Compliance

DfE generative AI standards

Guidance became standards. Standards set a minimum — which makes them the best procurement checklist a school has.

Direct answer
The DfE’s generative AI product safety standards set out the minimum requirements a generative AI product must meet to be considered safe in educational settings.

They replaced the earlier product safety expectations, with the current version published on 19 January 2026. They are written for suppliers, but schools can and should use them as a procurement checklist for any AI tool.

Policy accurate as at July 2026. UK education policy is moving quickly — inspection, curriculum and SEND reform are all mid-transition. Always confirm the current position with GOV.UK, Ofsted or your local authority before acting on it. This page describes how Edves supports schools; it is not legal or regulatory advice.

Why the wording change matters

The DfE originally published generative AI: product safety expectations in January 2025. In January 2026 this became a set of standards. The distinction is not cosmetic: guidance recommends, standards define a minimum requirement.

For schools, that gives you something you did not have before — a shared benchmark to hold any supplier against, rather than assessing each vendor’s marketing on its own terms. KCSIE has signposted schools to this guidance since the 2025 edition, and KCSIE 2026 references it alongside guidance on data protection and legal responsibilities for teacher-facing and pupil-facing AI tools.

What the standards cover

The standards span the areas below. Schools should ask suppliers to answer each in writing rather than accepting a general assurance of compliance.

AreaThe question to ask a supplier
FilteringDoes the product reliably prevent users generating or accessing harmful or inappropriate content, with filtering built in rather than bolted on?
Monitoring and reportingDoes it maintain robust activity logging, and can the school see it?
SecurityWhat protects the product against misuse, prompt manipulation and unauthorised access?
Privacy and data protectionWhat data is processed, where, by whom, and is it used for model training?
Intellectual propertyWho owns content generated, and what is the position on training data provenance?
Design and testingHow was the product tested for educational safety, and against what?
GovernanceWho is accountable at the supplier, and what happens when something goes wrong?

Always work from the current published version on GOV.UK rather than a summary, including this one.

The first question worth asking

Before working through the full list: can the product generate free-form content, or is it closed-loop and limited to approved material?

This single distinction determines how much of the rest matters. A closed-loop tool that can only surface pre-approved content carries a fundamentally different risk profile from one that can generate anything in response to a prompt. Many suppliers describe both as “AI-powered”.

How Edves is positioned

  • Teacher-facing by default. The generative components draft planning, feedback and communication for staff who edit and approve. The primary use case does not place a model in unsupervised contact with a child, which removes a large part of the risk surface.
  • Approval recorded. Every AI-drafted artefact carries a record of the human who approved it, which is the mechanism behind the DfE and Ofsted position that the school remains responsible for professional judgement.
  • Logging. AI interactions are logged and available to the school, not held opaquely by the supplier.
  • No model training on pupil data. Contractual, not a claim — see UK GDPR.
  • Tenant isolation. Data used to personalise stays within the school’s tenant.
  • Sub-processors disclosed, with processing locations identified.
  • Indicators show their inputs. Where the platform surfaces a risk indicator, a human can see the underlying signals and disagree, rather than receiving an unexplained score.

Edves will provide written answers against the current published standards during procurement. If any supplier — including this one — declines to do that, treat the refusal as the answer.

Filtering and monitoring is a separate obligation

A safe product does not discharge the school’s own filtering and monitoring duty. The 2026 update to the DfE filtering and monitoring standards asks schools to consider whether their provision can handle real-time, dynamic, personalised and AI-generated content, and reinforces the expectation of an annual review.

The technical point matters: DNS and URL-based filters cannot detect risk inside AI-generated material that never appears on a blocklisted page. If pupils use AI tools — and Ofcom research indicates a large and growing proportion do — this needs specific attention in the annual review rather than a note that filtering is in place.

KCSIE expects the review to be led by the senior leadership team member responsible for filtering and monitoring, supported by the DSL and IT, with a record kept of checks across devices and locations. See KCSIE and safeguarding.

Using the standards in procurement

  1. Send the standards to every AI supplier on your shortlist and ask for a written response to each.
  2. Ask the free-form versus closed-loop question first; it reframes everything else.
  3. Compare answers side by side rather than reading each supplier’s framing.
  4. Note who answers with evidence and who answers with reassurance. That difference is usually predictive.
  5. Put the answers into your DPIA rather than treating them as a separate exercise.
Common questions

Frequently asked

What are the DfE generative AI product safety standards?

A set of standards defining the minimum requirements a generative AI product must meet to be considered safe in educational settings. They replaced the earlier product safety expectations, with the current version published on 19 January 2026, and cover filtering, monitoring and logging, security, privacy and data protection, intellectual property, design and testing, and governance.

Why does 'standards' rather than 'guidance' matter?

Guidance recommends; standards define a minimum requirement. For schools it provides a shared benchmark to hold every supplier against, rather than assessing each vendor's marketing on its own terms.

What is the first question to ask an AI supplier?

Whether the product can generate free-form content or is closed-loop and limited to approved material. That single distinction determines the risk profile, and many suppliers describe both as AI-powered.

Does a compliant AI product satisfy our filtering and monitoring duty?

No. That duty is separate. The 2026 DfE filtering and monitoring standards update asks schools to consider whether their provision can handle real-time, dynamic, personalised and AI-generated content, because DNS and URL filters cannot see inside AI-generated material that never appears on a blocklisted page.

Will Edves answer the standards in writing?

Yes, against the current published version, during procurement. Any supplier declining to do so has effectively answered the question.

See it on your own school's data.

A 20-minute walkthrough using your curriculum, your cohorts, your attendance picture and your report card evaluation areas.

Book a demo

Keep reading