3 SEP 2026 — The UK's Cyber Security and Resilience Bill covers operators of essential services, digital service providers, managed service providers, data-centre operators and designated critical suppliers. It does not cover AI vendors or frontier model developers, and it does not cover central or local government. The second exclusion is larger than the first and gets almost no attention.
What the bill does
Proposed in the 2024 King's Speech and introduced to Parliament in November 2025, the bill updates the 2018 NIS regulations. It requires in-scope organisations to implement enhanced protections against specified threats, and gives government power to direct a regulated entity to take or cease specified actions when its systems present a qualifying risk — instructing a power station to stop using a particular AI model, in the example given.
Initial proposals included fines of £100,000 a day for in-scope organisations failing to protect against specified threats.
Excluded are AI vendors, frontier model developers and their products, along with central and local government, though the Government Cyber Action Plan promises to hold government to similar standards.
The government's argument is narrower than its critics allow
Baroness Kidron put the asymmetry directly, noting that an AI system used to attack the NHS has no requirement, duty or obligation to be checked before use. Lord Tarassenko cited OpenAI's recent warning about AI-orchestrated cyberattacks becoming unmanageable as strengthening the case for regulating vendors.
Cybersecurity minister Baroness Lloyd's response was that regulating AI vendors through this bill would not prevent misuse by hostile actors. That is a real argument rather than a deflection: a duty imposed on a UK-established vendor does not reach an adversary using a model developed elsewhere, and the entity with a choice about deployment is the operator.
The argument, however, answers only one of the two risks. Misuse of a legitimate product by a hostile actor is an operator-side problem. Capability shipped without adequate testing is a vendor-side problem, and the bill declines to address the second while giving a reason that only covers the first.
What was rejected matters as much as what passed
Two amendments were turned down. The first would have required AI vendors to demonstrate their products cannot cross defined red lines, including evading oversight or assisting weapons development. The second would have given the Secretary of State emergency powers to shut down a data centre or AI system.
Lloyd rejected the shutdown power as disproportionate, on the grounds that data centres are complex ecosystems and AI systems are distributed across jurisdictions. While technically accurate, that describes why such a power would be hard to use rather than why it would be wrong to hold.
The government's preferred alternatives are the AI Security Institute, which tests model security before release, and a voluntary AI Cyber Security Code of Practice informed by the ETSI EN 304 223 standard. Both are real instruments. Neither creates a duty anyone can be fined for breaching.
The direction-making power is the part with teeth
Most of the commentary is about who is in scope. The provision that will actually change behaviour is the power to direct a regulated entity to stop doing something, and the worked example given is telling a power station to stop using a particular AI model.
That is a substantial intervention in a commercial decision. An operator told to remove a model from a production process has to have somewhere to move to, and if the direction arrives mid-contract the cost of compliance falls entirely on the operator rather than on the vendor whose product triggered it.
This brings the argument back to the exclusion of vendors. A government that will not impose duties on vendors but reserves the power to order operators to stop using their products has chosen the instrument that puts every cost on the party with the least influence over the risk. That may still be the right way to assign the costs, and it should at least be named as such.
The government exclusion is the strange one
Excluding AI vendors is a contested policy choice with arguments on both sides. The exclusion of central and local government from a bill about the resilience of essential services is harder to account for, and it has attracted far less comment.
Public bodies run some of the most consequential systems in the country and have been among the most frequently breached. A regime that fines a private managed service provider £100,000 a day while leaving the councils and departments it serves under a separate voluntary plan has drawn a line that does not follow the risk.
The Government Cyber Action Plan may well hold departments to equivalent standards. It is not the same thing as being in scope of a statute with a penalty attached, and everyone involved knows the difference.
Why this is worth watching from here
Singapore's Cybersecurity Act, Malaysia's Cyber Security Act 2024 and Indonesia's forthcoming framework all take the same structural approach: designate critical information infrastructure, impose duties on the operators, and say nothing about the vendors whose products those operators run.
The UK debate is a preview of an argument this region has not yet had. When it arrives it will arrive in the same form — someone will point out that an operator can be fined for deploying a model it had no way to inspect, and the government will answer that it cannot regulate a developer in another jurisdiction.
We reported on the argument that AI-driven vulnerability discovery changes the economics of attack, where the counter-case was that automated capability arms both sides. A regulatory regime that binds only the defender's side of that exchange is making an implicit bet on which side compounds faster.