Lords weigh data centre shutdown powers

Lords weigh data centre shutdown powers

A Lords amendment to the Cyber Security and Resilience Bill proposes emergency powers to direct data centre shutdowns during severe AI-related incidents, while separate amendments on thresholds and critical suppliers…

Lords weigh data centre shutdown powers
Summary
  • The government Bill would regulate qualifying data centres under the NIS regime, generally from 1MW rated IT load and 10MW for enterprise facilities.
  • Amendment 84 proposes last-resort powers to direct data centre or large-scale AI system shutdowns during defined catastrophic emergencies.
  • A proposed risk-based data centre threshold was withdrawn, while a separate systemic critical-supplier amendment was not moved.

Peers are considering a proposal to give ministers last-resort powers to direct the shutdown of data centres during severe AI-related security or operational emergencies as scrutiny of the UK’s Cyber Security and Resilience (Network and Information Systems) Bill continues in the House of Lords.

Amendment 84, tabled by Lord Clement-Jones and supported by peers including Baroness Kidron and Baroness Harding of Winscombe, has not yet been considered by the House. It would allow regulations to confer powers on the Secretary of State to direct the shutdown of data centres, or AI systems deployed on a substantial scale, during an AI security or operational emergency.

The proposal is separate from the government’s core data centre provisions in the Bill. Those would bring qualifying facilities directly into the Network and Information Systems regime, with Ofcom acting as operational regulator.

Government guidance says third-party data centres with rated IT load of at least 1MW would generally enter scope, while the threshold for enterprise facilities operated solely for their owner’s IT requirements would be 10MW.

A high bar for emergency intervention

Amendment 84 defines an AI security or operational emergency around a compromise affecting relevant network and information systems where AI use or operation has caused or contributed to the incident and the resulting risk is considered catastrophic.

The definition sets a deliberately high threshold. Catastrophic risk would include a reasonable likelihood of large-scale disruption to critical infrastructure or essential services, significant degradation of UK national security, defence or intelligence capabilities, or severe large-scale harm to human life.

Under the amendment, regulations could require data centre operators supporting AI systems to install technical infrastructure necessary to comply with a shutdown direction, maintain secure communications with government, carry out emergency exercises, and complete post-incident processes before operations resume.

It would also permit regulations providing powers to close premises or turn systems off where officials reasonably believe relevant offences are being, have been, or may be committed. Parliamentary reporting and access to the High Court would form part of the proposed safeguards.

None of those powers exists by virtue of the amendment today. Parliament has recorded no decision on Amendment 84, and its eventual inclusion in the Bill remains uncertain.

Other Lords proposals have already fallen away

The status of other amendments illustrates why the distinction between a tabled proposal and legislation is important.

An amendment led by Baroness Kidron proposed allowing Ofcom to bring a data centre into scope irrespective of its rated IT load where disruption could significantly affect the economy or day-to-day functioning of society. That proposal was withdrawn after debate, and no decision was taken on it.

A separate amendment from Lord Ravensdale sought to constrain the designation of critical suppliers by requiring regulators to focus on systemic risk, supplier concentration, substitutability, and the potential for cascading failure. Parliament records that amendment as not moved.

The underlying Bill nevertheless represents a substantial change for UK data centre operators without either proposal. Government policy would designate data centres as essential services under the NIS framework and require qualifying operators to notify Ofcom, implement appropriate and proportionate cyber and operational resilience measures, and report significant incidents.

The regime also gives government and regulators broader mechanisms to respond to threats affecting critical digital infrastructure. Separate provisions in the Bill would allow ministers to direct regulated entities to take necessary and proportionate action where an imminent or live threat puts national security at risk.

Data centres were designated as UK critical national infrastructure in 2024, but the government says the sector currently lacks minimum statutory requirements for cyber security and operational resilience comparable with other regulated essential services.

The Bill therefore moves the sector from critical-infrastructure recognition towards direct regulatory obligations. The remaining parliamentary argument is increasingly about how far those powers should extend when conventional cyber incidents overlap with AI systems, concentrated suppliers, and physical facilities supporting essential services.

Amendment 84 pushes that question to its outer edge by proposing a mechanism for emergency shutdowns. Its status remains unresolved, while the withdrawn and unmoved amendments show that much of the detail being tested in the Lords may never reach the final legislation.


Stay updated with the latest insights and trends in the data centre industry by subscribing to our newsletter.

← Back

Thank you for your response. ✨