What KCSIE 2026 Says About AI

A guide for headteachers, DSLs and senior leaders

By Chris Calder, AI Education Consultant | Meta Pedagogy

What KCSIE 2026 says about AI, and what it misses

KCSIE 2026 takes effect on 1 September 2026. For the first time, generative AI appears explicitly in safeguarding policy, staff training, curriculum, filtering and monitoring and incident response. Schools cannot treat AI as a separate technology issue any more. It now sits inside the safeguarding structure alongside everything else.

This guide lists every AI reference in the final published document with paragraph numbers and identifies one significant gap the DfE has left unaddressed.

The new definition: AI-generated imagery is now covered

The most important change sits on page 6, before the numbered paragraphs begin. KCSIE 2026 redefines “nudes and semi-nudes” to include images that are “digitally altered or wholly generated using artificial intelligence, including what are sometimes described as ‘deepfakes’ or ‘deep nudes’.”

The language has also shifted from “sharing” to “making or sharing nudes and semi-nudes,” defined as the creation, sending or posting of such images by under-18s. The word “making” captures a student who generates a deepfake image of a classmate, not just a student who forwards one. Under the previous wording, creation alone was harder to frame as an incident.

This definition applies everywhere KCSIE references nudes and semi-nudes. Paragraphs 22, 29 and 35 (covering child-on-child abuse, safeguarding indicators and harmful behaviour) all now cover AI-generated imagery without needing to say “AI” in the text.

The 4Cs of online risk now include AI

Paragraph 163 sets out the four categories of online risk. Two of them have been updated to include AI.

Contact risk now includes “being subjected to harmful online interaction with other users or generative AI applications that simulate this.” That wording brings AI companionship tools, chatbots and any generative AI system that simulates human interaction into the contact risk category. KCSIE does not name specific products, but this is the paragraph that covers apps like Replika, Character.AI and similar tools where students form ongoing interactions with AI systems.

Conduct risk now includes “making, sending and receiving explicit images, including those generated using AI.” A student who uses an AI tool to generate explicit imagery of another student has committed a conduct offence under KCSIE, regardless of whether a real photograph ever existed.

Content risk (paragraph 163) references “misinformation, disinformation (including fake news) and conspiracy theories.” This is not AI-specific wording, but AI tools are increasingly the mechanism through which misinformation is generated and distributed.

What schools must now do

KCSIE 2026 creates specific obligations across six areas.

Paragraph 12 requires all staff to understand filtering and monitoring expectations at induction, including how they apply to AI tools. This applies to every member of staff, including those who do not work directly with children.

Paragraph 158 requires preventative education to address “the prevalence of deepfakes” as an online harm. Deepfakes must appear in your RSHE or PSHE curriculum, not just in a policy document. Students need to be taught what deepfakes are, how they are created and what the consequences are.

Paragraph 165 directs schools to the DfE’s guidance on generative AI in education for safety considerations and legal responsibilities when using AI tools with staff or students. Paragraph 166 points to the DfE/Chiltern Learning Trust training modules, specifically Module 3 on safeguarding, ethics and data protection risks.

Paragraph 171 requires governing bodies to ensure filtering and monitoring systems are reviewed at least annually. Reviews must be carried out by the named SLT member responsible, with support from the DSL and IT. They must include checks that filtering works on all internet-connected devices in all locations and a written record must be kept. Paragraph 175 links this directly to the DfE’s “Generative AI: product safety expectations” document, confirming that filtering and monitoring requirements apply to generative AI tools.

Paragraph 191 requires the child protection policy to include “consensual and non-consensual making or sharing of nudes and semi-nudes, including those generated using AI.” If your child protection policy does not reference AI-generated imagery, it is not compliant with KCSIE 2026.

What it means in practice

For DSLs, any incident involving AI-generated intimate imagery of a student is now treated identically to an incident involving a real photograph. There is no separate category, no lighter response, no ambiguity about whether a deepfake counts. A deepfake nude of a student is treated the same as a real nude of a student.

For headteachers, AI must appear in your child protection policy, your online safety policy, your filtering and monitoring review, your staff training programme and your curriculum. If Ofsted asks how your school addresses AI safeguarding risks and you cannot point to each of these, you have a compliance gap.

For governors, the filtering and monitoring review at paragraph 171 now requires a named SLT member, an annual review, a written record and a scope that includes AI tools, not just web filtering.

What KCSIE 2026 misses

KCSIE 2026 bans mobile phones from schools (paragraph 168). It addresses AI-generated imagery. It addresses AI systems that simulate human interaction. It says nothing about AI-enabled wearable technology.

A student can walk into school wearing Meta Ray-Ban smart glasses. Those glasses can photograph and record video of classmates with no visible indicator to the person being recorded. They can livestream to social media. They connect to Meta AI. They are not a phone. The mobile phone policy does not cover them. KCSIE 2026 does not mention them.

Smart watches with cameras, AI pins and other wearable devices that can record, photograph and run AI processing sit in the same gap. The document that governs online safety in schools from September 2026 does not acknowledge that AI-capable recording devices can be worn on a student’s face or wrist and bypass every phone ban in the country.

Schools need to address this without waiting for the DfE to update the guidance. Your acceptable use policy and your mobile phone policy should cover wearable technology capable of recording, photographing or connecting to AI services.

What your school needs to check

Review your child protection policy against paragraph 191 and confirm it references AI-generated imagery. Update your online safety policy to reflect the 4Cs as set out in paragraph 163, including the AI-specific wording in contact and conduct risk. Confirm your filtering and monitoring review is scheduled, has a named SLT lead and covers AI tools. Ensure staff induction includes AI safeguarding content as required by paragraph 12. Add deepfakes to your RSHE or PSHE curriculum. Extend your mobile phone policy to cover wearable technology. If any of these are not in place, book a free consultation with Meta Pedagogy.

Get In Touch

Get in touch to discuss your school’s AI strategy

admin@metapedagogy.co.uk