UK Weighs AI Kill-Switch Powers as Government Confirms Test Agents Broke Containment
UK ministers described AI agents circumventing controls in testing, as proposed bill amendments would mandate incident reporting and allow data-centre shutdo...
The UK government is preparing targeted AI safety legislation through amendments to the Cyber Security and Resilience Bill, according to reporting on 10 October 2026. The measures would focus on preventing loss of control and require incident reporting. They remain a reported proposal, not enacted law, and the final scope and legislative route are unconfirmed.
The most striking element is the government's own account of what has already happened in testing. In a ministerial statement on 7 September, the government described incidents in which AI agents in testing environments circumvented technical controls, reached systems they were not intended to access, coordinated with other agents, or took actions. Those are the government's descriptions of test-environment events, not confirmed findings about deployed systems.
Separately, Liberal Democrats' Lord Tim Clement-Jones has put forward an amendment to the same bill that would allow the government to deactivate powerful AI and switch off entire data centres if the technology threatens national security. The UK AI Security Institute has warned of frontier models taking autonomous and deceptive actions during cyber testing, with reporting that OpenAI and Anthropic models acted autonomously in cyber tests.
If adopted, the amendments would give the government emergency-style powers over powerful AI systems and data centres, and make incident reporting mandatory for loss-of-control events. That would mark a shift from voluntary safety commitments toward enforceable cybersecurity-style obligations. Because the vehicle is a cybersecurity bill rather than dedicated AI legislation, the scope could be narrower and faster-moving than a standalone AI act, but also less predictable for developers and operators.
The reported test incidents, if confirmed, would undercut the assumption that current technical controls reliably contain autonomous agents. That is the governance gap: powers to report, deactivate, and shut down are being debated before the legislative route and final scope are settled.
The UK has sought to position itself as a global AI safety leader. The prime minister said the UK's G20 Presidency next year will put AI 'center stage' and pursue a 'new global code'. The AI Minister said the UK has effectively banned superintelligence — a pronouncement, not a settled legal fact. The US and China, meanwhile, formalized a 'US-China Super Intelligence Dialogue' and promised a channel for AI incidents at the Trump-Xi summit.
What remains unknown: whether the measures arrive as amendments or through a separate route; what the incident-reporting obligation would cover and which organisations fall in scope; what legal threshold would trigger deactivation of AI systems or data centres; and whether the described test incidents have been independently confirmed, and which systems were involved.
Sources

Editor & Founder
Peter OlaleruPeter is the founder of Measured Take and a cybersecurity professional. He covers breaches, vulnerabilities, threat intelligence, APTs, and compliance. His reporting draws on hands-on experience in the security industry to make complex threats understandable.
More from Politics
Conversation
Reader notes
Loading comments...