The Cyber Security and Resilience Bill has had less attention than it deserves. It has no AI branding and no headline grabbing name. But it is moving through Parliament right now, and it will do more to shape how AI infrastructure gets secured in the UK than any AI specific law the government has proposed so far.

As of late August 2026, the Bill is at committee stage in the House of Lords, having already cleared every other stage in the Commons. Report stage, third reading and royal assent still lie ahead, so the detail can still shift. But the shape of it is settled enough to talk about now.

What the Bill Does

The Bill updates the Network and Information Systems Regulations 2018, the rules that currently apply to operators of essential services such as energy, transport, health, drinking water and digital infrastructure. It works on 3 fronts: it widens who counts as an essential service, it gives regulators more consistent powers, and it gives government a faster route to act when a threat is imminent.

The government’s own case for the Bill rests on some stark numbers. The UK was Europe’s most targeted country for cyber-attacks in 2024. Over 40% of UK businesses reported an attack that year. The estimated annual cost to UK businesses runs to £14.7 billion. These are the government’s figures rather than independently verified ones, so treat them as the scale of the problem as Whitehall sees it rather than a precise account.

The Data Centre Question

Here is the part that matters most for AICSA’s members. The Bill brings data centre services into scope as an essential service for the first time. Any data centre running at 1 megawatt or above, or 10 megawatts or above for larger enterprise sites, is automatically designated and takes on the full set of regulatory obligations that come with that status.

Data centres are not just infrastructure in the abstract. They are where AI models get trained and where they run in production. A regulatory regime built around energy grids and water suppliers is now, by extension, a regulatory regime for the physical backbone of AI. Managed service providers offering IT and cyber security services are also brought into scope, which will catch a good number of the organisations doing AI security work on behalf of clients. Large load controllers, the systems managing electrical load for smart appliances and grid balancing, are covered too. So is a new category of designated critical suppliers to essential and digital services, meaning the UK is choosing to regulate the supply chain directly rather than leaving each operator to assess its own suppliers.

New Duties Worth Knowing Now

Organisations in scope will need to report a harmful cyber breach to their regulator within 24 hours, with a full report following within 72 hours. The Secretary of State gains the power to set strategic priorities for regulators, which should mean more consistency across sectors that have historically been supervised very differently. Regulators also get stronger cost recovery powers to fund oversight, and government gains a power of direction to mandate rapid action during a national security level threat.

Why This Is an AI Story, Not Just a Cyber One

At the King’s Speech in 2026 the government chose not to introduce a standalone AI Act. Instead, it opted for the Regulating for Growth Bill, which creates sandboxing powers for testing AI products, and for incremental, sector by sector regulation. Read alongside that choice, and the Cyber Security and Resilience Bill is the closest thing the UK currently has to AI infrastructure law. It does not mention artificial intelligence in its title, and the government’s own factsheet gives AI only a brief mention, pointing to existing secure by design codes of practice for software and AI. But by regulating the data centres AI runs on and the managed service providers who secure AI systems for clients, it reaches a large part of the AI supply chain by another name.

This is exactly the convergence AICSA exists to track. A UK reader comparing this to the EU’s NIS2 will find the UK approach narrower in sector scope but more direct in supply chain oversight, since NIS2 leaves suppliers to be assessed by the organisations that use them, while the UK Bill puts critical suppliers under direct regulatory reach.

What AICSA Members Should Do Now

If your organisation runs or uses data centre capacity anywhere near the 1-megawatt threshold or provides managed IT or cyber security services to others, start checking now whether the Bill’s scope will reach you. Look at your incident reporting process against a 24-hour first notification and ask whether it would hold up. And keep watching this Bill rather than waiting for an AI Act that, on current evidence, is not coming in the form many expected.

AICSA will track this Bill through report stage and third reading in the Lords and will publish a follow up once it receives royal assent which is expected later in 2026 or early 2027, followed by secondary legislation.

Sources

Bill status (committee stage in the Lords, having cleared the Commons), checked 28 August 2026: https://bills.parliament.uk/bills/4035

Bill provisions, sector scope and the 24 hour/72 hour reporting figures: https://www.gov.uk/government/publications/cyber-security-and-resilience-network-and-information-systems-bill-factsheets/summary-of-the-bill

Data centre megawatt thresholds and the NIS2 comparison: https://www.mayerbrown.com/en/insights/publications/2026/03/united-kingdom-proposes-changes-in-the-cyber-security-and-resilience-bill-to-the-nis-regulations-with-key-differences-to-nis2

King’s Speech context on the Regulating for Growth Bill and the absence of a standalone AI Act: https://www.rmoklegal.com/news/news/kings-speech-2026-cyber-ai-digital-id-tech-law

The 40% attack figure and the £14.7 billion cost estimate are the government’s own figures as stated in its factsheet.