The UK government has opted not to extend the scope of its Cyber Security and Resilience (Network and Information Systems) Bill to include AI vendors. This decision was articulated by Cybersecurity Minister Baroness Lloyd of Effra, who argued that regulating frontier AI developers would not effectively prevent misuse of their products by hostile actors.
During a recent Grand Committee session, Lloyd emphasized the government's current initiatives to secure AI through alternate measures, including collaboration with the AI Security Institute (AISI) to test AI model security prior to their release. This approach is designed to establish a framework that prioritizes voluntary guidelines over mandatory regulations for AI service providers.
While this legislative strategy was put forth, members of the House of Lords raised concerns, suggesting that unchecked AI vendors could lead to risks similar to those experienced in past tech regulatory oversights. Baroness Kidron, a campaigner for digital rights, remarked on this issue, questioning whether companies could be trusted to abide by voluntary ethical guidelines. She highlighted the historical failures in online safety and privacy standards that originate from self-regulation in the tech industry.
Former Microsoft CEO Bill Gates' comments regarding the rapid but unchecked advancement of AI technologies echoed the sentiments of other lawmakers who proposed amendments to the bill. These amendments aimed to impose regulations on AI vendors to ensure they would not engage in harmful activities, such as evading human oversight or potentially contributing to malicious agendas.
Further debate included an amendment that would grant government authorities powers to shut down AI systems during emergencies. This proposal was similarly dismissed by Lloyd, who argued that the bill should remain technology-agnostic and focus on enforcing cybersecurity requirements for regulated organizations rather than targeting individual technology providers.
The government remains open to further discussion on AI regulation, especially considering the prevailing economic implications of AI technologies. The Grand Committee plans to revisit the CSR Bill for further examination soon.
Background and Implications
The CSR Bill was initially introduced during the 2024 King's Speech and later presented in Parliament in November 2025. With an aim to address the evolving cybersecurity landscape, it seeks to update existing regulations that govern essential service providers and digital service entities. However, its recent critiques have called attention to perceived gaps in addressing the role of AI technologies in cybersecurity.
Critically, the bill's intended framework lacks mandatory regulations for local and central government organizations, a point that shadow deputy PM Sir Oliver Dowden previously highlighted. The recent Government Cyber Action Plan, launched in conjunction with the CSR Bill discussions, touted that it would hold government bodies to standards paralleling those proposed in the Bill, albeit without legally binding obligations.
As the landscape of AI continues to evolve, the UK government's decision to limit direct oversight of AI vendors may set a precedent that could have significant long-term implications for cybersecurity and AI governance.




