Safeguarding
AI safeguarding in schools: what changes when a chatbot enters the classroom
An AI assistant is a new disclosure channel. Treat it like one, and most of the hard questions answer themselves.
Andy Wake, Founder and Managing Director7 min read
Schools already have mature safeguarding practice. The question AI raises is not whether that practice applies, but how it reaches a channel where a child may type something at 11pm that they would never say to an adult in person.
What is genuinely new
- Disclosure happens without an adult present, and without the pauses and cues a person would notice.
- The assistant may respond in a way that feels like counselling, which no general-purpose tool is competent to provide.
- Records of a disclosure may sit in a supplier's system rather than in the school's safeguarding record.
- Children may use the tool to produce or seek harmful content, including material relating to other children.
- The tool may be used by an adult to contact or influence a child outside school oversight.
The controls that matter most
- Decide, in writing, whether unsupervised open-ended chat is permitted at all, and for which age groups.
- Define what the assistant must do on a disclosure: acknowledge, avoid interrogating, signpost a named human, and trigger an alert.
- Route every safeguarding trigger into the school's existing system so the DSL sees it where they already look.
- Set retention explicitly. Safeguarding records follow statutory retention; general chat should not be kept indefinitely.
- Brief staff that the assistant is not a counsellor, is not a witness, and does not replace their professional judgement.
- Tell children and parents plainly what is recorded and who can see it.
Questions to ask a supplier
- What happens, technically, when a child discloses harm — and can you show me?
- Who sees the alert, how fast, and what if nobody responds?
- What is stored, where, for how long, and who is the data controller?
- Has this been assessed against the Age Appropriate Design Code?
- What content is filtered, and what has been tested rather than assumed?
A supplier who cannot answer those questions concretely is describing an intention, not a control. That is the point at which our own escalation guidance and risk checklist for schools and parents is worth working through before anything reaches a child.
Frequently asked questions
- What should an AI assistant do if a child discloses harm?
- Acknowledge the child calmly, avoid questioning them about details, make clear a person will help, and immediately route an alert to the designated safeguarding lead through the school's existing safeguarding system. It should never attempt to counsel, assess risk, or promise confidentiality.
- Should children use AI chatbots without supervision?
- Open-ended, general-purpose chat without supervision is not appropriate for children in a school context. Bounded, subject-specific tools with safeguarding routing, content limits and clear retention are a different proposition and can be used with an age-appropriate assessment in place.
- Does an AI tool for pupils need a DPIA?
- Yes. Processing children's data is treated as a high-risk indicator under UK GDPR, and the Age Appropriate Design Code sets additional expectations for services likely to be accessed by children.
Sources and further reading
- Age appropriate design: a code of practice for online services
Information Commissioner's Office
- Keeping children safe in education
UK Department for Education
Where to go next
- AI safeguarding hub for schools and parents
- Parent and educator portal
- Responsible AI hub
- The ALFI + EDIE Framework
More articles on the insights index.