Key changes include treating AI-generated harms such as deepfakes as a mainstream safeguarding reality, strengthened filtering and monitoring expectations with recorded annual reviews, mobile phone-free schools as the default position, and revised volunteer vetting.
The transition date
KCSIE 2026 was published on 7 July 2026 and is in force from 1 September 2026. Settings continue working to the 2025 edition until 31 August 2026. That gives a summer term window to review policies, and schools that leave it to the September INSET typically find the filtering and monitoring changes need more than an afternoon.
What changed
AI-generated harms
The 2026 edition reframes language around image-based abuse to explicitly include self-generated intimate images and videos including those generated using AI, such as deepfakes. This closes a grey area many schools had been stuck in: whether an AI-generated image of a pupil is a safeguarding matter. It is.
Practically, this means behaviour and safeguarding policies referring only to sharing of images need updating, and staff training needs to cover AI-generated content specifically rather than treating it as a subset of online safety.
Filtering and monitoring
Expectations are strengthened. Schools should review effectiveness at least once every academic year, with the review led by the senior leadership team member responsible for filtering and monitoring, supported by the DSL and IT, and a record kept of checks across all internet-connected devices in all relevant locations.
New content directs schools to the DfE’s generative AI product safety guidance, explaining how filtering and monitoring requirements apply to generative AI use. See DfE generative AI standards.
Mobile phones
The guidance moves toward mobile phone-free schools as the default position. Schools will need behaviour policies, communication to families and recording arrangements consistent with whatever position they adopt. See attendance and behaviour.
Vetting
Volunteer vetting arrangements are rewritten in light of the Crime and Policing Act 2026. Single central record processes should be checked against the revised expectations.
How safeguarding records should sit in a school system
Edves is not a safeguarding case management system, and schools should be wary of any platform claiming to be everything. What matters is how a school MIS interacts with safeguarding, and there are four principles.
- Separation. Safeguarding records sit behind separate permissions and are not visible in general pupil views. A supply teacher taking a register should not see a child protection note.
- Logging. Every access to a sensitive record is logged with user, time and record.
- Flagging without exposure. Staff who need to know that a pupil requires a particular approach can be told that, without the underlying detail being visible to everyone.
- Retention and transfer. Records follow the pupil correctly when they move school, and are retained per the school’s schedule rather than a supplier default.
Where the school record contributes
Safeguarding concerns rarely arrive as a single disclosure. They usually emerge from a pattern that several people each saw part of: attendance drift, a change in behaviour, withdrawal from activities the pupil previously chose, a decline in one subject, a family becoming unresponsive.
Each individually is unremarkable. Together they are a signal, and the reason they are missed is that they live in five different places.
Edves combines these into an indicator that prompts a designated member of staff to look. Two deliberate constraints:
- It surfaces the signals, not a score. A DSL sees why a pupil appeared and can dismiss it with a reason.
- It never takes an action. It prompts a human. No automated referral, no automated contact.
Any system that gives a safeguarding risk score without showing its working should be treated with real suspicion — both because indicators built from behavioural data reproduce existing bias, and because a DSL cannot professionally act on reasoning they cannot see.
Staff training on AI
KCSIE 2026 references DfE-partnered resources covering safeguarding, ethics, data protection and intellectual property risk in AI use, and DfE staff modules were updated during 2026. The direction is clear: a school using AI is expected to understand the implications and train staff accordingly.
DfE modules are a better training basis than a supplier’s slide deck, including ours. A reasonable approach is three short sessions — common language and why models produce confident errors; controlled comparison of AI output against a trusted curriculum source; then agreed practice on what may and may not be entered into a tool.
Verify with the source
This page summarises changes for the purpose of explaining how Edves fits alongside them. It is not a substitute for the published guidance. DSLs and governors should work from the current KCSIE text on GOV.UK.