Emily Darlington
MP for Milton Keynes Central · Labour · United Kingdom
“It is a pleasure to serve under your chairship, Ms McVey. I have rewritten my speech because I do not want to repeat all the things that have been said. I think we are in agreement, although we may have different perspectives. I want to take us back to 80 years ago, to a country house a few miles from Milton Keynes in my constituency.”
“British AI firms need three things to succeed: customers who will buy their products, the ability to increase supply to meet demand, and a USP that British AI is the most trusted. The Government can help with all three. First, we have to act as a good customer. Why should those NHS and MOD contracts not go to British AI firms?”
“With the activist Government in the US turning off technology and restricting its availability outside the US, that puts at risk not only our NHS but, most importantly, the defence of our realm against Russia, for which others may have more sympathy than we do.”
“Britain is standing at another one of those moments, as we see with our economy and our military tech coming together and pushing forward either for the good of the nation or for its ultimate damage. The potential benefits of artificial intelligence are enormous, and not only for the private sector.”
“We are overly reliant: despite the fact that we part-own Crown Hosting, that accounts for only 6% of public sector data; the rest is nearly all on Amazon Web Services, which is a significant risk. We need to look at how we diffuse the supply of compute power—the underused capacity—to increase that.”
“A maker exports its products, services and ideas around the world, as we did in world war two, but the UK is at risk of becoming an AI taker and simply handing over the keys to giant US tech firms that are buying up our best young AI companies.”
The complete record
Every one of 410 lines we hold for Emily Darlington, in date order, each linked to its source. Free to read, in full, without an account. Page 3 of 9.
“I appreciate that the hon. Member is into storytelling—it may be his next job—but what did he think was going to happen to the courts system when there was a 23% cut under the last Government? It was going to crumble. Does he not agree?”
“I am trying to understand the hon. Lady’s point. Is she saying that we should now extend jury trial to all trials, or that we should keep the status quo? Is she saying that it is sacrosanct and so should in fact be extended? I am confused.”
“These platforms shape what millions of people see during an election and they must be accountable. These amendments would enable Ofcom to demand action from these platforms, unless they want to face major consequences, by making electoral offences a priority offence under the law. With our success in forcing Grok to take action on notification, we know that we can act to protect people. No platform is too big or too powerful.”
“We must codify that the existing laws will apply to these digital behaviours, with a recognition that these are serious offences with serious consequences. Secondly, we must shine a light. If a video is artificially generated to impersonate a candidate, voters have the right to know. The hon. Member for Mid Norfolk (George Freeman) has described his own experience in this regard. We need much higher levels of disclosure and labelling of where information comes from, so that people can better understand what they are seeing. That is why we need more regulation and transparency around political advertising, with all paid digital advertising being kept publicly available in a library so that it is open for all to see. Thirdly, we must demand that major platforms play their proper role in society.”
“One seeks to weaken us, the other profits from whatever captures our attention, and together they distort the spaces in which many of us now make up our minds. We have come together to put forward amendments that would help the Representation of the People Bill to continue to maintain democracy as we expect it to. We already accept the election rules that require us to regulate spending, prohibit impersonation and enforce transparency. We choose to do that because our democracy is too important to leave unguarded, and the digital space where so many of our choices are now formed should be no different. If our duty is to protect people’s power to choose, these five things must follow. First, we must identify the crime. At the moment, lots of laws apply, but if it is not specific, it is hard for law enforcement to act.”
“The most personal form of power each of us has is the power to choose. When we mark our ballot, we exercise something profound and meaningful: our power to decide freely what kind of future we want, and that choice belongs to each of us. But today it is clear that our power to freely decide our future is under attack, not because our vote has been taken away or because of voter fraud, but because the environment in which we make up our minds is being deliberately distorted. Hostile states—especially Russia—are investing in digital tools designed to confuse, divide and destabilise us. At the same time, big tech has built systems that reward the strongest reaction: rage over fact, speed over accuracy and repetition over reflection.”
“This is a robust set of choices that we in the Chamber can make to protect the future that we live in together. They are not about shutting down arguments or preventing someone from speaking their mind; they are about protecting the space for each of us to make the choice freely, and for those spaces to be filled with genuine discourse and arguments.”
“One of the reasons that Meta will not take that content down is that we are not in an electoral period. These online methodologies are so powerful because they recognise the truth that we make our choices not just in the election period; we are making up our minds all the time. Let us get our election law in line with that reality. Finally, we are proposing an amendment that goes to the core of how we treat each other. We must take action to reduce the abuse of candidates. I commend Mr Speaker and his Conference for their important work on this issue, because we all know too personally where this leads. Not only have we already lost beloved colleagues and friends to violence, but we also lose the talented people who will be put off from running in the first place.”
“I completely agree. I think we all agree, no matter what side of the House we are on, that a misrepresentation of that kind distorts the electorate’s views. The reality is that it should be taken down. I think we can all agree on that fact. Fourthly, law enforcement and regulatory bodies must have the power to act. The Electoral Commission must have more power to investigate, with real-time access to the platform data that is vital to understanding the impact of algorithmic systems and the role of inauthentic behaviour through bots. Regulators must have the power to compel major platforms to take action, including in the case of the hon. Member for Mid Norfolk. We need to have a standard way to let the public know about incidents when they happen. They need to be informed. Fifthly, these rules must apply year-round.”
“If we were to link voting with brain development and maturity, that would mean that men get the right to vote about five years after women. Should we base it on that science?”
“My hon. Friend is making an excellent speech. Does he agree that although the Representation of People Act 1983 makes it illegal to misrepresent a candidate in an election, that offence is yet to be tested in relation to online misrepresentation? In fact, Ofcom and many platforms do not see themselves as being bound by that legislation.”
“How will we take forward those discussions, and extend the idea that already exists in legislation, through the Online Safety Act 2023, about safety by design, in order to ensure that products around cyber-security have this at their heart, and deliver the prevention mechanism that I think we all want to see—especially the small businesses and organisations that are victims of such attacks?”
“The new clauses raise a really important point about security by design implemented within companies, and within the companies that provide cyber-security technology to them. An hon. Friend of mine tabled an amendment, which we are not speaking about today, on a similar subject. Security and safety by design is something that we talk about quite often in this area. It may not be appropriate for this Bill, but I am keen to hear how we will progress those discussions, because ultimately we do want to prevent cyber-attacks. We need to make sure that companies, small and medium-sized enterprises, major infrastructure and local government all have access to technology and infrastructure that looks at security by design in its own design right from the outset, because that is what makes us most secure.”
“I thank the Minister for that commitment. Would he consider setting up a meeting between GDS and those MPs who have expertise in this area, so that we can share our expertise and reassure ourselves that this is going in the right direction and at the speed that is necessary?”
“The Molly Rose Foundation has done a brilliant briefing paper, which every MP should read, about why it does not support a ban: it wants the online world to be safe for children, but a ban does not make it so.”
“It is about free speech.” No, it is not about free speech. Freedom of speech was written into law in this country and spread around the world, so we understand how to protect it and limit its harm. The Online Safety Act was a missed opportunity. It also took seven years to get through this House, but we do not have seven years to wait. There would also be unintended consequences to a ban. I had the pleasure of meeting Ian Russell the other night, and we had a really powerful discussion. My heart goes out to him, as one parent to another, given what his family have been through. He does not jump to the easy solution of a social media ban.”
“Fifty-nine per cent of the 14 to 16-year-olds have been contacted by strangers, and more than a third of that was through Roblox, which is not covered by the Australian social media ban. Thirty-three per cent have been bullied, and a third of those was on Roblox. The Australian social media ban—which I assume is what the Liberal Democrats are talking about when they say they are in favour of a ban—does not cover YouTube or Roblox, and we have not even looked at whether it is effective. A ban is a blunt tool that essentially raises the flag of surrender to social media platforms and declares that there is no way of making social media safe. That is essentially what the Conservatives did when the Online Safety Act 2023 was passed: they said, “We cannot go far enough, so we are going to roll back.”
“Some 91% of them have a phone, and 80% have social media profiles. However, what will surprise the House is what young people consider social media profiles to be. We consider them to be Facebook or Instagram, while they consider them to be YouTube and Roblox—two organisations not covered by the Australian model. Additionally, 74% of those 14 to 16-year-olds spend two to seven hours online a day. Let me remind the House that, at that age, the brain development of young women is close to finished, while for young men, whose brain development does not finish until they are about 25, it is nowhere near complete. We know that from the science—just to be clear, that is not an opinion. Brain development in young women and girls happens differently, so should we therefore have different rules for young women and men?”
“We have taken this matter seriously since the very beginning of the parliamentary Session, and we have done a lot of work on it. I echo her call for Ministers to look again at the recommendations in our Committee’s “Social media, misinformation and harmful algorithms” report, which goes well beyond misinformation and into how the damage is done. Protecting our children and young people online is extremely important. The Online Safety Act was an important step forward, but it has not been fully implemented by Ofcom, it is not proactive enough, and it is too dependent on what social media companies themselves tell Ofcom. In the spirit of consultation—I know that we will get to that—I have done my own consultation with 500-plus 14 to 16-year-olds across my Milton Keynes Central constituency.”
“This week is Eating Disorders Awareness Week, and we must remember the acceleration of online harms. We have heard horrific accounts of ChatGPT giving young people diets of 600 calories per day, which is just appalling. We know the suffering and pain caused by seeing images tagged with the terms “ana”, “thinspiration” and other terms that should go. The promotion of such content is now a category 1 offence, and Ofcom should be weeding it out. The hon. Member for Winchester (Dr Chambers) is absolutely right to say that that measure should be extended to bots. I thank the Chair of the Science, Innovation and Technology Committee, my hon. Friend the Member for Newcastle upon Tyne Central and West (Dame Chi Onwurah), for her fantastic speech.”
“If young people get around the ban, as they do in Australia, they are less likely to report when they see harmful content or are being targeted on social media, because they worry that they will get in trouble for breaking the law. A ban would create a cliff edge at 16. No matter the person’s maturity—I have already talked about the different brain development in young women and men—their skills or what they have been taught, there is a cut-off at 16. All of a sudden it does not matter, and they go into a world that is not safe. Younger children do not have their own social media profiles; they use their parents’ devices. Often, they start with a video of Peppa Pig, and all of a sudden—who knows where it ends up? A ban would not address that. So, what is the solution?”
“I absolutely do. My full sympathy goes to that family in my hon. Friend’s constituency—it is the worst thing in the world for a parent to lose a child. But we have to get this right, which is why it is right that we have a consultation. It does no child any good if we jump to a conclusion that does not actually protect children. Although I maintain an open mind, I worry about a full ban. Some children rely on social media for connection, often including those who are exploring their sexuality—LGBTQ+ people—and those who are neurodivergent. The consequences for them could be devastating, so we need to consider their views.”
“I absolutely agree. Young people, particularly those in the mid-teenage years, understand this issue in a way that sometimes we do not because, quite frankly, our online experience is completely different from theirs. If Members want to test that, they should open an app such as Pinterest and compare what is fed into their Pinterest boards with their child’s Pinterest boards. It is a completely different experience. If Members do not have children, they should ask younger member of staff to open the same app on the different phones, and they will see a completely different world.”
“To protect children from child sexual abuse images, we need to talk to those behind iOS and Android to stop the creation of self-generated child sexual abuse images—some 70% to 80% of child sexual abuse images are self-generated—and we need to stop end-to-end encryption sites from sharing them. We have technology that can do that. We should always keep the ability to ban in our pockets, but any ban should be for particular apps. We should not ban our children and young people from having an online experience that is good.”
“The ratings on apps mean nothing, yet we have video game ratings that we as parents understand, so why are they not used? Should in-app purchases ever be allowed for young children? What is the age at which in-app purchases should be allowed in a game? We must consider the time limits for the different stages of brain development. We have guides on fruit and vegetables that recommend five a day to parents. We all know that. Schools use the same language, we use the same language, yet we have nothing to support parents in deciding how long a child should be online at different stages of brain development. I hope that the evidence that the Science, Innovation and Technology Committee collects will help inform that. We need to change addictive and radicalising platform algorithms.”
“Part of the answer is ensuring that content is related to ratings that we already understand as parents, such as those from the British Board of Film Classifications. I have been asking YouTube what rating YouTube Kids has for about a year now. Is it rated U? Is it 12A? Is it 15? It cannot tell me because it does not do things on that basis. As a parent I want to know the rating before allowing my children on an app, because parents have a role in this as well. All apps should be rated like videogames. Roblox has a 5+ rating, which does not exist in videogame ratings. We see ratings such as 4+ or 9+, but those are made up. At the parents forum that I did after the survey, one parent said that she walked in on her nine-year-old playing “guns versus knives”—on an app that is rated 5+.”
“That is a very important point about how sophisticated the technology has become. When we ask companies to take action to stop outcomes, the technology exists to do that. We are not asking them to reinvent the wheel or come up with new technology. It already exists because they are even microtargeting two different sides of the road. Having discussed this with experts, parents and—most importantly—young people, what do I think we need to consider? First, we need to fully and properly implement the Online Safety Act 2023. That must be done at speed, and it requires nothing from the House. It has been a request of the Secretary of State and the Minister, and I recommend that Ofcom gets on and does that as quickly as possible. We must make safe spaces for children online. How do we do that?”
“Is that defined as an “incident” or is it defined somewhere else in the Bill? I am a bit confused and am looking for some clarity.”
“I have a few questions for the Minister. I appreciate the clarity that the Bill brings to many of the services in its scope. I would like to understand how the definition of “incidents” will relate to hardware vulnerabilities that are discovered within a company, as we heard from some of the people who gave evidence to the Committee. It is unclear in the Bill. Perhaps it will be further defined in secondary legislation. I want to understand how an incident in which someone discovers a vulnerability in hardware—such as in a system-in-package—is reported, and how that information is then delivered by the regulator to other companies in the sector that may have similar technology, and to the other regulators, which may also want to flag that technology as a particular vulnerability.”
“Again, I welcome the Government amendments and clause 18; they are important to enabling us to share our vulnerabilities in an appropriate way with those people who may be involved. However, some of the aspects of those vulnerabilities that security services—GCHQ, His Majesty’s Government Communications Centre and others—raised with us relate particularly to not only foreign interference, but the potential for interference through technology embedded in our networks. How does the Minister see the measures working within our co-operation with different foreign nations, particularly during these volatile times?”
“As the Minister will be aware, I have spoken consistently of my concern about our reliance on hardware and tech that comes from potentially non-favourable state actors abroad. That also relates to Government procurement, which I have raised before, as the Minister will know. The Committee has already discussed how local government and Government Departments are not covered by this legislation, and how there is a separate strategy and document. Can the Minister expand on how protections against a reliance on foreign tech within critical infrastructure, in either the private or the public sector, are being dealt with in the Bill or in the strategy that has been published for the public sector? How will that be continually reviewed as our global geopolitical situation remains unstable?”
“As chair of the all-party parliamentary group on Hong Kong, I want to say on my behalf and that of many of its members how we horrified we are. This case exemplifies the systematic dismantling of Hong Kong’s judicial independence. The proceedings under the national security law do not operate within the independent or impartial judicial framework, and judges are designated by the Executive of the Hong Kong special administrative region. Trials are conducted without juries, evidential thresholds are lowered and the fundamental principle of the presumption of innocence is gone. How will the Government ensure that, on behalf of not just Jimmy Lai but all Hongkongers who live in the UK, we protect them from nefarious activity and this illegal law?”
“It widens the ambit of visibility and allows the UK state, as well as regulators, to understand what is going in the environment more broadly, because if there are trends—if a number of organisations report to a regulator that they have found that pre-positioning—they know that a malicious actor is planning something. The footprints are there.”
“David Cook: By way of example, NIS1 talks about reporting to the regulator if there is a significant impact. What we are seeing with some of the attacks that Jen has spoken about is pre-positioning, whereby a criminal or a threat actor sits on the network and the environment and waits for the day when they are going to push the big red button and cause an attack. That is outside NIS1: if that sort of issue were identified, it would not be reportable to the regulator. The regulator would therefore not have any visibility of it. NIS2 and the Bill talk about something being identified that is caused by or is capable of causing severe operational disruption.”
“Part of what NIS is doing and what the CSRB is looking to do is to take NIS and update it to make sure that it is covering the relevant things, but I also hope that we will see a new level of urgency and an understanding that the risks are very prevalent and are coming from different sources with all sorts of different motivations. There is huge complexity, which David has spoken to, around the supply chain. We really need to see the critical infrastructure and the core service providers becoming hugely more vigilant and taking their role as providers of a critical service very seriously when it comes to security. They need to think about what they are doing to be part of the solution and to harden and protect the UK against outside interference.”
“Last year, we saw the impact of disruptive attacks, but in the past few years we have also heard a lot more about state-sponsored attacks. I do not know how familiar everyone in the room is with Volt Typhoon and Salt Typhoon; they were widespread nation-state attacks that were uncovered in the US. We are not immune to such attacks; we could just as easily fall victim to them. We should take the discovery of Volt Typhoon as a massive wake-up call to the fact that although we are aware of the challenge, we are not moving fast enough to address it. Volt Typhoon particularly targeted US critical infrastructure, with a view to being able to massively disrupt it at scale should a reason to do so arise. We cannot have that level of disruption across our society; the impacts would be catastrophic.”
“The reality is that those organisations, which are global in nature, often do not pay due regard to UK law because they are acting all over the world and we are one of many jurisdictions. They are the threat vector that is allowing an attack into an organisation, but it then sits with the organisations that are attacked to deal with the fallout. Often, although they do not get away scot-free, they are outside legislative scrutiny and can carry on operating as they did before. That causes a vulnerability. The one-to-many attack route is a vulnerability, and at the moment the law is lacking in how it is equipped to deal with the fallout. Jen Ellis: In terms of what the landscape looks like, our dialogue often has a huge focus on cyber-crime and we look a lot at data protection and that kind of thing.”
“Q I want to go back to basics and get a bit of insight from you. What cyber risks are businesses currently facing, and how do you feel the Bill addresses those risks? David Cook: The original NIS regulations came out of a directive from 2016, so this is 10 years old now, and the world changes quickly, especially when it comes to technology. Not only is this supply chain vulnerability systemic, but it causes a significant risk to UK and global businesses. Ransomware groups, threat actors or cyber-criminals—however you want to badge that—are looking for a one-to-many model. Rather than going after each organisation piecemeal, if they can find a route through one organisation that leads to millions, they will always follow it. At the moment, they are out of scope.”
“But something to consider for the Bill is not accidentally putting national security requirements on those entities that cannot possibly meet them. When I was in government, in the past we accidentally required tiny entities, which could not possibly do so, to defend themselves against the Russians in cyber-space. If you translate that to any other domain—for example, saying that a 10-person company should defend itself against Russian missiles—it is insane, yet we do it in cyber-space. Part of the flow-down requirements that we see for contracting, when there is a Bill like this one, ends up putting those national security requirements on inappropriate entities. I really think we need to be careful how we manage that. Matt Houlihan: Can I make two very quick points?”
“In my experience, whether a board is engaged or not is a proxy indicator for whether they are looking at risk management properly, and you cannot change corporate culture through regulation—not quickly. There is something to be done around incentives to ensure that companies are really looking at their responsibilities across cyber-security. As the previous panellists have said, this is not just a technical thing. One of the things that is difficult to reconcile in my head—and always has been—is trying to levy national security requirements on companies that are not set up to do that. In this case I am not talking about Amazon Web Services, because AWS invests hugely in security. We have a default design principle around ensuring that the services are secure and private by design.”
“Q A huge thank you to the panel. Many of my colleagues have already asked the question, so I appreciate you talking about the futureproofing in quantum, the international regulatory environment and the use of standards alongside regulation to drive up quality. You all have a huge amount of UK clients, and I want to ask you about how good cyber culture gets embedded, and what the role of the Bill is within that. To pick up on Ben’s point around the security by design within his own firm, do you think that is well understood among your colleagues in the UK? How do we get the balance right between what is in the regulation and what should be done through a standards model, working with the British Standards Institution and others? Dr Ian Levy: The previous set of witnesses talked about board responsibility around cyber-security.”
“There are some notable cases that have been in the public domain in recent months where we have levied fines against organisations for data breaches. The first thing to realise is that we are still talking about only quite a small sub-sector—digital service providers, including cloud computing service providers, online marketplaces, search engines and, when they are eventually brought into scope, MSPs. A lot of MSPs will provide services for a lot of data controllers so, as I explained, if you have the resilience and security of information networks, that should help to make data more secure in the future.”
“Q I have a question for Ian Hulme. In your role at the ICO, you are clearly looking at data security. Data is obviously one of the main goals of cyber-attacks. Data issues cut across every sector, and you are looking at a really broad sector of data, from individual identifiers to names, addresses, bank accounts or whatever it might be. This could happen in any sector. How does the Bill give you additional powers to take action, particularly on those co-ordinated through AI or foreign actors, and do you think it is sufficient for what you feel we will be facing in the next five years? Ian Hulme : We need to think about this as essentially two different regimes. The requirements under data protection legislation to report a data breach are well established, and we have teams, systems and processes that manage all that.”
“Examples in the context of China include the Lenovo Superfish scandal in 2015, in which originally implemented ad software had hijacked the https certificate, which is there to protect your communication with the website, so that nobody sees what activity is happening between you and the website. Having that Superfish injection made that communication transparent. That was done before the product even came out of the factory. This is not a problem that a software solution can fix. If you were sourcing a Lenovo laptop, for example, the laptop, upon arrival, would be a security breach, and a privacy breach in that sense. We should definitely take it a step further and regulate hardware as well, because a lot of the time that is what state-sponsored attacks target as an attack surface.”
“Q I want to move from software to hardware that is particularly vulnerable to potential cyber-attack, particularly from the integration of Chinese tech into SIPs, possibly making them vulnerable to cyber-attack by someone who knows the code into those bits of hardware. Should we be doing more to protect against that vulnerability? Should that be covered by the Bill? Chung Ching Kwong: It should definitely be covered by the Bill, because if we are not regulating to protect hardware as well, we will get hardware that is already embedded with, for example, an opcode attack.”
“To me, this is an attestation that, “We understand cyber-security, we’ve had it put in front of us, and we have to address it in some way.” One of the biggest problems, which Andy talked about earlier, is that we have all these wonderful things that the Government are doing with regard to cyber-security, down to the micro-level companies, but there are 5.5 million companies in the United Kingdom that are not enterprise-level companies, and the vast majority of them have 25 employees or fewer. How do we get to these people and say, “This is important. You need to look at this”? This is a societal issue. The code of practice and having it registered through Companies House are the way to do that. We need to start small and move big. Only 3% of businesses are involved in Cyber Essentials, which is just that: the essentials.”
“Q I note your interest in how the Bill will affect smaller businesses. There is not much detail in the Bill, but how do you think the code of practice could create an environment that lifts everyone’s security up without prescribing too great a burden? Richard Starnes: You just stepped on one of my soapbox issues. I would like to see the code of practice become part of the annual Companies House registrations for every registered company.”
“Q9. If reports are correct, Elon Musk has climbed down today under pressure from this Government. Let’s be clear: stripping women naked without consent in real life or online is abuse. However, we do not know whether to trust what X says today, and this is not just happening on X. Will the Prime Minister join me and men and women across this House and across our nation to say to any app or AI company that we will not tolerate any abuse of men, women or children in this country and that we will act on enforcement?”
“I thank the Secretary of State for her absolutely clear message that what X is doing, through the use of Grok, is illegal. That is as much the platform’s responsibility as it is the user’s. I am afraid that there is less confidence in Ofcom’s ability to enforce the Online Safety Act as it stands, or in the improvements being made. Does she agree with the many people across the country who believe that we need to see real action from Ofcom by the end of this week, or we will judge Ofcom’s leadership as failing the British public?”
“I thank the Secretary of State and the Prime Minister for their leadership on defending Ukraine not just in wartime but in peacetime, which will really reassure the many Ukrainian families who have sought refuge in Milton Keynes and across the UK. I would like to ask the Secretary of State’s advice. It is clear that Russia is challenging not just Ukraine, but the UK. It is carrying out incursions into our airspace and our waters, using cyber-attacks to undermine us and using social media to undermine our democracy. What advice would the Secretary of State give the British public on creating vigilance against the Russian attacks we are seeing increasing, over and over, on the UK?”