Skip to main content
← All Articles & Guides
For Professionals DSL KCSIE 2026 Compliance

DSL Compliance Guide: KCSIE 2026 and Working Together 2026

A practical briefing for Designated Safeguarding Leads, deputy DSLs and school leaders on the requirements in Keeping Children Safe in Education 2026 , in force from 1 September 2026. It covers what changed from KCSIE 2025, the new AI, deepfake and filtering duties, mobile-phone-free schools, annex renumbering, DSL statutory duties, and a 20-point compliance checklist. KCSIE 2025 remains the current statutory guidance until 31 August 2026.

✍️ By The Safeguard Hub Team πŸ“… Updated July 2026 Β· Last reviewed July 2026 βŒ› 14 min read Part of The Safeguard Hub Articles Series
DSL KCSIE 2026 compliance guide

KCSIE 2025 applies until 31 August 2026. KCSIE 2026 is in force from 1 September 2026.

Keeping Children Safe in Education 2026 was published on GOV.UK on 7 July 2026 and replaces KCSIE 2025 from 1 September 2026. Until that date, all schools and colleges must continue to follow KCSIE 2025 in full. Use this guide to prepare. Do not update live policies until September. Read the full KCSIE 2026 document on GOV.UK β†—

What Changed from KCSIE 2025 to KCSIE 2026

KCSIE 2026 is a substantive update, unlike the largely technical 2025 edition. There are 14 confirmed changes, several of which require DSL action before 1 September 2026. For the complete list and a preparation timeline, see our KCSIE 2026 changes guide . The five areas of highest practical impact are set out below.

πŸ“–

1. Staff reading and annex structure

All staff must now read Part One in full. The condensed summary that some schools used for staff not working directly with children is withdrawn, and there is no shortened route for any group. The annexes have been renumbered: old Annex B becomes Annex A (Further information), old Annex C becomes Annex B (Role of the DSL), and a new Annex C covers the Summary of changes. Old Annexes D, E and F are removed or moved to Part Three. Any policy, induction slide or training handout that cites a KCSIE annex letter will need updating before September. See our annex changes guide for the full before and after mapping.

πŸ€–

2. Online safety, AI, mobile phones and filtering

KCSIE 2026 introduces explicit duties on AI-generated content, deepfakes and nudification apps. The terms "sexting" and "indecent image" are replaced in the peer-sharing context with making or sharing nudes or semi-nudes (covering photos, videos, livestreams and AI-generated content). Part Two adds a dedicated section on the safe use of generative AI. Filtering and monitoring must be reviewed at least once per academic year , led by the senior leader responsible for filtering and monitoring, with the governing body formally accountable for the outcome. KCSIE 2026, paragraph 168, confirms schools should be mobile-phone-free environments by default across lessons, transitions, breaks and lunch. See our dedicated guide: AI, Deepfakes and KCSIE 2026 .

βš”οΈ

3. Child-on-child abuse and the weapons-reporting duty

The child-on-child abuse definition is expanded to include serious violence, misogyny and AI-generated imagery. Paragraph 49 of KCSIE 2026 sets out the weapons-reporting duty: any member of staff who has a concern about a child carrying or using a weapon, or expressing an intention to do so, reports it to the DSL or a deputy, who then assesses the risk and takes appropriate action. This is not an automatic mandatory external report; it runs via the DSL. See: KCSIE 2026 and Serious Violence .

Part Five has been substantially rewritten around the progressive continuum from harmful sexual behaviour (HSB) through to sexual violence (paragraph 527). Paragraph 527 also clarifies that all incidents involving the sharing of nude or semi-nude images require a safeguarding response, whether consensual or non-consensual -- what differs is the nature and proportionality of the response, not whether one is needed. Paragraph 535 connects early intervention in misogyny to preventing escalation to sexual harassment and sexual violence: this makes misogyny a named DSL concern at the lower end of the continuum, not just a curriculum topic.

πŸ‘₯

4. Safer recruitment: volunteers and online checks

The supervision exemption for volunteers in regulated activity is removed by section 139 of the Crime and Policing Act 2026, with 1 September 2026 as the operational date set by KCSIE 2026 and the DfE. Schools must re-audit all existing volunteers and obtain enhanced DBS with children's barred list information for any volunteer now in scope. Online due-diligence checks on shortlisted candidates are added to safer recruitment requirements. Trainee teachers are explicitly confirmed to sit within the same allegations-against-staff framework as substantive staff.

🀝

5. Family Help, Operation Encompass, mental health and VAWG

Early help language is updated to reflect the Family Help model from Working Together 2026. Operation Encompass notification standards are tightened, with an explicit expectation that the child's voice is reflected in what schools receive and record. Mental health is reinforced as a named safeguarding pathway. New VAWG content connects misogyny, harmful sexual behaviour and serious violence. See our misogyny and incel culture briefing .

Summary: KCSIE 2026 is the most substantive update in several years. The five areas above cover the majority of the new action required. For the complete list of 14 confirmed changes, preparation timelines and an action checklist, read the full KCSIE 2026 changes guide .

The DSL Role: Statutory Duties Under KCSIE 2026

The core architecture of the DSL role is unchanged in KCSIE 2026. Every school and college must have a Designated Safeguarding Lead who is a member of the senior leadership team . The DSL's role is not delegable. While a deputy can act in the DSL's absence, ultimate accountability remains with the named DSL. [1]

KCSIE 2026, Annex B sets out the DSL role in full. The core statutory functions are:

Responsibility Statutory Basis
Manage referrals to MASH, children's services, police and specialist agencies KCSIE 2026 Part 2 / s.47 Children Act 1989
Liaise with the local authority and attend multi-agency meetings (e.g. Child Protection Conferences, CIN reviews) Working Together 2026
Maintain confidential safeguarding records securely, separate from general pupil records KCSIE 2026 Annex B / UK GDPR
Provide induction, training and regular updates to all staff on safeguarding KCSIE 2026 Part 1
Ensure safer recruitment procedures are followed, including re-auditing volunteers now that the supervision exemption is removed KCSIE 2026 Part 3
Maintain the Single Central Record (SCR) of all staff and volunteer checks KCSIE 2026 Part 3 / Annex A
Act as the point of contact for the designated teacher for looked-after children KCSIE 2026 Part 2
Ensure the governing body receives an annual safeguarding report and the annual filtering and monitoring review outcome KCSIE 2026 Part 2
Lead the school's response to online safety, including the annual filtering and monitoring review KCSIE 2026 Part 2 / online safety provisions
Assess and oversee AI tools deployed with pupils, including generative AI safe use arrangements KCSIE 2026 Part 2 / DfE AI guidance

The DSL must also attend Child Protection Case Conferences and, where the school is not invited, ensure the school submits a written report in advance. Where a child has a Child Protection Plan, the DSL should be the primary contact for the allocated social worker.

Information Security and Cyber Security

Paragraphs 176 to 178 of KCSIE 2026, under the heading "Information security and access management", set out that governing bodies and proprietors should take measures to safeguard children by protecting personal information and ensuring appropriate cyber security systems are in place , approached as part of the school's wider safeguarding responsibilities. Paragraph 177 directs schools to the Cyber security standards for schools and colleges . This duty existed in KCSIE 2025 and has been redrafted in 2026 with a clearer standalone heading and stronger framing connecting it explicitly to governing body safeguarding accountability. It is not a new obligation but it now carries greater prominence and a direct line from the governing body downwards.

Training Requirements

KCSIE 2026 sets out that the DSL must receive training that is updated at least every two years . In addition to formal training, the DSL must receive regular briefings (at least annual) to keep pace with emerging risks. This is distinct from the two-yearly formal requirement and is a separate obligation. [1]

All other staff must receive safeguarding training at induction and then at regular intervals. Under KCSIE 2026, all staff read Part One in full with no condensed alternative for any group. The frequency of refreshers is not prescribed but should be sufficient to ensure staff can identify and report concerns. Annual refreshers are standard practice and expected by Ofsted.

Online Safety: AI, Deepfakes and Mobile Phones Under KCSIE 2026

KCSIE 2026 is the first edition to name AI-generated content, deepfakes and nudification apps as explicit safeguarding risks rather than subsets of general online harm. The Four Cs framework continues to apply, and the content category now includes misinformation, disinformation and conspiracy theories (carried over from KCSIE 2025) alongside the new AI-specific risks.

Nudes and Semi-Nudes: Updated Terminology

KCSIE 2026 replaces the terms "sexting" and "indecent image" in the peer-sharing context with making or sharing nudes or semi-nudes . The definition is broad: it covers photographs, videos and livestreams, whether taken by the child, taken or created by another person, digitally altered, or wholly generated using AI, including deepfakes and nudification images. Schools should update any policy, training material or curriculum content that still uses the old terms. KCSIE 2026 also distinguishes consensual from non-consensual sharing between peers, noting that consensual sharing may warrant a different response, though not that it is acceptable.

Mobile-Phone-Free Environments

KCSIE 2026, paragraph 168, states that schools should operate as mobile-phone-free environments by default . This covers lessons, transitions, breaks and lunch. Schools that allow mobile phones must have a clearly defined exception policy and communicate it to pupils and parents before the start of term.

Generative AI: What KCSIE 2026 Requires of Schools

KCSIE 2026 introduces a dedicated section in Part Two on the safe use of generative AI . Schools must have arrangements for assessing AI tools against safeguarding criteria before deploying them with pupils. The DfE's Generative AI: product safety expectations for the education sector guidance (2023) continues to apply alongside the new statutory provisions.

Before Deploying Any AI Tool with Pupils

  • Data Protection Impact Assessment (DPIA): Mandatory for any AI tool processing pupil data. The DPO must be consulted and the DPIA documented.
  • Product safety expectations check: Assess the tool against the DfE's framework, which covers age appropriateness, data handling, content moderation, and transparency of AI-generated outputs.
  • Staff training: Staff using AI tools with pupils must understand the risks, including how generative AI can produce plausible but inaccurate content, how it can be misused for bullying or harassment, and the risk of AI-facilitated grooming.

AI-Generated CSAM and Deepfake Imagery

The generation of child sexual abuse material using AI tools is a criminal offence under the Sexual Offences Act 2003 as amended. KCSIE 2025 makes clear that schools must have policies covering AI-generated imagery, particularly non-consensual deepfake intimate images, alongside existing policies on the sharing of indecent images of minors. Any incident involving AI-generated CSAM must be reported to the police and the Internet Watch Foundation immediately.

AI in the Classroom: Permitted Use Policies

Schools should have a written AI acceptable use policy (or incorporate AI into their existing acceptable use policy) covering: which tools are approved, what data pupils may input, how AI outputs must be handled, and what constitutes misuse. Governors should receive a briefing on AI risks at least annually.

Filtering and Monitoring: Annual Review Required

KCSIE 2026 makes the annual filtering and monitoring review a formal governance requirement. The review must be led by the senior leader responsible for filtering and monitoring , working with the DSL and IT lead or support, and the outcome must be formally reported to and signed off by the governing body. This is a governance accountability, not an IT task.

The review must cover all internet-connected devices in all relevant locations, including school-owned devices used off-site. Schools that have historically treated filtering and monitoring as an IT-only function need to restructure this as a formal annual governance cycle before September 2026.

Minimum Standards

Schools must continue to use the DfE's Plan technology for your school self-assessment tool to verify their provision. The annual KCSIE 2026 review is a separate, additional requirement. Minimum standards still cover:

  • Whether the filtering solution is active on all devices used by pupils on school networks
  • Whether BYOD (Bring Your Own Device) policies adequately extend filtering to personal devices on the school network
  • Whether monitoring is active and alerts are reviewed by a responsible person in a timely way
  • Whether the filtering solution is updated regularly to address new harmful content categories

Monitoring vs Filtering: A Critical Distinction

Many schools have strong filtering but weak monitoring. Filtering prevents access to known harmful content. Monitoring detects harmful behaviour that filtering cannot prevent: for example, a pupil researching self-harm methods via a search engine that returns non-blocked results, or accessing grooming conversations via an end-to-end encrypted messaging app on a school device. KCSIE 2026 requires both. A school that can demonstrate filtering but not monitoring does not meet the standard.

Record-Keeping: What KCSIE Requires

Safeguarding records must be kept securely, separately from the main pupil file , and transferred to the receiving school when a child moves, even if the concern has not resulted in a formal referral. Records should be factual, dated, and written contemporaneously. They must be retained in accordance with your local authority's retention schedule, typically until the child reaches the age of 25, or longer if a Criminal Injuries Compensation claim is involved.

Safer Recruitment: KCSIE 2026 Changes

Part 3 of KCSIE 2026 sets out the pre-employment checks required for all staff and volunteers. Two significant changes apply from 1 September 2026:

  • Supervision exemption for volunteers removed: The legal change is made by section 139 of the Crime and Policing Act 2026 , which removes the supervision exemption from the definition of regulated activity. KCSIE 2026 and the DfE have told schools to treat 1 September 2026 as the operational date. From that date, a volunteer who teaches, trains, instructs, cares for or supervises children is in regulated activity regardless of whether they are supervised. Schools must re-audit all existing volunteers against regulated activity and obtain enhanced DBS with children's barred list information for those now in scope. Start this early -- DBS turnaround is the constraint.
  • Online due-diligence checks: Shortlisted candidates are now subject to online checks of publicly available information as part of pre-appointment safer recruitment.

The Single Central Record (SCR) must be maintained and available for Ofsted inspection, and now must capture the expanded volunteer population. At minimum, the SCR records:

  • Enhanced DBS check with children's barred list (renewed per school policy, commonly every three years or sooner upon risk assessment)
  • Right to work in the UK verification
  • Identity verification
  • Prohibition from teaching check (teachers only)
  • Overseas checks where an applicant has lived or worked outside the UK
  • References: at least two, including one from the most recent employer

Alignment with Working Together 2026

Working Together to Safeguard Children 2026 (in force since 18 March 2026) operates alongside KCSIE 2025 as the second pillar of the statutory framework for schools. KCSIE requires schools to follow the multi-agency arrangements set out in Working Together, so DSLs must read both documents together. [2]

Key Working Together 2026 Requirements That Affect Schools

  • Family Help replaces separate early help and Section 17 support: WT2026 merges targeted early help and Section 17 child-in-need support into a single multi-disciplinary "Family Help" offer, coordinated through one Family Help Plan with a single named lead practitioner. Schools remain key partners and should engage with local Family Help teams, not only make threshold referrals.
  • Multi-Agency Safeguarding Arrangements (MASA): Clearer defined roles for the three statutory safeguarding partners (local authority, police and integrated care board), with a duty to evidence improved outcomes for children rather than simply follow process.
  • Universal scope, including unborn babies: The guidance now applies to all children, including those in kinship care, special guardianship, and those adopted or looked-after, and extends protection to unborn children where concerns are identified.
  • Anti-racist and anti-discriminatory practice: An active duty. Leaders and frontline staff are expected to identify and actively challenge racism, bias and disproportionality, recognising that cultural misunderstanding and systemic stereotyping can lead to differential outcomes for minoritised children. Partners share data on disproportionality.
  • Information sharing strengthened: Working Together 2026 reinforces the presumption in favour of sharing information where a child may be at risk and references Operation Encompass and the Information Sharing Advice for Safeguarding Practitioners. DSLs should share even without explicit consent where safety is the concern.
  • Overlapping and specific harms: Assessments must recognise that children rarely experience a single type of harm in isolation. For example, the direct link between online and in-person exploitation. Stronger frameworks identify child sexual abuse, coercive control in teenage relationships, and the non-verbal vulnerabilities of babies and unborn children.
  • Domestic abuse: statutory school-notification duty. Following the Victims and Prisoners Act 2024, Operation Encompass is now a statutory duty (s.49A of the Domestic Abuse Act 2021): police must notify a child's school where they have reasonable grounds to believe the child is a victim of domestic abuse. A child is a victim in their own right if they see, hear or experience the effects of abuse.
  • Section 47 enquiries: A strengthened expectation of direct, meaningful work with the child during multi-agency child protection assessments.

20-Point KCSIE 2026 Compliance Checklist

Use this checklist to prepare for 1 September 2026. KCSIE 2025 remains in force until then. Do not update live policy until that date. Print and retain a completed copy for Ofsted and governor records.

Part 1, Policies and Governance

Part 2, DSL and Training

Part 3, Safer Recruitment and Records

Part 4, Online Safety, Filtering and Monitoring

Part 5, Multi-Agency Working and Referrals

DSL Support Contacts

NSPCC Learning (DSL training): learning.nspcc.org.uk
PSHE Association: pshe-association.org.uk
DfE Safeguarding guidance: gov.uk/topic/schools-colleges-childrens-services
NSPCC Helpline: 0808 800 5000

Statutory References

All DSLs should hold current copies of, and be familiar with, the following:

  • Keeping Children Safe in Education 2026 , DfE, published 7 July 2026, in force 1 September 2026. gov.uk β†—
  • Keeping Children Safe in Education 2025 , DfE, current statutory guidance until 31 August 2026.
  • Working Together to Safeguard Children 2026 , HM Government, in force March 2026. gov.uk β†—
  • Children Act 1989 : Section 17 (child in need), Section 47 (child protection enquiry)
  • Children Act 2004 : Section 10 (duty to cooperate) and Section 11 (duty to safeguard)
  • Online Safety Act 2023 : Platform duties relevant to schools and families
  • Counter-Terrorism and Security Act 2015 : Prevent duty for specified authorities including schools
  • Data (Use and Access) Act 2025 : Data-sharing and information-governance context for Operation Encompass notifications and safeguarding records
  • DfE: Generative AI : product safety expectations for the education sector (2023)
  • DfE: Plan technology for your school, filtering and monitoring self-assessment

If you have an immediate safeguarding concern about a child

  • Immediate risk to life: Call 999
  • Make a referral to children's services: Contact your local MASH. Find your local authority details at gov.uk β†—
  • NSPCC professional helpline: 0808 800 5000 (24/7)
  • Online abuse / CEOP report: ceop.police.uk β†—

Sources: [1] Department for Education (2026). Keeping Children Safe in Education 2026. gov.uk (published 7 July 2026, in force 1 September 2026). [2] HM Government (2026). Working Together to Safeguard Children 2026. gov.uk. [3] Department for Education (2023). Generative AI: product safety expectations for the education sector. gov.uk. [4] Ofsted (2024). Education Inspection Framework. gov.uk. Last reviewed: July 2026.

Share this article: 𝕏 X f Facebook in LinkedIn πŸ“± WhatsApp

πŸ”— Looking for related guidance?

KCSIE 2026 Changes Overview DSL Autumn Term Toolkit All Articles & Guides

Related Articles

Child Protection in England 2023 to 24: Key Statistics Ev… → KCSIE 2026: What's Changed and What Your School Needs to… → KCSIE 2026: What's Changing in Keeping Children Safe in E… → Parent Briefing: The Safeguarding Questions Every Parent… →