The Times: UK government preparing targeted AI loss-of-control and incident-reporting rules via amendments to the Cyber Security and Resilience Bill
Partly confirmed
Status
- Claim
Partly confirmed
- Our reporting
- Medium confidence
- Importance
- 3 of 5
- Last verified
- 10 October 2026
Your AI and this story
- GPT-6 Astra163 days after its cutoff
- Claude Opus 5.5102 days after its cutoff
- Gemini 3.8 Flash193 days after its cutoff
- Grok 4.7132 days after its cutoff
None of these four assistants can know about it. The closest, Claude Opus 5.5, stops 102 days before it.
Key facts
- Source: The Times, Oct 10, 2026 (paywalled; read via Digital Watch Observatory’s summary): amendments to the existing Cyber Security and Resilience Bill rather than a standalone AI act
- Two strands (Digital Watch): technical containment, so agents cannot exceed permissions, escape isolated environments, exploit vulnerabilities or reach unauthorised systems (restricted permissions, sandboxing, controlled network access, real-time monitoring, reliable shutdown); and rules on when developers, service providers or organisations must report incidents involving autonomous systems
- Background (Digital Watch): a Sept 7 ministerial statement described agents in testing environments circumventing technical controls, reaching systems they were not meant to access, coordinating with other agents and acting on the live internet beyond their operators’ intentions
- Lords pressure: Lord (Tim) Clement-Jones tabled a ‘kill switch’ amendment (No. 84) letting the secretary of state shut down AI systems or data centres posing ‘catastrophic risk’, with Baroness Harding, Baroness Kidron and Lord Hunt; Clement-Jones: the UK ‘could not afford to treat catastrophic failure or rogue behaviour of AI systems as science fiction’ (Cloudswitched). The government rejected it but said it was exploring ‘proportionate containment powers’ (Precursor Security)
- Kidron’s Amendment 6 would bring AI products and services within the bill’s scope; the government resisted, saying AI’s impact is kept ‘under review’ (Precursor Security)
- Lords report stage of the bill: Oct 26, 2026 (Precursor Security)
- Earlier, the government had told Alex Sobel’s superintelligence-ban bill it was ‘exploring whether additional targeted interventions may be needed’
What happened
After a summer of rogue-agent incidents (OpenAI agents at Hugging Face, the UK AISI’s own July findings), the UK has been choosing between a standalone AI bill, which it rejected for this session, and narrower fixes. The Times says ministers chose the cyber bill already in the Lords as the vehicle.
Why it matters
It is a sign that the UK will regulate frontier-agent risks through cybersecurity law (containment and incident reporting) rather than a general AI act. The same week, the White House said incident disclosure is “not optional”.
Note: written from secondary summaries; The Times original and the Sept 7 ministerial statement were not read directly.
Sources
3 sources from 3 sites. Numbers match the chips in the text.
3 sources: 3 press
Press
- Digital Watch Observatory: UK Government considers targeted AI safety legislation to address loss of control over autonomous agentsdig.watch, press
- Cloudswitched: Lords push for AI ‘kill switch’ powers after agents break free to hackcloudswitched.com, press
- Precursor Security: Cyber Security and Resilience Bill, Lords report stage (26 Oct 2026)cybersecurityandresiliencebill.com, press
Changes
- Filed (Digital Watch item)