P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

The Computer Misuse Act amendment before peers this afternoon creates no statutory defence, whatever its heading says

Amendment 164 obliges a review of whether a defence is needed, and a report saying whether ministers intend to legislate. That is a different and smaller thing, and it explains why it was tabled.

By Parminder Kumar Sharma · · 8 min read

A wood-panelled parliamentary committee room with green leather benches, a brass banker's lamp with a green shade, and a thick bundle of amendment papers open on a polished oak table beside reading glasses and a pen.

Grand Committee on the Cyber Security and Resilience Bill sits again this afternoon at 15:45, and Amendment 164 is on the list. Its heading reads:

"Computer Misuse Act 1990: statutory defence for cyber security activities"

It is sponsored by Lord Clement-Jones for the Liberal Democrats, with Lord Arbuthnot of Edrom and Lord Holmes of Richmond from the Conservative benches and Baroness Finlay of Llandaff from the Crossbenches. Cross-party, and the long-running ask of the security research community.

I pulled the operative text from the Bills API this morning, because the marshalled list PDF blocks automated fetching and the heading is not the clause.

The amendment does not create a statutory defence.

What it actually does

What the heading says, and where the clause stops

WHAT THE HEADING SAYS, AND WHERE THE CLAUSE STOPSAmendment 164, read from the marshalled list rather than its title.THE HEADING“Computer Misuse Act 1990: statutory defence for cyber security activities”A reviewwithin 12 months of Royal Assentwhether a defence is “necessary or desirable”A reportlaid before Parliamentfindings and conclusionsA statement of intentin that same reportwhether they will legislate, and whenTHE CLAUSE ENDS HEREAdefencenot hereThree duties, all procedural. The amendment creates no defence and does not claim to in its text.What it does obtain is an answer, in public, on a deadline. That is worth having, and it is not what the heading says.AND THE GOVERNMENT’S OWN WORDING, IN ITS OWN WORDS3 December 2025, Security Minister:“would protect them from prosecution”3 September 2026, same minister, in writing:“unlock the power of cyber security professionals”
The phrase “statutory defence” appears in the Security Minister’s December speech and does not appear in his written answer of 3 September, nine months later, which is the government’s most recent formal statement of what the Computer Misuse Act reforms will contain.
Amendment text read verbatim from bills-api.parliament.uk, amendment 10037334, marshalled list number 164, on 7 September 2026. Ministerial quotations from the gov.uk speech of 3 December 2025 and written answer UIN 22222 of 3 September 2026.

The clause, verbatim, requires that the Secretary of State "must, within 12 months of the day on which this Act is passed, carry out and publish a review of whether the introduction of a statutory defence under section 1 of the Computer Misuse Act 1990 ... is necessary or desirable".

The review "must consider, in particular" three things: the position of "cyber security researchers, vulnerability testers and threat-intelligence practitioners acting in good faith"; the "conditions and safeguards (including as to authorisation, proportionality and reporting)" any defence should contain; and "the approaches taken in other jurisdictions".

Then a report to Parliament setting out the findings, and "whether the Secretary of State intends to bring forward proposals for such a statutory defence, and, if so, the intended timetable for doing so".

Three duties, all of them procedural. The sponsors' own explanatory statement says so plainly: it "seeks to place a statutory duty on the Secretary of State to review, within 12 months, whether a statutory defence ... is needed".

So nobody is being misleading. The drafting is honest and the explanatory note is accurate. It is the heading that will travel, and the heading says something the clause does not do.

The reason a review duty is being asked for at all

Here is the part that makes this afternoon interesting, and it is visible only if you put two government statements side by side.

On 3 December 2025, the Security Minister Dan Jarvis told the FT Cyber Resilience Summit, and gov.uk published it:

"Which is why we are looking at a legal change to the Computer Misuse Act. This would create a 'statutory defence' for these researchers to spot and share vulnerabilities, which would protect them from prosecution, as long as they meet certain safeguards."

That is about as clear as ministerial language gets. Named mechanism, named effect.

On 3 September 2026, nine months later, the same minister answered written question UIN 22222, tabled by James Naish, on whether the department plans to review the effectiveness of the Act. The full relevant passage:

"The Government is conducting an ongoing review of the Computer Misuse Act 1990 and is actively taking forward reforms to the cyber landscape. Proposals to update the CMA will be introduced as soon as parliamentary time allows. The changes will allow law enforcement agencies to more effectively tackle threats posed by cyber criminals. The reforms will create a Cyber Crime Risk Order to place robust controls on the behaviours of cyber criminals, alongside new powers to search individuals believed to be concealing evidence on behalf of suspects. It will also unlock the power of cyber security professionals to better enable them to secure computer systems."

The phrase "statutory defence" is not in it.

The two named, concrete reforms are both enforcement powers: a Cyber Crime Risk Order, and new search powers. The researcher provision has become "unlock the power of cyber security professionals to better enable them to secure computer systems", which commits to no mechanism at all.

The same commitment, in the government's own words, four days ago and nine months ago

DateWhat was saidWhat it commits to
3 December 2025“This would create a ‘statutory defence’ for these researchers … which would protect them from prosecution, as long as they meet certain safeguards”A named legal mechanism with a named effect
3 September 2026“It will also unlock the power of cyber security professionals to better enable them to secure computer systems”No mechanism named. No effect named
3 September 2026, same answer“The reforms will create a Cyber Crime Risk Order … alongside new powers to search individuals”Two specific new enforcement powers, both named
Both quoted verbatim from primary sources: the gov.uk speech text of 3 December 2025 and Parliament's written questions record for UIN 22222, answered 3 September 2026. Both are Dan Jarvis in his capacity at the Home Office.

Read that table in the other direction and it explains the amendment. If the government were still committed to a defence in the terms it used in December, a review duty would be redundant. Asking for one is a way of finding out whether the December sentence is still operative.

What this means if you do security research in Britain

Nothing changes today, and nothing changes if the amendment passes. That is the honest answer and it is worth saying before the practical notes.

Take this with you

Where this actually leaves you

  • The legal position under section 1 of the Computer Misuse Act is unchanged, and will remain unchanged whatever happens this afternoon. Unauthorised access remains an offence with no good-faith carve-out.
  • If you are relying on the December 2025 commitment when scoping work, note that the government’s most recent formal statement, four days ago and in writing, does not repeat it. Plan against the law as it is.
  • Watch for the word used in the Minister’s reply this afternoon. If a defence is named, that is a restatement worth having on the record. If the answer is the September formulation, that is the answer.
  • The reform vehicle is a future National Security Bill, and the timing is “as soon as parliamentary time allows”, which is not a date. An amendment forcing a report within twelve months of Royal Assent is an attempt to attach one.
  • If you run a disclosure programme, keep documenting authorisation. Every version of a proposed defence, including the one in this amendment’s review criteria, turns on authorisation, proportionality and reporting. Whatever eventually arrives, that evidence is what you will need.
  • Grand Committee day four is Wednesday 9 September at 16:15, so if this is not reached today it is reached then.

The position

There is a version of this story where a cross-party group of peers finally legislated protection for security researchers this afternoon. That version will be written. It is wrong on the face of the document.

What is actually happening is smaller and, in its way, more revealing. Four peers have concluded that the way to make progress on a nine-month-old ministerial commitment is to compel a review of whether the commitment should be honoured, with a report to Parliament and a stated timetable. You do not ask for that when a promise is being kept.

The Minister's answer this afternoon is the thing to listen to, and the specific thing to listen for is whether the words "statutory defence" come back.

Sources

  1. PrimaryAmendment 164 to the Cyber Security and Resilience Bill, read verbatim from the Bills API: the operative text, the four sponsors, and the status recording that the House has not considered itUK Parliamentaccessed 2026-09-07
  2. PrimaryWritten question UIN 22222, tabled 28 August 2026 by James Naish, answered 3 September 2026 by Dan Jarvis: the government's most recent formal statement on Computer Misuse Act reformUK Parliamentaccessed 2026-09-07
  3. PrimaryKeynote address to the FT Cyber Resilience Summit, 3 December 2025, in which the Security Minister said a change would create a statutory defence protecting researchers from prosecutionHome Officeaccessed 2026-09-07

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

One email per briefing. Unsubscribe any time.