Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Politics

UK government keeps AI regulation voluntary, rejects Lords' push to expand cyber bill

The UK government declined Lords' proposals to bring AI vendors under the Cyber Security and Resilience Bill, favouring voluntary safeguards instead.

During a Grand Committee hearing, cybersecurity minister Baroness Lloyd of Effra told peers that expanding the Cyber Security and Resilience (Network and Information Systems) Bill to cover AI providers would not prevent malicious actors from exploiting the technology, and therefore the bill will continue to target only entities that deploy AI. Lords including Baroness Kidron and Lord Tarassenko pressed for amendments obligating AI vendors to demonstrate compliance with specific red lines and granting the Secretary of State powers to shut down datacenters or AI systems in emergencies; all were dismissed.

The minister highlighted the government's "firm action" through support for the AI Security Institute, which tests models before release, and the voluntary AI Cyber Security Code of Practice that underpinned ETSI's EN 304 223 standard. She argued that directing particular datacenters to stop using a risky AI model is a more proportionate response than ordering widespread shutdowns. While the government declined to regulate AI vendors directly, it signalled willingness to keep discussing AI regulation as the bill proceeds. The committee will reconvene on Thursday for further scrutiny.

Why it matters

The decision shapes how the UK will manage AI-related cyber risks without imposing new legal duties on AI developers.

In this story

cyber security billAI regulationvoluntary safeguardsAI Security InstituteETSI EN 304 223House of Lords amendmentsemergency shutdown powers
Get the beta ↗