AI and data protection · 7 min read

AI in safeguarding training: what to allow and what to refuse

A workable rule for generative AI in school safeguarding: the uses to allow, the ones to refuse, the vendor controls to check, and how to write it into policy.

By Ruslan Shaymardanov · · For Designated Safeguarding Leads, Heads of School and data protection leads

Where AI belongs in safeguarding training, and where it stops

Every Head who asks me about AI in safeguarding training arrives with the same two worries, in the same order. The first is that a machine writes something wrong and a member of staff acts on it. The second is that a child's name ends up inside a model owned by a company on another continent. Both worries are well founded, and both are answered by a short written rule rather than by a ban. Schools that write the rule get the drafting time back. Schools that leave the question open find staff pasting case notes into a free chatbot at ten at night, because nobody told them where the line was.

I build AI features into a safeguarding platform, so I have an interest here, and I would rather set the line too tight than defend a loose one. The line I work to fits in one sentence. Generative AI may work on the school's documents, and it may never work on the school's children. The rest of this piece is that sentence expanded into something a governing body can read and approve in a single meeting.

What the published guidance says

UNESCO published its Guidance for generative AI in education and research in 2023. It sets out a human-centred approach and asks governments and institutions to mandate the protection of data privacy and to set an age limit for independent conversations with generative AI platforms. It also puts human agency at the centre of the validation and design process, which for a school means a person owns the output and signs it.

The Department for Education keeps a page on generative artificial intelligence in education, last updated on 12 August 2025. It applies to schools and colleges in England, and international schools read it because it is specific. Two lines carry most of the weight. On data, the guidance says that personal data must be protected in accordance with data protection legislation and that it is recommended that personal data is not used in generative AI tools, and it warns that any data entered should not contain information that could allow an individual to be identified. On accountability, it says that the quality and content of any final documents remains the responsibility of the professional who produced it and the organisation they belong to, regardless of the tools or resources used.

That second line is the one to put in front of staff. A member of staff who generates a safeguarding briefing owns that briefing. The same guidance also tells schools to consider online safety, including AI, when they build their safeguarding policies, and to consult Keeping children safe in education, whose 2026 edition came into force on 1 September 2026. So the AI rule is not a separate document living with the IT team. It belongs beside the safeguarding policy, on the same review cycle, with the same approver.

What to allow

The allowed list is longer than most schools expect, because the useful work sits in documents rather than in cases. Each item below assumes a named person reads the output before anyone else does.

  • Drafting a training module from the school's own safeguarding policy, with the designated safeguarding lead reading and approving it before staff see it.
  • Answering a staff question about procedure from the school's own documents, where the answer points to the paragraph it came from.
  • Producing a first-pass translation of approved training into Russian, Kazakh or another staff language, then having a bilingual member of staff who knows the procedure check it.
  • Rewriting a dense policy clause into plain language for a staff handbook, with the original text kept next to it.
  • Building scenario questions from the policy, with the designated safeguarding lead choosing which scenarios are realistic for that campus.
  • Summarising a public document such as an inspection framework or a standard, where no personal data is involved.

What to refuse

The refused list is shorter and should be absolute, because a rule with exceptions is a rule staff will argue with at the wrong moment.

  • Any prompt containing a child's name, initials, class, date of birth, family circumstances, health information or anything else that identifies them.
  • Any question of the form "should I report this" about a live concern.
  • Publishing a module, a policy, a letter or a translation that no named person has read and approved.
  • Writing, completing or tidying a case record with a model.
  • Uploading a concern log, an incident form or minutes naming children to any tool the school has not assessed.
  • Using a model to weigh a low-level concern about an adult, to sift job applicants, or to decide anything that a person will later have to justify.

Why the live-concern question is the one that matters

The prompt that starts "a girl in Year 8 told me that her stepfather" is the one to design against, because it is the prompt a worried adult writes at the end of a long day. It is well intentioned every single time. It also puts identifying detail into a third-party system, and it invites a machine to make a judgement that Kazakh law, English statutory guidance and the ITFCP standards all place with a trained human.

A ban on its own does not stop that prompt. Staff write it because they need an answer and the person they want is not in the building. So the school owes them somewhere else to go: a named deputy, a phone number that works after hours, and a way to ask a procedural question without naming anyone. I have written about that gap in why staff need a safe place to ask policy questions. Close the gap and the risky prompt mostly stops appearing.

The controls to ask any vendor about

A supplier selling AI features to schools should be able to answer the following in writing, in the contract rather than on a marketing page. If an answer arrives as an adjective, ask again.

  • Does the supplier or its model provider train on the school's content, and where is that stated contractually?
  • Which model provider processes the text, and in which country does the processing happen?
  • What is detected and removed before text reaches a model, and what does the system do when that detection fails?
  • Is every generation logged with the prompt, the output, the model version and the person who ran it?
  • Can generated content reach staff without a named human approving it? The correct answer is no.
  • On termination, what is deleted, within what period, and what evidence of deletion does the school receive?
  • Where does the database physically sit, and does that satisfy the school's national data rules?

How to write it into the acceptable use policy

The document that works is one page, appended to the AI acceptable use policy the school already has, and approved on the same date as the safeguarding policy. It carries six things: the scope, the allowed list, the refused list, the named owner, the review date, and what happens when someone crosses the line. Keep the allowed and refused lists as lists, in the words staff use, and put them on the staffroom wall rather than in a shared drive.

Two clauses do most of the work. The first says that a named person approves every piece of AI-assisted content before it reaches staff or students, and that the approval is recorded with a date. The second says that no information identifying a child goes into any AI tool, with no exception for urgency. I have set out the approval mechanics in human review and attestation for AI-created training, and the wider case for careful use in how AI can augment school faculty training.

One more line is worth adding, because inspectors and evaluators ask it: name who checked the tool before the school started using it, and on what date. The Department for Education expects schools to assess a use case before adoption rather than after a complaint, and a single dated line in the policy answers that question in a visit without anyone hunting through email.

Where the platform fits

SafeguardIS drafts training from the school's own safeguarding and child protection policies with AI, and a named designated safeguarding lead reviews and approves every module before staff see it. Publishing logs a hash of the approved content, and certificates are countersigned by the head of school and the designated safeguarding lead, each carrying a code anyone can check on a public verification page. Training ships in English, Russian and Kazakh today. If your staff work in a language the platform does not ship yet, I build that language in for your school as part of the pilot.

Staff can ask an AI policy assistant questions that are answered from the school's own policies, which is the safe half of the question they would otherwise take to a public chatbot. The designated safeguarding lead keeps every safeguarding decision, and no child's details belong in a chat window. A policy audit feature checks the school's documents against ITFCP-aligned expectations and produces an action plan, and I run live workshops in English and Russian as well as whole-school safeguarding audits. Miras International School in Astana is the pilot school. To see the approval trail and the refusal behaviour for yourself, book a 20-minute walkthrough.

Questions school leaders ask

Can a school use AI to write safeguarding training at all?

Yes, provided a named person approves the result. Generative AI drafting from a school's own policy is a document task, and it is the strongest use of AI in safeguarding training for schools. The Department for Education is explicit that responsibility for the final content stays with the professional who produced it and the organisation they belong to. Record who approved each module and when, and the practice survives an inspection.

Is it ever acceptable to put a child's details into an AI tool?

Treat it as never. Department for Education guidance recommends that personal data is not used in generative AI tools and warns that entered data should not contain anything allowing an individual to be identified. Urgency is the moment staff are most tempted, so the rule needs no exception clause. Give staff a named person and an out-of-hours number instead, and the identified prompt stops being the easiest option.

What should a school ask a vendor before buying an AI safeguarding tool?

Ask seven things in writing: whether anyone trains models on school content, which model provider processes the text, in which country, what is redacted before text reaches a model, whether generations are logged with the person who ran them, whether content can publish without a named approver, and what is deleted at termination. Answers written as adjectives rather than as clauses are not answers.

Does the AI rule belong in the safeguarding policy or the IT policy?

Put the rule in the AI acceptable use policy and approve it on the same cycle as the safeguarding policy, with the designated safeguarding lead as an approver. Department for Education guidance asks schools to consider AI when building safeguarding policies and to consult Keeping children safe in education, whose 2026 edition came into force on 1 September 2026. Splitting the two documents is how the rule goes stale.

See training built from your own policies

In a 20-minute walkthrough you bring one policy and I show you the module it becomes, the DSL approval step, and the certificate behind it. If your staff work in a language the platform does not ship yet, I build that language in for your school as part of the pilot.

Book a 20-minute walkthrough
Ruslan Shaymardanov

Ruslan Shaymardanov

I have worked in international education since 2008, as an IB and MYP teacher, an IB DP economics teacher, an IB and CIS evaluator and workshop leader, and most recently as CIS accreditation coordinator at Miras International School in Astana. I built SafeguardIS because my own school needed it.

LinkedIn

References