Cybersecurity 2026

UK Law and Practice Contributed by: William Long, Francesca Blythe, Eleanor Dodding and Matthias Bruynseraede, Sidley Austin LLP

Relatedly, in its annual review published on 3 Decem - ber 2024, the NCSC noted significant advances in AI that will enable and enhance existing cybersecurity challenges. In January 2025, the DSIT published a sector-agnostic Code of Practice for the Cyber Security of AI (the “AI COP”) to establish the minimum cybersecurity stand - ards that developers and system operators should incorporate when building and using AI solutions. The AI COP, which is voluntary, is based on the AI Guide - lines and is intended to sit alongside the UK govern - ment’s 2023 White Paper “A pro-innovation approach to AI regulation”, which includes “Safety, Security and Robustness” as one of the five key principles – the focus of the AI COP. The AI COP is structured around 13 principles and stakeholders to which each principle primarily applies are identified. Requirements include AI security awareness training, system design and dataset considerations, incorporating threat-model - ling into the risk management process, and evaluation and testing. The AI COP aligns expectations across the AI lifecycle (including secure design, secure devel - opment, secure deployment, secure maintenance, and secure end-of-life) and places particular empha - sis on supply-chain security, dataset integrity, secure configuration and access controls, and incident man - agement processes. While the AI Guidelines and AI Code are non-statuto - ry, they are likely to be treated as benchmarks when assessing whether an organisation has implemented appropriate security measures, such as security-by- design “appropriate” security under Article 32 UK GDPR (particularly where AI systems process per - sonal data). 6.3 Cybersecurity in the Healthcare Sector Under the NIS Regulations, NHS trusts, foundation trusts, integrated care boards, and certain other healthcare providers are designated as OESs. Con - sequently, these healthcare providers are required to comply with the obligations of an OES as described in 2.2 Critical Infrastructure Cybersecurity Require- ments . Medical devices in the scope of the Medical Devices Regulations 2002 are expressly excluded from the

PSTI Act. However, the UK government is expected to continue its overhaul of the UK’s medical devices legislative framework following the application of the Medicines and Medical Devices Act 2021 (the “MMD Act”). The MMD Act grants the Secretary of State the power to introduce regulations relating to the manufacture of medical devices. In February 2024, the Department for Health and Social Care (DHSC) confirmed that it would introduce a package of legis - lative reforms for UK medical devices. In December 2024, the Medicines & Healthcare Products Regula - tory Agency (MHRA) issued a revised roadmap for reform (the “Roadmap”), announcing new guidance on cybersecurity requirements for software incorpo - rated into medical devices. In addition, strengthened post-market surveillance requirements for medical devices took effect in June 2025, increasing expecta - tions for incident detection, investigation, and report - ing (including when cyber vulnerabilities pose patient safety risks). In December 2025, the MHRA published an In Vitro Diagnostic (IVD) Medical Device Road Map. This roadmap outlines the planned priority delivera - bles for the IVD medical device work programme until mid-2027. The MHRA has produced a number of work pack - ages in its proposed Software and AI as a Medical Device Change Programme, with Work Package WP5 dedicated to “Cyber Secure Medical Devices”. This work package focuses on ensuring that cybersecurity is adequately reflected in software as a medical device (SaMD) requirements and explains that secondary legislation will be developed to impose cybersecurity and IT requirements to guard against cybersecurity risks in medical devices and IVDs that may result in device malfunction, loss or tampering with personal data, damage to the device and ultimately injury to the patient. Guidance will be developed on cybersecurity issues across the life-cycle management processes for medical devices and IVDs, and on the reporting of cybersecurity vulnerabilities. NHS England (including the functions formerly carried out by NHS Digital, the body responsible for informa - tion, data and IT systems in health and social care in the UK) has published a variety of guidance, includ - ing the Data Security and Protection Toolkit, which is an online self-assessment tool that all organisations

454 CHAMBERS.COM

Powered by