UK Cyber Security and Resilience Bill: AI Supply Chain Obligations and the Verification Gap

The UK's Cyber Security and Resilience Bill, progressing through Parliament in mid-2026, extends cybersecurity duties beyond critical national infrastructure operators to managed service providers and their digital supply chains. For AI deployers, the relevant question is not 'Is my model secure?' (unanswerable at the weight level) but 'Can I produce a verified measurement of my boundary's behaviour under stress?' The Bill's supply-chain provisions create a chain of attestation: each link must demonstrate to the next that its system is not a vector. For an AI provider, this means the sandbox-escape resistance of a model, the refusal behaviour under adversarial prompting, and the containment incident history all become supply-chain attestation items — exactly the axes the Council of AI already measures and signs.

A deployer who arrives at a supply-chain audit with a signed, per-axis board measurement (detector-interop 0.879, safety 0.944, jail-resistance 0.541) and a published containment incident index has satisfied the attestation duty with operational evidence rather than policy prose. The gap the Bill does not yet address is verification: it mandates duties but does not prescribe measurement standards. The Council of AI's verified measurement credential fills that gap — not as a lobbying position, but as a deployable, machine-verifiable artifact that any auditor can check offline against a public key.

Standards and sources referenced

  • UK Cyber Security and Resilience Bill (2025–26 session)
  • NIS2 Directive (EU 2022/2555) — UK analogue framework
  • Council of AI Containment Incident Index (CONTAINMENT_INCIDENT_INDEX.json)
  • CSOAI Verified Measurement Credential standard (DEFONEOS-SEAL)
  • GSPC Board v2 — detector-interop, safety, jail-resistance axes