The Register Home Page

back to article UK cyber bill targets AI users, not the vendors building it

The UK government has rejected proposals from members of the the House of Lords to bring AI vendors within the scope of the Cyber Security and Resilience (Network and Information Systems) Bill. Cybersecurity minister Baroness Lloyd of Effra argued that regulating AI vendors and frontier model developers through the bill would …

  1. Anonymous Coward
    Anonymous Coward

    I kind of agree with them on this. If someone used a crowbar to break into my house then I can't really blame the company that made the crowbar. They could have used a big screwdriver instead.

    All AI is doing is automating something you can learn to do yourself. The onus should be on you to protect yourself from it. Do we ban infosec books that show exploits? We do not.

    Having said all that they may need to have some oversight and regulation. I can't just go and buy a gun and for good reason. In fact it would be extremely difficult for me in the UK to get a firearms licence and I would be extremely limited with what I could with it which is sensible. You can 3D print a gun apparently and you can also build your own AI/ML model as well. Personally I would just regulate that using AI as a tool to do the infosec work for you is never offered for free and be done with it, not foolproof of course but it's goes some way to identify people that use it nefariously and limits it that way. You could give organisations the option to go on a list of domains/IP addresses that are off limits for the tools like the NHS but then I would rather the NHS fix any holes in it's security than hiding behind that because if these tools don't exploit it then eventually someone else will anyway.

    Tough choices but who am I to say what's the right one. I can only give my opinion.

    1. Anonymous Coward
      Anonymous Coward

      It should be illegal to provide an AI service which knowingly produces output that breaks the law. The provider of that service is complicit:- they are providing the output, not the user.

      1. Anonymous Coward
        Anonymous Coward

        As I pointed out. You could read a book or look at a website that tells you how to hack. The user is asking for the output but you the user can also create the output on your own. Would the provider of the book be complicit? All you are doing is taking a shortcut using AI/ML. Should we ban Kali Linux as well? Actually, should we ban Linux altogether due to the fact you can install hacking tools?

        This output that breaks the law can be used in one of two ways. White hat and Black hat. That there creates a conundrum the same as some laws prevent white hat hackers from exposing leaks for good.

        That was the point I was making. I'm no fan of AI/ML but we need to be measured in how we deal with it and what it has created because it's not going away and banning it from doing certain things isn't going to magically stop it. What happens if we ban it in the UK but the US doesn't? Do you think these companies are going to follow our laws around the world just because we said so?

        1. Anonymous Coward
          Anonymous Coward

          >>> I'm no fan of AI/ML

          What's wrong with ML? The production lines at my employer use machine vision to inspect the products very quickly and very accurately.

          To paraphrase Sturgeon: "Ninety percent of AI is crud."

          1. Anonymous Coward
            Anonymous Coward

            Using it to inspect product lines is not the topic we are discussing as per the article. I never said it didn't have it's uses. I'm just not a fan. I use the term AI/ML because there is no such thing as AI. There is no intelligence. It's probability based on data fed into it using maths on a massive scale with the ability to use that decision making to actually do something. It's no more intelligent than my vacuum cleaner. I turn it on and I feed it dirt. If I added filters and chambers to sort the dirt by particle size would I call my vacuum intelligent?

    2. Paul Herber Silver badge

      "Tough choices but who am I to say what's the right one. I can only give my opinion."

      You'll never make it as a politician.

      1. Anonymous Coward
        Anonymous Coward

        and for that my soul is safe.

    3. Sir Sham Cad

      Re: rather the NHS fix any holes in it's security

      The problem is knowing which holes exist (and there's rarely a week goes by without getting a Critical alert from the NCSOC for some new sploit in some core app or infrastructure) before the bad guys because AI can find these holes at machine speed and we're getting the info at meat speed and then trying to schedule in a patch as quickly as safely possible, meanwhile, at machine speed, the bots just keep on finding sploits.

      There's already legislation that requires us to have levels of Security compliance (DSPT-CAF) and responses to the aforementioned Critical sploit alerts (I got volunteered to handle the NIS notice on our win7 to win10 compliance - not recommended) but not, for example, Cisco, Fortinet, Orrible, Clippysoft etc... who all feature regularly on the NCSOC (s)hit parade.

      Basically because regulation of Big Tech is hard and victim blaming is easy.

  2. VoiceOfTruth Silver badge

    Cybersecurity minister Baroness Lloyd of Effra

    Well qualified, with a law and history degree.

    Her password is probably 'l3tme1n'.

    1. Paul Herber Silver badge

      Re: Cybersecurity minister Baroness Lloyd of Effra

      Was that her favourite songs by The Osmonds?

  3. LessWileyCoyote

    One potential problem with calling for constraints against AI providers is that they are situated outside the UK, and therefore outside the reach of our laws (like much of the IT infrastructure we use).

    Neither the US or China are likely to pay any attention to restraints constructed by our lawmakers, and international laws are increasingly ignored.

    1. Paul Herber Silver badge

      "situated outside the UK, and therefore outside the reach of our laws"

      You'll never make is as a US (Ontario branch) politician!

    2. Jason Bloomberg Silver badge

      they are situated outside the UK, and therefore outside the reach of our laws

      If they are providing services in or to the UK they must comply with UK laws or cease providing those serves.

      That's why Ofcom can fine foreign companies and entities for not complying with the Online Safety Act (OSA).

      UK governments could block those services if they don't comply with UK law but I doubt any has the backbone to do so. Especially given they like to brag about how they are "doing something", how big those fines are, even if they will never be paid.

      Ofcom fined '8579 LLC' £1.35 million, plus £1,000 a day, for failing to have age verification checks for their porn sites. As far as I can see all Ofcom have achieved is to provide a list of sites for those wanting to avoid age verification.

      1. JT_3K

        Oh no, that's terrible. Where would one find such an article from OFCOM? I mean, to corroborate your story for themselves?

        1. Anonymous Coward
          Anonymous Coward

          https://www.ofcom.org.uk/siteassets/resources/documents/about-ofcom/bulletins/enforcement-bulletin/all-cases/cw_01314/non-confidential-confirmation-decision-8579-llc.pdf

          [Footnote 53] "Ofcom’s reviews demonstrated that crazyporn.xxx, hoes.tube, justpornflix.com, and love4porn.com were each freely accessible on the open web from a UK IP address."

          This has been a public service announcement.

          Full disclosure: I get my wrist-related cardio-workout from a different service provider.

    3. Tron Silver badge

      Yes, in terms of tech, the UK = The Faroe Islands.

      But if the activists had their way, we wouldn't have an internet. They would demand that the government block it all. We have already lost too much of it courtesy of the overreach and censorship.of the OSA. And will no doubt lose more through mission creep.

      We are not children and the govt shouldn't attempt to parent us.

      Personally, I am avoiding the whole AI scam. Whilst noting in passing the irony that the sector it may cannibalise the most, is the tech sector that created it. Truly, revolutions eat their children.

  4. VMYak

    We don;t know what to do so we'll rely on 'self regulation'. Governments really are hopeless when it comes to anything that is a bit complicated.

    As Harry Hill's brother Alan (MP for Stains) used to say - "If its too hard I can;t think about it!"

  5. Groo The Wanderer - A Canuck Silver badge

    Voluntary safeguards. How cute - those have worked so very, very well with the tobacco, pharmaceutical, and online megacorp presences like Facebook to get them to stop targeting under-age users and abusing them with advertising. Maybe for an encore they can tell us that they've turned over the federal bank to a con artist like Drumpf.

  6. Anonymous Coward
    Anonymous Coward

    None of it matters

    Not one jot.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon