When new UK prime minister Andy Burnham took the helm in July, he made a number of changes to his cabinet, including the appointment of a new AI minister. Burnham also dissolved the Department for Science, Industry and Technology (DSIT), splitting its responsibilities among the cabinet office and transferring cybersecurity to the Departure for Culture, Media and Sport (DCMS).
Meanwhile, DCMS is being renamed the Department for Digital, Culture, Media and Sport.
Experts think many of the changes make sense. But some are warning they could have an impact on regulation such as the Cyber Security and Resilience Bill, with an article on Pinsent Masons suggesting delays are possible.
New Priorities
As part of the changes, cybersecurity, telecoms, digital identity, the Government Digital Service (DGS) and wider digital policy now sit within the expanded Department for Digital, Culture, Media and Sport.
AI strategy, public-sector AI adoption and the AI Security Institute have moved to the Cabinet Office. At the same time, science and industrial technology are now part of the new Department for Business, Innovation, Science and Trade.
The structure suggests Burnham sees technology “less as a standalone policy area” and “more as infrastructure for public-service reform, industrial growth and national resilience,” says Jamie Akhtar, CEO and co-founder of CyberSmart.
Yet the abolition of DSIT and the decision to split its responsibilities “tell different stories about prioritisation,” says Grace Carter, government affairs counsel, Elastic.
The cabinet office placement signals that AI is being treated as “a cross-government concern,” she says. But she does have some concerns.
For example, she points out that following the changes made by Burnham, cybersecurity “moves to a department where it doesn't feature in the name or the primary remit.”
At a time when the Cyber Security and Resilience Bill is working its way through parliament, the contrast is “hard to ignore,” says Carter. “The structural question this raises is whether AI and cyber policy can remain coordinated when responsibility for them sits in different parts of government, and what that means for the bodies, such as the AI Security Institute and National Cyber Security Centre (NCSC), which depend on close collaboration to function effectively.”
Jake Taylor, head of government at Filigran thinks the decision to move cybersecurity into DCMS is “intriguing.”
“This could ultimately prove to be a strategically astute decision, or it could introduce an additional layer of complexity at a time when cyber threats continue to evolve at pace.”
Yogesh Agarwal, CEO at RightCue, believes the new prime minister has “effectively split up a well-formed function into three separate departments.”
This matters because AI and cyber are so closely linked, says Agarwal. “AI systems create new attack surfaces, while cyber controls are needed to protect the data, models, systems and infrastructure that AI depends on. If AI governance and cyber resilience sit in different parts of government, there is a risk that regulation, guidance and accountability become less joined up.”
Logical Argument
However, experts agree that many of the cabinet moves make sense. For example, there is a logical argument behind GDS bringing cybersecurity with it to DCMS, says Taylor. “The department already plays a significant role in shaping the UK's digital economy, telecommunications and many aspects of the nation's critical national infrastructure.”
As cybersecurity increasingly becomes an issue of national resilience, rather than simply IT risk, he believes placing responsibility alongside the sectors that underpin everyday life “could encourage a more integrated approach to protecting critical services.”
Cabinet office placement also gives AI security – and by extension the AI Security Institute – more direct influence over cross-government decision making, according to Carter. “If that translates into faster, more joined-up guidance on AI security for the public sector, industry will benefit.”
At the same time, the appointment of John Healey as chancellor could be advantageous for security, Carter tells SC Media UK. “A longstanding advocate for increased defence investment, he now has the means to act on that ambition.”
Disruption Risk
Following the changes, the Cyber Security and Resilience Bill is the piece of legislation to watch most closely, says Carter. “It's the most significant cyber policy development the UK has in progress, and machinery of government changes of this scale have historically introduced delays as ministers establish priorities and officials are redeployed. Organisations anticipating clarity on reporting obligations and scope expansion should factor that uncertainty into their planning.”
Pinsent Masons has warned the restructuring creates practical questions about continuity and could add delay to an implementation programme already expected to extend towards 2029. That concern “is credible,” says Akhtar. “Even if the primary legislation continues on schedule, delays to consultations, guidance and secondary legislation could postpone its effect.”
There’s also a practical risk for industry engagement. Businesses need clarity on “who owns cyber policy, who is responsible for upcoming regulation, and which department they should engage with”, points out Agarwal. “If that becomes unclear, organisations may delay preparation or receive mixed messages.”
However, the restructuring won’t have a dramatic impact. As the changes come into place, the main risk is “disruption” rather than “a deliberate change of policy,” according to Akhtar.
Carry On As Normal
Jonathan Wright, partner at Hunton Andrews Kurth believes the government's restructuring is unlikely to change the overall direction of travel for UK cyber regulation. Instead, he thinks it may impact the timing and practical implementation of the new framework. “The legislation will only be the starting point. Businesses should now be considering how the new departmental structure, regulators and agencies will operate in practice, particularly how responsibility for cyber policy, oversight and enforcement will be allocated across government.”
For cybersecurity leaders, the message is simple: “Political change may affect timing and ownership, but it shouldn’t delay preparation,” says Agarwal. “The regulatory direction remains clear: Organisations should continue strengthening resilience, improving supplier oversight, and making sure AI and cyber risk are governed together, rather than in separate silos.”
With this in mind, carry on prioritising your organisation’s cyber strategy, advises Agarwal. “The new Cyber Security Pledge, which provides a tangible way for organisations to demonstrate their commitment to security, is still very much in place.”
The most valuable thing leaders can do right now is “engage early,” according to Carter. “Consultations, regulators and industry bodies are shaping legislation that isn't yet finalised, and those who contribute are better positioned to understand evolving expectations before they become mandatory requirements.”
Written by
Kate O'Flaherty
Cybersecurity and privacy journalist