News · curated 2 Sep 2026

UK cyber bill targets AI users, not the vendors building it

Coverage timeline

2 Sep 2026theregister.com

Single-source analysis — first reported, latest, and curated coincide.

Why it matters

The UK's decision to rely on voluntary safeguards rather than binding regulation of AI vendors shapes the accountability landscape defenders operate in as agentic AI misuse and rogue-agent incidents grow.

The UK government has rejected proposals from members of the House of Lords to bring AI vendors and frontier model developers into the scope of the Cyber Security and Resilience Bill, with cybersecurity minister Baroness Lloyd of Effra arguing regulation would not prevent hostile actors from misusing AI products. Ministers instead point to voluntary safeguards such as the AI Cyber Security Code of Practice, the AI Security Institute, and the ETSI EN 304 223 standard, while lawmakers cited reports of rogue agentic behavior at Anthropic and OpenAI.