What should AI operators prepare for the UK Cyber Security and Resilience Bill?
Prepare the evidence discipline NIS2 already demands: know your suppliers, log what your AI does, and report from records you hold.
AI operators should prepare the same evidence discipline that NIS2 already demands in the EU: know your suppliers, log what your systems and their AI components actually do, and be able to report incidents quickly from records you hold yourself. The Cyber Security and Resilience Bill was introduced to Parliament in 2025 and is still progressing as of mid 2026, so its final shape is not settled. The direction of travel reported at its introduction is wider scope including managed service providers, stronger incident reporting duties, and cost recovery powers for regulators. Preparing to the strictest plausible reading costs little now and de-risks whatever text finally lands.
The question matters in 2026 because UK organisations sat outside NIS2 while their EU peers absorbed it, and the Bill is the UK's answer: firms that wait for Royal Assent to begin will be building evidence pipelines under deadline pressure their EU counterparts took on gradually.
What is the Cyber Security and Resilience Bill?
It is the UK government's update to the Network and Information Systems Regulations 2018, the UK's implementation of the original EU NIS Directive. The UK did not adopt NIS2 after leaving the EU, so its regime has aged while the EU's moved on. The Bill, introduced to Parliament in 2025, is intended to close that gap. As of mid 2026 it remains in passage, which means its provisions should be read as direction of travel rather than settled law, and any preparation plan should be written to survive amendment.
What is the Bill expected to change?
As reported at introduction, and subject to amendment, the main expected changes are:
- Wider scope, bringing managed service providers into regulation given their privileged access to client systems.
- Stronger incident reporting duties, moving closer to the tight timelines EU entities already meet under NIS2.
- Cost recovery powers, allowing regulators to fund oversight activity from the firms they regulate.
- More flexible powers to expand scope and update requirements as the threat picture changes.
None of this is final until the Act passes, and details such as thresholds and timelines may move. The prudent posture is to prepare to the strictest plausible reading and treat anything softer as a bonus.
When will it become law?
No firm date can be stated responsibly while the Bill is in passage. What can be said is that the regime it replaces dates from 2018, the threat environment has not waited, and government statements have consistently framed the Bill as a priority. Organisations that treat the passage period as a preparation window will meet commencement with working evidence pipelines. Organisations that treat it as a delay will discover that supplier mapping and system logging cannot be retrofitted in a single compliance quarter.
Why does the Bill matter for AI operators specifically?
Because AI components are becoming part of the operational chains the Bill will regulate, and because AI supplied as a managed service sits exactly where the reported scope expansion points. An operator using a cloud AI service inside an essential service has added a supplier with privileged access to its data and a runtime it cannot observe. If reporting duties tighten, the operator will need to explain what that component saw and did during an incident, on a statutory clock, from evidence it may not hold. That is the same structural problem NIS2 exposed across the EU, arriving in UK law.
What evidence should you already be able to produce?
We suggest preparing four artefacts now, whatever the final text says. A supplier map covering every service, including AI services, that touches systems in likely scope, with access levels recorded. Local logging of what each system and AI component actually does, held in records you control. A rehearsed incident reconstruction: pick a window, answer what happened from your own records, and time the exercise. And contractual evidence duties flowing down to suppliers, so their part of an incident narrative arrives on your clock rather than theirs. All four are useful under the current NIS 2018 regime, all four are demanded in substance by NIS2, and all four will serve under any plausible final Bill.
“Preparing for an unfinished statute means building the evidence discipline every plausible version will demand.”
How does operator-owned AI simplify the preparation?
It removes the hardest dependency from the evidence chain. Mickai is a Sovereign Intelligence Operating System, a SIOS, that runs offline on operator-owned hardware behind a zero-egress inbound perimeter. Every action is sealed in an audit ledger signed under FIPS 204 (ML-DSA), bound to hardware-attested identity, and verifiable offline. For an operator preparing for the Bill, the AI layer generates its own compliance evidence locally as a property of the architecture: nothing to request from a vendor, no retention policy to negotiate, no support queue standing between an incident and its reconstruction.
How the architecture behind that evidence discipline fits together is set out at /sovereign-ai, and the film at /film shows the interface in operation.
Frequently asked questions
Is the Cyber Security and Resilience Bill law yet?
No. It was introduced to Parliament in 2025 and remains in passage as of mid 2026, so its provisions are not settled law and may change before Royal Assent. Descriptions of its content should be read as the direction reported at introduction, not as final requirements.
Will the Bill cover managed service providers?
That is the stated intention reported at introduction, reflecting the privileged access such providers hold into client systems. The final scope and thresholds depend on the text as passed. Providers of AI delivered as a managed service should assume they are in the direction of travel and prepare accordingly.
Does the UK follow NIS2?
No. NIS2 is an EU directive and does not apply in UK law. The UK runs its own regime under the NIS Regulations 2018, which the Cyber Security and Resilience Bill is intended to update. UK firms still meet NIS2 indirectly where they have EU operations, subsidiaries or customers passing obligations down contractually.
What should my company do now, before the Bill passes?
Map suppliers and their access levels, including AI services; log what systems and AI components do in records you hold; rehearse incident reconstruction against a real window and time it; and put evidence duties into supplier contracts. These steps carry value under the current NIS 2018 regime, under NIS2 where EU exposure exists, and under any plausible final Bill.
How does the Bill affect companies using cloud AI services?
If scope widens to managed service providers and reporting duties tighten, the inability to observe a cloud AI runtime becomes a concrete reporting problem: the operator owes the regulator a narrative it cannot assemble from its own records. Operators should either secure contractual evidence rights with tested response times or move the AI layer onto infrastructure they control.