Board responsibility for cyber still in legislators' sights - and that includes AI risks
Updated: 1 day ago
No fines for directors, but board oversight will be included in statutory guidance
The UK's Cyber Security and Resilience Bill will substantially update the UK's cyber regulatory framework as it applies to regulated entities; broadly, critical national infrastructure providers including public services. It continues to pass through UK Parliament, attracting significant attention from parliamentarians seeking to strengthen the legislation.
The House of Lords introduced amendments to mandate active board-level oversight of cyber security risk management, requiring board members to undertake specific cyber training, and make senior executives (CEOs, directors, partners) personally liable for penalties if their organisation's cyber compliance failure occurred through their consent, connivance, or neglect.
Whilst these amendments were rejected by government, Minister Baroness Lloyd of Effra confirmed that the new regulatory framework will mandate board oversight. The specific requirements will be included within statutory guidance rather than primary legislation, which allows government much more flexibility to adapt the policy as circumstances evolve.
It seems likely that regulated entities will be required, or at least strongly encouraged, to adopt the Cyber Governance Code of Practice. They are already required to assess themselves against the Cyber Assessment Framework, which includes a whole section on board direction, so regulated boards should already be familiar with the territory.
The Minister also noted an open question about whether the UK's corporate reporting framework is producing sufficient cyber risk disclosure from boards. Government opened a consultation on this question on 7th September.
Legislation will require boards to consider AI-driven risks to essential services
With AI-driven threats in the headlines, the Lords introduced amendments which would have explicitly brought AI products and services into the scope of regulation, established strict boundaries that regulated AI products must not cross, and given government statutory pre-deployment testing powers.
Whilst these amendments were also rejected, the Minister explained: "... the Bill takes an “all hazards, all threats, all technologies” approach. This requires regulated entities to manage all the risks relevant to their network and information systems. For example, if AI forms a part of the system that the essential service relies on—for example, in the provision of drinking water—that entity must assess and mitigate the risks it poses."
This is a sensible approach for boards, which should always look beyond media headlines and vendor marketing to consider all technologies that pose risks. This includes emerging technologies, such as AI and quantum computing, as well as legacy systems.

Boards should always look beyond media headlines and vendor marketing to consider all technologies that pose risks. This includes emerging technologies, such as AI and quantum computing, as well as legacy systems.
A narrow focus on customer data is coming to an end
Government has itself introduced numerous amendments to the Bill. Firstly, it has widened the scope of incident reporting to require regulated entities to report when any system data has been compromised - not just data relating to "users of" a regulated service.
This is a hugely welcome development. Most organisations have been inadvertantly encouraged by the UK GDPR to prioritise risks to customer or user data, since they are only required to report a breach to the Information Commissioners' Office when it involves this data. Yet the most devastating effects of cyber breaches are often completely unrelated to customer data, as we saw at JLR and Marks & Spencer.
Supplier risk in focus
Secondly, government has added new powers in the Bill to direct regulated entities if there is a national security risk in relation to their network and information systems. This would enable ministers to issue binding, confidential orders forcing regulated entities to restrict, modify, or completely remove hardware, software, or digital services provided by high-risk suppliers - particularly those with ties to hostile foreign states. Complementing this, the government introduced powers to establish a mandatory procurement referral scheme, allowing ministers to require advance national security screening for high-risk technology procurement contracts before they are signed.
Although we would not expect this particular power to be exercised very often, it is indicative of an increasing focus on supply chain risk. The boards of organisations that supply regulated entities should note: they are increasingly required to meet the same stringent cyber security standards as their customers, and cyber governance should accordingly be a priority.




