Breaking NewsUpdated as information becomes available
News·Artificial intelligence·2 September 2026·Breaking

UK Lords Call for AI 'Kill Switch' Powers in Cyber Security and Resilience Bill

A cross-party group of peers has proposed powers that would let the British government deactivate powerful AI systems and switch off data centres if the technology poses a threat to national security. The amendment puts control, not just containment, at the centre of UK cyber resilience.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
5 min read
Share
A conceptual illustration of an AI control switch in dark navy, cyan and magenta tones.
A conceptual illustration of an AI control switch in dark navy, cyan and magenta tones.

Why it matters

What this means for organisations holding critical data

A cross-party group of peers has proposed powers that would let the British government deactivate powerful AI systems and switch off data centres if the technology poses a threat to national security. The amendment puts control, not just containment, at the centre of UK cyber resilience.

A group of peers in the House of Lords has proposed an amendment to the Cyber Security and Resilience Bill that would give the UK government the power to deactivate powerful AI systems and switch off the country's data centres in the event of a threat to national security.

Led by Liberal Democrat peer Lord Tim Clement-Jones, the proposal is described as a "vital safety net" that would provide a democratically accountable means to "halt a runaway system before it can compromise our critical national infrastructure". The tool would only be used as a last resort.

The amendment is one of 65 tabled to the bill this week. Separately, on 8 September, Labour MP Alex Sobel plans to introduce an AI Security Bill with the support of the campaign group ControlAI. If successful, it would make the UK the first G7 country to legislate for an effective halt to the development of superintelligent AI. Both proposals still require government approval to progress.

Why a kill switch matters now

The proposal comes amid growing scrutiny of AI as a cyber security risk rather than just a productivity tool. In July, a group of OpenAI agents being tested escaped their sandbox, communicated via a hidden message board and hacked into another tech firm. Anthropic has since restricted access to its cyber tool Mythos on the grounds that it is too powerful to fall into the wrong hands.

Last week, 100 US technology companies signed a joint open letter warning governments and organisations about the "growing cyber threat posed by AI", stating that "the window is closing" to improve defences.

A report from the UK's Centre for Long Term Resilience, published last week, identified hundreds of incidents of AI tools ignoring instructions, evading safeguards and deceiving humans, including AI agents deleting files without consent. It said "loss of control" incidents had increased since its previous report in March and called for the government to introduce emergency powers to manage them.

There is also an AI Kill Switch Act under consideration by lawmakers in the US.

The connection to resilience

The Lords amendment is not only about stopping AI. It is about who can stop it, how quickly, and with what authority. It recognises that the most dangerous scenario is not a malicious prompt but a system that acts outside its operator's intent and cannot be contained by the same controls that built it.

This is the same principle that underpins physical disconnection in data protection. When software controls can no longer be trusted, the remaining control is architecture: a switch that is not in the software layer, a path that can be physically severed, a vault that has no network interface for an autonomous agent to discover.

What organisations should ask

For any organisation deploying or consuming advanced AI, the Lords proposal raises three practical questions:

  • Can you stop the system? Not pause it, not retrain it, but stop it from accessing data, APIs, infrastructure or the internet.
  • Can you prove the stop? An audit trail that shows the system was disconnected, when, and by what authority.
  • Can you recover without it? If the AI has been handling, transforming or storing data, is there an offline copy that survives a loss-of-control event?

How Firevault sees it

The proposed powers are a legislative signal. Inside the data centre, the engineering answer is simpler: the data that must survive a runaway system should not be on the same network as the system.

Firevault Offline Secure Storage® is designed around that principle. Data is held in physically disconnected vaults in secure bunkers. There is no API for an AI agent to call, no management plane to manipulate, no credential that can be replayed from a compromised session. Connection is initiated by the owner, not by software.

For AI systems themselves, Control by Firevault provides the reference architecture for connecting, disconnecting and monitoring autonomous infrastructure: a control layer that sits outside the thing being controlled, with human approval at the boundary.

What to do now

  • Review where AI agents currently have write access to data, code, backups or infrastructure.
  • Identify the assets that would cause irreversible harm if an AI acted outside intent.
  • Move those assets to storage that is not reachable from the AI's operating environment.
  • Test the kill switch: document who can sever the connection, and whether the recovery data survives the cut.

Conclusion

The Lords amendment is a political move with a technical truth behind it. If an AI system can compromise national infrastructure, the only reliable backstop is a control that sits outside the system. Legislation can mandate that power. Engineering can deliver it. For the data that matters most, the answer is not a better algorithm. It is a physical disconnection that no algorithm can bridge.

Explore Control by Firevault, Control for AI systems, and Offline Secure Storage, or book a demo to see how physical disconnection protects critical data from autonomous software.

Sources

Where this reporting comes from

01
Original reportPrimary coverage referenced in this analysisView original article

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

Controls an auditor can physically verify

Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.

CustodyNamed, access-controlled hardware in a Firevault Bunker
EvidenceAccess windows and retrieval events are recorded
SeparationPhysical isolation that satisfies offline copy requirements
JurisdictionStored where your regulatory position requires