Artificial Intelligence is quickly becoming part of everyday business operations, from customer support and marketing to cybersecurity and operational automation. However, recent debates surrounding the UK’s Cyber Security and Resilience (Network and Information Systems) Bill highlight an important shift: responsibility for secure AI use may fall more heavily on organisations deploying AI than on the companies that build it.

The UK government has rejected proposals to bring AI model developers directly into the scope of the legislation, arguing that regulating vendors would not necessarily prevent malicious use of AI systems. Instead, the bill focuses on strengthening cybersecurity requirements for organisations operating critical systems and infrastructure.

For business leaders, the message is clear: if your organisation uses AI, you remain responsible for managing the associated cyber risks.

Businesses Cannot Assume AI Vendors Carry All the Risk

Many organisations assume that security responsibility sits primarily with the AI provider. The latest parliamentary discussions suggest otherwise.

Government ministers have maintained that the legislation should remain technology-neutral, placing obligations on organisations that operate critical systems rather than on the technology manufacturers themselves.

This means businesses using AI tools should be asking questions such as:

  • What data is being shared with AI systems?
  • How are outputs verified before use?
  • What controls prevent unauthorised access?
  • How are AI-related risks assessed and documented?

As AI becomes more deeply integrated into business workflows, governance and oversight become increasingly important.

Need Advice on Microsoft 365 Security?

Get free insights into the health of your IT estate, with no pushy sales, and no obligation to sign up.

Voluntary Standards Are Becoming the Benchmark

Instead of imposing direct regulatory requirements on AI vendors through the bill, the UK government is pointing towards industry standards and voluntary frameworks.

One example is ETSI EN 304 223, a cybersecurity standard that establishes baseline security requirements for AI models and systems throughout their lifecycle. The standard addresses risks such as:

  • Data poisoning
  • Model manipulation
  • Prompt injection attacks
  • AI system resilience
  • Security monitoring and auditability

The framework promotes secure design, deployment, maintenance, and retirement of AI systems.

For businesses, adopting recognised standards may become a competitive advantage when demonstrating due diligence to customers, partners, insurers, and regulators.

AI Risk Management Is Becoming a Board-Level Issue

Concerns raised during the House of Lords debate included the potential for AI systems to evade oversight, assist hostile actors, or behave in unexpected ways. While opinions vary on the scale of these risks, there is growing agreement that organisations need formal governance around AI deployment.

Practical safeguards include:

  • AI usage policies
  • Human review processes
  • Security testing of AI-enabled systems
  • Access controls for AI platforms
  • Continuous monitoring and audit logging
  • Supplier security assessments

Organisations that treat AI like any other critical business system will be better positioned to manage risks as regulations evolve.

Managed Service Providers and Critical Suppliers Face Greater Scrutiny

The wider Cyber Security and Resilience Bill extend cybersecurity obligations beyond traditional critical infrastructure sectors. Managed Service Providers (MSPs), large datacenters, and designated critical suppliers are all being brought further into scope.

This is particularly relevant for organisations that:

  • Outsource IT management
  • Use cloud-first infrastructure
  • Depend heavily on third-party technology providers
  • Operate within critical supply chains

The government estimates that hundreds of additional MSPs will be subject to cybersecurity requirements under the updated framework.

Businesses should expect increased focus on supply chain security, third-party risk assessments, and incident reporting over the coming years.

What This Means for Your Business

The debate around AI regulation is far from over, but one theme is consistent: organisations cannot rely solely on AI vendors to manage cybersecurity risks.

Business leaders should:

  1. Review how AI is currently being used across the organisation.
  2. Identify where sensitive data may interact with AI systems.
  3. Establish governance and approval processes for AI adoption.
  4. Assess third-party AI suppliers and service providers.
  5. Align security controls with recognised frameworks and standards.

Even if future legislation eventually targets AI developers directly, organisations deploying AI will still need to demonstrate responsible and secure use.

Need Help Understanding AI and Cybersecurity Compliance?

AI adoption creates significant opportunities, but it also introduces new responsibilities. Our support team can help you evaluate AI-related risks, strengthen cybersecurity controls, review supplier security, and prepare for evolving regulatory requirements.

If you’re unsure whether your current AI usage aligns with emerging best practices, get in touch for a practical, business-focused discussion.

Want help with your IT?

Get free insights into the health of your IT estate, with no pushy sales, and no obligation to sign up.