Technology and AI
A direction to drop a model replaces the power to shut a data centre
By Staff Writer | 3 September 2026

Peers asked for a last resort power to close a data centre in a security emergency. The government refused it and offered something narrower instead: a direction telling a regulated operator to stop using one artificial intelligence model. The same afternoon it kept the companies that build those models outside its scope altogether.
The Cyber Security and Resilience (Network and Information Systems) Bill reached the first day of committee in the House of Lords on 1 September. Its long title is to make provision, including provision amending the Network and Information Systems Regulations 2018, about the security and resilience of network and information systems used or relied on in connection with the carrying on of essential activities. The Bill is sponsored by the Department for Science, Innovation and Technology and is carried in the Lords by Baroness Lloyd of Effra.
The government arrived with a package of its own amendments. The principal one creates a direction power, described by the minister in these terms: it enables the Secretary of State to direct entities in scope of the power where they are using, or may potentially use, vendor supplied goods, services or facilities in connection with their network and information systems that could create national security risks.
Two kinds of risk were named. The first is a product supplied by another company being harnessed as a tool for sabotage, surveillance or espionage. The second has nothing to do with hostile intent: goods or services that are critical points of failure because of defective design or vulnerabilities.
That second limb is the one to read twice. A supplier whose product is merely badly built, and whose customer runs an essential service, is now inside the reach of a direction.
Why the shutdown power was refused
An amendment would have given the Secretary of State a last resort power to order the shutdown of a data centre or a widely deployed artificial intelligence system during a security or operational emergency. The government said the Bill already goes further than the equivalent European rules by allowing it to direct regulated entities where a national security risk arises in relation to their network and information systems, and that such a direction could require an entity to cease using and isolate a particular model.
We believe this is a more proportionate and effective response, as data centres operate in highly complex ecosystems and AI systems are often distributed across different data centres and jurisdictions.
Baroness Lloyd of Effra, Parliamentary Under-Secretary of State
The minister added that it is much less desirable to direct multiple data centres to shut down, with the impact this could have on the services that rely on them, than to direct them to cease using a model. A power station, on her example, could be told to stop using a particular model rather than to stop operating.
The developers stay outside
A separate amendment would have brought providers of artificial intelligence services within the Bill. The government refused it, on the ground that doing so would not address the harms some of those products can pose and would not prevent their misuse by hostile actors. It pointed instead to the AI Security Institute and to a voluntary code of practice, and said the Bill covers all hazards, all threats and all technologies, so a regulated entity relying on a model must assess and mitigate the risks that model brings.
Peers were not persuaded. One asked how a hospital could be required to defend itself against a system carrying no obligation of its own under the Bill.
Have we not learned from countless experiences before, in online safety, privacy and AI itself, that allowing tech companies to set and mark their own homework endangers the public and our national security?
Baroness Kidron, Crossbench peer
A further amendment would have required relevant digital service providers to follow guidance issued by the AI Security Institute. The government said that is not the Institute's role. It did say it is examining whether further targeted interventions are needed for the largest AI related national security risks, and that its thinking is at an early stage.
What a supplier should take from it
The commercial point sits underneath the constitutional one. If your customer operates an essential service, the state may now direct that customer on what it may use, and the direction lands on the customer rather than on you. A contract that assumes a supplied product will remain in service for its term, and prices change control on that assumption, is being written against a power that did not exist when the precedent was drafted.
The obligation to check the product still sits with the buyer. The developer of the model, for now, is asked rather than told. Committee resumes and the question comes back at report.