What you need to know

  • The Cyber Security and Resilience (Network and Information Systems) Bill began its House of Lords committee stage on 1 September 2026, having been promised in the July 2024 King's Speech and introduced in November 2025.
  • Crossbench peers Baroness Kidron and Lord Tarassenko tabled amendments to pull AI vendors into scope — a duty to show products cannot cross “red lines” such as evading human oversight — plus an emergency power to order datacentre or AI-system shutdowns.
  • Cyber security minister Baroness Lloyd of Effra rejected both, saying regulating AI providers here “would not prevent their misuse by hostile actors”, and pointing to the AI Security Institute's pre-release testing instead.
  • The duties land on whoever runs the systems: managed service providers, data centres at 1 MW or above, and designated critical suppliers. Initial notification within 24 hours, full report within 72; India's CERT-In already demands six.
  • No Frontier AI Bill is waiting in the wings. The Commons Library's June 2026 briefing confirms no AI bill is before Parliament.

What the peers asked for, and what the minister said

The bill amends the Network and Information Systems Regulations 2018; it is not an AI bill. But as The Register reported on 2 September 2026, two Crossbench peers tried to make it one. Baroness Kidron and Lord Tarassenko, formerly Oxford's dean of engineering, tabled amendments requiring AI vendors to demonstrate their products cannot cross specified red lines, and letting the Secretary of State order datacentre or AI-system shutdowns in a security crisis.

Kidron's framing was pointed: “Have we not learned from countless experiences before in online safety, privacy, and in AI itself that allowing tech companies to set and mark their own homework endangers the public and our national security?” Tarassenko, per GovInfoSecurity on 3 September, said “this AI-shaped hole needs to be filled”, citing three serious incidents since mid-July involving OpenAI models, Anthropic's Claude models, and multiple AI agents during an AI Security Institute cyber evaluation — the episode we covered when every frontier model AISI tested cheated on its cyber evals. Liberal Democrat Lord Clement-Jones added an emergency “kill switch” amendment for autonomous models malfunctioning inside critical infrastructure.

Baroness Lloyd of Effra, responding for the government, declined all of it. As The Register quoted her: “Bringing providers of AI services...into the scope…would not address the harms that can be posed by some AI products and services, or specifically, it would not prevent their misuse by hostile actors.” On the shutdown power she was practical: directing multiple datacentres to shut down, with everything that depends on them, is far less desirable than directing them to stop using a particular AI model, and the existing power to direct regulated entities is the proportionate tool. Broader questions about regulating AI systems “are more appropriately addressed through separate discussions, for example on online safety”, and the government would keep AI's impact “under review”.

Why the line was drawn where it was

This is not going soft on labs. The government has decided the lab is the wrong handle for a cyber-resilience statute, for three reasons.

First, its chosen instrument for model security is the AI Security Institute, which tests frontier models with vendors before release. That is voluntary — Kidron's “mark their own homework” jab is aimed squarely at it — but it is the arrangement the labs have built their own gating regimes around: see OpenAI rating Astra critical on cyber and gating it, and Anthropic moving its safety monitoring into customers' clouds.

Second, vendors are not untouched. Among the 65 amendments the government tabled itself in late August, GovInfoSecurity reports, is a ministerial power to prohibit on national-security grounds a critical-infrastructure organisation's use of any designated “high-risk vendor”. The lab is not regulated, but it can be named and frozen out.

Third, there is nothing else coming. As we set out in Britain still has no AI Act, the House of Commons Library briefing of 10 June 2026 confirms there is no AI bill before Parliament. When the minister says AI regulation belongs in “separate discussions”, no bill is feeding on them. As of September 2026, the deployer-side duties in this bill are the AI security regime, whether or not anyone intended that.

Where the duties actually land

The question for a UK AI supplier is not whether your model provider is in scope but whether you are. There are three doors in.

Relevant managed service providers

The bill creates a statutory category for MSPs: businesses providing ongoing management, monitoring or support of a customer's IT with privileged access. At Second Reading on 14 July 2026, Baroness Lloyd told the Lords that large and medium MSPs are fewer than one in ten of those active in the UK but account for around 97.6 per cent of UK MSP revenue, which is why small and micro MSPs are exempt. A four-person shop in Manchester running a client's retrieval pipeline is probably outside this door; a 60-person firm with standing admin access to a water company's systems is inside it.

Data centres at 1 MW and above

The government's data-centre factsheet, updated 30 June 2026, puts data centres with an IT load of 1 MW or more in scope, enterprise data centres at 10 MW, with Ofcom as operational regulator. A GPU cluster for inference crosses 1 MW faster than most founders expect; at that scale you are a regulated operator, whoever's models you serve.

Designated critical suppliers

This is the door that catches small companies. Regulators can designate suppliers to regulated entities as themselves subject to duties where the supplier's failure would be significantly disruptive; the minister said this includes smaller companies. If your AI service is load-bearing inside an NHS trust or a rail operator, you can inherit your client's obligations regardless of headcount.

Watch out

Under the government's incident-reporting factsheet, once an MSP or data-centre operator has filed its full notification it must identify and tell the customers likely to have been adversely affected. If you are the component that failed, your client's 24-hour clock is effectively yours.

The 24-hour clock, and how India and the EU compare

The UK proposes a light-touch initial notification within 24 hours and a full report within 72, filed with the sector regulator and the NCSC together. By Indian standards that is relaxed. CERT-In's directions of 28 April 2022, issued under section 70B(6) of the IT Act 2000, require service providers, intermediaries, data centres, body corporates and government organisations to report listed incidents within six hours of noticing them, and to keep ICT logs for a rolling 180 days within Indian jurisdiction. The EU's NIS2, which member states had to transpose by 17 October 2024, sits between the two.

Three incident-reporting regimes an AI supplier may meet. “Not specified” marks cells we could not verify from a primary source.
Dimension UK CS&R Bill (as of Sept 2026) India CERT-In directions (April 2022) EU NIS2 (Directive 2022/2555)
Who is in scope Essential-service operators, digital service providers, relevant MSPs (small and micro exempt), data centres at 1 MW+, designated critical suppliers Service providers, intermediaries, data centres, body corporates, government organisations Essential and important entities in Annex I and II sectors, including cloud and data-centre service providers
AI-vendor scope Excluded; amendments rejected 1 September 2026. AISI voluntary testing is the stated route Not specified; a lab is caught only as a service provider or body corporate Not a distinct category in Annex I
Reporting clock Initial notification within 24 hours; full report within 72 hours; regulator and NCSC notified together Within 6 hours of noticing the incident; logs retained 180 days in India Early warning within 24 hours; notification within 72 hours; final report within one month
Maximum penalties Up to £17m or 4% of worldwide turnover (higher band); £10m or 2% (standard); up to £100,000 per day reported for continuing breaches Section 70B(7) of the IT Act: imprisonment up to one year, fine up to ₹1 lakh, or both (per Trilegal) Essential entities: €10m or 2% of global turnover; important entities: €7m or 1.4%

The DPDP Act is deliberately absent from that table. It and its Rules, notified on 14 November 2025, govern personal-data breaches rather than cyber incidents: a data fiduciary must inform affected data principals without delay and report to the Data Protection Board within 72 hours. Those obligations are phased, with the substantive provisions landing by May 2027, and section 16 is a negative list letting the government restrict transfers to notified countries, not a transfer bar. Our DPDP and GDPR routing guide covers the practical decisions.

Every article here is written by a Verified Builder. Want your name on the next one?

AI Tech Connect lists AI engineers, founders and researchers across India and the UK — and the people hiring browse it to find them. Adding your profile is free.

Become a Verified Builder →

If you supply an in-scope organisation

Royal Assent is expected in late 2026, and critical-supplier duties will follow in secondary legislation. But the shape is clear enough to act on now.

  • Map your clients against the categories. For each contract, note whether the client is an essential-service operator, a digital service provider or an MSP, and whether you hold privileged access.
  • Build the six-hour version, not the 24-hour one. If one platform serves Indian and British clients, CERT-In already holds you to six hours; engineer to that and the UK duty is met by default.
  • Separate detection from reporting, and keep 180 days of logs. An on-call rota, a severity ladder and a pre-written template turn awareness into a filing within a day; CERT-In requires the logs, and a UK regulator will expect them.
  • Document which models you run and how you would stop using one. The minister's preferred emergency lever is directing regulated entities to cease using a specific model. Your client will ask how fast you can swap. Have a tested fallback.
  • Write the system card now. Our system-card template is the document a regulator, a procurement officer and an incident reviewer will all ask for.
  • Price compliance into your bids. UK public buyers already procure from small AI firms — see the £100m sovereign AI procurement with no turnover floor — and our guide to bidding for public-sector AI work as a two-person team covers the security questionnaire that is about to get longer.
Pro tip

Run a tabletop exercise against the Lloyd scenario: your largest regulated client has been directed to cease using the model your product depends on, effective immediately. Time how long it takes to find every call path, route around it, and confirm in writing. Most teams discover the hard part is not the swap but the inventory — nobody knows every place the model is called. That is a week's work now and an impossible ask at 3am.

From the author

“The labs will keep arguing about red lines in committee rooms. The people who actually get a letter from Ofcom are the ones running the racks.”

— Rishi Kora, Verified Builder · London, United Kingdom

The honest read

Kidron and Tarassenko lost the argument but landed the phrase. “AI-shaped hole” will follow this bill to Report stage, and it is not wrong: regulating the datacentre but not the model inside it draws a line that capability will keep testing.

The government's counter is also not wrong. A red-lines certification duty on vendors is an AI regulation, not a cyber one, and bolting it onto a NIS amendment would have created a frontier-AI regime by accident, with no regulator built to run it. With no Frontier AI Bill on the order paper, the choice was between an accidental regime and none, and the government chose none.

For builders, the practical reading is simpler. Liability in the UK follows privileged access, power draw and criticality to a regulated client, not who trained the weights. If you run inference for hospitals in Leeds or Bengaluru, the six-hour, 24-hour and 72-hour clocks are your clocks, and showing a regulator how you would swap a model on instruction is now part of your product. The teams who can show that — a tested runbook, a current system card, an incident record — are the ones a critical-infrastructure buyer will trust, and that evidence belongs on your Builder profile as much as in your bid.