Education · 3 September 2026 · 5 min read

Keeping Children Safe in Education 2026: what schools need to know

The biggest revision to KCSIE in years is now in force. Here's what changed, and how PrimaryTech helps schools meet it.

Get insights
Devin, digital transformation lead, delivering INSET day training at a local school with teachers sat down watching him talk next to an interactive screen

Keeping Children Safe in Education (KCSIE) 2026 came into force on 1 September 2026, replacing the 2025 guidance. It's the largest single-year revision to the statutory guidance in several years, and every school and college in England must have regard to it from the start of this academic year.

Below, we've summarised the headline changes and how our team can help you meet them, whether you work with us already or you're weighing up where to start.

This summary focuses on the technology and data changes: filtering and monitoring, AI in the classroom, mobile phones, cyber security and data protection. Annex C of the full guidance covers the complete set, including significant updates on mental health, child-on-child abuse and children questioning their gender.

What to action this term

  • Refresh induction materials now Annex A has gone
  • Update your child protection policy to name AI-generated and digitally altered imagery
  • Add AI chatbots and companion-style apps to your online risk assessment
  • Rewrite your mobile phone policy against the new default
  • Confirm cyber security sits within your safeguarding arrangements, not just your IT plan
  • Diary your annual filtering and monitoring review, and decide which SLT member signs it off
  • Check your DSL job description references filtering and monitoring
  • Audit volunteer roles against the new DBS threshold
  • Check your privacy notices reference the Data (Use and Access) Act 2025


What's changed?

Every member of staff must now read Part One in full

The condensed summary version of Part One (previously Annex A) has been withdrawn. All staff, including catering, site, office and admin staff, and volunteers, are now expected to read the full document, not a summary. If your induction pack or training slides reference the old Annex A, it's worth an update.

AI-generated and “deepfake” images are now explicitly in scope

The guidance makes clear that "nudes and semi-nudes" includes images that are digitally altered or wholly AI-generated. Any incident involving the sharing of such images, consensual or not, now requires a safeguarding response. New sections also cover the safe, effective use of generative AI in the classroom. The updated 4Cs framework reflects this too: contact risk now explicitly includes harmful interactions with generative AI that simulates human interaction, such as chatbots and companion-style systems, and conduct risk explicitly references making, sending or receiving explicit images, including AI-generated ones.

Schools should be mobile phone-free by default

The guidance now states that schools should be mobile phone-free environments, with anything else by exception only. The expectation is that pupils don't have access to phones across the whole school day, lessons, between lessons, breaks and lunch, with heads deciding how to achieve that in their own context. If your phone policy predates this, it needs a rewrite, and the practical questions (storage, medical exemptions, staff enforcement, parent comms) are worth working through before they arrive as complaints.

Cyber security is now framed as safeguarding

The guidance now points directly to the DfE Cyber security standards for schools and colleges and places cyber resilience inside safeguarding responsibilities. The logic is straightforward: compromised safeguarding records or stolen pupil data have direct safeguarding consequences, so protecting personal information counts as protecting children.

Filtering and monitoring must be reviewed every academic year

Schools must now formally review the effectiveness of their filtering and monitoring systems, measured against the DfE Filtering and Monitoring Standards, at least once every academic year, led by the SLT member responsible for filtering and monitoring, supported by the DSL and IT support. The point of the change is that responsibility can no longer sit solely with a technical team or an external provider. The DSL role must now explicitly include understanding filtering and monitoring systems and processes, reflected in the job description, and staff safeguarding training must cover filtering and monitoring responsibilities and escalation routes.

Safer recruitment: the supervision exemption is gone

The Crime and Policing Act 2026 removed the supervision exemption from regulated activity. Volunteers who regularly teach, train, instruct or supervise children (more than 3 days in a 30-day period, or overnight) now need an enhanced DBS check in their own right, even when supervised by a vetted colleague.

Data protection references updated

References throughout now include the Data (Use and Access) Act 2025 alongside the Data Protection Act 2018 and UK GDPR, worth checking your privacy notices and data protection policy reflect this.


How PrimaryTech helps you meet it

This update lands across all five of our education pillars. Here's where our existing services line up.

SAFEGUARDING

The evidence base for your annual review

The review has to be led by your SLT member with the DSL and IT support, that part can't be outsourced, and we wouldn't offer to. What we do is the legwork underneath it: configure automatic alerting and weekly reports, and provide training for your DSL and SLT. They own the review. We make sure the system works.

DIGITAL LITERACY

AI policy and staff training that reflects the new guidance

We already run AI policy reviews, INSET days and bolt-on staff CPD training for schools. We've updated our materials to cover the new deepfake and generative AI safeguarding language, so your staff and RSHE curriculum stay current.

DIGITAL STANDARDS

Data governance that keeps pace with the law

Where we support Google Workspace or Microsoft 365 data governance, retention and DLP (data loss prevention) policy, we'll prompt a review of your data protection documentation alongside the technical setup, so your policies reference the Data (Use and Access) Act 2025 as well as UK GDPR.

CYBER SECURITY

Cyber resilience is now a safeguarding matter

KCSIE 2026 references the DfE Cyber security standards directly and treats protecting personal data as part of safeguarding children. We take schools through Cyber Essentials certification, managed detection and response, and the evidence trail governors need, so a cyber incident doesn't become a safeguarding incident.

LEADERSHIP & GOVERNANCE

Induction, sign-off and policy rewrites

We can't read Part One for your staff, but we can help build or refresh your induction materials, including non-teaching staff and volunteers, and set up a simple sign-off record so your governors have evidence of coverage, not just a policy that says it should happen. We also help rewrite mobile phone policy against the new default, covering the practical questions (storage, medical exemptions, staff enforcement and parent comms).

Not sure where your school stands?

Talk to us about support with your filtering and monitoring review, an AI policy check, a cyber resilience check, or a wider look at how KCSIE 2026 affects your setting.

Get in touch today.

Want advice specific to your organisation?

Articles are useful, but nothing beats a conversation about your actual setup. Start with a free health check.

Get Your Free IT Health Check