← Back to articles
news4 min read

KCSIE 2026: The New AI Safeguarding Rules Schools Must Meet by September

Keeping Children Safe in Education 2026, in force from 1 September, treats AI-generated deepfake imagery as a safeguarding incident and tightens filtering duties for every English school.

Q
Quill

The Department for Education published the final version of Keeping Children Safe in Education (KCSIE) 2026 on 7 July. It comes into force on 1 September, and for the first time it treats AI-generated harm as a mainstream safeguarding category rather than a footnote. For UK school leaders, this is the AI policy document that actually carries legal weight, and most staff have not read it yet.

What has actually changed

KCSIE has always required schools to categorise and respond to indecent imagery involving pupils. The 2026 version rewrites that language. Terms such as "nude, semi-nude" and "sexting" are replaced with a broader definition: "self-generated intimate images and/or videos including those generated using AI, e.g. deepfakes." In practice, this means a fabricated or digitally altered sexual image of a pupil under 18 must be treated exactly like a real one, triggering the same referral and reporting duties for the designated safeguarding lead (DSL), regardless of whether the image was ever a genuine photograph.

The guidance also broadens what counts as contact risk to include generative AI applications that can simulate harmful online interaction, such as chatbots that groom, manipulate or impersonate. That is a meaningful expansion: it puts general-purpose AI apps, not just obvious grooming platforms, inside the scope of what schools are expected to monitor for.

Filtering and monitoring duties have been tightened too. Schools must now review the effectiveness of their filtering and monitoring systems at least once every academic year, with that review carried out by the senior leader responsible for the area, and results reported to governors. Given that pupils increasingly reach generative AI tools through browsers and personal devices rather than school-managed platforms, this review can no longer be a box-ticking exercise around a single content filter.

Schools are now expected to treat AI-generated sexual imagery of a child exactly as they would a genuine photograph. That single change reframes deepfakes from a hypothetical harm into a routine safeguarding scenario DSLs must be trained to handle.

How this links to the DfE's product safety standards

KCSIE 2026 does not sit alone. It follows the DfE's Generative AI: product safety standards, published in January 2026, which set out 13 requirements a generative AI product must meet to be considered appropriate for use in schools. Those standards cover filtering, data protection, and, notably, new sections on cognitive development, emotional and social development, and manipulation risk, pushing suppliers to show they have considered emotional dependence and not just content safety.

Read together, the two documents shift AI oversight from advisory to closer-to-mandatory. The product safety standards tell schools what to demand from a vendor before procurement. KCSIE tells them what to do once something goes wrong. A school that adopts an AI tool without checking it against the DfE standards, and without updating its child protection policy to reflect KCSIE's new deepfake language, is now out of step with both documents at once.

Why this matters more than another pilot announcement

Much of the AI-in-education conversation this year has centred on pilots, procurement deals, and teacher training numbers. KCSIE 2026 is different because it is statutory guidance schools are legally required to have regard to, not a recommendation. Ofsted inspections and safeguarding audits will reference it directly from September. A governing body that cannot show its child protection policy reflects the new AI and deepfake wording, or that its filtering review happened this academic year, is exposed in a way that has nothing to do with whether staff enjoyed their last INSET day on ChatGPT.

It also reframes a debate that has largely been about academic integrity and workload. AI-generated intimate imagery of pupils, AI chatbots that simulate harmful relationships, and AI tools that quietly track a child's emotional state are safeguarding risks first, and edtech questions second. Schools that have built AI policies around plagiarism and homework will need to widen the lens.

What to do

  • Update the child protection policy before September to use KCSIE 2026's language on AI-generated imagery, not the old "sexting" terminology, and brief all staff, not just the DSL, on the change.
  • Schedule the annual filtering and monitoring review now, with a named senior leader accountable, and specifically test how the system handles generative AI access on both school and personal devices.
  • Cross-check any AI tool already in use, from writing assistants to wellbeing chatbots, against the DfE's 13 product safety standards before the new academic year, and be prepared to drop tools that do not meet them.
  • Add a short, plain-language briefing for parents on AI-generated deepfake imagery, since KCSIE's changes assume families understand the term as well as staff do.

What to watch

Ofsted's inspection handbook has not yet been fully aligned to the new KCSIE language, and how inspectors interpret "regard to" AI safeguarding duties in practice will only become clear once the first post-September inspections happen. Multi-academy trusts should also watch whether the DfE issues sector-specific templates, since several safeguarding consultancies are already selling policy wording that may not match the final text precisely.

safeguardinguk-policykcsiedeepfakesdfechild-protection

NEWSLETTER

Join 10,000 educators

Every week: the AI tools, research, and classroom strategies that matter most. No noise, no hype — just what works.

No spam. Unsubscribe anytime.