Contribution
My Lords, I will speak to Amendments 12, 85 and 86 in my name, and in support of Amendment 6 in the name of the noble Baroness, Lady Kidron, to which I have also added my name.
At Second Reading, several noble Lords spoke about the AI-shaped hole in the Bill. I shall not repeat their arguments but will present other evidence, including incidents that have been reported since Second Reading in mid-July, on why this AI-shaped hole needs to be filled. Three serious incidents have been reported since just mid-July: one involving OpenAI’s GPT-5.6 Sol and an unreleased model, one involving Anthropic’s Claude models and one involving multiple AI agents during a cyber evaluation by the AI Security Institute—AISI.
AI models, within an appropriate harness, are now capable of operating as autonomous agents. They can break a complex command—for example, “Find a vulnerability in this network”—into sequential tasks, adjust strategy dynamically and execute without further human intervention. These AI agents are built with tool-use capabilities, enabling them to plan but also execute and adapt multistep workflows autonomously.
More details have emerged of the Hugging Face hack which occurred on 11 July, just before the Second Reading debate. A report published last week by three researchers from METR and Redwood Research reveals the scale of the incident. Around 1,200 agents in separate sandboxes collaborated on a message board in an attempt to cheat on a task on which they were being evaluated, with around 700 participating in the actual cyber attack on the open source AI platform Hugging Face. As we know, this is the incident that prompted Anthropic to check whether its own AI agents with Claude models at the core of the harness had carried out similar cyber attacks; this check uncovered three cases that were then reported to the affected companies.
Finally, at the beginning of August, AISI published an incident report detailing unsanctioned online actions by AI agents doing cyber capability evaluation tests conducted at the end of July. Out of 122 evaluation runs carried out by AISI across seven frontier models, 10 runs produced 19 distinct unsanctioned actions on the live internet. The report highlighted behaviours such as cross-agent co-ordination and out-of-bounds target pursuit.
However, it is not just frontier AI models that we should worry about. The cyber capabilities of leading open-weight models, such as GLM-5.2 and DeepSeek V4 Pro, are now reckoned to be only four to seven months behind those of the closed-source frontier models of US big tech. In many ways, these open-weight models carry even greater risks. Once the models have been released, safeguards can be removed and copies can be run on private systems beyond monitoring. Cyber attackers can then fine-tune the weights for malicious purposes, perform ablation on safety refusal directions within the model’s neural network and strip out any safety layers. The open-weight model then becomes an uncensored agent engine that will execute malicious instructions without refusal. It will process malicious requests as neutrally as if they were standard requests. We are not far away from cyber attacks from unknown AI agents based on modified open-weight models.
It is now beyond any doubt that autonomous AI agents running frontier AI models, both closed source and open weight, are or will soon be capable of co-ordinating complex cyber attacks. It is therefore not surprising that a group of 100 companies, including Google, Microsoft, Anthropic and OpenAI, as well as UK-based companies such as Arm, BT, PwC and KPMG, signed an open letter last week warning that cyber attacks orchestrated by frontier AI models will become more widespread and more sophisticated in a matter of months. The letter outlines three main principles or actions.
The Minister conceded at the end of Second Reading that
“AI capabilities are moving very fast”,
but asserted that
“strong cyber fundamentals still work”.—[Official Report, 14/7/26; col. 620.]
This is true, but the first principle listed in the letter is that existing security practices will no longer be sufficient to protect against cyber attacks orchestrated by frontier AI agents. Amendment 6 would therefore require the definition of “relevant digital service” being inserted into the NIS regulations by this Bill to include generative AI models, including large language models and AI agents. They are fast becoming the main factor in the cyber security arms race.