Sponsored

A security tool at a UK data centre flags an unusual sequence of network activity. Its machine-learning model gives the event a risk score, but an analyst initially decides that the evidence is too weak to escalate. Hours later, more signals arrive and the incident is confirmed.

Under the Cyber Security and Resilience Bill, the time of first awareness would matter. The latest parliamentary text would give an in-scope operator 24 hours from that point for an initial notification and 72 hours for a full notification. Yet Ofcom, the proposed regulator for data centres, has not said when the output of a probabilistic defence tool should become reliable enough to inform that judgement.

That is the gap between two pieces of work now moving on different timetables. Parliament is writing incident clocks into law. Ofcom has opened an autumn engagement on AI in cyber defence and expects to publish findings in early 2027. The regulator has asked about trust, assurance, accountability and compliance, but it has not proposed a model-specific test, audit method or documentation standard.

The gap does not make defensive AI unusable. It does make evidence around its use a supervisory issue, especially when an alert influences whether a statutory clock has started.

The bill sets the perimeter and the clocks

The current bill, dated 7 September and amended in Lords Grand Committee, would add data infrastructure to the Network and Information Systems regime. It names the Office of Communications as the competent authority and treats qualifying data-centre services as essential services.

The threshold is a rated IT load of at least 1 megawatt for a commercial data centre and at least 10 megawatts for one provided on an enterprise basis. The bill defines rated IT load as the maximum electrical power available to operate the IT equipment housed in the facility.

This is proposed law, not a duty already in force. The bill has completed Lords committee stage, with report stage scheduled for 26 October. The government’s implementation factsheet says data-centre and incident-reporting measures would commence through secondary legislation after Royal Assent, following further technical work.

The reporting scope is deliberately wider than an outage. The text defines a data-centre incident to include one that could have had, has had, is having or is likely to have a significant impact on the security or operation of the relevant systems, on service continuity, or another significant impact in the UK.

Once the operator is first aware that such an incident has occurred or is occurring, the proposed clocks run in parallel. The initial notification, containing the operator’s name, the affected service and brief details, is due within 24 hours. The fuller notice is due within 72 hours and, so far as known, must cover timing, duration, whether the event is continuing, its nature and its actual or potential impact. A copy goes to the national computer security incident response team at the same time as it goes to the regulator.

The bill does not say that every automated alert creates organisational awareness. Nor does it excuse an operator that configures its systems or escalation process so poorly that significant signals are routinely ignored. The boundary between those positions will matter.

Probabilistic tools can rank anomalies, connect weak signals and accelerate investigation. They can also produce false positives, miss unfamiliar attacks, drift as network conditions change, or behave differently after a vendor updates a model. A score without its operating context cannot show whether an incident was significant or when a responsible decision-maker had enough information to recognise it.

Ofcom’s 15 September engagement acknowledges the problem at a high level. It says AI works differently from many other security technologies because of its probabilistic nature. It will hold discussions with regulated companies, technical experts and vendors during the autumn, looking at both the benefits and the questions around trust, assurance, accountability and existing cyber-security requirements.

Its 2026/27 AI strategy goes a little further. Ofcom says strong oversight and understanding of a security control affect confidence in AI, and envisages work on vendors and third-party assurance with the Department for Science, Innovation and Technology and the AI Security Institute. It still does not prescribe an assurance threshold.

The evidence an operator will need

There is already useful government guidance, but it does not answer the regulatory question on its own. In April, Ofcom told existing operators of essential services to assess frontier-AI risks, implement appropriate measures aligned with the NCSC Cyber Assessment Framework and follow relevant NCSC advice.

The NCSC’s secure AI development guidance calls for documented models, data, prompts, limitations and failure modes. Its deployment guidance recommends high-quality audit logs, incident procedures, benchmarking and red-team evaluation.

Those controls point towards a practical evidence file. A data-centre operator using AI in detection or triage should be able to show which model and version produced an alert, what data it observed, how its performance was validated in the operator’s environment, and what thresholds routed an event to human review. Records should preserve changes to the model, prompts and configuration, the analyst’s decision, later evidence and any override.

Performance should be measured against the task that affects reporting, rather than a vendor’s general benchmark. For a detection tool, that means false negatives as well as false positives, time to escalation, results on unfamiliar attack patterns and behaviour after material changes. A fallback is also necessary when the model or its supplier becomes unavailable.

These are inferences from the proposed reporting duties and existing security guidance, not requirements Ofcom has yet published for AI-enabled defence. They would, however, let an operator reconstruct why it treated a signal as an incident at a particular time. They would also let the regulator test whether human oversight was real or merely a label attached to automated triage.

Assurance must meet the reporting timetable

Ofcom does not need to certify every model before operators can use AI. A single pass-fail test would age quickly and could encourage firms to treat assurance as a procurement event. The more durable approach is evidence tied to the control’s role, followed by monitoring as the system and threat environment change.

But the regulator will need to be more specific than its opening engagement if AI is to influence statutory incident decisions. Operators need to know what proof Ofcom will accept for detection performance, vendor claims, model changes, auditability and human escalation. They also need clarity on how a regulator will examine a delayed notification when the earliest signal came from a tool with an uncertain output.

The bill’s clocks are visible. The assurance test is not. Before the data-centre duties commence, those two strands need to meet in guidance that makes faster defence compatible with accountable reporting.

Sources

Imogen Fairchild

Contributing writer at Clarqo.