UK rejects bid to put AI vendors in cyber bill
The UK government has rejected House of Lords proposals to bring AI vendors and frontier model developers within the scope of the Cyber Security and Resilience (Network and Information Systems) Bill. Cybersecurity minister Baroness Lloyd of Effra told the Grand Committee that regulating AI providers through the bill would not stop hostile actors from misusing their products.
Lloyd said the government is pursuing AI security through other routes, including support for the AI Security Institute and the voluntary AI Cyber Security Code of Practice, which informed the ETSI EN 304 223 standard. Peers argued that voluntary rules are inadequate, citing reports of rogue agentic behavior involving Anthropic and OpenAI, Bill Gates’ concerns about commercial incentives, and OpenAI’s warning that AI-orchestrated cyberattacks could become too widespread to manage.
Ministers also rejected amendments that would require certain vendors to prove their systems could not cross red lines, such as evading human oversight or aiding chemical weapons development. A proposed emergency power to shut down a datacenter or widely deployed AI system was also dismissed, with Lloyd saying the bill would instead allow directions to regulated entities, such as ordering a power station to stop using a particular AI model.
The CSR Bill was first proposed in the 2024 King’s Speech and introduced in Parliament in November 2025. It updates the NIS 2018 regime, extends oversight to managed service providers, datacenter operators, and designated critical suppliers, and previously drew attention for proposed £100,000 daily fines.