UK lawmakers are considering giving the government emergency powers to deactivate powerful AI systems and shut down data centers if the technology poses a national security threat.
The proposed “kill switch,” introduced as an amendment to the Cyber Security and Resilience Bill, is intended as a last-resort mechanism to stop a runaway AI system before it can compromise critical national infrastructure.
At the same time, the UK government has introduced separate amendments to the same cybersecurity bill that would allow ministers to prevent critical infrastructure organizations from using technology suppliers deemed high risk. The new authority is aimed at supply-chain threats, where attackers can compromise a smaller technology provider and use its access to reach more sensitive organizations.
The move follows a recent cyberattack that forced a small UK power generation facility offline for four days.
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“A government-mandated remote shutdown capability for data centers is a pre-installed denial-of-service mechanism waiting for the wrong hands. The amendment to the UK’s Cyber Security and Resilience Bill would require operators to build and maintain the exact infrastructure an attacker would need to cause the disruption the legislation claims to prevent. Compromise the authorization channel, and the government has handed the attacker a shutdown switch labeled “safety.”
“Responsibility for containing an AI system sits with the operator running it. If you’re deploying AI on critical infrastructure and cannot kill your own workload when it goes sideways, a minister reaching for a centralized override just confirms nobody expected operators to manage their own systems.
“Cybersecurity minister Baroness Lloyd rejected the proposal, arguing that directing an organization to stop using a specific AI model is more proportionate than shutting down shared infrastructure thousands of services depend on. She’s right.
“The supply-chain provisions in the same bill, letting ministers block critical infrastructure operators from using high-risk technology suppliers, respond to something real. An Iran-linked cyberattack forced a small UK energy generator offline for four days in July. Controlling which vendors touch critical networks addresses the entry point. A kill switch addresses the blast radius after the breach has already happened, and it does so by adding a new attack surface to defend.”
John Strand, Owner, Black Hills Information Security, Inc.:
“I feel like conversations like this in legislatures around the world are incredibly important, and I think many of the provisions being discussed absolutely should be put in place.
“However, I also think the way the conversation is arcing fundamentally misses the point of what AI actually is.
“AI is not something that can be controlled simply by regulating powerful companies like Anthropic, Google, and OpenAI. The technology is already dispersed. With roughly $5,000 worth of hardware, someone can run a highly functional model locally that may be slower than the most powerful commercial models, but can potentially be every bit as destructive.
“If our entire strategy for AI safety is built around restricting what large companies can do with potentially dangerous models, we’re addressing only one part of the problem. Those restrictions may be valuable, but they don’t address what happens when capable models are downloaded, modified, fine-tuned, and operated completely outside those environments.
“There needs to be a much larger conversation about mitigating controls. We need to be thinking about how organizations detect and respond to AI-enabled attacks, how infrastructure is protected when the attacker has access to these capabilities, and what defensive technologies need to change when powerful AI is available to practically anyone willing to invest a few thousand dollars in hardware.
“Regulating the largest AI companies may be part of the answer.
“It cannot be the entire answer.”
I seriously doubt that this is the answer. Thus I hope this gets the time and consideration that this does deserve.
Related
This entry was posted on September 3, 2026 at 4:41 pm and is filed under Commentary with tags UK. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
UK considers new powers to shut down dangerous AI and block risky tech suppliers
UK lawmakers are considering giving the government emergency powers to deactivate powerful AI systems and shut down data centers if the technology poses a national security threat.
The proposed “kill switch,” introduced as an amendment to the Cyber Security and Resilience Bill, is intended as a last-resort mechanism to stop a runaway AI system before it can compromise critical national infrastructure.
At the same time, the UK government has introduced separate amendments to the same cybersecurity bill that would allow ministers to prevent critical infrastructure organizations from using technology suppliers deemed high risk. The new authority is aimed at supply-chain threats, where attackers can compromise a smaller technology provider and use its access to reach more sensitive organizations.
The move follows a recent cyberattack that forced a small UK power generation facility offline for four days.
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“A government-mandated remote shutdown capability for data centers is a pre-installed denial-of-service mechanism waiting for the wrong hands. The amendment to the UK’s Cyber Security and Resilience Bill would require operators to build and maintain the exact infrastructure an attacker would need to cause the disruption the legislation claims to prevent. Compromise the authorization channel, and the government has handed the attacker a shutdown switch labeled “safety.”
“Responsibility for containing an AI system sits with the operator running it. If you’re deploying AI on critical infrastructure and cannot kill your own workload when it goes sideways, a minister reaching for a centralized override just confirms nobody expected operators to manage their own systems.
“Cybersecurity minister Baroness Lloyd rejected the proposal, arguing that directing an organization to stop using a specific AI model is more proportionate than shutting down shared infrastructure thousands of services depend on. She’s right.
“The supply-chain provisions in the same bill, letting ministers block critical infrastructure operators from using high-risk technology suppliers, respond to something real. An Iran-linked cyberattack forced a small UK energy generator offline for four days in July. Controlling which vendors touch critical networks addresses the entry point. A kill switch addresses the blast radius after the breach has already happened, and it does so by adding a new attack surface to defend.”
John Strand, Owner, Black Hills Information Security, Inc.:
“I feel like conversations like this in legislatures around the world are incredibly important, and I think many of the provisions being discussed absolutely should be put in place.
“However, I also think the way the conversation is arcing fundamentally misses the point of what AI actually is.
“AI is not something that can be controlled simply by regulating powerful companies like Anthropic, Google, and OpenAI. The technology is already dispersed. With roughly $5,000 worth of hardware, someone can run a highly functional model locally that may be slower than the most powerful commercial models, but can potentially be every bit as destructive.
“If our entire strategy for AI safety is built around restricting what large companies can do with potentially dangerous models, we’re addressing only one part of the problem. Those restrictions may be valuable, but they don’t address what happens when capable models are downloaded, modified, fine-tuned, and operated completely outside those environments.
“There needs to be a much larger conversation about mitigating controls. We need to be thinking about how organizations detect and respond to AI-enabled attacks, how infrastructure is protected when the attacker has access to these capabilities, and what defensive technologies need to change when powerful AI is available to practically anyone willing to invest a few thousand dollars in hardware.
“Regulating the largest AI companies may be part of the answer.
“It cannot be the entire answer.”
I seriously doubt that this is the answer. Thus I hope this gets the time and consideration that this does deserve.
Share this:
Like this:
Related
This entry was posted on September 3, 2026 at 4:41 pm and is filed under Commentary with tags UK. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.