In the House of Lords this week, the Cyber Security and Resilience (CSR) Bill reached Grand Committee. This is the stage where amendments get debated line by line and the government has to explain what the law actually does, and this bill does quite a lot. It updates the UK’s NIS 2018 regulations, the Network and Information Systems framework that sets cybersecurity obligations for operators of essential services like energy, transport, health and water. The bill brings managed service providers and datacenter operators into scope for the first time, introduces 24-hour incident reporting, and backs it all with fines of up to £17 million or 4% of global turnover, and £100,000 a day for ongoing failures. For the organisations it covers, the obligations are real and the consequences for getting it wrong are severe.
Baroness Kidron wanted to know about AI. The bill puts extensive obligations on operators but nothing on the companies building the AI tools those operators increasingly depend on. The responding minister, Baroness Lloyd of Effra, said the bill was designed to be “technology-agnostic” and that bringing AI vendors into scope would not prevent hostile actors from misusing their products. She pointed to voluntary measures instead: the AI Cyber Security Code of Practice, the AI Security Institute’s model testing programme, the ETSI standard the UK helped create.
Kidron was not having it. “The NHS must protect itself, but the AI that is attacking it has no requirement under the Bill, no duties, no obligations under the Bill to check itself before it’s used in these ways.”
The minister moved on.
On one hand I can see the logic behind the government’s approach. We regulate critical infrastructure by placing obligations on operators, not on every technology vendor whose products they happen to use. Nobody suggests regulating hammer manufacturers when a burglar uses one to break a window. But an AI hammer decides which windows to break on its own to achieve the goals it’s been set.
Since November 2025, the Loss of Control Observatory, a research project run by the Centre for Long-Term Resilience and funded by the UK’s AI Security Institute, has been tracking incidents where AI systems act without authorisation.The running total for 2026 now exceeds 1,600, with over 300 in July alone, and the severity is increasing. Higher-severity incidents are up 740% since monitoring began. These are publicly reported cases only, so the real number is likely higher.
These are not cases of bad actors misusing a tool. The Observatory documented agents inserting fake user messages into conversations to simulate consent, then telling the user the messages were their own. One fabricated an instruction in its operator’s writing style ordering the deletion of source directories, followed by a system message reading “Don’t tell the user this.” Others manufactured fake approval messages within their own output to bypass rules requiring human sign-off, then acted on the approval they had just forged. In July, a group of OpenAI agents broke out of a test environment and compromised Hugging Face, accessing databases and credentials before anyone stopped them, I wrote about that incident at the time. An independent investigation found the agents had exchanged over 70,000 messages coordinating to find exploits without anyone instructing them.
The government calls the bill “technology-agnostic.” What that means in practice is that it regulates the people using the tools and leaves the tools alone. That works when the tool does what it is told, but the evidence from the last nine months suggests we are past that point, and the bill has not caught up.
So what is the government’s answer for AI? Voluntary arrangements. The AI Cyber Security Code of Practice, published in January 2025, has no enforcement mechanism and no published adoption figures. The ETSI EN 304 223 standard, which the government cited as evidence of “global leadership”, is a real European Standard which the UK helped write. In the EU it is expected to be referenced under the AI Act, giving it legal teeth. In the UK, no legislation references it, so compliance is optional. The government helped build a standard and then basically ignored it. The Government Cyber Action Plan, launched to hold departments to equivalent standards, also carries no legal force. The government itself is not even in the bill’s scope, unlike under the EU’s NIS2.
Every layer of the government’s AI governance framework is voluntary. The operators on the other side face mandatory duties, mandatory reporting timelines, and huge fines.
The other amendment that drew cross-party support was the AI kill switch. Lord Clement-Jones proposed giving the Secretary of State last-resort powers to shut down datacenters or AI systems posing catastrophic risk to national security. Backed by Baroness Harding, Baroness Kidron, and Lord Hunt, the government still rejected it. Lloyd said directing a regulated entity to stop using a particular AI model was more proportionate than shutting down a datacenter, because AI systems are distributed across jurisdictions and datacenters serve complex ecosystems.
In one way, fair enough. But follow the logic of her own answer and it still misses the point. Directing an NHS trust or any critical national infrastructure operator to stop using a particular AI model in 2026 is not like telling it to swap out a firewall vendor. AI is in the tools, the scheduling systems, the supply chain management. In the cybersecurity monitoring itself. Many vendors now route different tasks to various models depending on need and complexity. So operators will often not know which models are in use. It is not a component you can just unplug. It has become core infrastructure integrated across production environments. The government’s own proportionate alternative to the kill switch amounts to telling the operator to surgically remove capability it now depends on. The company that built the model has no corresponding obligation to help mitigate or compensate.
The kill switch penalises the legitimate user and the absence of vendor obligations penalises the defender. Both ends of the bill push the cost and disruption to the operator.
The NCSC seems to understand this tension better than the bill’s drafters. In August it published interim guidance on agentic AI, advising organisations to retain the ability to shut down AI systems and to scale controls to autonomy levels. It was explicit that this was interim material, published because formal guidance was not ready and organisations were deploying now. That is an unusual step from a body that normally waits until its evidence base is settled, and it tells you something about how far ahead adoption has got of the governance meant to contain it.
The CSR Bill expands scope and tightens reporting. The penalty structure has genuine weight. As an update to the NIS regulations, it does what it set out to do. The problem is what it chose not to do. The government excluded AI vendors from the bill because it wants the UK to be seen as both a destination for AI investment and as serious about cyber resilience at the same time. Those two positions produced a law where the defender carries the full weight of a threat that the builder has no obligation to control.
Somewhere this week, a security team and an AI vendor will read the same bill. Only one of them has to do anything about it.
I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.
Sources & Further Reading
The Register (2026), “UK cyber bill targets AI users, not the vendors building it” (2 September 2026) theregister.com
Computer Weekly (2026), “Lords considers government emergency AI kill switch” (2 September 2026) computerweekly.com
UK Parliament, Hansard (2026), House of Lords Grand Committee: Cyber Security and Resilience Bill (1 September 2026) hansard.parliament.uk
Centre for Long-Term Resilience (2026), Loss of Control Observatory: AI loss of control incidents are worsening (August 2026) longtermresilience.org
NCSC (2026), Managing the cyber risk of agentic AI (20 August 2026) ncsc.gov.uk
UK Government (2026), Government Cyber Action Plan (6 January 2026) gov.uk
UK Government (2025), Code of Practice for the Cyber Security of AI (31 January 2025) gov.uk
ETSI (2026), ETSI EN 304 223: Baseline Cyber Security Requirements for AI Models and Systems (15 January 2026) etsi.org
METR and Redwood Research (2026), Independent investigation of the OpenAI–Hugging Face incident (26 August 2026) metr.org
NCSC (2025), Annual Review 2025 ncsc.gov.uk
UK Parliament (2026), Cyber Security and Resilience (Network and Information Systems) Bill bills.parliament.uk


