top of page

KCSIE this September: the digital bits leaders most often skim past

Sep 6
3 min read

Keeping Children Safe in Education 2026 came into force on 1 September.

Most of the attention has gone to safer recruitment, mental health and the removal of Annex A, which is fair enough — those are the big changes. There are four digital changes in this edition that land on the board’s desk rather than the IT departments, and they tend to get read quickly in August and not returned to.

None of them ask you to understand technology. All four are governance questions.


1. The filtering and monitoring review is now an annual expectation, with a record

Annual review has been encouraged for a while through the DfE filtering and monitoring standards. KCSIE 2026 puts it more firmly into statutory guidance: effectiveness reviewed at least once every academic year, and schools able to demonstrate that the review took place. [CHECK: confirm the wording against the published guidance before you publish]

The accountability is clearer too. The review is led by the senior leader responsible for filtering and monitoring, supported by the designated safeguarding lead and by IT. It is not something to hand wholesale to whoever administers the software.


What a review record should contain

•     The date, and who led it

•     Which devices and which locations were tested, including school-owned devices used off site

•     What was found

•     What changed as a result


The board question

“When was our last review, who led it, and can I see the record?”

If the answer is that the software does it automatically, ask a second question. The software produces reports. Somebody still has to read them and decide whether the settings are right for your school, and that decision is what the standard is asking you to evidence.


2. Cyber security is now framed as part of safeguarding

KCSIE 2026 addresses information security and access management directly, and points to the DfE cyber security standards for schools and colleges. Protecting personal information and having appropriate cyber security in place is described as part of safeguarding children, rather than as a separate technical concern. [CHECK: paragraph numbers — around 176 to 178 — verify against the PDF if you want to cite them]

For a board, that means cyber stops being only a finance and risk item. A compromised mailbox in a school is a safeguarding matter, because of what school mailboxes contain: safeguarding conversations, parent contact details, records about individual children.

The board question

“Where does cyber security sit on our agenda, and is the DSL part of that conversation?”

If cyber is discussed in the finance committee and safeguarding in the safeguarding link meeting, the two halves of this never meet.


3. AI has moved into the online safety definitions

The online risk categories have been updated to reflect AI, and the guidance now points to the DfE material on generative AI in education. Separately, the DfE updated its filtering and monitoring core standard in June 2026 so that the definition of filtering explicitly includes AI-generated content alongside text, images, audio and video. Terminology around nudes and semi-nudes now covers digitally altered and AI-generated images. [CHECK: the June 2026 standards update — confirm the date and wording]

This is not abstract. It makes a specific question reasonable to put to your filtering provider, and you should expect a specific answer back.


The board question

“Does our filtering cover AI image generation and nudification tools, and how do we know?”

If the answer is that the provider handles it, ask for the product name, the category list and the date somebody last checked the setting.


4. Annex A has gone, so all staff read the whole of Part One

The shortened version of Part One no longer exists. Every member of staff is now expected to read and understand Part One in full. There is a new overview intended as a quick reference, but it does not replace the reading.

The digital consequence is about records. Your evidence of who has read and understood it needs to be real rather than a tick collected at induction and never revisited, particularly for staff who join mid-year, supply staff and volunteers.


The board question

“How do we know staff have read it, rather than been sent it?”


Three things worth doing this term

•     Read Annex C. It is the summary of changes and it is the fastest hour you will spend on this all year.

•     Put one properly prepared digital and online safety item on a board agenda before Christmas, with a named person presenting it.

•     Ask to see the filtering and monitoring review record, rather than asking whether one exists.

 
 
 

Comments


bottom of page