<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/uk-cyber-bill-targets-ai-users-not-the-vendors-building-it-god4pafwv" -->

---
title: UK cyber bill targets AI users, not the vendors building it
description: The UK government has rejected House of Lords proposals to bring AI vendors and frontier model developers within the scope of the Cyber Security and Resilience...
canonical: https://daily.dev/posts/uk-cyber-bill-targets-ai-users-not-the-vendors-building-it-god4pafwv
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: UK cyber bill targets AI users, not the vendors building it | daily.dev
og:description: The UK government has rejected House of Lords proposals to bring AI vendors and frontier model developers within the scope of the Cyber Security and Resilience...
og:url: https://daily.dev/posts/uk-cyber-bill-targets-ai-users-not-the-vendors-building-it-god4pafwv
og:image: https://api.daily.dev/og/posts/GoD4PAfWv.png
og:image:alt: UK cyber bill targets AI users, not the vendors building it
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# UK cyber bill targets AI users, not the vendors building it

**[The Register](https://daily.dev/sources/theregister)** · 5 min read · 0 upvotes · 0 comments

## Summary

The UK government has rejected House of Lords proposals to bring AI vendors and frontier model developers within the scope of the Cyber Security and Resilience Bill. Cybersecurity minister Baroness Lloyd argued regulating AI vendors directly wouldn't stop misuse by hostile actors, pointing instead to voluntary measures like the AI Security Institute and the AI Cyber Security Code of Practice. Peers, including Baroness Kidron and Lord Tarassenko, pushed back citing rogue agent incidents at Anthropic and OpenAI and warnings from Bill Gates and an OpenAI open letter about AI-driven cyberattacks. The government also rejected proposals for mandatory 'red lines' for AI products and emergency shutdown powers over datacenters or AI systems, instead allowing regulators to direct regulated entities like datacenter operators to stop using specific AI models. The bill, which updates 2018 NIS regulations, continues committee scrutiny.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.theregister.com/security/2026/09/02/uk-cyber-bill-targets-ai-users-not-the-vendors-building-it/5293738>

## Questions this post answers

### Does the UK Cyber Security and Resilience Bill regulate AI vendors and frontier model developers directly?

No, the bill does not bring AI vendors or frontier model developers within its scope. The UK government rejected House of Lords amendments that would have regulated AI companies directly, arguing this would not prevent misuse by hostile actors. Instead, the bill imposes cybersecurity duties on regulated entities like datacenter operators, who can be directed to stop using a specific AI model if it poses a qualifying risk.

_Track how AI governance and cybersecurity regulation evolve for teams building compliance strategies on daily.dev._

### What is the AI Cyber Security Code of Practice in the UK?

It is a voluntary set of guidelines from the UK government intended to secure AI systems, with no legal obligations attached. It informed the first global AI cybersecurity standard, ETSI EN 304 223. UK ministers point to it as an alternative to direct statutory regulation of AI vendors under the Cyber Security and Resilience Bill, a stance criticized by peers as allowing tech companies to self-regulate.

_Developers weighing voluntary versus mandatory AI security standards can follow the debate on daily.dev._

## Similar posts on daily.dev

- [UK Government Sound Alarm Over AI Security Risk](https://daily.dev/posts/uk-government-sound-alarm-over-ai-security-risk-ligwbbmck) · IT Security Guru · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#ai-regulation](https://daily.dev/tags/ai-regulation)

[View this post on daily.dev](https://daily.dev/posts/uk-cyber-bill-targets-ai-users-not-the-vendors-building-it-god4pafwv)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"UK cyber bill targets AI users, not the vendors building it","url":"https://daily.dev/posts/uk-cyber-bill-targets-ai-users-not-the-vendors-building-it-god4pafwv","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/uk-cyber-bill-targets-ai-users-not-the-vendors-building-it-god4pafwv"},"datePublished":"2026-09-02T09:47:57.900Z","dateModified":"2026-09-02T09:48:23.225Z","description":"The UK government has rejected House of Lords proposals to bring AI vendors and frontier model developers within the scope of the Cyber Security and Resilience...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/f543cfbeb049b20d78e15cf554482155?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/f543cfbeb049b20d78e15cf554482155?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"The Register","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"The Register","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/66aa2113fdad463992ffcbf0e8963fda","url":"https://daily.dev/sources/theregister"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/uk-cyber-bill-targets-ai-users-not-the-vendors-building-it-god4pafwv","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,ai-regulation","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"The Register","item":"https://daily.dev/sources/theregister"},{"@type":"ListItem","position":3,"name":"UK cyber bill targets AI users, not the vendors building it"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/uk-cyber-bill-targets-ai-users-not-the-vendors-building-it-god4pafwv#faq","mainEntity":[{"@type":"Question","name":"Does the UK Cyber Security and Resilience Bill regulate AI vendors and frontier model developers directly?","acceptedAnswer":{"@type":"Answer","text":"No, the bill does not bring AI vendors or frontier model developers within its scope. The UK government rejected House of Lords amendments that would have regulated AI companies directly, arguing this would not prevent misuse by hostile actors. Instead, the bill imposes cybersecurity duties on regulated entities like datacenter operators, who can be directed to stop using a specific AI model if it poses a qualifying risk. Track how AI governance and cybersecurity regulation evolve for teams building compliance strategies on daily.dev."}},{"@type":"Question","name":"What is the AI Cyber Security Code of Practice in the UK?","acceptedAnswer":{"@type":"Answer","text":"It is a voluntary set of guidelines from the UK government intended to secure AI systems, with no legal obligations attached. It informed the first global AI cybersecurity standard, ETSI EN 304 223. UK ministers point to it as an alternative to direct statutory regulation of AI vendors under the Cyber Security and Resilience Bill, a stance criticized by peers as allowing tech companies to self-regulate. Developers weighing voluntary versus mandatory AI security standards can follow the debate on daily.dev."}}]}
```

