Why AI Has Become a Safeguarding Issue, Not Just a Technology Issue

For most of the past decade, conversations about technology in schools centred on screen time, social media, and the use of personal devices. AI tools have shifted that conversation considerably. Unlike social media, where the risks are largely peer-to-peer and behavioural, generative AI introduces a category of risk that involves the quality and nature of the content produced, and in some cases, the personal data that feeds into it.

A pupil using a free AI chatbot on their phone to help with homework is not just engaging with a website. They are interacting with a system that can produce unreliable information, generate age-inappropriate content if prompted in certain ways, and in some configurations retain or process the input it receives. Headteachers who treat this as a purely academic integrity question — is this cheating or not? — are missing the safeguarding dimension entirely.

The DfE's position is that schools must address AI as part of their broader online safety obligations. Keeping Children Safe in Education already requires leaders to ensure pupils are protected from harmful online content and that staff are equipped to recognise and respond to online risks. AI tools now fall squarely within that scope.

What DfE Guidance Currently Requires of Schools

The DfE has issued specific guidance on the use of generative AI in education, updated to reflect the pace of adoption. The guidance does not prohibit AI use but places clear expectations on school leaders to ensure any tools used (by staff or pupils) are appropriate, proportionate, and governed responsibly.

Specifically, schools are expected to assess AI tools for age-appropriateness before making them available to pupils, to have a written position on how AI can and cannot be used in educational settings, and to ensure that staff using AI in their professional work understand the data implications. The guidance also references the importance of critical thinking education: preparing pupils to evaluate AI output rather than treating it as authoritative.

Headteachers should note that DfE guidance does not carry the same legal force as statutory obligations under KCSIE, but inspectors treat significant divergence from it as a governance concern. Governors will ask whether the school's approach is aligned, and Ofsted inspectors are increasingly familiar with what good AI governance in a school looks like.

Pupil-Facing AI Tools: What to Assess Before Approving

The volume of AI tools being marketed to schools is substantial, and the claims made about their safety, educational value, and data practices vary enormously. Before approving any AI tool for pupil use, leaders should work through a structured assessment that covers at minimum: the tool's content moderation and filtering, where data is stored and processed, the age range it is designed for, and what the provider's terms of service actually say about data retention.

Several tools marketed as educational are built on general-purpose models with content filters that are configurable but not always set to an appropriate level by default. The fact that a tool is sold with a school licence does not automatically mean it has been correctly configured for the age range using it. Someone in the organisation needs to verify that before deployment.

The DfE-aligned AI safeguarding guidance for UK schools provides a structured framework for this assessment, including the questions to ask vendors before granting access to pupil-facing systems.

Content Filtering: Where Most Schools Have a Gap

Most schools have invested in content filtering infrastructure for school-managed networks and devices. These systems typically block categories of harmful content and are updated regularly against new threats. The gap that AI introduces is twofold.

First, many AI tools are accessed via HTTPS connections that legacy filtering systems cannot inspect without SSL inspection being enabled, a configuration that many schools have not implemented. A pupil on a school device may be able to access an AI chatbot that would otherwise be blocked simply because the filter cannot see the content of the encrypted connection.

Second, content filtering infrastructure typically does not extend to personal devices used on home networks. AI tools reached through a personal phone at lunch or after school fall entirely outside the school's technical controls. This is not unique to AI, but it is worth naming clearly: filtering is a partial control, not a complete one, and any AI safeguarding strategy must account for what happens outside the school network.

The practical response is not to abandon filtering but to pair it with education. Pupils who understand why certain tools are restricted, and who have the critical thinking skills to evaluate AI output, are better protected than those who are simply blocked without explanation.

Staff Training Obligations: Who Needs to Know What

KCSIE requires all staff to receive safeguarding training that is updated at least annually. As AI tools have become a recognised safeguarding concern, that training now needs to address how to identify and respond to AI-related risks in the same way it addresses other online risks.

All teaching and support staff should understand the basics: what generative AI tools are, the categories of risk they introduce for pupils, and how to report concerns when they arise. The designated safeguarding lead needs a deeper level of understanding, sufficient to lead the school's response to an AI-related safeguarding concern and to advise on policy.

For staff who use AI tools in their own professional practice — drafting reports, creating resources, communicating with families — there is a separate training obligation around data handling. Staff pasting pupil data into a public AI tool without understanding the implications is a data protection risk as well as a potential GDPR concern.

Writing a Safeguarding Section Into Your AI Policy

Many schools have produced AI policies that address academic integrity and staff guidance but have not included a dedicated safeguarding section. This is increasingly a gap that governors and inspectors will notice.

A safeguarding section in an AI policy should address: the risks AI tools pose to pupil welfare, the controls in place to mitigate those risks (technical filtering, device policy, curriculum content), the roles responsible for assessing AI tools before pupil use, the process for responding to an AI-related safeguarding concern, and the training requirement for staff.

The section does not need to be lengthy, but it needs to exist and be coherent. A policy that treats AI purely as a pedagogical or integrity question, without acknowledging the safeguarding dimension, is incomplete.

What Governors Should Be Asking at Their Next Meeting

Governing bodies have a strategic oversight role in safeguarding, and AI is now a topic they should be scrutinising with the same seriousness as other online safety issues. Useful questions for governors include: Has the school carried out an assessment of every AI tool currently accessible to pupils? Has the AI policy been reviewed by the designated safeguarding lead? Do all staff receive training that covers AI-related safeguarding risks? Has the school identified a lead for AI governance, and are they reporting to governors regularly?

A headteacher who cannot answer these questions at a governor meeting in 2025 is in a weaker position than one who can demonstrate a considered, documented approach. The groundwork is not complicated, but it requires deliberate attention. It needs to start before the next Ofsted inspection, not after.