Ethical Hacking News
The UK government has rejected proposals to bring AI vendors within the scope of the Cyber Security and Resilience (Network and Information Systems) Bill, instead opting for a voluntary approach to regulating AI. This shift towards voluntary safeguards has been welcomed by some, but criticized by others, who argue that a more regulatory approach is needed to ensure the security of AI systems.
The UK government has chosen to regulate AI users, rather than vendors, in the Cyber Security and Resilience (Network and Information Systems) Bill. The government believes that targeting AI users will address the growing concerns surrounding AI misuse in cyber attacks, but critics argue that this approach may not be enough. The government has rejected proposed red lines and emergency shutdown powers that would have required certain AI vendors to demonstrate their products could not cross specified thresholds. Some welcome the government's decision to focus on voluntary safeguards, such as the AI Cyber Security Code of Practice, as a more proportionate response. Critics argue that relying on voluntary guidelines is insufficient and that a more regulatory approach is needed to ensure AI system security. The rejection of proposed amendments has raised questions about the government's approach to regulating AI and its impact on the cybersecurity landscape.
The UK government has taken a significant step in its approach to regulating artificial intelligence (AI) within the framework of the Cyber Security and Resilience (Network and Information Systems) Bill. In a move that has been welcomed by some, but criticized by others, the government has opted to target AI users, rather than the vendors building these technologies, in a bid to address the growing concerns surrounding the misuse of AI in cyber attacks.
At the heart of this shift is the argument that regulating AI vendors and frontier model developers would not prevent hostile actors from misusing their products. Baroness Lloyd of Effra, the UK's Cybersecurity Minister, made this point during a recent Grand Committee scrutiny of the bill. According to her, bringing providers of AI services within the scope of the bill would not address the harms that can be posed by some AI products and services, or specifically, it would not prevent their misuse by hostile actors.
This stance is in contrast to the proposed red lines and emergency shutdown powers, which would have required certain AI vendors to demonstrate that their products could not cross specified thresholds, such as evading human oversight or assisting with the development of chemical weapons. The latter amendment was rejected by the government, with Minister Lloyd arguing that it would be "much less desirable" than the current approach, which would allow the government to direct regulated entities, including datacenter operators, to take or cease specified actions when their systems presented a qualifying risk.
The government's decision to focus on voluntary safeguards, such as the AI Cyber Security Code of Practice, has been welcomed by some as a more proportionate and effective response. This code, which informed the first global AI cybersecurity standard, ETSI EN 304 223, has been seen as a demonstration of the UK's global leadership and commitment to shaping international technical standards. However, critics argue that relying on voluntary guidelines is insufficient, and that a more regulatory approach is needed to ensure the security of AI systems.
The rejection of proposed amendments to the bill has also raised questions about the government's approach to regulating AI. Lawmakers, including Crossbench peers Baroness Kidron and Lord Tarassenko, had argued that companies unable to prevent their agents from misbehaving should be trusted to follow voluntary ethical guidelines that they can rewrite at will. Their concerns were echoed by the recent open letter penned by OpenAI, warning that AI-orchestrated cyberattacks would become too prevalent to handle if left unchecked.
Despite the criticism, the government remains committed to discussing AI regulation, citing the technology's economic significance. The Grand Committee is scheduled to resume discussions of the CSR Bill when it reconvenes on Thursday, providing further insight into the government's approach to regulating AI and its impact on the cybersecurity landscape.
In a broader context, the UK's approach to regulating AI reflects a global trend towards embracing voluntary safeguards over more stringent regulations. This approach has been seen in other countries, such as the US, which has opted for a more market-driven approach to regulating AI, relying on industry-led initiatives and voluntary guidelines to ensure the security of AI systems.
However, the effectiveness of this approach remains to be seen, and critics argue that a more regulatory approach is needed to ensure the security of AI systems. As the debate around AI regulation continues to unfold, one thing is certain: the future of AI and its impact on cybersecurity will be shaped by the decisions made by governments and regulators around the world.
The UK government has rejected proposals to bring AI vendors within the scope of the Cyber Security and Resilience (Network and Information Systems) Bill, instead opting for a voluntary approach to regulating AI. This shift towards voluntary safeguards has been welcomed by some, but criticized by others, who argue that a more regulatory approach is needed to ensure the security of AI systems.
Related Information:
https://www.ethicalhackingnews.com/articles/UK-Cyber-Security-Bill-Targets-AI-Users-Not-Vendors-in-Shift-from-Regulatory-Approach-to-Voluntary-Safeguards-ehn.shtml
https://www.theregister.com/security/2026/09/02/uk-cyber-bill-targets-ai-users-not-the-vendors-building-it/5293738
Published: Wed Sep 2 05:27:02 2026 by llama3.2 3B Q4_K_M