KCSIE 2026: Six Weeks to Get Ready
KCSIE 2026 has been published and comes into force on September 1. It makes phone-free schools the default, brings AI-generated content into safeguarding practice, updates data protection for the DUAA, and rewrites volunteer vetting. Schools have six weeks to update policies.
The 60-second Briefing
- The DfE published Keeping Children Safe in Education 2026 on July 7 2026. It comes into force on September 1, at which point the 2025 edition ceases to apply.
- The guidance states that schools should be mobile phone-free environments by default, with any other approach "by exception only."
- AI-generated intimate images and deepfakes are now explicitly named as safeguarding concerns. The online safety chapter has been expanded to reflect the current threat picture.
- Data protection references have been updated throughout to reflect the Data (Use and Access) Act 2025. The guidance restates that data protection laws should never prevent information sharing to keep children safe.
- Volunteer vetting has been rewritten under the Crime and Policing Act 2026. The supervision exemption from regulated activity has been removed. Any volunteer in a teaching, training, instructing or supervising role for more than three days a month, or overnight, is now in regulated activity and needs a DBS check.
On July 7, the Department for Education published the final version of Keeping Children Safe in Education 2026. It is the statutory safeguarding guidance every school and college in England has to follow, and it comes into force on September 1. Between now and then, schools operate under the 2025 edition. From that Tuesday morning onwards, the new one applies, without transition period or notice.
This is the KCSIE that catches up with the arguments the sector has been having for the past two years. Read the annex of changes and it feels less like a policy update and more like a highlights reel of things that have been discussed at every governors' committee, safeguarding CPD session, and IT-and-safeguarding meeting since spring 2024. Phones, deepfakes, AI-generated content, data protection under the DUAA, filtering and monitoring, volunteer vetting, boarding, sport, medical conditions, and young carers all get their attention. Schools that have been paying attention over the past two years will find themselves largely ready. Schools that have not have a difficult six weeks ahead of them.
Let me walk through what has actually changed and where the sharpest operational questions sit.
The change most people will notice first is the mobile phone position. KCSIE 2026 states that all schools should be mobile phone-free environments by default, with anything other than this by exception only. Pupils should not have access to their phones throughout the school day, including lessons, time between lessons, breaktimes and lunchtime, with Heads deciding how to achieve this in their own context. That last clause matters. This is a default, not a mandate, but the burden of proof has flipped. Under the 2025 guidance, a school with an unrestricted phone policy could describe its position as one of several defensible approaches. Under the 2026 guidance, the same school will have to justify why it is operating an exception. That is a very different conversation.
I wrote about this in Banning Devices, Building Minds, and the arguments there have not changed. Phones are a distraction, phones are a safeguarding surface, and a school that removes them from the day is doing something structurally useful for pupils' focus and their pastoral care. What has changed is the position of the statutory guidance. Schools that have already banned phones will find the September update straightforward. Schools that have adopted a more permissive approach, or have hidden behind a policy they don't really enforce, are now looking at a September that requires either a policy change or a rigorous documented exception rationale.
The second cluster of changes is around AI, deepfakes and online safety. The guidance expands the online safety chapter to bring AI-generated content firmly into safeguarding practice. AI-generated intimate images, deepfakes used in bullying or harassment, and the wider category of synthetic media are all named. The framework schools are asked to use for online safety risks has been refreshed around the familiar four Cs (content, contact, conduct, commerce), with each category updated to include the AI-specific threats we have been talking about for two years.
This is where a couple of earlier posts on this blog become relevant. Facing the Deepfake Threat argued that IT teams have to move into the classroom and support pastoral staff in understanding the mechanics of synthetic media, because the "block and ignore" approach to filtering had run out of road. Caught in the Crossfire made the parallel case that safeguarding leads cannot simultaneously innovate on AI in the classroom and treat AI as a defensive-perimeter problem. KCSIE 2026 does not resolve that tension, but it does codify the direction of travel. Schools have to teach pupils about deepfakes, they have to identify and respond to AI-facilitated harm, and their filtering and monitoring architecture has to be capable of doing something useful in an environment where the threat is generated on the device itself rather than downloaded from a blocklist.
The third change worth spending time on is data protection. The guidance has been updated throughout to reflect the Data (Use and Access) Act 2025, which took effect in January this year and which I covered in The DUAA: More Carrot, Less Stick. The most important line to notice, though, is one that has been in KCSIE for years and which the 2026 edition restates with additional weight: data protection laws should never prevent information sharing for the purposes of keeping children safe. That is aimed squarely at the DSLs, DPOs and IT teams who have hidden behind GDPR compliance as a reason not to share safeguarding information across a school or between agencies. It should not have needed restating. That it has been restated tells you the DfE has heard enough stories about the wrong side of that argument.
Now the sleeper change. It has been covered in the specialist safeguarding press but has not had the attention the phone or AI stories have, and I think it will hit independent schools harder than either of them. The safer recruitment section has been rewritten under the Crime and Policing Act 2026, which removed the supervision exemption from regulated activity. Under the previous framework, a volunteer working with children under the supervision of a regulated adult was not themselves in regulated activity and did not require a DBS check. That exemption has gone. From September, any person volunteering in a school or college in a role that involves teaching, training, instructing or supervising children on more than three days in a month, or overnight, is in regulated activity, with the associated DBS check requirements.
Anyone who runs an enrichment programme should now be very awake. Weekend expedition leaders. Volunteer sports coaches. Alumni running debating clubs. Parent helpers on residential trips. CCF section commanders. Silver Book scheme volunteers. Duke of Edinburgh assessors on overnight expeditions. That is a lot of volunteers, in schools that have historically leaned on informal parent and alumni networks to make enrichment work. The Every Child Can post I wrote last week ended with the thought that the interesting question is how enrichment shows up in the data spine. Add to that: enrichment now needs to show up in the safer recruitment register too. Any school planning DofE, CCF or sports-fixture support for next academic year should be running a DBS audit of its volunteer pool this month, not next.
A handful of other new sections are worth flagging briefly. There are updates on sport, on school premises safeguarding requirements, on boarding and residential accommodation (which independent boarding schools should read carefully), on children with medical conditions, on young carers, and on mobile phone policy in its own right. Filtering and monitoring provisions have also been tightened, though the underlying expectations follow the same shape as recent guidance from the DfE and NCSC.
For those with a technology, data protection or safeguarding remit, the practical work between now and September is genuinely large but reasonably clear.
To make that work easier to sequence, I have put together a free KCSIE 2026 Summer Checklist, a policy, audit, training and sign-off list mapped to the substantive changes in the guidance, available to subscribers of the blog.
The first piece is the policy sweep. Child protection policy, acceptable use policy, mobile phone policy (if separate), online safety policy, safer recruitment policy, data protection policy. All need to be reviewed against KCSIE 2026 and adjusted where necessary. Governors then need to be briefed and formally sign off before the term starts. For most schools this is two to three weeks of work if it starts now and a scramble if it does not.
The second is safeguarding training. All staff need to be briefed on the new provisions before September. That includes teaching staff, support staff, boarding staff where relevant, catering, grounds, transport and any regular contractors. The volunteer vetting changes need particular attention because they are a hard change to explain informally.
The third is the volunteer audit itself. A list of every volunteer the school has had in the past academic year, cross-referenced against the new regulated-activity definition and against current DBS status. Anything short of a complete list is not a plan. If a volunteer meets the new definition and does not have a current enhanced DBS check, the school either needs to arrange one or accept that the volunteer cannot continue in the role from September. There is no soft-launch on this. It is a statutory change.
The fourth is a review of filtering and monitoring, which the DfE has been quietly making more prescriptive with each iteration. Anyone whose filtering provider is running on an approach that predates the current DfE and NCSC expectations should be checking now rather than in October.
For anyone reading this on the day of publication, or in the week after, the honest picture is that KCSIE 2026 is a substantial statutory update arriving at the point in the year when senior teams have the least available time. That is not by chance. September updates have become the DfE's pattern for a reason, and the pattern relies on schools using the summer term end and the summer holidays for policy work and training preparation. That may or may not be fair, but it is the reality. The schools that emerge from September in a good position will be the ones that use this term to do the reading and the summer to do the paperwork.
There is one thought worth ending on. The 2026 guidance is the KCSIE that has caught up with the actual world schools have been operating in. Phones as a default distraction, AI-generated content as a real safeguarding threat, information sharing as a positive duty rather than a defensive worry, and volunteers as people whose access to children needs to be evidenced. None of that is a surprise to anyone who has been paying attention. What has changed is that these positions are now statutory rather than aspirational, and the September date puts a clock on them.
Six weeks. Use them.
See you in the digital staffroom.