# What Does AI Mean for Safeguarding in Schools?

Canonical URL: https://blog.theaieducator.io/posts/what-does-ai-mean-for-safeguarding-in-schools
Publication: Dan Fitzpatrick Insights
Author: Dan Fitzpatrick
Topic: AI Governance and Responsible Leadership
Published: 2026-09-27T07:19:16.000Z
Modified: 2026-09-27T07:19:53.778Z

KCSIE 2026 changed one definition, not your whole safeguarding duty. Here is what the statutory guidance actually says about AI, where the real requirements sit, and the four checks worth doing this term.

## In brief

Keeping children safe in education 2026, in force since 1 September 2026, makes one explicit change about AI: its definition of a nude or semi-nude image now includes images that are digitally altered or wholly generated by artificial intelligence, including deepfakes and deep nudes (paragraph 6). It creates no separate AI safeguarding duty. The detailed AI expectations sit in the Department for Education's generative AI product safety standards, which are non-statutory and bind nobody unless a school makes them a condition of purchase, and most companion chatbots fall outside the Online Safety Act entirely. So the leadership task is not a new policy. It is four checks on systems a school already runs: the definitions in the child protection policy, filtering and monitoring, what staff and the designated safeguarding lead know, and the route a concern travels once it is raised.

## Key takeaways

- Keeping children safe in education 2026 makes one explicit change about AI: paragraph 6 now defines nudes and semi-nudes to include images that are digitally altered or wholly generated using artificial intelligence, including deepfakes and deep nudes.
- That change creates no new duty. It brings AI-generated imagery inside the child protection process a school already runs, with the same thresholds, records and referral routes.
- The Department for Education deliberately declined to expand AI content inside the statutory guidance, and its consultation response points instead to the Generative AI Product Safety Standards launched in January 2026.
- Those product safety standards are the substantial AI safeguarding document, and they are non-statutory. They only protect children in a school that makes them a condition of approving a tool.
- Ofcom's guidance of 18 December 2025 sets out that a chatbot which only lets a user talk to the bot, does not search multiple sites and cannot generate pornographic content falls outside the Online Safety Act, which covers many companion apps children use.
- The Absorption Test is Dan Fitzpatrick's suggested way of framing the work: four checks on the child protection definitions, filtering and monitoring, staff and DSL knowledge, and the reporting route.
- The risk concentrates rather than averages. Pew Research Center found 12 percent of US teens using chatbots for emotional support, while Internet Matters found 71 percent of vulnerable children using them and 26 percent of those preferring a bot to a person.

Four weeks into the new academic year, most school leaders have read that AI has changed their safeguarding duties. One clause in the statutory guidance actually did. The rest of what you have been told is a procurement standard with no legal force, a regulator whose reach stops short of the products children are really using, and a great deal of marketing from companies that sell filtering software.

That is not a reason to relax. It is a reason to give this term to the four things that will make a difference rather than to the one thing that will not, which is writing a separate AI safeguarding policy.

## What did KCSIE 2026 actually change about safeguarding and AI?

It changed one definition, and that single change matters more than its length suggests. [Keeping children safe in education 2026](https://www.gov.uk/government/publications/keeping-children-safe-in-education--2/part-one-overview-for-all-staff), in force since 1 September 2026, now defines nudes and semi-nudes to include images that "may also be digitally altered or wholly generated using artificial intelligence, including what are sometimes described as 'deepfakes' or 'deep nudes'" (paragraph 6).

Read what that does. It does not create a new duty. It pulls AI-generated imagery inside a duty you have discharged for years. The moment a fabricated image of one of your pupils appears, it is a nude or semi-nude under the statutory definition, which means your existing child protection process applies to it in full: the same response, the same referral thresholds, the same records, the same people.

That is the whole of the explicit AI content in the guidance. I have looked for more and there is not more. If you are waiting for a chapter on chatbots, it is not coming this year, and the Department said so itself.

## Why is there so little AI in the statutory guidance?

Because the Department for Education decided there should be. Its own [consultation response](https://assets.publishing.service.gov.uk/media/6a4cc3467abea59ac13fd2a8/Keeping_children_safe_in_education_2026_Government_consultation_response.pdf) records that respondents raised exactly the risks you would expect, naming "AI-generated sexual images and deepfakes, grooming or harmful chatbot interactions, misuse of pupil or staff data", and asked for clearer expectations inside the document rather than links out of it. The Department declined, and pointed instead to its generative AI policy paper and to the "Generative AI Product Safety Standards launched in January 2026".

This is worth understanding rather than resenting. Statutory guidance that named specific technologies would be out of date within a year, and schools would be held to a standard written about products that no longer exist. Keeping the guidance about harms and keeping the technology in a separate document that can be revised quickly is a defensible choice.

It also has a consequence nobody has said out loud to leaders. The detailed AI safeguarding expectations are real, they are specific, and they are not law.

## Where do the real AI safeguarding requirements live?

In a non-statutory procurement standard, which is a much better document than its status implies. The DfE's [generative AI product safety standards](https://www.gov.uk/government/publications/generative-ai-product-safety-expectations), last updated on 19 January 2026, describe what an AI product used in a school should do. Three of those expectations should change how you buy.

A product should "identify and alert local supervisors to searches for, or access to, harmful or inappropriate content". It should "identify and alert local supervisors of disclosures that indicate a possible safeguarding issue", holding current contact details for the safeguarding lead and alerting within an agreed timescale. And since the January 2026 update it should "detect signs of learner distress" and follow an agreed pathway when it does, as well as avoid anthropomorphizing itself, avoid responses such as "You can trust me" that isolate a learner, and avoid sycophancy and flattery as motivation.

Those are safeguarding requirements written for the age we are in. They are also unenforceable. No vendor breaks the law by ignoring them. Which means the standards only protect children in your school if you make them a condition of [approving AI tools for schools](https://blog.theaieducator.io/posts/approving-ai-tools-for-schools) rather than a document you cite in a policy. The only hold a school has over a vendor is the decision to buy or not to buy, and it is worth using while you still have it.

## Why won't regulation cover the chatbots children actually use?

Because most companion chatbots fall outside the Online Safety Act, and this is the gap almost no school leader I speak to knows about. Ofcom's own guidance on [AI chatbots and online regulation](https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/ai-chatbots-and-online-regulation-what-you-need-to-know), published on 18 December 2025, sets out that a chatbot service is not regulated where it only allows people to interact with the chatbot itself and no other users, does not search multiple websites or databases to answer, and cannot generate pornographic content.

Sit with that description for a moment and picture the product it fits. A one-to-one companion app. No other users. No search. No explicit content. A thirteen-year-old talking to it at one in the morning about something they have told nobody else. On Ofcom's own account of scope, that service carries no duties to that child.

So the position, in England, as of this term: the statutory guidance covers the image, the procurement standard covers the product you chose to buy, and the product a child downloaded on their own phone is covered by neither. Whatever protection exists for that child in that conversation is the protection your school built. This is a moving picture and the government has said it is keeping the framework under review, so check the current position before you brief governors on it.

## The Absorption Test

The work AI creates for you is not a new policy; it is four checks on systems you already run. That is the question I put to leadership teams who tell me they need an AI safeguarding policy, and I call it the Absorption Test: does the safeguarding machinery you already run absorb AI, or does AI fall straight through it? Four systems are tested, in this order: the definitions in your child protection policy, your filtering and monitoring, what your staff and your designated safeguarding lead actually know, and the route a concern travels once someone raises it. A school that passes has changed four documents and one training slide. A school that fails writes a new policy nobody reads, and the concern still arrives at the IT helpdesk.

I offer this as a way of framing the work rather than as a tested method. Take the four checks in order, because each one depends on the one before it.

### Does your policy's definition include images that were never real?

Open your child protection policy and find where it defines a nude or semi-nude image. If that definition describes a photograph, it is now narrower than the statutory guidance, and the gap is not academic: it is the sentence a member of staff will read at the moment they are deciding whether what a pupil has shown them counts. Widen it to match paragraph 6, including digitally altered and wholly AI-generated images. Then check the same wording in your acceptable use policy, your behavior policy and your online safety policy, because it usually appears in all four and is usually only corrected in one.

### Can your filtering and monitoring see AI tools at all?

Most systems were configured against categories that predate generative AI, so a nudification site may sit in an uncategorized bucket while a mainstream AI assistant is blocked outright, which is precisely the wrong way round. Ask your provider two questions: which AI categories exist, and what happens to a site that fits none of them. Then confirm the annual review the guidance requires is actually happening, led by the senior leader responsible, with the safeguarding lead and IT support in the room and a dated record at the end of it. A review nobody can date did not happen.

### Do your staff know this is a safeguarding matter and not an IT matter?

This is where most schools fail, and it fails quietly. A pupil tells a teaching assistant that someone has made a fake image of them. The assistant, acting in good faith, treats it as a technology problem, because the word AI was in the sentence. It goes to the network manager. Two days pass. Under the statutory definition that was a nude image of a child and the clock started when the pupil spoke. One slide in your next safeguarding briefing fixes it: if it involves a child, it goes to the designated safeguarding lead, whatever the technology in the story. The same slide should cover what a child confiding in a chatbot might indicate, and the fact that a disclosure made to a machine leaves no trail anyone in your building can see.

### Where does the concern go, and does anyone check that it arrived?

Follow one real route end to end. A pupil raises a fabricated image with a lunchtime supervisor. Where does it go, how fast, who records it, who decides on a referral, and who tells the pupil what happened next? Do the same for a concern raised by a parent and for one thrown up by monitoring software. If any of the three routes has a step that exists only in someone's head, that is your term's work, and it has nothing to do with AI. It is the same question as [who is accountable when AI gets it wrong](https://blog.theaieducator.io/posts/who-is-accountable-when-ai-gets-it-wrong), asked about children rather than about decisions.

## What I Tell Leadership Teams

That the volume of AI safeguarding advice is inversely related to its usefulness. Across the leadership teams I work with, the pattern is consistent: the schools that feel least prepared are usually the ones that have read the most, because most of what is available is written by companies whose product is the answer to the question they have just posed. I have spent time on the other side of that conversation, advising the Department for Education, KHDA in Dubai and the Ministry of Education in Kazakhstan on this sort of guidance, and as a school trustee reading the safeguarding report rather than writing it. The documents that survive contact with a real school are short, and they change something that was already there.

The other thing I say, and it lands less comfortably: if your AI safeguarding response is a new policy, you have chosen the artifact that is easiest to produce and hardest to use. Nobody reads the second safeguarding policy. They read the first one, once, in September, and then they act on what they remember. Put the change where they will meet it.

## "Isn't this overblown?"

Sometimes, and the honest answer depends on which children you mean. [Pew Research Center's survey of 1,458 US teens and parents](https://www.pewresearch.org/internet/2026/02/24/how-teens-use-and-view-ai/), published on 24 February 2026 and conducted between 25 September and 9 October 2025, found 13 to 17 year olds using chatbots mostly for ordinary things: 57 percent to look something up, 54 percent for schoolwork, 47 percent for fun. Only 12 percent had used one for emotional support or advice. On the average teenager, the alarm is overstated.

Safeguarding has never operated on the average child. [Internet Matters, surveying 1,000 UK children aged 9 to 17 for its report Me, Myself and AI](https://www.internetmatters.org/hub/press-release/new-report-reveals-how-risky-and-unchecked-ai-chatbots-are-the-new-go-to-for-millions-of-children/) in July 2025, found 64 percent of children using chatbots and 35 percent of those users describing it as like talking to a friend. Among the children the study classed as vulnerable, 71 percent used chatbots, 26 percent said they would rather talk to a bot than to a real person, and 23 percent gave as their reason that they had nobody else to talk to. That is the group your safeguarding system exists for, and it is the group most drawn to the product with no duty of care.

The image risk is not hypothetical either. The [Internet Watch Foundation reported on 10 August 2026](https://www.iwf.org.uk/news-media/news/hundreds-of-british-under-18s-reporting-nude-or-sexual-imagery-of-themselves-say-its-faked-or-manipulated/) that 420 reports from British under-18s in the first six months of 2026 concerned imagery the child believed was faked or manipulated, against 397 across the whole of 2025, with 268 of those confirmed on assessment compared with 221 in the previous full year. Half a year past a full year. These are children reporting fabricated images of themselves, which means some of them are sitting in registration on Monday.

## What good looks like by the end of this term

A school that has taken this seriously has four dated records and no new policy. The definition in the child protection policy matches paragraph 6 and the same wording has been carried into the other three documents that repeat it. The filtering and monitoring review has happened, is minuted, and names what the system does with an uncategorized AI site. Every member of staff has been told, in one sentence they can recall under pressure, that anything involving a child goes to the safeguarding lead regardless of the technology. And one reporting route has been walked from end to end by someone who then wrote down where it broke.

None of that requires a view on whether AI is good for education. It requires you to notice that a definition changed, and to move four pieces of paper before somebody needs them. If you are working out what your staff actually need to know, and what can safely be left out, that is the kind of work I support through AI training for schools, and my [newsletter](https://theaieducator.io/?utm_source=blog.theaieducator.io&utm_medium=referral&utm_campaign=what-does-ai-mean-for-safeguarding-in-schools#newsletter) carries the guidance changes as they land. If the data question is the one in front of you rather than the imagery one, start with [whether staff can put student data into ChatGPT](https://blog.theaieducator.io/posts/can-staff-put-student-data-into-chatgpt), and if a pupil is already in the frame, [what to do when a student is accused of using AI](https://blog.theaieducator.io/posts/student-accused-of-using-ai) sets out the process.

Governance work of this kind is rarely urgent until it is, and the schools that come through an incident well are the ones that did the boring version of it in a quiet week. This is the quiet week. [AI training for schools](https://theaieducator.io/ai-training-for-schools?utm_source=blog.theaieducator.io&utm_medium=referral&utm_campaign=what-does-ai-mean-for-safeguarding-in-schools) is where I help leadership teams turn a guidance change into something their staff can act on.

## Sources and further reading

- Department for Education, [Keeping children safe in education 2026](https://www.gov.uk/government/publications/keeping-children-safe-in-education--2/part-one-overview-for-all-staff), statutory guidance, in force 1 September 2026 (paragraph 6).
- Department for Education, [Keeping children safe in education 2026: government consultation response](https://assets.publishing.service.gov.uk/media/6a4cc3467abea59ac13fd2a8/Keeping_children_safe_in_education_2026_Government_consultation_response.pdf), 2026.
- Department for Education, [Generative AI: product safety expectations](https://www.gov.uk/government/publications/generative-ai-product-safety-expectations), non-statutory guidance, last updated 19 January 2026.
- Ofcom, [AI chatbots and online regulation: what you need to know](https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/ai-chatbots-and-online-regulation-what-you-need-to-know), 18 December 2025.
- Internet Matters, [Me, Myself and AI: understanding and safeguarding children's use of AI chatbots](https://www.internetmatters.org/hub/press-release/new-report-reveals-how-risky-and-unchecked-ai-chatbots-are-the-new-go-to-for-millions-of-children/), July 2025 (1,000 children aged 9 to 17).
- Pew Research Center, [How Teens Use and View AI](https://www.pewresearch.org/internet/2026/02/24/how-teens-use-and-view-ai/), 24 February 2026 (1,458 US teens and parents, fieldwork 25 September to 9 October 2025).
- Internet Watch Foundation, [Hundreds of British under-18s reporting nude or sexual imagery of themselves say it's faked or manipulated](https://www.iwf.org.uk/news-media/news/hundreds-of-british-under-18s-reporting-nude-or-sexual-imagery-of-themselves-say-its-faked-or-manipulated/), 10 August 2026.

*Dan Fitzpatrick is the founder of The AI Educator and writes and speaks on how leaders should respond to AI. [More about Dan](https://theaieducator.io/about?utm_source=blog.theaieducator.io&utm_medium=referral&utm_campaign=what-does-ai-mean-for-safeguarding-in-schools).*

## Frequently asked questions

### Does KCSIE 2026 require schools to have a separate AI safeguarding policy?

No. Keeping children safe in education 2026 contains no requirement for a separate AI policy. Its only explicit AI wording widens the definition of a nude or semi-nude image at paragraph 6. The practical response is to update existing policies and processes rather than to write a new document.

### What exactly does KCSIE 2026 say about AI-generated images?

Paragraph 6 states that nudes and semi-nudes may be "digitally altered or wholly generated using artificial intelligence, including what are sometimes described as 'deepfakes' or 'deep nudes'". A fabricated image of a pupil is therefore a nude image under the statutory definition and triggers the usual child protection response.

### Are the DfE generative AI product safety standards legally binding on schools?

No. They are non-statutory guidance, last updated on 19 January 2026. They describe what an AI product should do, including alerting a safeguarding lead to disclosures and detecting signs of learner distress. A school gives them force by making compliance a condition of approving and buying a tool.

### Are AI companion chatbots regulated under the Online Safety Act?

Often not. Ofcom's guidance of 18 December 2025 places outside the Act any chatbot service that only lets people interact with the bot itself, does not search multiple websites or databases, and cannot generate pornographic content. That description fits many one-to-one companion apps children use. The framework is under review.

### Who should a concern about an AI-generated image of a pupil go to?

The designated safeguarding lead, immediately, exactly as for any other nude or semi-nude image of a child. The most common failure is that staff treat it as a technology problem and route it to IT support because the word AI appeared, which loses days at the start of a child protection response.

### What should a leadership team actually do about AI and safeguarding this term?

Four things. Widen the definition of a nude or semi-nude image in the child protection policy and the three documents that repeat it. Confirm filtering and monitoring covers AI sites and that the annual review is dated. Tell staff it goes to the DSL. Walk one reporting route end to end.

---
Source: [What Does AI Mean for Safeguarding in Schools?](https://blog.theaieducator.io/posts/what-does-ai-mean-for-safeguarding-in-schools)
Publisher: [The AI Educator](https://theaieducator.io)
