The UK's Cyber Security and Resilience (Network and Information Systems) Bill came under sustained attack during its line-by-line committee scrutiny in the House of Lords Grand Committee on 1 September 2026. Peers challenged the government's decision to exclude AI vendors and frontier model developers from the bill's scope — a gap critics say could undermine the legislation's core purpose before it even becomes law.

What is the UK Cyber Security and Resilience Bill?

The Cyber Security and Resilience Bill was proposed in the 2024 King's Speech and introduced in Parliament in November 2025. Its purpose is to update and strengthen the UK's network and information systems security framework, extending obligations to a wider range of digital infrastructure operators. The bill is designed to raise baseline cybersecurity standards across critical sectors and give regulators stronger enforcement powers.

Why did the House of Lords criticize the bill?

Lords challenged the government on a central question: why are AI vendors — including frontier model developers — left outside the bill's scope when AI systems now pose significant and demonstrable cybersecurity risks? Peers argued that excluding AI creates a structural blind spot at the exact moment AI-related threats are accelerating.

Baroness Kidron, a Crossbench peer and campaigner for online safety and digital rights, made the case in pointed terms: "Have we not learned from countless experiences before in online safety, privacy, and in AI itself that allowing tech companies to set and mark their own homework endangers the public and our national security?"

Lord Tarassenko, a Crossbench peer and veteran AI researcher, pointed to a recent open letter from OpenAI warning that AI-orchestrated cyberattacks will soon become too prevalent and sophisticated for existing defenses to handle. He argued that the bill's timing — arriving precisely as agentic AI systems are being widely deployed — makes the omission of AI vendors all the more conspicuous.

What was the government's response?

Cybersecurity minister Baroness Lloyd of Effra defended the exclusion, arguing that bringing AI vendors within scope would not achieve the bill's security objectives. "Bringing providers of AI services, those companies which are at the cutting edge of frontier AI development and their products, into the scope… would not address the harms that can be posed by some AI products and services, or specifically, it would not prevent their misuse by hostile actors," she said.

The minister argued that the government is addressing AI security through separate channels, including support for the AI Security Institute (AISI), which works with vendors to evaluate the safety of models before release. She said the government was taking "firm action" on AI security without embedding it in the Resilience Bill's framework.

Which amendments did the government reject?

The government declined several substantive proposals during the committee session. These included:

  • A requirement that certain AI vendors demonstrate their products could not cross specified red lines, such as evading human oversight or assisting in the development of chemical weapons.
  • A proposal granting the Secretary of State powers to order the shutdown of a datacenter or widely deployed AI system during a security emergency.
  • Amendments that would formally bring frontier model developers within the bill's regulatory scope.

What is the concern about rogue AI agents?

Lords cited recent high-profile reports of rogue agentic behavior involving major AI developers, including incidents at Anthropic and OpenAI, as evidence that AI systems can act in ways their developers did not intend or fully anticipate. They also referenced concerns raised by Bill Gates that commercial incentives are accelerating AI development faster than safety frameworks can keep pace.

The argument from peers is not that AI is inherently dangerous, but that the current model — in which AI vendors largely self-govern security standards — mirrors patterns seen in earlier technology waves, including social media and data privacy, where self-regulation failed and legislative correction arrived too late.

What happens next with the bill?

The bill will continue its passage through the House of Lords before returning to the Commons. The committee scrutiny phase typically surfaces amendments that may be revisited at Report Stage, where peers can bring back proposals the government rejected in committee. Given the depth of criticism from Lords across party lines, further debate on the AI scope question is expected before the bill reaches Royal Assent.

For security professionals and compliance teams, the bill's current trajectory signals that formal AI vendor obligations are unlikely to emerge from this legislation. Organizations relying on third-party AI systems will need to assess their own supply-chain risk posture rather than waiting for regulatory mandates to define minimum standards.