
Every September, school leaders ask the same question: What changed, and what do we actually need to do?
For 2026, the answer is tricky. Generative AI, phone scams, and rapidly evolving apps mean keeping school safety policies up to date takes far more work than it used to.
Here is what the updated Keeping Children Safe in Education (KCSIE) guidance expects in practice, where schools usually run into trouble, and a quick checklist for the new term.
Why Online Safety Updates Are so Challenging
Online safety moves much faster than standard subjects. Apps release new features every few weeks, statutory guidance changes every summer, and AI tools pop up constantly. A curriculum or staff slides written two years ago won’t cover deepfakes, voice cloning, or AI chatbots.
For Designated Safeguarding Leads (DSLs) and PSHE leads, finding time to research these tech changes and rewrite schemes of work every August is an exhausting task.
Core Requirements for 2026–27
The updated guidance focuses on three main areas:
1. Active Filtering and Monitoring
Web filters are standard in UK schools, but KCSIE expects leadership teams to actively manage them – not just set them and forget them. DSLs need to know:
- What content gets blocked (and what occasionally slips through).
- Who gets system alerts and how fast staff respond to high-risk search terms.
- How to spot pupils bypassing school Wi-Fi using VPNs, proxy sites, or mobile data.
2. Staff Training Pathways
KCSIE sets out that all staff need online safety training during induction, followed by yearly updates. For 2026–27, this needs to cover practical issues rather than just reading a PDF policy:
- Staff duties during daily web filter checks.
- Enforcing mobile phone rules consistently across all classrooms.
- Spotting new risks like deepfakes and AI scams.
- Maintaining professional boundaries on messaging apps and basic cybersecurity.
3. Student Education Across Key Stages
Schools must deliver age-appropriate online safety lessons across Key Stages 3, 4, and 5 covering the 4 Cs of risk:
- Content: Exposure to illegal or harmful material, including AI misinformation.
- Contact: Interaction with dangerous adults or peers, including financial sextortion.
- Conduct: Harmful behaviour like cyberbullying, group chat abuse, and sharing non-consensual images.
- Commerce: Online gambling, phishing, and financial scams.
Where Schools Usually Run into Problems
Compliance issues almost never happen because staff don’t care. They happen because staff run out of time.
“A web filter stops a pupil from opening a bad site on a desktop lab computer. It doesn’t teach them what to do when they see a deepfake or get pressured in a group chat on their own phone at home.”
Common trip hazards include:
- Outdated Lesson Materials: Slide decks age quickly. Many older packs don’t mention voice cloning, AI chatbots, or modern phone scams.
- Repetitive Staff CPD: Making experienced teachers sit through the same baseline induction modules every year wastes time. Many schools now separate full induction training from 15-minute yearly updates on what changed over the last 12 months.
- Messy Records: When inspectors ask for proof of staff completion, DSLs often have to manually pull data together from spreadsheets, paper sign-in sheets, and separate platforms.
Building Pupil Judgement
Teaching online safety isn’t about memorising lists of rules like “don’t talk to strangers.” It’s about giving pupils the judgement they need when no teacher or parent is standing over their shoulder.
Young people need time to look at real-world examples, understand how algorithms try to keep them scrolling, and practice handling awkward social situations online. When pupils understand how recommendation loops work or how scammers clone voices, they build actual digital resilience.
September Digital Safeguarding Checklist
Five practical checks to run through before term starts:
- Review filtering logs: Confirm who receives technical alerts, how quickly logs are checked, and that staff know how to report filter breaches.
- Sort staff training routes: Set up full induction modules for new starters and a concise 2026–27 update module for returning staff.
- Audit your student curriculum: Check that your scheme of work covers current risks like AI ethics, group chats, sextortion, and algorithm loops across KS3, KS4, and KS5.
- Check your records: Make sure you can export a single report showing staff CPD completion and student progress for governors or Ofsted.
- Revisit reporting routes: Remind pupils how to report concerns inside school, as well as external services like CEOP and Childline.
How OSA Handles the Heavy Lifting
Keeping lessons, staff CPD, and safety guidance updated takes hours of work.
We update every OSA course every summer—matching changes to KCSIE, new apps, and recent case studies—so school teams don’t have to spend their break rewriting resources.
OSA whole-school subscriptions include:
- Updated Student Curricula (KS3–KS5): Lessons covering AI literacy, online relationships, algorithms, and digital wellbeing, with auto-graded quizzes.
- CPD Staff Training: Separate tracks for new staff induction and annual KCSIE updates, complete with downloadable certificates.
- Central Dashboards: Simple tracking tools to show compliance records across all year groups instantly.
See our 2026–27 Staff CPD Overview: https://www.onlinesafetyalliance.org/cpd-2026/
See our Student Curriculum Options: https://www.onlinesafetyalliance.org/certificate/
