Quick Exit
● Statutory Guidance ✓ In force 1 September 2026 Published 7 July 2026 Reviewed July 2026

KCSIE 2026: What's Changed and What You Need to Do

5
Parts, structure unchanged
8
changes that matter in practice
All
staff now read Part One in full
1 Sept
the date it applies from

The Department for Education published Keeping Children Safe in Education 2026 on 7 July. It comes into force on 1 September 2026. Until 31 August you carry on working to the 2025 version, which is still the guidance you are held to.

This is a bigger year than last. Annex A has been withdrawn, so the shortened Part One that many schools handed to caretakers, kitchen teams and office staff no longer exists. The supervision exemption has come out of regulated activity, which means volunteers you previously left unchecked because a member of staff was in the room will now need an enhanced DBS with barred list information. Part Five has been rewritten. And for the first time the guidance states plainly that a nude image of a child can be one that was never photographed at all.

On This Page

!

What's Changed in KCSIE 2026

Annex C of the guidance carries the official summary of changes. Reading it against the 2025 text, eight things will actually alter what schools do. They fall into four groups.

1. Annex A has been withdrawn

Annex A gave staff who do not work directly with children a condensed version of Part One. It has gone. From September, every member of staff reads Part One in full. There is a new one page overview, but it sits alongside the full text rather than replacing it. If your reading records currently split staff into two groups, you will need a single list.

2. Volunteers have lost the supervision exemption

The Crime and Policing Act 2026 removed the supervision exemption from regulated activity. A volunteer who teaches, trains, instructs, cares for or supervises children now needs an enhanced DBS check with children's barred list information, whether or not somebody is supervising them at the time. The DBS flowchart schools have relied on has been deleted from the guidance, because it no longer describes the law.

3. Nudes, deepfakes and mobile phones

The terms "indecent image" and "sexting" are out. KCSIE 2026 uses "making or sharing of nudes or semi-nudes", and defines that to include photographs, videos and livestreams that were taken by the child, taken by somebody else, digitally altered, or generated entirely by artificial intelligence. Part Two adds a section on the safe use of generative AI, and sets out the expectation that schools operate as mobile phone free environments.

4. More on pupil need, and on premises

There is new or heavily expanded content on young carers, children who need mental health support, children with medical conditions, and LGB and gender questioning children. Part Two also adds a section on safeguarding requirements relating to school premises, including toilets and changing facilities. Some of this restates what good schools already do. Some of it will need a policy change before September.

🌐

Nudes, Semi-Nudes and AI-Generated Images

The definition has widened a long way, and the practical effect is that an incident can now exist without a camera ever being involved.

Nudes and semi-nudes

Photographs, videos and livestreams. Taken by the child, taken or created by another person, digitally altered, or wholly generated using artificial intelligence.

Deepfakes and deep nudes

AI generated or AI manipulated sexual imagery of a child. This is a safeguarding incident even where no real photograph of that child exists.

Consensual and non-consensual sharing

The guidance separates the two and notes that consensual sharing between peers may call for a different response. That is not the same as saying it is acceptable.

What This Means in Practice

  • Change the wording in your Online Safety and Child Protection policies to "nudes and semi-nudes", and say explicitly that AI generated imagery is covered.
  • Brief staff that a deepfake nude is recorded, responded to and escalated exactly as a photographed image would be. The instinct to treat it as less serious because it is fake is the thing to head off.
  • Build AI generated image abuse and image based misogyny into RSHE and online safety teaching, using PSHE Association approved resources.
  • Check your reporting routes make sense to a pupil who wants to report an image that is not really of them.
🤖

Generative AI in Schools

Part Two adds a section on the safe use of generative AI, and the Four Cs framework now names it directly. Contact risk covers AI applications that simulate a relationship with a child. Conduct risk covers making, sending and receiving explicit images, including ones produced with AI.

How the Guidance Treats AI Tools

  • An AI tool is treated as an environment a child interacts with, not a piece of software they operate. The risks named include simulated relationships, dependency, bullying and image generation.
  • You need to know what data a tool processes, whether pupil personal data is uploaded to it, and whether the supplier uses that data to train its models.
  • Age appropriate content filtering and transparency about AI generated content remain the baseline for anything used with pupils.
  • If pupils can reach an AI tool, your filtering and monitoring needs to be able to see it.

The DSL and DPO Working Together

Your data protection officer belongs in filtering decisions, AI risk assessments and DPIAs, cyber security governance and the annual technology review. Governing bodies are now told directly to safeguard children by protecting personal information and ensuring appropriate cyber security systems are in place, which puts cyber security on the safeguarding side of the line rather than leaving it with IT.

Before September: complete a DPIA for each generative AI tool used with pupils, and confirm your filtering and monitoring can actually see it.

🛡

Filtering, Monitoring and Mobile Phones

The filtering and monitoring standards themselves have not moved. What has changed is how much evidence you are expected to be able to produce, and how quickly.

The Annual Review

Review filtering and monitoring at least once every academic year, led by the senior leader responsible, with the DSL and IT contributing.

Cover all internet connected devices in all relevant locations, and keep a formal record of it.

Make sure monitoring alerts reach the DSL and are actually read, not just logged.

Set out your mobile phone free approach clearly in policy, in line with the DfE's expectation.

📚

The Structure of KCSIE 2026

Part One: Safeguarding information for all staff

Read in full by every member of staff, annually. Annex A withdrawn, so there is no condensed version any more.

All staff

Part Two: The management of safeguarding

Child protection policy, DSL cover, information sharing, generative AI, mobile phones, cyber security, premises, young carers, mental health.

Leadership

Part Three: Safer recruitment

Vetting, DBS checks, regulated activity rewritten with the supervision exemption removed, volunteers, work experience, homestay, duty to refer.

HR and leadership

Part Four: Safeguarding concerns or allegations made about staff

The harm threshold and concerns below it, LADO referrals, low level concerns, supply and trainee teachers.

DSL and SLT

Part Five: Child-on-child sexual harassment and sexual violence

Rewritten around a continuum running from harmful sexual behaviour through to sexual violence, consent, online and image based incidents, referrals to Family Help.

DSL

Annexes A to C

Annex A is further information, previously Annex B. Annex B is the role of the designated safeguarding lead, previously Annex C. Annex C is the summary of changes. The old Annex A has been withdrawn, and the homestay guidance has moved into Part Three.

👨‍🏫

What This Means for DSLs

The core of the role has not changed. Four areas have picked up new expectations you will need to evidence.

Online safety and AI

  • Make sure curriculum and staff training cover AI generated nudes, deepfakes and image based misogyny.
  • Work with the DPO on DPIAs for generative AI tools used with pupils.
  • Confirm filtering and monitoring reaches AI tools and every pupil accessible device, including personal devices on the school network.

Volunteers and safer recruitment

  • Re-audit every volunteer against the new definition of regulated activity. Supervision no longer takes anyone out of scope.
  • Arrange enhanced DBS checks with barred list information for the volunteers who are now in scope.
  • Replace any internal guidance or induction material built on the withdrawn DBS flowchart.

Early help and Family Help

  • Work out where the line sits for you between universal early help and targeted Family Help, and brief staff on the referral routes.
  • Apply the widened Part One indicators, which now include modern slavery, pregnancy and parenthood, and risk of exclusion.
  • Use the strengthened information sharing position. The guidance is trying to give staff more confidence to share, not less.

Training and cover

  • Put proper cover in place for when you are unavailable. The guidance suggests a confidential shared mailbox as one way of doing it.
  • Deliver whole staff Part One training on the full text, with one reading record from September.
  • Brief governors and trustees on the volunteer DBS change before term starts, because it has a cost and a lead time attached.

Your September Checklist

Part One and staff training

Volunteers and recruitment

Online safety, AI and phones

Policies, premises and pupil support

Official KCSIE 2026 Documents

Related Safeguarding Resources