The KCSIE 2026 change most likely to land on a DSL desk without warning — and the one schools are least prepared for. What the guidance says and what to do about it.
Of the four AI changes in KCSIE 2026, this is the one that most often lands on a DSL's desk with no warning and no precedent to follow. It is also the one schools are least prepared for. Here is what the guidance now says, what it means in practice, and what to do if it happens in your school.
Want your school's AI documents written for you — free?
I'm a school governor and I've built the full KCSIE-2026-ready set for my own school: AI policy, staff acceptable use agreement, governor briefing and parent letter. I'm doing the same free for a small number of schools while I build case studies. No catch, nothing to buy.
Email me and say "send me the AI documents" — I'll reply with what I need to know. Takes you two minutes.
Email neil@askcolin.uk Or call 07971 775986Neil Kidd · Governor, Worple Primary School · Prefer the detail first? Keep reading.
What KCSIE 2026 actually changed
The guidance now makes explicit that images encountered in a safeguarding context may be digitally altered or entirely AI-generated, including deepfakes. In plain terms, the old defence — "but it isn't a real photograph" — no longer sits anywhere useful. AI-generated sexual imagery of a child is treated as the safeguarding matter it is, and schools are expected to respond accordingly rather than treating it as a technology curiosity or a prank.
Alongside this, AI chatbots are named as a potential contact risk — the same category as an unknown adult online rather than merely unsuitable content — and the annual filtering and monitoring review is expected to cover AI tools.
Why primary schools are not exempt
The instinctive response in a primary school is that this is a secondary problem. It isn't, for three reasons:
- Older siblings and shared devices. Primary-age children encounter these tools second-hand, often on a sibling's phone or a family tablet.
- The apps are trivially easy. "Nudify" and face-swap apps require no technical skill whatsoever, and are marketed as entertainment.
- Photos of your pupils are already public. Class photos, sports day pictures, school social media accounts — the raw material sits online, and that is the uncomfortable part for schools that publish freely.
What to do if it happens
Treat it as a safeguarding incident from the first moment, not as an IT problem or a behaviour issue:
- Do not view, copy, share or forward the image. The rules on handling indecent images of children apply regardless of whether the image was generated by AI. Follow your existing child protection procedures for such material.
- Record what was reported, not the content itself. Who reported it, when, what platform, who is said to be involved.
- Escalate to the DSL immediately, then follow your usual referral routes — children's social care, the police, and your local safeguarding partners as your procedures require.
- Consider both children. Where a pupil created the image, they are both a perpetrator and a child, often one who did not grasp what they were doing. The response has to hold both facts.
- Support the child depicted. The harm is real to them regardless of the image being fake — that distinction rarely comforts a ten-year-old.
- Review afterwards. What made it possible, what filtering or education gap it exposed, and what changes in response.
Key point for DSLs: "AI-generated" changes nothing about how the material is handled. Existing child protection procedures for indecent images apply in full.
What to put in place before it happens
- Name it in your child protection policy. A short paragraph confirming that digitally altered and AI-generated imagery falls within your existing procedures.
- Cover it in DSL and staff training. Most staff have never considered how they would respond, and the middle of an incident is a poor time to find out.
- Include AI tools in your filtering and monitoring review. KCSIE 2026 expects this, and it should include image-generation and companion chatbot apps.
- Talk to parents. Most parents have no idea these apps exist. A short, calm parent communication does more than any technical control.
- Review what you publish. A sensible photo policy for the school website and social media reduces the raw material available.
For the full picture of what changed this year, see our KCSIE 2026 AI changes summary, and our guide to writing a school AI policy that reflects it. The parent letter in the free document set covers this topic directly — it is usually the piece schools find hardest to write themselves.
Not sure where your school stands?
I write AI policies, staff agreements, governor briefings and parent letters for UK schools — currently free for a small number of schools building case studies.
Frequently asked questions
Does KCSIE 2026 cover AI-generated images?
Yes. The 2026 guidance makes explicit that images in a safeguarding context may be digitally altered or entirely AI-generated, including deepfakes, and expects schools to respond to them within their existing child protection arrangements.
How should a school respond to an AI-generated indecent image of a pupil?
Treat it as a safeguarding incident under existing child protection procedures for indecent images: do not view, copy or share the material, record the report, escalate to the DSL immediately and follow your usual referral routes to children's social care and the police.
Are primary schools affected by deepfake risks?
Yes. Primary-age children encounter these apps through older siblings and shared devices, the tools require no technical skill, and photographs of pupils are frequently already public on school websites and social media.
What should schools tell parents about AI image apps?
That the apps exist, are easy to use and are often marketed as harmless fun, that the school treats AI-generated imagery as a safeguarding matter, and who to contact if a child discloses something. A short, calm letter is usually more effective than technical detail.
Does our filtering review need to include AI tools?
KCSIE 2026 expects the annual filtering and monitoring review to take account of AI tools, which in practice should include image-generation sites and companion chatbot apps as well as general AI assistants.