top of page
Search

Navigating KCSIE 2026: AI, EdTech and what schools need to do next

Updated: Aug 10

In preparation for the start of the academic year on 1 September 2026, the Department of Education has issued updated statutory safeguarding guidance: Keeping Children Safe in Education (KCSIE) 2026.


While much of the guidance reinforces existing safety protocols, this year's update has added implications for safeguarding in schools and in particular, how schools must approach Artificial Intelligence (AI) and digital safety.

KCSIE was updated in 2026, with the changes coming into effect in September.
KCSIE was updated in 2026, with the changes coming into effect in September.

As page 12, paragraph 21 states,


"All staff should be aware that technology is a significant component in many safeguarding and wellbeing issues. Children are at risk of abuse and other risks online as well as face to face"

The focus of the new updates mean that senior leadership and Designates Safeguard Leads (DSLs) are expected to be active and strategic in ensuring AI safety and digital monitoring.


In this post, we look at the rationale for the changes. We then look at the changes themselves before exploring practical, actionable steps that schools and leaders can take.


General changes


  • One of the most noticeable general changes is that all staff, including non-teaching staff, are expected to read Part 1 of KCSIE in full. The previous requirement of reading just Annex A has been removed.


The Summary section on Page 5 states,


"Governing bodies and proprietors should ensure that those staff who work directly with children read as least Part one of this guidance. Governing bodies and proprietors, working with their senior leadership teams and especially their designated safeguarding lead, should now ensure that those staff who do not work directly with children read Part one of this guidance."

  • Part Five has been substantially rewritten to address child-on-child abuse. This includes harmful sexual behaviours, harassment, violence and misogyny.


  • There is new content covering violence against women and girls (VAWG). This provides clearer frameworks for staff to recognise early warning signs, address misogynistic behaviours and develop a whole-school culture that challenges harmful attitudes.


  • Schools are now expected to operate as mobile-free environments by default. Page 45, paragraph 168 states,


"All schools should be mobile-free environments by default; anything other than this should be by exemption only."

Pages 45-46 provide statutory guidance (link) on this and explains that schools are expected to implement a policy where pupils do not have access to their mobile phone at any time during the school day, including during lessons, transition times and breaktimes.


  • KSCIE 2026 contains additional guidance relating to children who are LGB or gender questioning, providing schools with guidance of supporting these pupils in relation to safeguarding.


  • More robust Enhanced DBS checks are required for volunteers, removing certain supervision exemptions.


  • The mental health section has been substantially updated. The revised guidance places a stronger emphasis on early intervention, clear referral pathways and recognising how risks like online bullying and AI-driven harassment impact pupil well-being.


  • There is also a shift in language towards community-based early help and family help, preceding planned legislative changes.


AI and online safety


While is is important to know about the overall changes in KCSIE 2026, we now focus specifically on the implications for using technology in school.


1 - AI-Generated Content, Deepfakes and the 4C's framework


What has changed?


KCSIE 2026 has modernised the definitions of online risk to address generative AI.


  • Updated terminology for "Nudes and Semi-Nudes": The updated guidance explicitly includes digitally created nude, or partially nude images created with generative AI alongside human-generated media. Incidents involving the creation or sharing of this material trigger a formal safeguarding response. Pupil's attitude towards this behaviour would be considered indictive of a school's overall culture.


Page 51, paragraph 191 includes "consensual or non-consensual making or sharing of nudes and semi-nudes, including those generated by AI" as a form of child-on-child abuse. This kind of behaviour should trigger actions according to school policies regarding child-on-child abuse.


Page 125, paragraph 537 also includes "consensual or non-consensual making of nudes or semi nudes" as a form of sexual harassment. Page 123, paragraph 527 states that "Schools and colleges should be aware of the importance of making it clear that there is a zero-tolerance approach to sexual harassment and sexual violence; that it is never acceptable and will not be tolerated." This section goes onto to describe the need for a culture of reporting and not accepting this behaviour as 'normal' or 'banter'.


  • Revised "4C's" Model: The 4C's of online risks: 'contact', 'conduct', 'content' and 'commerce' have been modified to include risks posed by generative AI.

  • Page 44, paragraph 163 explains that contact risks include interaction with "users or generative AI applications that simulate this" (harmful online interaction)

  • Conduct risks are expanded to include as an example, "making, sending and receiving explicit images, including those generated using AI"

  • Content risks include exposure to "misinformation, disinformation (including fake news) and conspiracy theories.


The rationale


Recent data from the UK Safer Internet Centre (source) shows that over half of young people aged 8 - 17 regularly engage with generative AI tools. Generative AI tools are increasingly readily accessible, built into a wide range of apps and search engines. Some of these tools are capable of generating hyper-realistic content, leading to a rise in peer-on-peer extortion, image manipulation and bullying. Furthermore, legislative updates, such as the Crime and Policing Act 2026 have criminalised the creation and distribution of AI nudification tools. KCSIE 2026 therefore aligns with these developments.



Practical tips for schools


  • Update online safety and Acceptable Use Policies. Schools should ensure that Acceptable Use Policies (AUPs) are clear about pupil and staff use of AI. Clear boundaries should be defined around creating images, copying personal data into AI prompts and academic integrity. AUPs should be frequently referred to in lessons, form times, computer rooms and assemblies and children should be clear about the rationale behind rules.


  • Review public photo policies (image scraping prevention). Automated bots can 'harvest' images from school websites, social media pages or digital publications. Schools can take steps like reducing high-resolution, head-on photos on public facing sites and avoid attaching names to photos.


  • Educate pupils on chatbot dynamics. RSE/PSHE lessons in particular are a good opportunity to discuss the nature of AI tools with pupils. Children should be reminded that generative AI tools are algorithm-driven and lack any sense of empathy. Accordingly, they should not replace human support networks.



2 - Mandatory annual filtering & monitoring reviews with clear governance


What has changed?


Previous guidance encouraged annual reviews through the DfE Technical Standards. The updated version of KCSIE 2026 takes this further, making filtering and monitoring checks as an explicit statutory requirement.


Page 46, paragraph 171 states,


"As part of this process (filtering an monitoring), governing bodies and proprietors should ensure their school or college has appropriate filtering and monitoring systems in place and that a review of their effectiveness is carried out at least once every academic year."

  • Mandatory Annual Review. Governing bodies and proprietors must ensure that an annual review of the effectiveness of filtering and monitoring systems is carried out at least once per academic year and that this is documented.


  • Shared leadership accountability. The review must be led by a member of the Senior Leadership Team (SLT), working alongside the DSL and IT staff. The review cannot be offloaded solely to external IT providers or network administrators.


  • DSLs role and job descriptions. DSLs are expected to have a good understanding of filtering and monitoring systems, to enable them to play an active part in their use and review. This requirements should be evident in the job description of members of SLT and the DSL.


  • Evidenced testing. Schools must maintain records of when reviews are carried out. This should include checks conducted across all internet-connected devices, locations and guest networks.


The rationale


This aspect of the updates to KCSIE 2026 reflect the previous situation which could occur where information was not shared between IT leads and safeguarding leads. Safeguarding leads were not always aware of what was 'blocked', when flags would be raised and how settings functioned on non-standard devices, such as tablets or on guest Wi-Fi. Bringing filtering under the oversight of SLT ensures that technical controls match real-world safeguarding risks.


Practical tips for schools


  • Establish a filtering and monitoring log. Create a clear, centralised register, including the date, scope and results of filtering tests, including who conducted them and any actions taken.


  • Audit AI tools in the filtering system. Test how the network filter handles standalone AI applications (i.e. Chat GPT, Claude, image generators.) Decide which tools are approved for school use and block unvetted or unsafe applications.


  • Update the DSL job description. Review and amend the job specifications of the DSL and Deputy DSL to include oversight and review procedures for filtering an monitoring systems.


3 - Cybersecurity as an integral safeguarding pillar


What has changed?


KCSIE explicitly connects safeguarding to the DfE Cyber Security standards for Schools and Colleges. Protecting student information, including sensitive and personal data and maintaining secure IT environments are now recognised as being fundamental to keeping children safe.


Page 48, paragraph 176 states,


"Governing bodies and proprietors should take measures to safeguard children by protecting personal information and ensuring their school or college has appropriate cyber security systems in place. This should be approached as part of the school or college's wider safeguarding responsibilities."

The rationale


Cyber incidents or data breaches can compromise sensitive child protection records, expose personal information or lead to extortion. KCSIE 2026 recognises that protecting children's personal and sensitive data is a key part of protecting their psychological wellbeing.


Practical tips for schools


  • Align with DfE cybersecurity standards. Ensure that Multi Factor Authentication (MFA) is enabled for all staff accounts. Ensure that back ups are isolated and off site and that data protection protocols are regularly reviewed.


  • Conduct staff training in AI and data security. Conducts staff training on AI and data security. Remind staff not to enter personal or sensitive data into unapproved generative AI tools, to ensure that security permissions are set on documents and to send links instead of attachments where appropriate and possible.


4 - Addressing wearable technology and smartwatches


What has changed?


While KCSIE 2026 focuses heavily on software-level risks (generative AI, chatbots, deepfakes and network filtering), it offers little guidance on the effects of wearable smart technology (other than smartphones) in schools. By smart technology, we mean devices that can connect to the internet, which increasingly includes glasses, watches, bags and items of clothing. Many of these devices also feature cameras and microphones.


KCSIE 2026 required strict annual checks on school internet filtering. However, many smartwatches and wearables feature independent, cellular SIMs or eSIMS. If a pupil accesses the internet, an AI tool, messaging or social media through a smartwatch, this bypasses the school's monitored Wi-Fi and filtering systems.


The rise of smart glasses and smartwatches equipped with cameras and microphones presents a real safeguarding risk to children, as well as a risk to staff. This is particularly true in terms of:


  • Filming in sensitive areas of school (i.e. changing rooms, toilets)

  • Silent image capture, including to train AI tools or create deepfakes


Broader regulatory framework


While KCSIE 2026 does not dedicate a standalone section to wearables, other UK guidance can help.


Under the Children's Wellbeing and Schools Act 2026, statutory guidance requires schools to be mobile-free environments. Under the definition of personal smart devices subject to restrictions, the DfE includes "smartwatches and interactive devices capable of messaging, recording or internet access."


Any non-consensual, inappropriate capture of media via wearable technology would fall under the criminal definitions outlined in KCSIE 2026.


Practical tips for schools


  • Broaden device-use in AUPs. Ensure that Acceptable Use Policies (AUPs) explicitly list smart watches, fitness trackers, smart glasses and other smart wearables alongside mobile phones.


  • Set clear expectations for parents. Communicate safeguarding developments, legislation and school policies with parents. Clear and early communication will reduce friction and misunderstanding and securing parental support is essential.


  • Brief staff on wearable capabilities. Brief staff on the capabilities and warning signs of smart technology use so that they can identify when devices are being used covertly.



School action plan for September implementation


  1. Update the whole-school safeguarding and online safety policies to reflect AI risks (deepfakes, 4Cs, image scraping).

  2. Schedule an annual filtering and monitoring review involving SLT, DSL and IT leads.

  3. Ensure that all staff undergo whole-school safeguarding training on Part 1 (note the withdrawal of the 'Annex A only' requirement).

  4. Verify that DSL job descriptions explicitly list filtering and monitoring oversight.

  5. Audit school website and social media channels to mitigate image scraping risks.

  6. Confirm acceptable use guidelines for AI tools in terms of both staff and pupil use and make sure that AI tools are checked and approved.


Summary


KCSIE 2026 is a substantial document and the changes made this year in terms of technology are significant. If members of SLT, DSLs, IT staff, teachers, staff, students and parents work together and fulfill their roles, the aims of KCSIE, can be met.


The developments to KCSIE recognise the seriousness of online harm and demand that schools treat digital infrastructure with the same priority as physical security. By updating policies, conducting filtering reviews and providing clear guidelines, as well as asking for external help when needed, schools can create environments where children can feel safe in an increasingly digital world.



Disclaimer: I am a practicing teacher, writing to share practical insights and commentary on statutory safeguarding updates. This article is intended for educational and informational purposes only and does not constitute formal legal or regulatory advice. Schools should consult official Department of Education (DfE) guidance and their legal and safeguarding advisers when reviewing whole-school policies.



 
 
 

Comments


© 2023 by Owen Dobbing . Powered and secured by Wix

bottom of page