AI Companies and the Cyber Security and Resilience Bill
How HL Bill 32 reaches AI vendors, frontier developers, AI data centres and the organisations that deploy AI, after the Government kept AI out of scope at Lords Committee.
Last updated: 14 September 2026
AI companies are not a named category in the Cyber Security and Resilience Bill, and in September 2026 the Government rejected amendments to add them. An AI business is caught if it provides a cloud computing or managed service, runs a large data centre, or is designated a critical supplier. Organisations using AI manage that risk under their own duties.
Does the Cyber Security and Resilience Bill regulate AI?
Not directly. The Bill amends the Network and Information Systems Regulations 2018 and adds new powers, but it contains no clause about artificial intelligence. It regulates the organisations that deliver essential, digital and managed services, whatever technology they use.
At Lords Committee Stage, which sat on 1, 3, 7 and 9 September 2026, a cross-party group led by Lord Clement-Jones pushed to bring AI developers and frontier model providers inside the regulatory perimeter. Baroness Lloyd of Effra, the minister taking the Bill through the Lords, declined. She argued that regulating AI vendors through this Bill would not stop hostile actors misusing their products.
The Government also rejected an amendment for an AI kill switch: emergency powers to shut down AI systems and the data centres running them. AI Minister Kanishka Narayan said existing powers already allow the Government to intervene.
How can an AI company still fall within scope?
Scope turns on the service you provide, not on whether it involves AI. There are five routes that matter for AI businesses. Telecoms services are excluded from all of them: public electronic communications networks and services are carved out of the digital, managed and essential service definitions.
| Route into scope | Typical AI business | Regulator | Threshold | Main duties |
|---|---|---|---|---|
| Relevant digital service provider (RDSP): cloud computing service | AI platforms offering on-demand, self-service, scalable model hosting, inference or GPU capacity to customers | Information Commission | Not a micro or small enterprise (clause 7(8)) | Register (reg 14), security duties (reg 12), 24h/72h incident reports (reg 12A), customer notice (reg 12C) |
| Relevant managed service provider (RMSP) | AI firms that manage a customer's IT systems under contract with access to those systems, such as managed AI operations or AI-driven SOC services | Information Commission | Not a micro or small enterprise (clause 9(4)) | Register (reg 14C), security duties (reg 14B), 24h/72h incident reports (reg 14E), customer notice (reg 14G) |
| Critical supplier (reg 14H, clause 12) | An AI supplier whose disruption could significantly affect the economy or society through an OES, RDSP or RMSP it supplies | Sector competent authority, or the Information Commission for suppliers to RDSPs and RMSPs | Case-by-case designation, not a size test | Security and incident reporting duties that follow designation |
| Operator of essential services: data centre service | Operators of data centres housing AI compute | Ofcom | Rated IT load of 1MW or more, or 10MW or more if run on an enterprise basis | Security duties, information to the regulator (reg 8ZA), data centre incident reports (reg 11A) |
| Part 3 essential activities (clause 24) | Any activity the Secretary of State later specifies by regulations as essential | Regulatory authority designated in the regulations | Set by future regulations; none made yet | Set by future regulations under clause 29 |
The micro and small enterprise exemption uses Commission Recommendation 2003/361/EC: broadly fewer than 50 staff and annual turnover or balance sheet total of €10m or less. Group data is normally aggregated, so a small AI subsidiary of a large group is unlikely to qualify.
Is a hosted AI model or API a cloud computing service?
It depends on the service. Clause 7(3) of HL Bill 32 defines a cloud computing service as a digital service that enables access to a scalable and elastic pool of shareable computing resources, such as networks, servers, software and storage, where:
- there is broad remote access to the service
- it can be provided on demand and on a self-service basis
- the pool of resources may be distributed across two or more locations
- it is not provided solely for the provider's own business, and it is not a managed service
A GPU cloud, model hosting platform or pay-as-you-go inference API sold to the public appears to meet most of these limbs. "Shareable" requires multiple users sharing common access from the same equipment with processing carried out separately for each user, which is how most multi-tenant inference works.
The position is less clear for a single-tenant deployment, a model licensed to run on the customer's own infrastructure, or an AI feature built into a wider software product. Neither the Bill nor the Government's relevant digital service providers factsheet mentions AI, and the Information Commission has not issued guidance on it. Treat the question as unsettled and document your own analysis. Our cloud service providers guide covers the definition in more detail.
When does an AI company count as a managed service provider?
A managed service under new regulation 1(3B) is a service provided under a contract for the ongoing management of a customer's IT systems, through support and maintenance, monitoring, active administration or similar, delivered by connecting to or accessing the customer's network and information systems. Access can be on site or remote.
Selling an AI product is not enough on its own. An AI company moves towards this definition when it runs, monitors or administers systems inside the customer's environment on an ongoing basis. Examples include managed machine learning operations, an AI-driven security operations service with access to the customer's estate, or agentic tools the provider operates on the customer's behalf with standing access.
A managed service cannot also be a cloud computing service, so a business must work out which definition fits each offering. Both routes are regulated by the Information Commission. See our managed service providers guide.
Can an AI supplier be designated a critical supplier?
Yes. Clause 12 inserts new regulation 14H, which lets a sector regulator designate a supplier to an operator of essential services, and lets the Information Commission designate a supplier to an RDSP or RMSP. Designation requires that the supplier relies on network and information systems for the supply, that an incident affecting those systems could disrupt essential, digital or managed services, and that the disruption is likely to have a significant impact on the economy or day-to-day functioning of society.
Regulators must consider whether the customer could get the goods or services from an alternative source. That test favours designating AI platforms that are embedded deeply in essential services and hard to swap out, rather than commodity tools.
This is the route most likely to reach a frontier developer or specialist AI vendor that is neither a cloud nor a managed service provider. Our critical suppliers guide explains the designation process and the right to make representations.
What does the Bill mean for organisations that use AI?
Because the Bill regulates the entity delivering the service, AI risk sits with the operator, digital service provider or managed service provider that deploys it. Their existing duties to take appropriate and proportionate measures to manage risks to their network and information systems cover AI models, agents, copilots and inference services like any other component.
In practice that means an NHS trust using AI triage, an energy company using AI in operational forecasting, or a managed service provider running AI tooling across client estates must be able to show how those components are secured, monitored and recovered. Regulators assess this against frameworks such as the NCSC Cyber Assessment Framework.
Contracts are where AI vendors feel the Bill first. In-scope customers will push security requirements, incident cooperation, notification timelines and audit rights down to their AI suppliers, whether or not those suppliers are regulated themselves.
Are data centres hosting AI compute regulated?
Yes, above the thresholds. Clause 4 makes the provision of a data centre service an essential service in a new data infrastructure subsector. A data centre is in scope where its rated IT load, the maximum electrical power available for its IT equipment, is 1MW or more.
A higher threshold of 10MW applies to a data centre run on an enterprise basis, meaning it is owned or managed by a business solely to provide IT services for that business. An AI lab running its own training cluster would fall under the 10MW test. Many AI facilities exceed both figures.
Ofcom is the competent authority. Operators must meet security duties, give Ofcom information under regulation 8ZA, and report data centre incidents under regulation 11A. The Government's rejection of the kill-switch amendment means there is no AI-specific shutdown power over these facilities. See our data centres guide.
How are AI-related incidents reported?
The Bill widens the definition of "incident" to any event having, or capable of having, an adverse effect on the operation or security of network and information systems. Prompt injection that exfiltrates data, a poisoned model that corrupts outputs, or an AI agent that disrupts a service can all qualify. So can a near miss that was capable of causing harm.
- Initial notification within 24 hours of first becoming aware of a reportable incident
- Full notification within 72 hours of the same moment of first awareness, not 72 hours after the initial report
- RDSPs report to the Information Commission under regulation 12A; RMSPs under regulation 14E; operators of essential services to their competent authority under regulation 11
- Copies go to the CSIRT at the same time
- RDSPs and RMSPs must also notify affected UK customers under regulations 12C and 14G
Reporting only applies to incidents with a significant impact, judged against the factors set out in each regulation.
What penalties apply to AI companies in scope?
An AI company regulated as an RDSP, RMSP, operator of essential services or critical supplier faces the Part 2 penalty regime under clause 21:
Higher maximum: the greater of £17,000,000 and 4% of turnover, for failures such as breaches of security duties and incident notification duties.
Standard maximum: the greater of £10,000,000 and 2% of turnover, for failures such as registration and information requirements.
Part 4 is separate. Clause 43 lets the Secretary of State give national security directions to regulated persons. Contravening a direction carries up to £17,000,000, rising to the greater of £17,000,000 and 10% of turnover only once regulations under clause 49(5) are in force, plus up to £100,000 per day while the contravention continues.
What other UK AI legislation and oversight is in play?
The Government's position is that AI-specific rules belong elsewhere, and several developments sit alongside the Bill:
- AI Security Institute. A research organisation within the Department for Science, Innovation and Technology that tests frontier models before and after release. It has no statutory powers under the Cyber Security and Resilience Bill.
- Joint Committee on Human Rights. On 14 September 2026 the committee published a report calling for a wide-ranging AI Bill, a single statutory AI regulator and duties across the AI lifecycle.
- Artificial Superintelligence Bill. Introduced by Alex Sobel MP on 8 September 2026 as a Ten Minute Rule Bill, it would prohibit the development of artificial superintelligence. Bills of this kind rarely become law.
- Part 3 of the Bill. Clause 24 lets the Secretary of State specify further essential activities by regulations. This is the Bill's own mechanism for extending scope later, though no regulations have been made.
What should AI companies and AI users do now?
- Map each AI product against the cloud computing and managed service definitions, and record your conclusion and reasoning.
- Check whether you are a micro or small enterprise, counting linked group companies.
- Identify customers that are operators of essential services, RDSPs or RMSPs, and judge whether you could be hard to replace for them.
- Build AI scenarios such as prompt injection, model poisoning and agent misuse into incident response, and test you can meet the 24 hour and 72 hour clocks.
- If you use AI inside an in-scope service, add models and AI suppliers to your asset and supplier registers and evidence controls against the NCSC Cyber Assessment Framework.
- Prepare for security and notification clauses in customer contracts.
- Commission penetration testing and red teaming of AI features and supporting infrastructure.
- Track Report Stage: a rejected AI amendment could return.
Frequently Asked Questions
Does the Cyber Security and Resilience Bill apply to AI companies?
Not as a named category. At Lords Committee in September 2026 the Government rejected amendments to bring AI vendors and frontier model developers into scope. An AI company can still be regulated if it provides a cloud computing service, provides a managed service, operates a data centre above the thresholds, or is designated a critical supplier. Each route depends on what the business actually does.
Is an AI model API a cloud computing service under the Cyber Security and Resilience Bill?
It may be. Clause 7 defines a cloud computing service as a digital service giving broad remote access, on demand and self-service, to a scalable and elastic pool of shareable computing resources. Many hosted model and inference APIs appear to fit, but no regulator has confirmed how the definition applies to AI services. Providers should assess their own service against each limb of the definition.
Did the Lords add an AI kill switch to the Cyber Security and Resilience Bill?
No. Lord Clement-Jones moved an amendment at Lords Committee giving emergency powers to shut down AI systems and the data centres running them in a crisis. The Government rejected it, with AI Minister Kanishka Narayan arguing that existing powers already allow it to intervene. Peers can return to the issue at Report Stage, for which no date had been announced by 14 September 2026.
Are AI data centres regulated under the Cyber Security and Resilience Bill?
Yes, if they meet the thresholds. A data centre service becomes an essential service where the rated IT load is 1MW or more, or 10MW or more for a data centre run solely for the operator's own undertaking. Ofcom is the competent authority. Large AI training and inference facilities will often exceed these figures, whether run by a colocation provider or by an AI company itself.
Do organisations using AI have new duties under the Cyber Security and Resilience Bill?
Not AI-specific duties, but AI is not exempt. An operator of essential services, digital service provider or managed service provider must manage risks to the network and information systems it relies on, and AI models, agents and third-party AI tools form part of those systems. An incident caused through an AI component is reportable on the same 24 hour and 72 hour clock as any other.
Can an AI vendor be designated a critical supplier?
Yes, in principle. Under new regulation 14H a regulator can designate a supplier to an OES, RDSP or RMSP if an incident affecting the supplier's systems could disrupt essential or digital services, with a likely significant impact on the economy or day-to-day functioning of society. Regulators must consider whether customers could obtain the service elsewhere, so hard-to-replace AI platforms are the likeliest candidates.
What penalties could an AI company face under the Cyber Security and Resilience Bill?
Only an AI company regulated through one of the Part 2 routes faces Part 2 penalties. The standard maximum is the greater of £10,000,000 and 2% of turnover, and the higher maximum, for failures such as security duty and incident notification breaches, is the greater of £17,000,000 and 4% of turnover. Separate Part 4 sanctions apply only to contravening a national security direction.
Is the UK introducing a separate AI Bill?
Not yet. On 14 September 2026 Parliament's Joint Committee on Human Rights called for a wide-ranging AI Bill and a single statutory AI regulator. On 8 September 2026 Alex Sobel MP introduced the Artificial Superintelligence Bill, a Ten Minute Rule Bill that would prohibit superintelligent AI. Neither is Government legislation, and Ten Minute Rule Bills rarely become law.
Official sources
- Cyber Security and Resilience (Network and Information Systems) Bill: UK Parliament bill page
- Read HL Bill 32 in full
- GOV.UK factsheet: relevant digital service providers
- GOV.UK factsheet: designating critical suppliers
- GOV.UK factsheet: data centres
- Information Commissioner's Office: guide to NIS
- AI Security Institute
- The Network and Information Systems Regulations 2018
Related guidance
- Cloud service providers
- Managed service providers
- Data centres
- Critical suppliers
- Large SaaS providers
- Cyber Security and Resilience Bill: AI scope at Lords Committee
- New powers to block risky suppliers
- Five Eyes AI warning: what boards must know
- Key changes the Bill makes
- Cyber Security and Resilience Bill FAQ
Need help working out where your AI services sit?
Precursor Security helps AI companies and the organisations deploying AI assess scope under the Cyber Security and Resilience Bill, test AI systems and prepare for incident reporting.