(1 week, 4 days ago)
Lords ChamberMy Lords, I am grateful for the opportunity to take part in this debate, and I add to the plaudits directed at the noble Baroness, Lady Kidron, who has prosecuted her agenda on digital safety and digital rights for more than a decade with acute skill and has certainly moved the dial on many occasions. May I also say how pleased I am that the Minister has survived the reshuffle cull? As she knows, I had a small desire that she would move to the environment department, so that we could refer to her as Baroness Lloyd of Effra of Defra, but we will have to wait. And may I say how sad I am that the noble Baroness, Lady Chapman, has left the Government? She was an absolutely excellent Minister. I declare my interest as an adviser to Digital Futures, which deploys AI engineers into companies and assesses their AI capabilities.
In November, the House of Lords Science and Tech Committee described the UK tech economy as an incubator economy. More recently, Amanda Brock from OpenUK made the point that we should not seek, when we talk about AI sovereignty, to build the whole AI tech stack by ourselves. Somewhere between those two statements lies the way forward, because we are in an interconnected world: we cannot simply ignore the rest of the world, but we must do better than be the incubator economy we have been for so many years. We must support British companies to scale and grow in this area.
Let me make five recommendations to the Government. The first is obviously to invest in our infrastructure: to invest in the UK companies that are making the chips, building the data centres and investing in the cloud. I was lucky recently to meet a British company, Fractile, which makes chips. It is a British company, based between Bristol, London and Cambridge, and it has recently raised $200 million, but it plans to stay and grow in Britain. This is exactly the kind of company that we should be supporting. As for not building the stack ourselves, let us look at our competitive advantage, of which Fractile is a good example. It is in a very niche business and has identified a need for a particular chip to support large language models which uses less energy and generates less heat. It is this kind of small infrastructure play that can reap huge dividends for the UK AI economy and is exactly what we should be looking at. We should be looking at grid connections and at building British data centres.
I also echo the earlier comment about creating a national data sovereignty platform. It is absolutely right that one of our unique advantages in this space is the access we have to the data of British citizens, which should be handled carefully but which gives us an enormous advantage, particularly in areas such as the NHS.
The third way forward is to invest as much as possible. I am delighted that the Government have set up sovereign AI—it is only £500 million, but that is still a significant sum; it is less than the €5 billion that the EU has set aside, but we are just a small island—and the fund that has been set aside for AI hardware. I hope that the Minister will reassure us that that £500 million will be fully allocated to sovereign AI and clear up some of the confusion. Her colleague said yesterday that it was moving to DBIST, but I am now told that it is moving to the Cabinet Office. Some clarity on that would be useful.
I referred earlier to my work with Digital Futures. Skills are hugely important in this area. I gather that there are predicted to be around 900,000 vacancies in the tech economy in the next few years and there was a drop in engineering apprentices of some 42% over the last few years. A focus on building the skill economy that we so vitally need to support these industries is important.
Finally, my killer point is that the best way forward would be to abolish the government department that is laser-focused on science, innovation and technology, and to scatter its constituent parts across three different departments and No. 10. That would be a masterstroke, and would allow our civil servants to spend six months trying to sort out where on earth they are meant to be going, rather than implementing policy and delivering. The Minister will not be surprised that I have descended into my default state of facetiousness. The abolition of DSIT is a huge error, considering the urgency this agenda requires and that it has taken three years to get this department up and running and to find its feet. It was a beacon of excellence in Whitehall; many people in the tech economy are sad to see its demise.
(1 week, 5 days ago)
Lords Chamber
Baroness Lloyd of Effra (Lab)
As I mentioned, the Government co-operate with others in numerous multilateral forums. We have taken forward the OECD principles in many of these and they include some of aspects to which my noble friend referred. We will continue to talk to allies about all these aspects. On risks, it is important to emphasise that we are both providing advice to companies on what measures they can take to improve their resilience and taking new powers, through the Cyber Security and Resilience (Network and Information Systems) Bill, to protect our essential services from attacks, wherever they emanate from.
My Lords, should China, or indeed any other country, wish to co-operate with us on AI policy, whom should they call? The Minister at DBIST, DCMS or the Cabinet Office, or the Prime Minister’s AI adviser at the Office for the Prime Minister and the Cabinet?
Baroness Lloyd of Effra (Lab)
We set out yesterday in our Written Ministerial Statement the allocation of responsibilities under the Government going forward. The strategy will be looked after by the Cabinet Office, which is taking the lead for AI strategy and public sector AI adoption. The Department for Business, Innovation, Science and Trade will take on responsibility for the science and innovation portfolio. As I mentioned at the beginning, it is a whole of government approach. You will find discussion of AI policy implications in every sectoral dimension, from financial services to maritime, because it is a technology that affects all areas. That is another reason why we need to look at regulation with a sector by sector approach, because it affects different sectors differently.
(2 weeks, 6 days ago)
Lords ChamberMy Lords, it is a pleasure to take part in this debate at Second Reading. I am taking part not because I was once hacked but because I was very briefly the Cyber Security Minister—which is almost as surprising as learning that I was once the Minister of Fashion.
Several themes have emerged during this very interesting debate and I always find it interesting to debate a Bill on technology, because the process of legislation is so ponderous and takes so long while digital technology moves so fast. I think there is a recurring theme, of course, that everything is digital. The other thing I always find odd when we debate legislation such as this is how we seem to continue to work in silos. AI has been mentioned so many times and it so important, but I recognise the need for legislation to provide the Government with a framework, just as the Online Safety Act has provided the Government with a framework on which we can move forward on online safety. I am less concerned about executive action and endless consultation; I want the Government to have the powers to move quickly in this important area.
As an opening remark, I will say something perhaps counterintuitive, which is that cyber security as well as being a threat is also a great opportunity. It is very important for us not to lose sight of the fact that the UK is one of the leading countries in the world for cyber security expertise. We have a cluster of great companies built around GCHQ. We must not lose sight as we debate these important issues of the fact that we have world-leading expertise that can contribute to the growth in our economy. When we talk about the defence investment plan, for example, it is important to talk about the huge opportunities we have to create great defence tech companies. Nor should we lose sight of the opportunity to create great British cyber security companies, which goes to the whole debate about potential sovereignty and giving us our own capability.
Let me begin by echoing a number of speeches about how important it is to work in lockstep with our EU partners. It is a piece of irony that this legislation emerges in effect from a European directive that we were beginning to debate when I was the Cyber Security Minister. In fact, the legislation is necessary because we can no longer transpose European legislation directly into British legislation. The noble Baroness, Lady Ludford, mentioned the GDPR, and it is a fact that Brussels can often take the lead in regulation such as this, and that big multinational companies tend to look at the biggest regulatory space in order to adhere to it. So it is important that we are mindful of how Brussels plans to proceed in this area, even if we find areas where we can be more flexible.
People have talked about our bad record in the UK on cyber security on account of cyber security attacks. I suspect that that is because we remain, I think, the most digital nation in the EU, and the English language as well provides us, weirdly, with some kind of vulnerability. But we are at the forefront of cyber security attacks, and it is important that we have the legislation and the bodies capable of responding to them.
Several themes have emerged. When I was the Cyber Security Minister, we began preparations for the National Cyber Security Centre: I thought that was incredibly important. I used to have a mantra that business in particular needed one front door that it could walk through to get the advice and expertise it needed to draw on to protect itself. We have talked constantly in this debate about 12 regulators, and I echo the calls to provide a uniform platform that can read across all the regulators, and they can add on top of that any sector- specific needs they meet.
I also recognise the calls from many noble Lords to say that this is perhaps an artificially constrained Bill, focusing on only a few vital sectors that are important to protect, instead of, as it were, seeing the whole picture and understanding, as many noble Lords have said, that cyber security pervades everywhere. There are so many ways in which we should look to protect ourselves in this age, one of which, of course, is in not losing sight of the hardware. The Minister spoke about software as a service. It is very important to remember that many of our public service providers, for example, still rely on ageing infrastructure, which provides huge vulnerabilities to cyber security attacks. I wonder whether the Government have a strategy to update much of the hardware that is still being used.
I was also interested in the remarks made about how vendors of software should be accountable. That is a very important avenue to explore: perhaps we could introduce kitemarks and audits of software providers to ensure that they are providing cyber-secure software that is as robust as it can be—again, as the noble Baroness said, we can count on the fingers of one hand the main providers of the software that is used in a vast number of businesses—and that they also work with us, as it were, to be on the front line.
It is interesting that this issue has become one of sovereignty. I am fascinated by the debate on the use of Palantir, for example. Personally, I have no problem working with Palantir. I think it provides a vital service, and I hope that the Government will be cautious in listening to the siren calls of people who say “Don’t work with these companies” simply because they disagree with the slightly bizarre views of some of their chief executives. Nevertheless, it perhaps calls for the Government to have a consistent story on this.
One thought that occurred to me during this debate was what has happened to the debate about encryption? This is a dog that no longer seems to be barking. In the last few years, we have had a vigorous debate on potential backdoors to encryption and security services being given, as it were, cyber keys to access encrypted services such as WhatsApp and Signal, and we saw a big pushback from the tech industry on how that would create big cyber vulnerabilities. I wonder whether the Government have come to a settled view on that.
Returning to the theme of the opportunities for the economy, the need to invest in cyber skills in our workforce is absolutely vital. We need to create a cyber workforce and a cyber defence force that work to protect the country, as well as giving companies the kind of skills base they need to make themselves secure. I echo the call from the noble Baroness, Lady Ludford, about boards. I was astonished to read in the House of Lords Library briefing that the number of board members with a responsibility for cyber has apparently fallen. I do not know if that is true, but I wonder whether it is possible to work with business bodies such as the IoD and the CBI to make it a strong corporate governance recommendation that every board should have somebody with a responsibility for cyber.
As I said at the beginning, this is a partnership: it is business, as much as government, that will protect us from cyber. For example, there has been reference to the insurance industry. One of the best ways we can ensure that companies invest in cyber security is to make it mandatory for them to get cyber insurance—which you cannot get unless you put cyber-secure measures in place—and to employ law firms to protect themselves from liability and to put in place important cyber measures.
I have not had a chance to support the noble Lord, Lord Clement-Jones, in his 50-year call for ethical hackers to be allowed to hack. I also echo the earlier call to hear the Minister’s views on the rise of bots and their impact on cyber security.
My Lords, earlier today, the noble Viscount, Lord Colville, and I were saying that we were both quite late down this list and feared that everything would already have been said. That appears to be the case, but, fear not, I will still use my eight minutes.
I support the Bill and I agree with many noble Lords that we also need a much more comprehensive cyber security strategy. Like others, I have some specific suggestions for this specific Bill. My unique contribution, if it is unique, is not that I am an engineer and tech expert, as the noble Lord clearly is. I think that, in health terms, I would be described as an expert by lived experience, in that I suspect I am the only noble Lord today, probably the only noble Lord on the roster, who has actually been a CEO faced with a cyber attack. I have been that CEO whose company has been targeted by a gang of hackers, trying to work out how to navigate the crisis. I have had to go out and communicate to regulators, to customers, to shareholders.
To Ministers, indeed—to my noble friend himself. In those days, the National Cyber Security Centre did not exist—I am obviously referring to my time as chief executive at TalkTalk. Instead, we were directed to the Metropolitan Police’s hostage negotiation team. They were lovely but unfortunately had no tech experience at all. In fact, we did no better ourselves. The security expert who came to brief the TalkTalk board had just come from Mexico, where he had been trying to get a bank manager back who had been kidnapped.
That was only 11 years ago. At TalkTalk, we took the view that communicating was the only way to help our customers and therefore the only way to save the company, and I stand by that decision now, but not everyone takes that view. I was accused at the time of being hopelessly naive for going out, within 24 and 48 hours, on to the airwaves and saying, “My customers have been attacked and, no, I don’t know exactly what has happened”. That is the timetable in this legislation. Most CEOs I talk to say, first, “God, I’m glad I wasn’t in that situation. That’s my nightmare”. Secondly, they are surprised when I say that, actually, I would communicate earlier if I was in that situation again and not later. Cyber attacks are a modern-day taboo in the business world. Business leaders are terrified of admitting that they have been attacked, and I am afraid that that means that mandating reporting is essential, because, 11 years after I was in that situation, I do not think that that has changed. I think that unless we make it mandatory to report, people will not do it.
I was surprised at the time, in 2015, that had Sainsbury’s or Tesco been hacked, I would not have had to tell anybody—I had just come from Sainsbury’s in my previous job. It is really depressing, 11 years later, to see that retail is still excluded. I cannot quite understand why water is “essential” but food is not. I think that Covid taught us that our food retail supply chain is an essential service, and those who work in it are essential workers.
Managed service providers are in, but generative AI is out. Only a decade ago, that might have been OK, but it is not now. In the other place, the Minister said there are powers in the Bill so that we can get it right in the future. Well, we need to get it right now, and we also need the powers to try to keep up. I am not against giving Ministers the power to keep this live, but that is not an excuse for not being up to date today. As other noble Lords have said, it looks, sadly, as though the EU has got this more right than we have. We should be humble enough to admit that, rather than be afraid and insist on doing the wrong thing.
The other area I have some lived experience in, which, again, has been mentioned by other noble Lords, is the challenge of 12 NIS regulators and the lack of join-up. When the TalkTalk hack happened, we immediately stood up a series of workstreams—the obvious things such as trying to work out what had happened. That is the biggest problem with a cyber attack—you genuinely do not know whether you have been attacked by a nation state or kids in a bedroom. You somehow hope it might be the former, but more often than not it turns out to be the latter. So you have to know what has happened and you have to start communicating before you know what has happened. That is two workstreams. You have to work out how to get your systems back up again. That is another workstream. Even 11 years ago, without any of these additional regulators, we had to have a “communicating with regulators” workstream.
Now, spare a thought for the poor managed service providers. They are companies that serve transport, telecoms, energy and the NHS. I think they might have a full house. If you were a managed service provider that was the victim of an attack, you would probably have to deal with all 12 regulators. Those of us who have been here for a while know that if you give 12 different public sector bodies the ability to define terms, they will define them in 12 different ways and have 12 different forms. That will stop you, in the first day or the first week of a cyber attack, doing the things that you should be doing to try to protect your customers. As an expert through lived experience, I plead with the Minister: join-up is essential. It should not be optional. We all know it is hard to do. If you do not sort it out in the Bill, it will not happen. Please do not make that join-up a forum.
I can take myself back to October 2015 and imagine having to communicate with—as much as I love it—the DCRF. If we had had to convene a meeting of 12 regulators in the heat of the crisis to work out what to do, that would not have helped anybody. So we need either a single regulator, as the noble Lord, Lord Birt, so eloquently set out, or a lead regulator, as I know the Government are looking at in a number of other areas, to try to reduce the burden of regulation. I very much support what my noble friend Lord Effingham said: regulation does look like it is necessary here but we need to be careful that we are not just layering burden upon burden, and doing it 12 times most definitely is.
I feel I have said nothing original at all but have said it possibly from a unique perspective. I am rare among former chief executives who have experienced a cyber attack in that I am willing to talk about it, which is exactly why this legislation is important. But I very much hope that, as with so many tech issues, the Minister will hear that we agree more than we disagree and that we could work together to improve the Bill, as this House is often quite good at doing.
(1 year, 1 month ago)
Lords Chamber
Lord Vallance of Balham (Lab)
As the noble Lord points out, there has been a decrease in PhD funding through UKRI from 2018 to 2022. The overall number of PhD students has not gone down, but the sources of funding have become more diversified. It is an important issue for the UK to be good and capable in the numbers of PhD students we have. Two new programmes are being developed as part of the AI opportunities plan: the AI fellowship programme and the AI scholarship programme. Both will be important to ensure that we have the skills we need to deliver on the plan. I take the point about the number of students who have gone from computer science into PhDs. That is an area that we need to look at and understand. As the noble Lord is aware, some of it is a classification question, in relation to EU students, but there is no doubt that we need to keep the number of students doing PhDs up.
My Lords, to follow on from the noble Lord’s point about skills, behind the flashiness and excitement of AI lie some boring things that have to be done. One of the big challenges to support an AI ecosystem in the UK is the byzantine procurement rules of government. Can the Minister tell us what he is doing to ensure that small and growing British-based AI companies have a crack at getting government contracts and therefore growing?
Lord Vallance of Balham (Lab)
This is an area close to my heart. It is a crucial part of stimulating innovation right across the patch. Government procurement ought to be a way in which innovation companies get their first indication of a signal, in many cases, of a potential customer. A commercial innovation hub has been set up in the Cabinet Office, precisely to try to make it much easier to deal with SMEs and others, which has historically been extremely difficult to do from a government procurement perspective.
(1 year, 6 months ago)
Lords Chamber
Lord Vallance of Balham (Lab)
The so-called Small but Risky task force that was set up in response to an exchange of letters between the Secretary of State and the CEO of Ofcom is undertaking a review of all the risks of these small units. I do not know the detail of whether it has broken it down into the categories suggested by the noble Baroness but I think that is an extremely good idea and I hope it will do it, because it is an important activity.
My Lords, having recognised the Herculean task that Parliament has given Ofcom in terms of regulating platforms—Ofcom is set to become probably the world’s most formidable regulator in this space, with commensurate expertise—I will trot out a quick cliché and say, let us not allow the best to be the enemy of the good but support Ofcom as it navigates this very complex environment. Picking up what the Minister mentioned earlier about education, can he update the House on Ofcom’s plans for what is clunkingly called “media literacy”, because prevention is better than cure and the more we can educate children, and indeed adults, on the perils of the internet and how to navigate it safely, the better it will be? It seems almost to be a bit of an orphan within Ofcom’s responsibilities.
Lord Vallance of Balham (Lab)
I think the noble Lord is right that Ofcom has a very large task ahead of it. It is a very professional organisation and one that takes all its duties very seriously. I cannot comment in detail on what it is doing on the media side, but I know that that is part of what it intends to do. I will pick up on something else he said: the urgency now is to get this implemented and the danger is that we add lots of things to it now. We must get on and do this. It is very important to get this working. We know that the enforcement starts just after March and that the new codes for children will come out in early summer. Getting this moving is the key priority, and working out how to stop the really unacceptable activity that goes on on some of these sites.
(1 year, 6 months ago)
Lords Chamber
Lord Vallance of Balham (Lab)
Clearly, this is a UK-wide issue. I am pleased that Scotland has been at the forefront of data in health for many years and has done an extremely good job of getting that into the right place. As we develop the national data library, these questions of data collection, interoperability, curation—which is incredibly important—and systems to ensure privacy and protection will be discussed widely right across the UK. We need to make sure that everything is interoperable, otherwise we will undo the value that we are creating.
My Lords, I welcome the Minister’s focus on delivery, which is vital if we are to make an impact in AI. I say with the greatest respect to my noble friend Lord Holmes that legislation is the last thing we need. The coalition Government’s experience with the Government Digital Service was to find that we made rapid progress before powers were devolved down to individual departments, which then did everything in their power to make sure that nothing worked. While the Minister focuses on the delivery of the AI action plan, could he sort out the confusing quango landscape that now exists after 14 years of endless initiatives, and perhaps have a central function which relentlessly pushes through this excellent plan?
Lord Vallance of Balham (Lab)
I thank the noble Lord very much. I will not add to his comments about the 14 years of endless initiatives, but it is crucial that when we do something such as this, we do it properly. Obviously, my experience was in setting up the Vaccine Taskforce to do just that, and this is the same sort of problem. We have to get everybody across government working on this; there is a big delivery task. Delivery should be our focus and we should keep holding ourselves to account for timelines and deliverables.