Ian Murray MP: speeches

433 published records · newest first.

Speeches

  • 6 Jan 2026 · Cyber Security and Resilience (Network and Information Systems) Bill · Hansard source
    More

    I beg to move, That the Bill be now read a Second time. A happy new year to you, Mr Speaker, and to all the House staff. This is the first opportunity I have had to say that to you. On 3 June 2024, a busy Monday morning in south-east London, criminals attacked Synnovis, an organisation that processes blood tests on behalf of our national health service. They did not turn up physically, but logged on to computers thousands of miles away and set off ransomware—malicious software that encrypts files from afar, making them unusable. The attack had a ripple effect across London hospitals. It delayed 11,000 appointments, blood transfusions had to be suspended and the company lost tens of millions of pounds. This was not an isolated case. In the year leading up to September 2025, the National Cyber Security Centre dealt with 204 “nationally significant” incidents, meaning that they seriously disrupted central Government or our critical public services. That is more than double the 89 incidents in 2024. No one disputes that we must do everything we can to protect the UK from these attacks. The UK is the most targeted country by cyber-attacks in Europe, and it was the fifth most targeted nation in 2024 by nation state-affiliated threat actors. In 2024, it is estimated that UK businesses experienced over 8.5 million cyber-crimes in the 12 months preceding the survey, and that in that year more than four in 10, or 43%, of UK businesses were subject to a cyber-attack, affecting more than 600,000 businesses in total. Significantly, cyber-attacks are estimated to cost UK businesses almost £15 billion each year, equivalent to 0.5% of the UK’s annual GDP, notwithstanding the wider economic effects of intellectual property theft or the experience of patients, as in the first example. The average cost of a significant cyber-attack for an individual business in the United Kingdom is estimated to be just over £190,000. There has been a 200% increase in global cyber-attacks on rail systems in the past five years, increasing the likelihood of severe disruption to the economy and to people’s daily lives.

  • 6 Jan 2026 · Cyber Security and Resilience (Network and Information Systems) Bill · Hansard source
    More

    The banking sector is obviously in the regulators’ scope for cyber-security, and there have been a number of outages, as my hon. Friend mentions. The general principle is that cyber-attacks no longer come in through the front door, but through third parties and suppliers. We have seen that, for example, in the recent incidents at Heathrow and in cloud outages with Amazon Web Services and other such companies. They are covered by their own regulations. As I said in answer to my hon. Friend the Member for Lichfield (Dave Robertson) about Jaguar Land Rover, those companies will not be in the scope of the Bill, but we hope that the financial services sector, which is a leader in cyber-security for a whole host of fairly obvious reasons, will take that forward. The recent attacks on British icons such as Marks & Spencer and Jaguar Land Rover will loom large in people’s minds. Many Members across the Chamber have already mentioned them. Supply chains were thrown into chaos, with small businesses paying the price, which clearly shows the ripple effect across the economy—on other businesses, smaller businesses and patients, such as in the public service examples mentioned earlier—when one part of the system is attacked. We are clear that all businesses—that covers financial services, Jaguar Land Rover, Marks & Spencer and others—must take immediate steps to protect themselves. That is why, in October, members of the Cabinet wrote to the FTSE 350 companies urging them to strengthen their defences by doing three things: first, to make cyber risk a board priority; secondly, to require suppliers to have a cyber essentials certificate; and thirdly to sign up to the early warning service. That was followed by a similar letter to entrepreneurs and small businesses in November with bespoke advice for smaller teams. We know that those actions work. Organisations with cyber essentials are 92% less likely to claim on cyber insurance than those that do not. Businesses know best how to protect themselves; we are not here to regulate for the sake of regulating. Government are taking action too. As I announced this morning, the Government cyber action plan sets a radically new model for how Government will strengthen their cyber-resilience and is backed by over £210 million of investment. Government Departments will be held to standards equivalent to those set out in the Bill. That is why the public sector and the Government are not included in the scope of the Bill. The Government should not need to legislate for themselves; we should just get on with making sure that we are leading the charge and that the cyber action plan strengthens the Government’s cyber-resilience. [ Interruption. ] I do not know if that was an attempt at an intervention from the Opposition Front Bench, but I am happy to take it.

  • 6 Jan 2026 · Cyber Security and Resilience (Network and Information Systems) Bill · Hansard source
    More

    It is worth clarifying for the House that we brought forward the Government cyber-security strategy this morning because the 2022 consultation undertaken by the previous Conservative Government was not acted upon. This Government are acting on those threats, bringing forward a plan that we will subsequently see through, and I think the hon. Lady should acknowledge that.

  • 6 Jan 2026 · Cyber Security and Resilience (Network and Information Systems) Bill · Hansard source
    More

    The Bill builds on the 2018 regulations, which were a hangover from the EU when we adopted them in this country. The Bill expands on those. As my hon. Friend the Member for Harlow (Chris Vince) just suggested, this is about economic growth as well as protecting our systems, so we have to find a balance between ensuring that our regulators have the powers and tools to regulate properly and giving businesses and our public services the confidence to use digital technology knowing that we have the most secure cyber-security in Europe, if not the world. We are very good at this stuff, and that is the balance to be sought. This Bill is about economic growth rather than about the over-regulation of businesses. I do not say this flippantly, but cyber-security is one of those areas where if everything is working, nobody notices, but when it is not working, suddenly everyone notices and it is everyone’s problem. That is why we are bringing the Bill forward and extending the scope of the powers.

  • 6 Jan 2026 · Cyber Security and Resilience (Network and Information Systems) Bill · Hansard source
    More

    There are some key dates to monitor progress in the action plan itself. I wrote to my hon. Friend, the Chair of the Science, Innovation and Technology Committee, this morning on the publication of the action plan to lay out some of those issues; the letter will be landing soon. I would be happy to discuss that in front of the Committee in more detail. I hope that the Committee, and indeed the Opposition and our own Labour Members, hold us to account for delivering on this, because it is fundamentally important to Government, whether it be digitisation, modernising Government or winning the case with the public about why digitisation is so important and why Government should be as secure as possible and lead the charge on that across the whole economy. I hope that we and the Committee can take that forward in the weeks and months ahead. As I said, the Government cyber action plan launched this morning is backed by over £210 million of investment and Government Departments will be held to standards equivalent to those set out in the Bill. I hope that that partially answers the question from my hon. Friend the Chair of the Science, Innovation and Technology Committee. Although the focus of the Bill is on essential services, it will also indirectly help businesses, including those damaged by the recent attacks, and Government. Almost all organisations today rely on data centres, outsourced IT or some kind of external supplier. By extending the Bill’s oversight, we are preventing attacks that could, in theory, reach thousands of organisations. The Bill also gives new powers to regulators responsible for enforcing the NIS framework. Effective compliance is crucial to the success of any regime. These reforms could be world-leading on paper, but without proper enforcement they are meaningless.

  • 6 Jan 2026 · Cyber Security and Resilience (Network and Information Systems) Bill · Hansard source
    More

    I thank my hon. Friend for all he did on the issues facing Jaguar Land Rover. I know that the matter is close to his heart and, indeed, it was a really big issue across the country, showing how a cyber-attack can affect not just one company, but has a ripple effect throughout the economy. Of course, the Government stepped in to unlock a £1.5 billion bolster to Jaguar Land Rover’s cash reserves to help it through that problem. I should say to my hon. Friend, and I will come to it later, that Jaguar Land Rover and other private organisations are not in the scope of this Bill. [ Official Report , 29 January 2026; Vol. 779, c. 9WC.] (Correction) The reason is that individual private companies should take their own cyber-security seriously and ensure that the risks of such incidents and threats are minimised as much as possible. The Bill widens the scope of the existing regulations, which do not include that, but of course the Government are working closely with Jaguar Land Rover, Marks & Spencer and other high-profile cases, because we know the impact they can have on our economy. Indeed, had the Government not stepped in and resolved that issue, the impact on Jaguar Land Rover, and the tens of thousands of employees at the plants and in the supply chain, would have been catastrophic and is not worth thinking about. I thank my hon. Friend for raising that issue. As I said, as always, the story is one of technology and cyber-threats moving faster than policymakers can possibly keep up with, but today we are fixing that. The first change in the Bill is to widen the scope of the 2018 regulations. To keep up with the changes of the past eight years, we are adding a few new things to that list, starting with large-load controllers. That includes any organisation that manages a significant flow of electricity to or from a smart appliance. It might be a company that supports electric car charging, for example. Bringing these entities into scope will safeguard our power supply and give consumers confidence in using energy-smart appliances, all of which are critical as we advance towards our clean power 2030 mission and net zero. The second change is that we are adding large data centres in recognition of their growing importance to our day-to-day lives and to the economy. These are vast digital warehouses for the United Kingdom, home to servers that host everything from patient records to their bank details. This is the data that underpins modern life and all our lives and communities, and it must be protected. We are expanding the scope of the regulations to include managed service providers as well. Those are organisations that provide ongoing functions, such as an IT help desk, to an outside client. Their access makes them an attractive target for cyber-attacks as criminals can find one weak spot and bring countless organisations down. For example, in 2014, an attack on a service provider for the Ministry of Defence compromised the personal data of around 270,000 people—military personnel, reservists and veterans. As organisations rely more and more on outsourced tech, we have to close this gap. In fact, weaknesses in the supply chain have become such a risk that we will go even further by allowing regulators to designate certain organisations as critical suppliers. That includes certain suppliers to essential services that could have a significant impact on the economy or society as a whole—for example, key suppliers to water companies, grid operators or air traffic control. These critical suppliers will be subject to cyber-security duties, which we will set out in secondary legislation.

  • 6 Jan 2026 · Cyber Security and Resilience (Network and Information Systems) Bill · Hansard source
    More

    While physical security and national security are issues for all of us, so is cyber-security. The Bill builds on the 2018 regulations to widen the scope into other areas of the economy where such issues have become much more prevalent—for example, data centres. I hope that doing so will give industries and sectors, including their employees, the confidence to report things to the regulators. Giving powers to the regulators will give businesses the confidence that they can report stuff; it is not a regulatory heavy hand dampening businesses. I hope that I can assure my hon. Friend and the rest of the House on that. Before that significant number of interventions, I was talking about why this issue matters and gave statistics for recent cyber-security activity in the United Kingdom. As a result of all that, one of the very first things we did as a new Government after the election was announce this new cyber-security Bill, just 10 working days in. Since then, the Department has been talking to cyber experts, businesses and regulators to turn these proposals into the comprehensive, serious and proportionate piece of legislation that we present for Second Reading today—one that protects the public and strengthens national security without placing undue burdens on businesses. I appreciate that that is a fine balance, but I think that this Bill finds that balance, so I am confident that the whole House will support it.

  • 6 Jan 2026 · Cyber Security and Resilience (Network and Information Systems) Bill · Hansard source
    More

    Cyber-security is the responsibility of the Department for Science, Innovation and Technology, but the Cabinet Office has a clear resilience issue as well, as we heard from the right hon. Member for Hertsmere (Sir Oliver Dowden), who was in the Cabinet Office previously. The DSIT Secretary of State will make those regulations, but a plethora of regulators are involved in this process—energy, water and data centres all have different regulators. The regulators that regulate those sectors are being empowered through the expanded number of sectors being brought into the legislation to take the responsibility.

  • 6 Jan 2026 · Cyber Security and Resilience (Network and Information Systems) Bill · Hansard source
    More

    I could not agree more. I gave the example of the Synnovis incident that brought blood transfusions in London to a halt, affecting thousands of patients. Our everyday lives are affected by this. As we modernise and digitise our economy and our Government, we have to ensure that our systems are as secure as possible, and cyber-security is right at the heart of that. This is not just a defensive issue; it is very much an economic growth issue as well, as we can see from the impact it has on our economy, our public services and the day-to-day lives of people, as in the example of our train systems that I just mentioned.

  • 17 Dec 2025 · Digital ID System · Hansard source
    More

    Department for Science, Innovation and Technology and Cabinet Office Ministers are working closely to deliver the new digital ID scheme. The scheme will be inclusive, secure and effective. It will give the public more control over their data than they have now, and it will make public services easier to access. A major inclusion programme, backed by £11.7 million, will support those at risk of digital exclusion, ensuring that the system is accessible and secure for all as we modernise our public services.

  • 17 Dec 2025 · Digital ID System · Hansard source
    More

    The data will be safe. It will be a fragmented system, and it will have the highest possible data security standards attached.

  • 17 Dec 2025 · Digital ID System · Hansard source
    More

    It is up to the Petitions Committee to schedule those debates, and I am sure the Committee will schedule that debate in Westminster Hall in due course. I can only reiterate that the Government are proposing this national ID scheme to modernise public services, improve security, streamline right-to-work checks and give the public control over their data. I am not quite so sure why the hon. Lady objects to the government modernising. We have analogue government with a digital population, and we live in a new world where the economy is modernising and digitising all the time, and government has to catch up.

  • 17 Dec 2025 · Digital ID System · Hansard source
    More

    I can merely give the Christmas advice to the hon. Gentleman not to drink in Strangers Bar and listen to people who are in there.

  • 17 Dec 2025 · Digital ID System · Hansard source
    More

    One of the aspects of digital ID that is under-debated in this House is the fact that those who are furthest away geographically and economically from digital inclusion will benefit the most from it. That is why we are investing millions of pounds into the digital inclusion programme, which has just announced 80 projects, including many in my hon. Friend’s constituency. We have to make sure that the entirety of the public, wherever they are in the country and whichever economic situation they are in, benefit from digital government and better public services.

  • 17 Dec 2025 · Digital ID System · Hansard source
    More

    Modernising government was at the heart of our manifesto, and the Government are proposing this national digital ID scheme to modernise our public services, improve security and streamline right-to-work checks. Since we introduced the digital veterans card, it has been downloaded 11,000 times, and 260,000 people have already downloaded the gov.uk app and 13.2 million people have started to use One Login as part of the gov.uk service. In the new year, a public consultation will be launched, alongside wider engagement, which has already begun, with expert organisations and wider stakeholders. A major digital inclusion programme will also be rolled out alongside that.

  • 17 Dec 2025 · Supply Chain Resilience · Hansard source
    More

    I think the hon. Gentleman acknowledges in his question the amount of funding that is going into the area that he represents and the wider Northern Ireland communities. UKRI plays a key role in strengthening supply chains, supporting regional innovation hubs and aligning research with local economic development goals. This Government’s funding rounds highlight partnership opportunities, including with the Advanced Manufacturing Innovation Centre that he has mentioned, where projects can complement those facilities, boosting regional innovation and productivity. That builds on initiatives such as the local innovation partnership funding, which empowers local leaders to target research and development investment and unleash the full potential of innovation in his and the wider Northern Ireland region.

  • 17 Dec 2025 · Supply Chain Resilience · Hansard source
    More

    I thank the Chair of the Select Committee for her question. Of course, technological advancement in AI is going to change the way that the Government work, and the way that all of us work, but the key thing about the publication of UK Research and Innovation’s document this afternoon is that it is implementing a record £86 billion-worth of investment over the spending review period—the largest ever investment in research and development. We have to trust UKRI and this Government to put that money into the places that will benefit the country most, and that means more jobs in more communities all over the country.

  • 17 Dec 2025 · Supply Chain Resilience · Hansard source
    More

    I congratulate the hon. Gentleman on his fantastic event in Parliament last week on this subject. I am delighted that Queen’s University Belfast is benefiting from £5 million in funding from the programme, which is part of a £13 million wider package from this Government to support making UK supply chains more resilient. The Government are investing a record £86 billion over the spending review period, which is the largest ever investment in research and development, and Ministers regularly discuss a range of issues with Cabinet colleagues to ensure that those programmes align with wider Government priorities on economic resilience and innovation.

  • 17 Dec 2025 · Topical Questions · Hansard source
    More

    Space is fundamental to many civil and defence requirements. It is vital that we collaborate closely across Government and with our allies. Just last month, the European Space Agency Council of Ministers committed £1.7 billion of funding focused on just that: growth and national security.

  • 15 Dec 2025 · Online Safety Act 2023: Repeal · Hansard source
    More

    This is a huge issue and all of us in this House are very concerned about misinformation and disinformation, and the impact on our democracy. Indeed, I am sure that in the time that I have been speaking here in Westminster Hall, my own social media will have been full of bots and all sorts of other things that try to encourage people to get involved in this debate, in order to influence the algorithm. That can fundamentally disturb our democracy, and is something we are looking at very closely. The Cabinet Office and ourselves are looking at the misinformation and disinformation issue, as is the Department for Culture, Media and Sport in terms of the media outlook and how elections are run in this country. We should all be very clear about not having our democratic processes undermined by such algorithmic platforms that serve up the kind of content that provides misinformation and disinformation to the public.

  • 15 Dec 2025 · Online Safety Act 2023: Repeal · Hansard source
    More

    It is great to see you in the Chair, Sir John. I did not realise you were such a technophobe until we heard from the shadow Minister, the hon. Member for Hornchurch and Upminster (Julia Lopez). I am disappointed that you were not able to contribute to this debate. I thank my hon. Friend the Member for Sunderland Central (Lewis Atkinson) for moving the motion on behalf of the Petitions Committee, and I thank him and other speakers for their contributions. I have not been on the RTG fans message board that my hon. Friend mentioned, but I am sure it has been very busy this weekend. I wondered if some of the trolls mentioned by the hon. Member for Bromley and Biggin Hill (Peter Fortune) were perhaps wearing black and white over the weekend. My hon. Friend the Member for Sunderland Central raised an important point, however: it is the site managers and volunteers who are hosting those forums, keeping them legitimate and working very hard to abide by the law. Jambos Kickback is an important site for my football team, and many people use it to find out what is going on. It is run by volunteers with no money at all—just for the sheer love of being on the forum together—so I fully understand what the petitioner wants to bring forward. I thank my hon. Friend for the measured way in which he put forward the e-petition. He called for robust, effective and proportionate regulation, which is what the Government are trying to do through the Online Safety Act. The shadow Minister highlighted that by going through the ledger of the positive and negative issues that the Government face, and indeed that were faced when her party was in government. The one thing on that ledger that is non-negotiable is the safety of children online—I think all hon. Members made that point; in fact, I am disappointed that those who do not make that point are not in this debate to try to win that argument, because I would be very interested to hear what they have to say. The petition received over 550,000 signatures. Although I appreciate the concerns that it raised, I must reiterate the Government’s very strong response that we have no plans to repeal the Online Safety Act. Parents should know and be confident that their children—I am a father of two young girls, aged five years and ten months—are safe when they access popular online services and that they can benefit from the opportunities that the online world offers. That is why the Government are working closely with Ofcom to implement the Act as quickly and as effectively as possible to enable UK users to benefit from the Act’s protections. This year, 2025, has been one of significant action on online safety. On 17 March the illegal harms codes of practice came into effect. Those codes will drive significant improvements in online safety in several areas. Services are now required to put in place measures to reduce the risk of their services facilitating illegal content and activity, including terrorism, child sexual abuse and exploitation, and other kinds of illegal activity. I asked the officials for a list of the priority offences in the Act; there were 17, but that number has increased to 20, with the new Secretary of State at the Department adding some others. It is worth reading through them because it shows the problem and the scale of it. I was really struck by Members who talked about the real world and the online world: if any of these offences were happening in the real world, someone would be carted off to jail immediately rather than being allowed to continue to operate, as they do online. The priority offences are assisted suicide; threats to kill; public order offences such as harassment, stalking and fear of provocation of violence; drugs and psychoactive substances; firearms and other weapons; assisted illegal immigration; human trafficking; sexual exploitation; sexual images; intimate images of children; proceeds of crime; fraud; financial services fraud; foreign interference; animal welfare; terrorism; and controlling or coercive behaviour. The new ones that have been added by the Secretary of State include self-harm, cyber-flashing and strangulation porn. Do we honestly have to write that into a schedule of an Online Safety Act to say that those things are unacceptable and should not be happening on our computers? On 25 July, the child safety regime came into force. Services now use highly effective age assurance to prevent children in the UK from encountering pornography and content that encourages, promotes and provides instructions for self-harm, suicide or eating disorders. Platforms are also now legally required to put in place measures to protect children from other types of harmful content, including abusive or hateful content, or bullying and violent content. When we visited schools, we spoke to headteachers, teachers and parents about the real problem that schools have in trying to deal with the bullying effects of social media. According to Ofcom’s 4 December report that some hon. Members have referenced already, many services now deploy age checks, including the top 10 most popular pornographic sites, the UK’s most popular dating apps and a wide range of other services, including X, Telegram, Reddit, TikTok, Bluesky, Discord, Xbox and Steam. This represents a safer online experience for millions of children across the UK; we have heard that it is already having an impact. The Government recognise, however, the importance of implementing the duties proportionately. That is why proportionality is a core principle of the Act and is built into many of the duties contained within it. Ofcom’s illegal content and child safety codes of practice set out recommended measures that are tailored to both size and risk to help providers to comply with their obligations —it is really important to emphasise that. When recommending steps that providers can take to comply with their duties, Ofcom must consider the size and risk level of different types and kinds of services. Let me just concentrate on that for a minute. For instance, Ofcom recommends user blocking and muting measures to help to protect children from harmful content, including bullying, violent content and other harmful materials, and those recommendations are tailored to services’ size and risk profile. Specifically, Ofcom recommends that all services that are high risk for this content need to implement those measures in full. However, for services that are medium risk for this content, Ofcom suggests that they need to implement the measures only if they have more than 700,000 users. However, while many services carry low risks of harm, risk assessment duties are key to ensuring that risky services of all sizes do not slip through the net of regulation. For example, the Government are very concerned about small platforms that host the most harmful content, such as forums dedicated to encouraging suicide or self-harm. Exempting all small services from duties requiring them to tackle that type of content would mean that those forums would not be subject to the Act’s enforcement powers, which is why we reject the petitioner’s views. Even forums that might seem harmless carry potential risks, such as where adults can engage directly with child users. The Government recognise the importance of ensuring that low-risk services do not have unnecessary regulatory burdens placed upon them, which I hope reassures the shadow Minister. That is why, in the statement of strategic priorities issued on 2 July, the Government set out our expectation that Ofcom should continue focusing its efforts on safety improvements among services that pose the highest risk of harm to users, including small but risky services. The Government also made it explicitly clear that Ofcom should ensure that expectations on low-risk services are proportionate. Alongside proportionate implementation of the Act, the Government also understand the need to communicate the new regulations effectively, and to work with companies within its scope to ensure that compliance is as easy as possible. To deliver that, Ofcom is providing support to online service providers of all sizes to make it easier for them to understand and comply with their responsibilities under the UK’s new online safety laws. For example, Ofcom has already launched a regulation checker to help firms to check whether they are covered by the new rules, as well as a number of quick guides for them. I will address some of the issues raised by Members. My right hon. Friend the Member for Oxford East (Anneliese Dodds) started by raising the issue of pornography and other harmful content. User-to-user services that allow pornographic content, and content that promotes, provides instructions for or encourages suicide, self-harm or eating disorders, must use highly effective age assurance to prevent all children under 18 from accessing that type of content. Services must take proportionate steps to minimise the risk of children encountering that type of content when using them, and they must also put in place age assurance measures to protect children from harmful content, such as bullying and violent content. Ofcom’s “Protection of Children Codes of Practice” set out what steps services can take to comply, and Ofcom has robust enforcement powers available to use against companies that fail to fulfil those important duties. We are already seeing that enforcement happening, with 6,000 sites having taken action to stop children from seeing harmful content, primarily via age checks. That shows the scale of the issue. Virtual private networks have also been mentioned by a number of Members, including the shadow Minister. Following the introduction of the child safety duties in July, Ofcom reported that UK daily active users of VPN apps temporarily doubled to around 1.5 million—the average is normally about 750,000. Since then, usage has dropped, falling back down to around 1 million daily users by the end of September. That was expected, and it has also happened in other jurisdictions that have introduced age checks. According to an Ofcom rule, services should “take appropriate steps to mitigate against methods of circumvention that are easily accessible to children”. If a provider is not complying with the age assurance duties, by promoting VPN usage to bypass age assurance methods, Ofcom can and should take enforcement action. The use of VPNs does not protect platforms from not complying with the Act itself.

  • 15 Dec 2025 · Online Safety Act 2023: Repeal · Hansard source
    More

    Sir John, you are indeed very kind. My hon. Friend gave two examples during his speech. First, he mentioned brakes that were available only for high-end and expensive cars, and are now on all cars. Secondly, he mentioned building regulations, and how we would not build a balcony without a barrier. Those examples seem fairly obvious and almost flippant, but it seems strange that we would regulate heavily to make sure that people are safe physically—nobody would ever argue that it would be a complete disregard of people’s freedom to have a barrier on an 18th-floor balcony—but not online. We do that to keep people safe, and particularly to keep children safe. As my hon. Friend said, if we are keeping adults safe, we are ultimately keeping children safe too. We have to continue to monitor and evaluate. I was just about to come on to the post-implementation review of the Act, which I am sure my hon. Friend will be very keen to have an input into. The Secretary of State must complete a review of the online safety regime two to five years after part 3 of the Act, which is about duties of care, fully comes into force. The review will therefore be completed no sooner than 2029. These are long timescales, of course, and technology is moving, so I understand the point that he is making. I recall that in the Parliament from 2010 to 2015, we regulated for the telephone, so we move slowly, although we understand that we also have to be nimble to legislate. The Lib Dem spokesperson, the hon. Member for Harpenden and Berkhamsted, asked whether the Act has gone far enough. Ofcom, the regulator, is taking an iterative approach and will strengthen codes of practice as online harms, technology and the evidence evolve. We are already making improvements, for example strengthening the law to tackle self-harm, cyber-flashing and strangulation. The hon. Lady also asked whether Ofcom has received an increase in resources. It has—Ofcom spending has increased by nearly 30% in the past year, in recognition of its increased responsibilities. She also asked about a digital age of consent. As I mentioned, we have signed a memorandum of understanding with Australia and will engage with Australia to understand its approach. Any action will be based, of course, on robust evidence.

  • 15 Dec 2025 · Online Safety Act 2023: Repeal · Hansard source
    More

    I thank my hon. Friend for the work that she does on that Committee. Of course, the Government have to respond in detail to such reports and we look forward to the recommendations it brings forward. Often we see conspiracy theories in the online world, but there is no conspiracy theory here: the Government are not trying to defend a position against what evidence might come forward. We have just signed a memorandum of understanding with Australia to look at their experiences of protecting children online and whether there are things that we can do in this country. It has to be evidence-based, and if the evidence base is there, we will certainly make sure to act, because it is non-negotiable that we protect young people and children online.

  • 15 Dec 2025 · Online Safety Act 2023: Repeal · Hansard source
    More

    A whole host of legislation sits behind this, including through the Electoral Commission and the Online Safety Act, but it is important for us to find ways to ensure that we protect our democratic processes, whether that be from algorithmic serving of content or foreign state actors. It is in the public domain that, when the Iranian servers went dark during the conflict with the US, a third of pro-independence Facebook pages in Scotland went dark, because they were being served by foreign state actors. We have seen that from Russia and various other foreign actors. We have to be clear that the regulations in place need to be implemented and, if they are not, we need to find other ways to ensure that we protect our democracy. At a small tangent, our public sector broadcasters and media companies are a key part of that. To stay with my hon. Friend the Member for Milton Keynes Central (Emily Darlington), she made an excellent contribution, with figures for what is happening. She asked about end-to-end encryption. We support responsible use of encryption, which is a vital part of our digital world, but the Online Safety Act does not ban any service design such as end-to-end encryption, nor does it require the creation of back doors. However, the implementation of end-to-end encryption in a way that intentionally binds tech companies to content will have a disastrous impact on public safety, in particular for children, and we expect services to think carefully about their design choices and to make the services safe by design for children. That leads me to online gaming platforms and Roblox, which my hon. Friend also mentioned. Ofcom has asked the main platforms, including Roblox, to share what they are doing and to make improvements where needed. Ofcom will take action if that is not advanced. A whole host of things are happening, and we need the Online Safety Act and the regulations underpinning it to take time to feed through. I hope that we will start to see significant improvements, as reflected on by my hon. Friend the Member for Sunderland Central. My hon. Friend the Member for Milton Keynes Central mentioned deepfakes. That issue is important to our democracy as well. The Government are concerned about the proliferation of AI-enabled products and services that enable deepfake non-consensual images. In addition to criminalising the creation of non-consensual images, the Government are looking at further options, and we hope to provide an update on that shortly. It is key to protecting not only our wider public online but, fundamentally, those who seek public office. The Government agree that a safer digital future needs to include small, personally owned and maintained websites. We recognise the importance that proportionate implementation of the Online Safety Act plays in supporting that aim. We can all agree that we need to protect children online, and we would not want low-risk services to have any unnecessary compliance burden. That is a balance that we have to strike to make it proportionate. The Government will conduct a post-implementation review of the Act and will consider the burdens on low-risk services as part of that review, as mentioned in the petition. We will also ensure that the Online Safety Act protects children and is nimble enough to deal with a very fast-moving tech world. I thank all hon. Members for providing a constructive debate and raising their issues. I look forward to engaging further in the months and years ahead.

  • 15 Dec 2025 · Online Safety Act 2023: Repeal · Hansard source
    More

    My hon. Friend makes a good point; let me come back to him in detail on the VPN issue, as his question relates to what we are planning to do in our review of the Online Safety Act, including both what was written into the legislation and what was not. My hon. Friend the Member for Darlington (Lola McEvoy), who is no longer in her place, highlighted the really important issue of chatbots, which has also been mentioned by a number of other Members. Generative AI services including chatbots that allow users to share content with one another or search live websites to provide search engines are already regulated under the Online Safety Act. Those services must protect users from illegal content and children from harmful and age-inappropriate content.

Published records only — not a full account of an MP’s work. How we work →