CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

UK cyber bill targets AI users, not the vendors building it

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5870

As cited

Copy frozen at (site build).

government policy

UK cyber bill targets AI users, not the vendors building it

The UK government rejected House of Lords proposals to regulate artificial intelligence (AI) vendors under the Cyber Security and Resilience Bill, arguing that including AI companies would not prevent hostile actors from misusing their products. Instead, the government pointed to existing initiatives like the AI Security Institute and a voluntary AI Cyber Security Code of Practice as sufficient safeguards. Peers countered that relying on voluntary compliance by technology companies has failed in other sectors and that regulated organizations would face obligations while AI vendors would not.

Why it matters: UK security professionals and critical infrastructure operators face a regulatory framework that mandates their AI security practices while imposing no legal duties on the AI vendors whose systems they deploy, creating a compliance asymmetry that may hinder effective risk management.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary