KCSIE 2026: Can Your School Prove Its AI Decisions?
By the Neurameet Team · · 7 min read
Share on LinkedIn
Keeping Children Safe in Education (KCSIE) came into force on 1 September, and for the first time it treats AI as a safeguarding concern, not an IT one. AI in schools has mostly been an IT matter, or something colleagues used quietly to speed up planning, marking and admin. That has all changed.
AI moves into safeguarding
For the first time, the KCSIE places AI directly inside safeguarding. It now appears across online safety, filtering and monitoring, staff training, the curriculum, child-on-child abuse and governance.. In the context of KCSIE, AI no longer can be viewed as something that occasionally touches safeguarding. It now has to be built into the same reviews, training and overall governance as any other safeguarding risk.
This is a significant shift for school leaders, DSLs, governors and DPOs who now all have a bigger role to play in protecting pupils from AI related harm. External to schools, stakeholders such as partners, suppliers, and contractors now have to go further than they have done previously in mitigating against AI risks, and actively working to prevent harm from AI systems.
KCSIE catches up with AI
Schools have been using AI tools such as Copilot and ChatGPT as writing partners for a while, some with a settled approach, many without one yet. KCSIE 2026 has moved fast, and schools must now build governance around a technology that didn’t exist in classrooms a few years ago.
What school leaders need to know:
Filtering and monitoring
This refers to the way that schools keep pupils safe online while they’re on school devices, or on the school network. Filtering prevents harmful content reaching pupils and colleagues, whilst monitoring flags concerning content that gets past the filter.
Schools need to carry out an annual review of filtering and monitoring. The KCSIE 2026 (para 173) guidance identifies “governing bodies and proprietors” as now formally responsible for the outcome of the review, not just informed of it afterwards.
Schools need to carry out an annual review of filtering and monitoring. The KCSIE 2026 (para 173) guidance identifies “governing bodies and proprietors” as now formally responsible for the outcome of the review, not just informed of it afterwards.
Being accountable for this review means there has to be a decision trail: including who participated in the review, what was raised, what was agreed, and when. A verbal update in a governors' meeting doesn't meet the evidence standard on its own. To stand up as evidence that this duty was met, governing bodies and proprietors' oversight and decisions need to be recorded and dated accurately. Further to this, conversations that are not adequately recorded lack weight in front of a DPO, a safeguarding auditor, or an Ofsted inspector.
For most schools, the problem isn't that the annual review doesn't happen. It's that the conversation happens and then the evidence disappears. Perhaps whoever was in the room has moved on, or maybe the notes are on a slip of paper now lost in the back of last year’s planner.
AI within the 4Cs
Online safety guidance has long used 4 categories to describe risk: content, contact, conduct and commerce. In KCSIE 2026, AI is now situated in all categories.
- Content: AI-generated and deepfake images are now treated the same as any other image-based safeguarding concern, irrespective of what tool created them.
- Contact: KCSIE itself now defines this risk category as "harmful online interaction with other users or generative AI applications that simulate this”. A generative AI chatbot is now assessed the way schools would assess a stranger making contact online, not simply as content to filter.
- Conduct: how pupils and colleagues use AI themselves, from generating harmful content to misrepresenting AI-assisted work as their own.
- Commerce: the commercial platforms behind these tools, and what happens to the data schools and pupils put into them.
Safeguarding, security and privacy
The practical consequence of AI sitting inside all 4Cs is that safeguarding, IT security and data privacy stop being separate conversations. Safeguarding leads who are assessing AI tools for pupil use must also ask data protection and security questions, these include what happens to what a pupil types into the AI tool, and who else can access that data.
Most schools' safeguarding policies will have been written before KCSIE 2026, and the emergence of AI needing to be considered directly in the context of safeguarding. Most safeguarding policies will not say anything yet about AI-generated content or AI-facilitated grooming. That is not a criticism of any DSL. It's simply that the guidance describing this new obligation didn't exist until now.
There's a simple practical test worth applying to new AI being used in schools. If a school is trialling an AI tool, whether it's pupil-facing or used by colleagues to support planning or marking, someone should be able to answer three questions: what data does it collect, where is that data stored, and does the DPO know it's being used. If the answer to any of those questions is "we don’t know," that's the conversation to have first, not after the tool is already embedded.
What schools can do now
Five quick wins, before the safeguarding policy review.
- Name who owns the annual filtering and monitoring review, and put a date in the diary for it.
- Write down the outcome of that annual review and save it somewhere that governors can easily access later. It should include: what was discussed, what was decided, and by whom.
- Update safeguarding training with AI-specific scenarios not just a reference to online safety.
- Ask these direct questions before adopting an AI tool: what happens to the data a pupil or member of staff puts into it, and who has access to that data.
- Bring governors into the loop before an audit does, so the accountability KCSIE now places on them is something they've actually had time to familiarise themselves with.
More than a box to tick
At first glance, the reframing of AI as a safeguarding concern might look like a compliance exercise. At its heart, schools are being asked for evidence that it has made careful, recorded decisions about AI. The self evaluation evidence Ofsted asks for, the governor accountability KCSIE now requires, and the trust parents, carers and families place in a school to look after their children's data are really the same thing looked at from different angles. A school that can show, clearly and with dates, how it thought through an AI decision isn't just meeting a requirement. It's demonstrating the kind of careful, considered leadership that safeguarding has always been.
How Neurameet fits into this
Neurameet was built by school leaders, for schools. Our co-founder Rich is a senior leader in a UK secondary school, so he’s working through KCSIE 2026 along with the rest of the sector. At Neurameet, we’re not watching from the outside.
KCSIE now expects a decision trail. A governors' meeting where AI risk is reviewed is an important place for that trail to start. Neurameet turns all the meetings and conversations a school runs on into a structured, dated record: who was there, what was raised, what was agreed and who owns the next step. That record no longer depends on whoever happened to be taking notes.
Neurameet doesn't replace the judgement a DSL or governing body has to apply around safeguarding or AI, these decisions are human led. Neurameet ensures that once judgements are made, they can be found by the DPO, or at the request of an inspector. This is significant for a duty that now depends on whether a decision was recorded and dated.
We'd also expect to put Neurameet through the same questions we suggested above:
- What data do we collect? Meeting recordings and the minutes made from them. Recordings are automatically deleted after a retention period your school sets.
- Where is it stored? It's encrypted to AES-256 and held in ISO 27001-certified data centres in the UK. We're Cyber Essentials certified, registered with the ICO and compliant with UK GDPR. Your data is never used to train external AI models.
- Does your DPO know it’s being used? Our Trust Centre gives them everything they need to review it. Only your school can access your data, and Your leadership team decides who sees what through role-based permissions.
Curious to see what your next governors’ meeting could look like? Book a 30-minute demo and we'll show you what a Neurameet record looks like.