The Resilience Bill: what it means for tech vendors and outsourcers
PwC UK’s Warren Tucker, Technology Lead, and Bobbie Ramsden-Knowles, Crisis and Resilience Global Co-Lead, explore how the rapid rollout of generative AI and agentic platforms into business operations creates potential new resilience blind spots for tech companies.
In our latest PwC CEO Survey, more than 80% of CEOs said they are investing in technology like AI. Organisations are embedding AI into increasingly critical workflows, creating a new category of resilience risk that many continuity frameworks were never designed to address. This fundamentally changes business continuity as it relates to keeping systems available. It means we now need resilience for AI failures to ensure that automated decisions, recommendations and actions remain operational during disruption.
Tech companies are increasingly likely to find themselves in the front line where their services are autonomously running parts of their customers’ businesses. Accountability is transferring to firms that were never structured to hold it.
Tech companies underpin every organisation’s resilience
As the pace at which companies are adopting agentic tools and systems increases, reliance on these technologies deepens. As a result, we’re seeing the locus of commercial and operational risk and accountability shift inexorably from enterprise customers to the tech companies that supply them.
Recent outages across hyperscale cloud providers, cyber security platforms and software ecosystems have demonstrated that concentration risk remains one of the biggest resilience challenges facing modern enterprises.
Scale reduces many risks, but it does not eliminate them. This is a profound change for many technology firms and for the organisations using their services. In short, it means an AI-enabled enterprise must increasingly rethink what constitutes a Minimum Viable Company (MVC) in the event of a partial or major IT disruption or attack. An MVC is the smallest version of an organisation that can still function, serve customers and survive during a disruption or crisis.
This tees up a critical question for boards of tech companies: are we really ready for when our enterprise customers come knocking, looking for answers or at worse, compensation in the event our agentic AI platforms are the cause of such disruption?
There is currently no established framework for how enterprises and their AI platform providers should coordinate in a crisis, who triggers the response or what ‘containment’ even looks like in an environment characterised by fragmented contracting and federated risks.
This does not mean the ground is empty. Regulation is already moving to address the concentration risk these platforms create. In the EU, the Digital Operational Resilience Act (DORA) has applied since January 2025 and gives regulators direct oversight of the critical technology providers the financial sector depends on. In the UK, the Critical Third Parties regime introduced by the PRA, FCA and Bank of England came into force in January 2025 on the same principle. And in July 2026, HMT announced its first designations of four global cloud services and technology providers. What these regimes have yet to sufficiently answer are the operational questions at the heart of this article: in an agentic failure, who triggers the response, who coordinates across providers and what does containment actually look like? Closing that gap between regulatory intent and operational reality is where the most pressing work now sits.
It’s also becoming increasingly clear that tech companies (including software, AI and platforms) are ‘Tier Zero’ to all Minimum Viable Company frameworks. They need to have their own clear plan for what the smallest set of people, processes, data and technology needs to look like to continue operating safely and compliantly during such a disruption. And they need to be able to communicate that plan across the value chain. They will increasingly need to understand how their own services and products underpin the MVC concept for their own customers.
The rapid evolution into becoming a digital outsourcer
Businesses have always outsourced processes like Finance, HR and Supply Chain to third party providers that employed people and assumed contractual accountability for continuity. When providers won a contract, they took on the liability and disaster recovery obligations that went with it.
Now we’re seeing GenAI and agentic systems replicate that model. When a business deploys AI agents to manage 50% of its call centre volume, automate financial reporting or manage procurement workflows, the enterprise is effectively digitally outsourcing those functions. But not to a firm with legally binding and enforceable SLAs and business continuity plans.
Instead, they’re outsourcing to a platform whose own underlying availability is controlled and maintained by others. And none of the mega-providers will have signed up to the operational liabilities that a traditional outsourcer would have once accepted.
Organisations will be outsourcing operational decision-making and execution, not to another organisation, but to a collection of models, agents, APIs and cloud platforms operating across multiple providers.
An old versus new world framework makes the changes clear:
|
Old world continuity
|
New world continuity
|
|
Supplier or human provider
|
AI agent and platform provider
|
|
Contract
|
API dependency between platforms
|
|
SLA
|
Foundation models across processes
|
|
Escalation path
|
Multiple cloud providers and platforms
|
|
Liability model
|
Distributed and shared accountability
|
Tech firms are not geared up to be agentic digital outsourcers assuming all risk and responsibility, so they need to build the right contractual, technical and organisational controls now.
From risk to reward
Tech companies need to be able to define their role across the value chain. If they fail to get ahead of this, they risk becoming the attributable party when the first major AI-driven operational failure hits a household-name business. That reputational and commercial risk should focus minds.
Platform providers and tech companies that do develop credible resilience and continuity frameworks should also capture a significant competitive advantage - the ability to state, with evidence, that their platform is not just powerful but trustworthy and resilient.
Looking ahead, we expect resilience itself to become a product. IT services companies are well-positioned to develop new business models around ‘cyber backup’ capabilities - offering clients clean, standalone AI environments and human-led fallback services that can be activated when primary platforms fail. For tech firms that move early, this isn’t just risk mitigation - it’s a new revenue line and a powerful differentiator.
What should I do now as a tech company?
Tech companies should be taking a very deliberate approach. At a high level, there are four key steps.
- Map the true customer dependency: know which of your customers’ critical processes your tech, software or AI platforms are running for them, and where a single failure could cause a cascade; this may or may not be in your span of control (e.g. single sign-on).
- Address contractual gaps: decide deliberately what resilience commitments, liability positions and exit provisions you are willing to stand behind, before a customer or regulator decides for you.
- Rehearse the crisis: run joint failure scenarios with your largest customers so the first time you coordinate a response is not during a live incident - this will also clarify accountabilities and expectations (written or unwritten).
- Price resilience of your software and AI platforms as part of the product: build the clean fallback environments and human-led alternatives that let you offer continuity as an evidenced, paid-for capability rather than an implied promise.
This last point is a no-regrets action - customers will either need to ‘sign-up’ or actively decide against taking on your resilience services and to accept the consequences of doing so.
If you’d like to discuss how to maximise resilience and your differentiation as a tech, software, AI or platform business - or you’re an enterprise considering how to get the most from your tech, AI, software or platform provider as it relates to business continuity and your Minimum Viable Company position - get in touch with Warren or Bobbie.
Cyber Resilience Programme activities
techUK brings together key players across the cyber security sector to promote leading-edge UK capabilities, build networks and grow the sector. techUK members have the opportunity to network, share ideas and collaborate, enabling the industry as a whole to address common challenges and opportunities together. Visit the programme page here.
Upcoming events
Latest news and insights
Learn more and get involved
Cyber Resilience updates
Sign-up to get the latest updates and opportunities from our Cyber Resilience programme.
Meet the team
Jill Broom
Head of Cyber Resilience, techUK
Jill leads the techUK Cyber Resilience programme, having originally joined techUK in October 2020 as a Programme Manager for the Cyber and Central Government programmes. She is responsible for managing techUK's work across the cyber security ecosystem, bringing industry together with key stakeholders across the public and private sectors. Jill also provides the industry secretariat for the Cyber Growth Partnership, the industry and government conduit for supporting the growth of the sector. A key focus of her work is to strengthen the public–private partnership across cyber to support further development of UK cyber security and resilience policy.
Before joining techUK, Jill worked as a Senior Caseworker for an MP, advocating for local communities, businesses and individuals, so she is particularly committed to techUK’s vision of harnessing the power of technology to improve people’s lives. Jill is also an experienced editorial professional and has delivered copyediting and writing services for public-body and SME clients as well as publishers.
- Email:
- [email protected]
- Website:
- www.techuk.org/
- LinkedIn:
- https://www.linkedin.com/in/jill-broom-19aa824
Read lessmore
Annie Collings
Senior Programme Manager, Cyber Resilience, techUK
Annie is the Programme Manager for Cyber Resilience at techUK. She first joined as the Programme Manager for Cyber Security and Central Government in September 2023.
In her role, Annie supports the Cyber Security SME Forum, engaging regularly with key government and industry stakeholders to advance the growth and development of SMEs in the cyber sector. Annie also coordinates events, engages with policy makers and represents techUK at a number of cyber security events.
Before joining techUK, Annie was an Account Manager at a specialist healthcare agency, where she provided public affairs support to a wide range of medical technology clients. She also gained experience as an intern in both an MP’s constituency office and with the Association of Independent Professionals and the Self-Employed. Annie holds a degree in International Relations from Nottingham Trent University.
- Email:
- [email protected]
- Twitter:
- anniecollings24
- LinkedIn:
- https://www.linkedin.com/in/annie-collings-270150158/
Read lessmore
Olivia Staples
Junior Programme Manager - Cyber Resilience, techUK
Olivia Staples joined techUK in May 2025 as a Junior Programme Manager in the Cyber Resilience team.
She supports the programs mission to promote cyber resilience by engaging key commercial and government stakeholders to shape the cyber resilience policy towards increased security and industry growth. Olivia assists in member engagement, event facilitation and communications support.
Before joining techUK, Olivia gained experience in research, advocacy, and strategic communications across several international organisations. At the Munich Security Conference, she supported stakeholder engagement and contributed to strategic communications. She also worked closely with local and national government stakeholders in Spain and Italy, where she was involved in policy monitoring and advocacy for both public and private sector clients.
Olivia holds an MSc in Political Science (Comparative Politics and Conflict Studies) from the London School of Economics (LSE) and a BA in Spanish and Latin American Studies from University College London (UCL).
Outside of tech, Olivia enjoys volunteering with local charities and learning Norwegian.
- Email:
- [email protected]
Read lessmore
Authors
Warren Tucker
Partner and Technology Leader, PwC UK
Bobbie Ramsden-Knowles
Crisis and Resilience Global Co-Lead, PwC UK