V

Viscount Camrose (Con)

Speaking in the House of Lords on 1 September 2026

Debate

Cyber Security and Resilience (Network and Information Systems) Bill

Contribution

My Lords, I shall begin with Amendment 12 in the names of the noble Lord, Lord Tarassenko, and the noble Baroness, Lady Kidron. I completely understand the necessity and urgency of taking action on these things. The noble Lord, Lord Tarassenko, set out the absolute urgency and the growing weight of the problem that we need to solve here. I have my doubts—I am delighted to carry on talking about this—about the significant expansion of and change in the role of AISI to take on these additional responsibilities. Those are practical doubts; I am certainly not disputing the desirability of fixing this problem. Equally, we have to think practically about how this works alongside the Information Commissioner’s Office and the relative role of each. I thought my noble friend Lord Holmes set it out very well. We are going to need to look carefully at who regulates what—we are going to come to this in the next group—but we need to do so with quite a bit more information about their resources and goals and how we see each regulator taking this forward. I am afraid that there is a very much larger discussion that we will have to take forward on this matter. Although I understand the desire to maximise the use of AISI in giving it these statutory functions via Amendment 85, we on these Benches are hesitant about consolidating powers in a separate non-governmental body. No matter how effective that body continues to prove to be in its original and existing role, taking power outside Parliament may not be the most effective way to ensure rigour and accountability. The Secretary of State should of course have regard to what AISI says and closely monitor its output, but I am concerned—although willing to be convinced on this—that placing it on a statutory footing risks diverting responsibility away from the Secretary of State. We hold the same position on Amendment 92. Giving AISI standard-setting, inspection and enforcement powers risks creating an unaccountable body with a greatly increased remit out of what is currently a vital and successful research body. I feel that that risk is too great for both sides. Instead, we would rather see powers vested in the hands of accountable public figures. It is for this reason that we support the principle behind Amendment 84 in the name of the noble Lord, Lord Clement-Jones, which would provide the Secretary of State with the power to shut down AI systems during large-scale emergencies. It would also provide a necessary stopgap in the hands of an accountable Secretary of State while requiring Parliament to be informed of the decision taken. Additionally and importantly, it would not inhibit the growth of safe and responsible AI across the AI sector, which could be an additional worry with the pre-deployment checks in Amendment 85. Amendment 75 tabled by the noble Baroness, Lady Kidron, would introduce red lines for relevant AI digital services. I confess that I was very impressed when I read the red lines because I thought that she had written them herself, but she gave away—perhaps foolishly—that they came from the brilliant Stuart Russell. Needless to say, the list is entirely sound, at least for today. We agree that AI services should not partake in actions that threaten the safety of individuals, businesses or nations, but our hesitation arises from the fact that, while their logic is clear, the red lines themselves are necessarily speculative at a moment in time, however eminent and wise their creator. Further, AI models would have to demonstrate that they cannot perform the capabilities listed, so they would essentially be asked to prove a negative. Aside from the fact that this would place an administrative burden on the providers, as we all know, AI models develop in ways that are nearly impossible to predict and quantify. I am unclear how frontier labs would be able to engineer their models so that, for example, they would demonstrably not self-improve so as to pose “a risk to the authenticity and integrity of the processed data”. Similarly, I am unsure how the regulators will be expected to quantify these capabilities because, to a large extent, they are a function of not just ability but degree. In theory, the requirement not to support the development of chemical weapons might be violated by a model that simply gives basic chemistry lessons. Would that model be banned or would it be forced not to answer questions about chemistry? I do not want to trivialise this matter by giving too simple an example, but I am trying to convey just how difficult it will be to design the precise scope and extent of the necessary regulations. I worry that they currently seem arbitrary. They would be onerous on firms and regulators and slow down safe and responsible growth where it exists in our domestic AI industry. I would suggest a different or additional approach, principles based rather than capabilities based. Ensuring, for example, that labs and associated businesses are focused on integrity, prevention, human control, threat minimisation and transparency, rather than attempting to regulate specific examples of AI malpractice, could prove more effective at serving the dual goal of AI growth and AI safety. As I have argued many times, I am afraid, in other Bills and debates, the only way legislation can keep ahead of technology is to pursue principles over rules about specific features.

More from Viscount Camrose (Con)

Other recent Hansard contributions by the same speaker.

About Hansard

Hansard is the official verbatim record of proceedings in the UK Parliament. Every word spoken in the Commons and Lords is recorded and published — this page is a single contribution from that record.