The King's Speech in May promised a bill to fix the law that criminalises Britain's own cyber defenders. Five months on, that bill has not been introduced, and ministers cited its absence as the reason to reject a fix on offer right now.
Estimated reading time: 7 minutes
In short. The King's Speech on 13 May 2026 announced a National Security Bill, with a subheading and a page of its own, that would update the Computer Misuse Act 1990 and "unlock the power of cyber security professionals." UK Parliament's own bills database shows no bill matching that description has been introduced in either House. A separate, narrower bill announced the same day was fast-tracked and became law in eight weeks; its text, checked directly, does not mention the Computer Misuse Act once. On 7 September, in a live Bill's committee stage, a government minister cited the still-missing bill as the reason to reject an amendment that would have required only a 12 month statutory review, offering no date beyond "as parliamentary time allows." Three documented mistakes: four stars.
The Computer Misuse Act 1990 makes it a crime to access a computer system without the owner's permission, full stop. It was written before the World Wide Web existed for the public, and it draws no line between a hostile state hacker and a security researcher who finds a flaw in an NHS hospital's network and reports it. Campaigners have asked for a narrow statutory defence for good faith security research since at least 2021. The government has now told Parliament, in writing, that fixing it is a priority. It has also told Parliament, five months running, that the bill meant to do the fixing does not exist yet.
The claims, tested
| The government's own words | What the record actually shows | Verdict |
|---|---|---|
| King's Speech 2026 background briefing notes, page 118, under the heading "National Security Bill": the Bill will "reform the cyber landscape, including by updating the Computer Misuse Act 1990," creating new police powers, and will "also unlock the power of cyber security professionals to better enable them to secure computer systems" [1] | UK Parliament's Bills database lists exactly three items matching "National Security": the National Security Act 2023 and the National Security and Investment Act 2021, both already law before this King's Speech, and the National Security (State Threats) Act 2026, which received Royal Assent on 8 July 2026, eight weeks after being announced. The King's Speech notes themselves describe that Act's bill as "separate" from the one carrying Computer Misuse Act reform [1]. Its enacted text, table of contents to schedules, does not mention the Computer Misuse Act once [2] | The specific bill named to fix this law, with its own subheading in the government's own briefing document, has not been introduced in either House more than four months after it was promised |
| Baroness Lloyd of Effra, Minister for Space, Cyber and Regulatory Reform, House of Lords Grand Committee, 7 September 2026, rejecting Lord Clement-Jones's Amendment 164 to the Cyber Security and Resilience Bill (which would have required only a 12 month statutory review, not full reform): "The Home Office has already carefully reviewed the Computer Misuse Act and proposes to introduce a defence to Section 1... The Home Office recognises that legislating in this area is a priority and will do so as parliamentary time allows" [4] | Moving the amendment he later withdrew, Clement-Jones told the same Committee: "We have been waiting for the outcome of that Home Office review for more than five years," and that the same fix had already been raised during the passage of the Crime and Policing Act and the Data (Use and Access) Act. Closing the debate, he said he had "had no contact from anybody in the Home Office about what they might insert in the Bill" and did not know "whether anybody in this Committee has had notice of when a Bill might come forward" [4] | "As parliamentary time allows" is the only date offered, on an issue the government's own lead correspondent in Parliament says has already run five years without one, and the government would not accept a fallback amendment that just asked it to report back within a year |
| GOV.UK's "Enforcement" factsheet for the Cyber Security and Resilience Bill, the same live Bill the amendment was tabled to: the most serious breaches by regulated operators carry penalties "up to £17 million, or 4% of a regulated entity's worldwide turnover, whichever is higher" [6] | The Bill compels operators of essential and digital services to find and fix their own vulnerabilities under threat of those fines. Doing that work means hiring the same good faith researchers who remain criminally exposed under Computer Misuse Act Section 1 [3] for the unauthorised access their job requires, the contradiction Clement-Jones put to the Committee directly: "the Government continue to criminalise the very security professionals and ethical researchers whom these operators must hire to test and harden their systems" [4] | The same Bill fines operators millions of pounds for not securing their systems and leaves the people who would help them do it facing prosecution, and government did not resolve that contradiction in Committee, only postpone it |
The mistakes, counted
The named bill does not exist (1). The King's Speech briefing document does not gesture vaguely at future cyber legislation. It gives the Computer Misuse Act reform its own bullet point, under a bill with its own name and its own page, promising a defence for professionals and new police powers together [1]. Checked against Parliament's own bills database on 16 September 2026, more than four months after that promise, no bill answering that description has had a first reading in either House. A different, narrower bill, announced the same day for a different purpose, proscription-style powers against state threat actors, was fast-tracked instead and became law in eight weeks [2]. Speed was available when the government wanted it.
A fallback amendment asking only for a deadline was rejected too (2). Clement-Jones's Amendment 164 to the Cyber Security and Resilience Bill did not even ask for the Computer Misuse Act to be fixed there and then. It asked the Secretary of State to review, within 12 months, whether a statutory defence was needed, and report to Parliament [4]. The government rejected that too, on the grounds that a review tied to this Bill's narrower scope was "unlikely to provide the Government with new information on how the Act should be reformed" [4], an odd objection to raise against a proposal whose entire purpose was accountability, not research. Clement-Jones withdrew the amendment rather than force a vote he could not win, on the government's word that it takes the issue seriously. His own closing account of what that word is worth: five years of a Home Office review with no outcome, and personally, as the peer who has pressed this hardest, "no contact from anybody in the Home Office about what they might insert in the Bill" [4].
The government is enforcing the problem it has not fixed (3). The Cyber Security and Resilience Bill that carried this debate is not an abstract strategy document. It creates real, enforceable duties, backed by penalties of up to £17 million or 4% of worldwide turnover for the most serious breaches [6], on the operators of essential and digital services. Meeting that duty in practice requires hiring vulnerability researchers and penetration testers to probe systems the way an attacker would. Computer Misuse Act Section 1 still makes that unauthorised access a crime regardless of intent [3]. The government is, in the same Parliamentary session, fining regulated operators for security failures and leaving the professionals who fix those failures without the legal protection the government's own minister agrees they need.
Credit where due
None of this is a minister denying a problem. Baroness Lloyd of Effra told the Committee plainly that she recognises "the strength of feeling on reforming the Computer Misuse Act" and that "the UK should have the right legislative framework" [4]. The Home Office's proposed fix is more specific than a vague aspiration: a defence to Section 1 for accredited cyber security researchers carrying out defined activity, developed, she said, with the National Cyber Security Centre, law enforcement and the cyber security industry, and Clement-Jones confirmed he had been personally briefed on the detail in February [4]. And the Cyber Security and Resilience Bill itself, the live legislation this debate happened inside, is real and moving, now at Report stage in the Lords, not a shelved strategy. The government has a design for the fix. What it has not produced, in five years, is the bill to carry it, or a date by which one will arrive.
Verdict
Four stars, from three documented mistakes. A government briefing document promised a named bill to stop the law criminalising Britain's own cyber defenders. That bill does not exist, on Parliament's own records, more than four months after it was announced with a subheading of its own. When peers offered the government an easier route, a duty to review and report within a year, tied to a Bill already moving through Parliament, the government turned that down as well, and offered nothing firmer than "as parliamentary time allows." Meanwhile the government's own live legislation fines the operators who need those researchers millions of pounds for the security failures those researchers are best placed to find. The design for the fix exists. The bill to deliver it does not, and nobody in the House of Lords, including the peer who has spent five years asking, has been told when it will.
Sources
- King's Speech 2026: background briefing notes, Prime Minister's Office, 10 Downing Street, published 13 May 2026
- National Security (State Threats) Act 2026 (c. 24), legislation.gov.uk, Royal Assent 8 July 2026
- Computer Misuse Act 1990 (c. 18), legislation.gov.uk
- Cyber Security and Resilience (Network and Information Systems) Bill, House of Lords Grand Committee, Hansard, 7 September 2026
- Government rejects Computer Misuse Act amendment to protect cyber professionals, Computer Weekly
- Enforcement, Cyber Security and Resilience (Network and Information Systems) Bill factsheets, GOV.UK / Department for Science, Innovation and Technology