← Back to articles
news4 min read

The DfE Now Has 13 Safety Standards for AI Tools. Are They Enforced?

England's Department for Education expanded its generative AI product safety standards to 13 in January 2026, but compliance is voluntary and unverified by any regulator.

Q
Quill

A checklist, not a law

On 19 January 2026, at the UK AI for Education Summit, the Department for Education quietly expanded its generative AI product safety expectations from nine to 13 standards. The update added four new areas: cognitive development, emotional and social development, mental health, and manipulation for commercial gain, sitting alongside older requirements on filtering, data protection and security.

On paper this looks like progress. The DfE moved from calling these "expectations" to calling them "standards", language that suggests a floor rather than a suggestion. In practice, nothing about their legal status has changed. No inspector checks compliance. No regulator audits vendors against the list. A supplier can claim to meet all 13 standards and never be tested on the claim.

What the four new standards actually ask for

The cognitive development standard asks edtech developers to "make every effort to mitigate the potential for cognitive deskilling, or long-term developmental harm to learners" — a soft instruction with no defined threshold for what counts as deskilling or how a vendor would demonstrate they avoided it.

The manipulation standard addresses a narrower but sharper concern: that AI tools embedded in a child's school day are uniquely positioned to nudge behaviour or spending, given the trust a school relationship implies. The mental health and emotional development standards extend safeguarding logic that already runs through KCSIE 2026 into the product design layer, asking suppliers to consider how a chatbot's tone or persistence might affect a vulnerable pupil.

All four are worded as effort obligations — "make every effort", "should consider" — rather than measurable pass/fail criteria. That wording matters enormously for anyone using the standards as a procurement gate.

Why this lands on school leaders, not vendors

The standards are addressed to "edtech developers and suppliers", but the DfE has built no enforcement mechanism that touches those suppliers directly. There is no accreditation scheme, no kitemark, and no penalty for non-compliance. The practical effect, several school compliance advisers now argue, is that the 13 standards function as a checklist for buyers, not a rulebook for sellers: a school evaluating a new AI tool can put a supplier's marketing claims against the DfE's 13 questions and see where the gaps are, but the burden of asking, verifying and rejecting sits entirely with the school.

That is a familiar pattern in England's AI-in-education policy this year. The £23m EdTech Testbeds programme pushes evidence-gathering onto pilot schools. KCSIE 2026 pushes AI safeguarding duties onto designated safeguarding leads. The 13 standards push product vetting onto whoever holds the procurement decision, typically a headteacher or a multi-academy trust's IT lead, few of whom have the technical background to interrogate a vendor's claims about mitigating "cognitive deskilling".

The standards give schools a better question to ask. They do not give schools a reliable way to check the answer.

What vendors are doing with it

Several edtech suppliers have already published compliance statements referencing the updated 13 standards, treating the list as a marketing asset as much as a safety commitment. That is not necessarily cynical — a written compliance statement is more scrutiny than existed a year ago — but it means the standards are being interpreted and self-certified by the same companies they are meant to hold accountable, with no independent party checking the self-certification against the product.

What to do

  • Before adopting any new AI tool, ask the supplier directly to map their product against the DfE's 13 standards, in writing, rather than accepting a general compliance claim.
  • Treat the four 2026 additions — cognitive development, emotional and social development, mental health, manipulation — as prompts for your own testing, not settled facts about a product. Trial the tool with a small group and watch for how it responds to distressed or manipulative-sounding pupil messages.
  • Log procurement decisions against the standards in your AI policy documentation. If KCSIE inspectors or parents ask why a tool was approved, a dated checklist against the 13 standards is stronger evidence of due diligence than a vendor brochure.
  • Do not assume DfE-referenced compliance equals independent verification. Ask whether any third party has tested the claims, and if not, factor that gap into your risk assessment.

What to watch

Watch whether the DfE moves from standards to a formal accreditation or approved-supplier list, which would be the logical next step if procurement chaos continues. Also watch the EdTech Testbeds programme for early evidence on which tools genuinely meet the cognitive development and manipulation standards under independent scrutiny, since that evidence base does not yet exist.

Sources: Third Space Learning, National College, Edves, Simfin, and DfE summit coverage from January 2026.

policyprocurementsafeguardingEnglandDfE

NEWSLETTER

Join 10,000 educators

Every week: the AI tools, research, and classroom strategies that matter most. No noise, no hype — just what works.

No spam. Unsubscribe anytime.