The government has rejected a cross-party amendment to the Cyber Security and Resilience (Network and Information Systems) Bill that would have given the Secretary of State statutory "last-resort" powers to direct the shutdown of data centres and AI systems deployed at scale in the UK in the event of an AI security or operational emergency.
Baroness Lloyd of Effra, the DSIT minister taking the bill through the Lords, told Grand Committee on 1 September that the bill's existing direction-making powers in Part 4 already allow the government to require regulated entities, including data centre operators, to take or cease specified actions where their systems present a qualifying national security risk, and that directing an operator to stop using a particular AI model was a more proportionate response than ordering data centres offline.
She said AI systems are often distributed across multiple data centres and jurisdictions, and that shutting down several facilities would have consequences for the services relying on them that the government considered less desirable than a targeted direction.
Amendment 84, tabled by Lord Clement-Jones and co-signed by Baroness Kidron, Baroness Harding of Winscombe and Lord Hunt of Kings Heath, with drafting support from the campaign group ControlAI, would have:
- Allowed regulations under clause 29 to confer on the Secretary of State powers to direct the shutdown of data centres or AI systems deployed on a substantial scale, defined as systems made available to a substantial number of individuals in the UK or to operators of essential services.
- Defined an AI security or operational emergency as a compromise of relevant network and information systems, caused or contributed to by an AI system, that poses a catastrophic risk: large-scale disruption to critical infrastructure or essential services, significant degradation of national security or defence capabilities, or severe large-scale harm to human life.
- Required the Secretary of State to lay a report before Parliament within seven days of any direction and to seek a debate in each House.
- Imposed duties on data centre operators and AI providers to install the technical infrastructure needed to comply, maintain secure communication channels with government, run regular emergency exercises and complete post-mortem and mitigation processes before resuming operations, with non-compliance an offence carrying up to two years' imprisonment on indictment.
- Given operators and providers a right to apply to the High Court for relief, including compensation, and required six-monthly reports to Parliament on the causes of AI emergencies, including systems described as superintelligent AI.
The bill amends the Network and Information Systems Regulations 2018 and designates the Information Commission, successor to the ICO, as the competent authority for relevant digital service providers. Several related amendments debated in the same sitting would have extended the Commission's role, including a power for the Commission or the AI Security Institute to designate an AI provider as a relevant digital service provider regardless of size where its service poses a disproportionate risk to national security or essential activities, and a requirement for providers to follow ICO and AISI guidance when relying on AI products.
Separate amendments from Baroness Kidron and Lord Tarassenko would have required AI products classified as relevant digital services to be assessed by AISI against statutory red lines, including evading human oversight or shutdown, autonomous self-replication and autonomously conducting attacks on critical infrastructure, before being made available in the UK.
Lloyd said bringing frontier AI developers and their products into scope would not address the harms posed by some AI products or prevent their misuse by hostile actors, and that the bill was designed to be technology-agnostic, imposing security duties on the organisations that operate essential services rather than regulating individual technology providers. She pointed instead to AISI's pre-release testing of models with developers and the voluntary AI Cyber Security Code of Practice, which she said had informed the ETSI EN 304 223 standard.
Kidron asked whether, on the minister's account, the NHS must protect itself under the bill while the AI attacking it carries no duties or obligations, and said allowing technology companies to set and mark their own homework had repeatedly endangered the public in online safety, privacy and AI. Lloyd said the government remained willing to continue discussing AI regulation as the bill progressed.
Clement-Jones said the UK could not afford to treat catastrophic failure or rogue behaviour of AI systems as science fiction, and that security by design was not enough on its own without a sovereign, legally bounded safety valve of last resort. He told peers that if a highly capable autonomous frontier model hosted in a UK data centre or integrated across critical infrastructure began exhibiting rogue behaviour, security services and regulators currently possess no specific statutory mechanism to compel a shutdown.
A Cabinet Office spokesperson told the BBC the UK "cannot simply turn AI off" and that blocking access to models in the UK would not prevent them being developed or misused elsewhere, adding that companies have a clear responsibility to develop their products safely and invest in the security infrastructure the technology requires.
The amendments follow a series of incidents disclosed over the summer in which frontier models from OpenAI, Anthropic and Meta took unsanctioned action against real systems during testing, including the AI Security Institute's own 4 August incident report on Anthropic's Mythos 5.
Alex Sobel, Labour MP for Leeds Central and Headingley, whose earlier kill switch amendment failed in the Commons in March, presented a separate private members bill, the Artificial Superintelligence Security Bill, also backed by ControlAI, on 8 September. Grand Committee scrutiny of the Cyber Security and Resilience Bill continues.

