cyber evaluation by the AI Security Institute—AISI.

AI models, within an appropriate harness, are now capable of operating as autonomous agents. They can break a complex command—for example, “Find a vulnerability in this network”—into sequential tasks, adjust strategy dynamically and execute without further human intervention. These AI agents are built with tool-use capabilities, enabling them to plan but also execute and adapt multistep workflows autonomously.

More details have emerged of the Hugging Face hack which occurred on 11 July, just before the Second Reading debate. A report published last week by three researchers from METR and Redwood Research reveals the scale of the incident. Around 1,200 agents in separate sandboxes collaborated on a message board in an attempt to cheat on a task on which they were being evaluated, with around 700 participating in the actual cyber attack on the open source AI platform Hugging Face. As we know, this is the incident that prompted Anthropic to check whether its own AI agents with Claude models at the core of the harness had carried out similar cyber attacks; this check uncovered three cases that were then reported to the affected companies.

Finally, at the beginning of August, AISI published an incident report detailing unsanctioned online actions by AI agents doing cyber capability evaluation tests conducted at the end of July. Out of 122 evaluation runs carried out by AISI across seven frontier models, 10 runs produced 19 distinct unsanctioned actions on the live internet. The report highlighted behaviours such as cross-agent co-ordination and out-of-bounds target pursuit.

However, it is not just frontier AI models that we should worry about. The cyber capabilities of leading open-weight models, such as GLM-5.2 and DeepSeek V4 Pro, are now reckoned to be only four to seven months behind those of the closed-source frontier models of US big tech. In many ways, these open-weight models carry even greater risks. Once the models have been released, safeguards can be removed and copies can be run on private systems beyond monitoring. Cyber attackers can then fine-tune the weights for malicious purposes, perform ablation on safety refusal directions within the model’s neural network and strip out any safety layers. The open-weight model then becomes an uncensored agent engine that will execute malicious instructions without refusal. It will process malicious requests as neutrally as if they were standard requests. We are not far away from cyber attacks from unknown AI agents based on modified open-weight models.

It is now beyond any doubt that autonomous AI agents running frontier AI models, both closed source and open weight, are or will soon be capable of co-ordinating complex cyber attacks. It is therefore not surprising that a group of 100 companies, including Google, Microsoft, Anthropic and OpenAI, as well as UK-based companies such as Arm, BT, PwC and KPMG, signed an open letter last week warning that cyber attacks orchestrated by frontier AI models will become more widespread and more sophisticated in a matter of months. The letter outlines three main principles or actions.

The Minister conceded at the end of Second Reading that

“AI capabilities are moving very fast”,


but asserted that

“strong cyber fundamentals still work”.—[Official Report, 14/7/26; col. 620.]

This is true, but the first principle listed in the letter is that existing security practices will no longer be sufficient to protect against cyber attacks orchestrated by frontier AI agents. Amendment 6 would therefore require the definition of “relevant digital service” being inserted into the NIS regulations by this Bill to include generative AI models, including large language models and AI agents. They are fast becoming the main factor in the cyber security arms race.

--- Later in debate ---
Baroness Lloyd of Effra Portrait Baroness Lloyd of Effra (Lab)
- Hansard - - - Excerpts

I thank noble Lords for their amendments, and I recognise the concerns that have been expressed. Technology is evolving at a rapid pace, and it is important that we harness the benefits and, equally, protect against the risks it may pose.

The noble Lord, Lord Holmes of Richmond, asked about the approach that we take. We understand how quickly technology is evolving, and it is important that we have a flexible and future-proof approach. If we limit ourselves to specific technologies, we will not capture new developments. For instance, when the NIS regulations were introduced in 2018, we could not have predicted the role that AI and quantum would play in cyber. That is why the Bill takes an “all hazards, all threats, all technologies” approach. This requires regulated entities to manage all the risks relevant to their network and information systems. For example, if AI forms a part of the system that the essential service relies on—for example, in the provision of drinking water—that entity must assess and mitigate the risks it poses.

More generally, the Government take the concerns very seriously. The UK is taking a leading role with our approach to AI security. I will set out my response to each amendment in turn, but while we do not consider the amendments proposed to be the right approach, I reassure noble Lords that the Government are exploring whether additional targeted interventions may be needed in future to address the most significant AI-related national security risks. As the Government’s thinking is at an early stage, I would be open to future engagement with noble Lords on potential options. Any future approach would need to have carefully designed measures, with the evidence base proportionate to and targeted at the risks in question, while minimising unintended impacts on growth, innovation and the operation of critical services.

I turn to the amendments. The intention of the NIS regime is to require organisations to protect themselves from risks that could compromise their network and information systems, which could include a cyber attack, a natural disaster or even human error. That protection would be appropriate and proportionate to the risks faced by those organisations, including state-of-the-art technology such as AI. I reassure noble Lords that this would include relevant risks from AI embedded within the systems of regulated organisations. To take one example, healthcare providers in scope of the regime would be required to manage risks associated with the AI products they use to provide their services. This is because essential services in scope must look at, and work to mitigate, risks posed to their network and information systems.

As AI is increasingly becoming embedded across the economy, we will keep its impact on the regulatory landscape under review. The Bill is focused on the cyber security and resilience of network and information systems; broader questions about the regulation of AI systems are more appropriately addressed through separate discussions, for example on online safety.

Bringing providers of AI services—those companies at the cutting edge of frontier AI development—and their products into the scope of the NIS regime, which Amendment 6 seeks to do, would not address the harms that can be posed by some AI products and services. Specifically, it would not prevent their misuse by hostile actors. Instead, the Government are already taking firm action in more appropriate ways, which also speaks to the concerns that Amendment 75 would aim to address and which the noble Baroness, Lady Foster, asked about.

First, the UK AI Security Institute, as noble Lords are well aware, is world leading in its research on advanced AI capabilities. AISI was set up to build a rigorous scientific understanding of the capabilities of the most advanced AI systems and the risks they pose. It works with developers to strengthen security before models are released and ground policy decisions in evidence rather than speculation, especially as they relate to national security matters.

Secondly, the UK Government are taking a leading role in addressing these risks in both the domestic and international setting. As the noble Lord, Lord Tarassenko, and others have set out, including the noble Viscount, Lord Camrose, it is critical that this approach has global impact. Our AI cyber security code of practice has formed the basis of the world’s first global standard, EN 304 223, which sets baseline security requirements for developers and deployers across the AI life cycle. This demonstrates our global leadership and commitment to shaping international technical standards, which go wider than some of the issues raised in this Bill.

Underpinning all this is a simple but powerful message, which was set out in a joint Five Eyes statement in June. It recommended that as AI capabilities evolve all industry, including vendors, should seek to step up their cyber defences. This is a clear call to action for all organisations, including the Government, and a reminder that the key tenets of cyber hygiene still stand strong. That is also why we are committed to building a national-scale AI-enabled cyber defence for the UK, Cyber Shield. It will scan UK systems continuously to discover vulnerabilities and apply national-level mitigations.

The noble Baroness, Lady Kidron, tabled Amendment 75, which sets out several red lines on AI capabilities that would enable an AI system to facilitate significant risks to the UK. The noble Baroness will recognise that AI is one of many technologies that can be used for beneficial and harmful purposes, as she has mentioned on previous occasions. In addition to the example of chemistry questions, banking services can be used to connect families but might also be used to finance illegal terrorist activities. Equally, while powerful AI capabilities can be used by malicious actors to cause harm to the UK, they might also be used by the national security community to defend the UK and by UK organisations and companies to protect themselves from harm. It is therefore not in the UK’s national interest to restrict UK organisations and the public sector accessing powerful AI capabilities, especially given the global nature of AI risks. It is also unlikely that AISI would be able to give conclusive assurances regarding AI models in the way envisaged in this amendment. Testing shows what a model can do, but not conclusively what it cannot, as the noble Viscount, Lord Camrose, pointed out.

The noble Lord, Lord Tarassenko, tabled Amendment 12, which would require RDSPs to follow guidance issued by the AI Security Institute. For the reasons I set out on Amendment 6 and because it is not AISI’s role to provide guidance of this nature, I do not think it would be appropriate. I will set out more detail on AISI’s role later in my response.

On Amendment 84, tabled by the noble Lord, Lord Clement-Jones, we have chosen to go further than our EU counterparts and the NIS2 regime to respond to these risks by bringing forward powers in the Bill to direct regulated entities if there is a national security risk in relation to their network and information system. This may be used, for instance, to require a regulated entity to cease using and isolate an AI model.

We believe this is a more proportionate and effective response, as data centres operate in highly complex ecosystems and AI systems are often distributed across different data centres and jurisdictions. It is much less desirable to direct multiple data centres to shut down, with the impact this could have on services that rely on them, than to direct them to cease using an AI model. This is important, as our economic security will grow as UK companies grow as they increase AI adoption as we develop our domestic capabilities and attract global talent, underpinned by our data centre and digital infrastructure.

I refer to my introductory remarks on exploring further targeted interventions. This includes examining whether proportionate containment powers could provide a more effective and targeted response, including powers to restrict access to specific AI systems where necessary to prevent or mitigate serious harm. The amendment tabled by the noble Lord, Lord Clement-Jones, also seeks a regular report on AI security. In December 2025, the AI Security Institute published Frontier Al Trends Report, which sets out high-level trends on AI progress based on two years of government-led testing of leading models.

Amendments 85, 86, 92 and 98, tabled by the noble Lords, Lord Tarassenko and Lord Clement-Jones, are a testament to AISI’s leading role and expertise. They seek to provide AISI with powers to address potential risks arising from frontier AI models. I have already set out the important role that AISI plays building a rigorous scientific understanding of the capabilities of the most advanced AI systems and the risks they pose, working with developers to strengthen security before models are released and grounding policy decisions in evidence rather than speculation. These amendments would give AISI a role that it was not designed to fulfil. AISI’s focus on frontier technology and trusted relationships with the world’s leading AI labs allow it to keep pace with the fast-moving technology, thereby providing critical awareness of the most novel and serious AI risks. This amendment would undermine the voluntary collaboration on which AISI operates. A regulatory role for AISI is therefore the wrong answer, but the Government remain committed to ensuring that AISI is equipped to fulfil its vital role and will continue to keep the House updated on its work as appropriate.

As I have just set out, such amendments raise a real risk of placing barriers on AI adoption and deployment in the UK. Due to the scope of the Bill, the amendments cannot address wider AI harms or cyber security in the wider economy. I share concerns about the potential of hostile actors using frontier AI models against our essential services. Placing these restrictions on their deployment in the UK, as amended, would not be effective.

I shall respond to the direct question asked by the noble Baroness, Lady Kidron, on large language models. Large language models are not typically considered online search engines in respect of the CSRB. While some LLMs can be seen to share similar characteristics and may utilise online search engines, their functions tend to be much broader.

I hope that I have addressed the points raised—well, I hope that I have at least touched on all the points raised today. On the points made on changes to the Government, I very well recall the numerous discussions that we have had on AI over the past few months and continue to be the point of continuity on them. As I have said, the Government will be happy to engage with noble Lords as options are being considered. We always stand ready to protect our national and economic security.

Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - -

If I have understood what the Minister said, the NHS must protect itself, but the AI that is attacking it has no duties or obligations under the Bill to check itself before it is used in those ways. That is what I think is the Government’s position, and I would be grateful, when she responds, if she could answer that.

I also want to say two other things. One is that I think these issues will come back on Report, so I would be grateful for some proper discussion before then, so that we can see whether we come to a certain place. I do not have it at my fingertips—I may be helped by one of my colleagues—the amount of search that now happens through AI, but it is almost ludicrous to suggest that LLMs are not search. It is deliberate that I got that answer.

Lord Tarassenko Portrait Lord Tarassenko (CB)
- Hansard - - - Excerpts

It is 5 trillion a year.

Baroness Kidron Portrait Baroness Kidron (CB)
- Hansard - -

Five trillion, a year. I am grateful to the Minister for answering my question because, very often, that does not happen. That really points at a problem.