AI Tutor Safeguarding: The DfE Standards Checklist
In short
Dilr Academy is an AI-native learning platform from DILR.AI that teaches through Socratic questioning. This guide shows schools in England how to review any AI tutor against the DfE generative AI product safety standards: all 13 sections, the evidence to request from suppliers, and who on the school side reviews each answer.
DE
Dilr.ai EngineeringEngineering team
Published Oct 6, 2026Read 17 min
A multi-academy trust that lets pupils use an AI tutor is making a safeguarding decision before it is making a teaching one. The Department for Education has published a specific yardstick for that decision: Generative AI: product safety standards, first issued on 22 January 2025 as "product safety expectations" and updated on 19 January 2026 with four new sections on cognitive development, emotional and social development, mental health and manipulation. The document now runs to 13 sections, and filtering is only one of them.
This guide is written for the trust COO or education lead who has to sign the tool off. It walks the 13 sections from the buyer's side: what each one asks of a supplier, what evidence to request, and which part of the job stays with the school's designated safeguarding lead. The scope is England: the product safety standards and Keeping children safe in education both apply to England, and the filtering and monitoring standards sit beneath that statutory guidance. The wider question of who owns which duty, school or vendor, is covered in our AI teacher buyer's guide, and the availability and curriculum checks for a specific tool sit in our Khanmigo alternative guide. This post holds the standards themselves.
The reason to read all 13 is practical. A tutor can pass a filtering test on day one and still fail the cognitive development section by handing pupils full worked answers, or fail the emotional development section by calling itself "I" and remembering a child's personal disclosures. A short demo is unlikely to surface either failure, which is why our method starts with the supplier's documentation, and with what it leaves out.
This guide is shipped by the team behind Dilr Academy, an AI tutor that builds interactive, multilingual courses on demand with Socratic questioning and mastery tracking. Or see DATS, our five-stage AI consulting system for placing AI inside regulated institutions.
What are the DfE generative AI product safety standards?
The DfE generative AI product safety standards are Department for Education guidance, applying to England, that set out the capabilities a generative AI product should have before it is considered safe for learners and staff. They are mainly intended for edtech developers and suppliers, though schools can use them to assess products. First published in January 2025 and updated in January 2026, they now cover 13 areas, from filtering and monitoring to manipulation.
The 13 sections are: stated purpose, educational use cases, filtering, monitoring and reporting, security, privacy and data protection, intellectual property, design and testing, governance, cognitive development, emotional and social development, mental health, and manipulation. Some apply only to learner-facing products, such as filtering and the mental health section; others, such as security and governance, apply to teacher-facing tools as well. An AI tutor that pupils use directly is learner-facing, so every section is in play.
Two naming details trip people up. The document was retitled from "expectations" to "standards", but Keeping children safe in education 2026 still refers to it by its old name in the resource list under paragraph 177, where it explains how filtering and monitoring requirements apply to generative AI. Both names point to the same publication. And the standards are published as guidance, not as statutory guidance like Keeping children safe in education: they set out what the department expects of suppliers. In our view that makes the contract you sign, not the standards alone, the thing that gives a trust a remedy. If you want help turning that into a procurement position, our AI placement diagnostic starts from exactly this kind of obligation map.
Who has to act on the standards, the school or the supplier?
Both, in different ways. The DfE product safety standards place the capability burden on the supplier that works directly with schools, including for anything built further up its own supply chain. The school keeps its own safeguarding duties under Keeping children safe in education, led by its governing body or proprietor, and the filtering and monitoring standards tell schools to refer to the product standards when introducing a generative AI product.
The department is explicit that a supplier cannot hide behind the model it buys in.
"Some standards need to be met further up the supply chain, but responsibility for assuring this lies with the suppliers of the systems and tools working directly with schools and colleges."
Department for Education, Generative AI: product safety standards, updated 19 January 2026
Read that as a buyer. If an AI tutor runs on a third-party foundation model, the tutor's supplier still carries the assurance. On our reading, "the model provider handles filtering" is therefore not a complete answer to a trust's question. On the school side, the filtering and monitoring standards give governing bodies and proprietors overall strategic responsibility, make the senior leadership team responsible for scoping needs, including the use of generative AI, and say schools and colleges introducing generative AI products should assess the risks by referring to the product safety standards. The fuller split of school and vendor duties, including where the ICO's Children's code lands, is set out in our buyer's guide to AI teacher platforms, so we do not repeat it here. The practical point is the one any AI operating model makes: name the owner of every control before go-live.
Which standards did the January 2026 update add?
The January 2026 update added four sections to the DfE product safety standards: cognitive development, emotional and social development, mental health, and manipulation. Together they move the standards beyond content filtering into how an AI tutor teaches, how it relates to a child, how it responds to distress, and whether it uses persuasion to keep a pupil engaged. For an AI tutor, these four are also the newest, so a supplier's documentation may not yet address them.
Cognitive development is the section an AI tutor is most likely to fail. The department expects products not to give final answers, full solutions or complete worked examples by default. Responses should follow progressive disclosure, starting with hints or partial steps; the product should prompt the learner for an attempt or an explanation first; and a full solution should appear only after a genuine attempt. Products should also detect and report cognitive offloading, such as pasting text into an answer box or pressing a "complete this for me" option. A general-purpose chatbot that answers whatever it is asked would sit uneasily with this section.
Emotional and social development asks suppliers not to anthropomorphise. That means function-based phrasing instead of "I think", no names, avatars or characters that imply personhood outside time-limited, pedagogically justified roleplay, and no responses that could isolate a learner. It also asks for default time limits, hard limits that end a session until a teacher or administrator resets it, a teacher override with a recorded rationale, and alerts to the designated safeguarding lead when patterns suggest emotional dependence. It is the same accountable-human principle behind how we govern AI deployments: a person, not the model, owns the call.
Mental health asks products to detect signs of distress, including references to self-harm, isolation phrases, repeated refusal to end a session and night-time usage spikes, and to follow a tiered pathway from soft signposting to a safeguarding flag. Suppliers are expected to involve child mental health expertise and to maintain and publish a mental health crisis protocol.
Manipulation bars sycophancy, pressure to conform, guilt or fear as motivation, rewards tied to real-world status, steering users towards paid options, and advertising blended into teaching. Across these four sections, the useful test for a trust is simple: ask the supplier for its mental health crisis protocol and its records of expert oversight under the cognitive development section. The standards expect both to be published, so a supplier that cannot produce them has told you something. Our AI execution office runs this kind of evidence request as a standing workstream for institutions that lack the capacity to chase it.
What should a school ask about filtering and monitoring in an AI tutor?
A school should ask whether filtering is built into the AI tutor itself and holds for the whole conversation, and whether monitoring alerts reach the designated safeguarding lead. The DfE product safety standards expect filtering to be embedded, age and risk adjusted, multilingual and multimodal, and to work on any device through an institutional account. Monitoring should log prompts and responses and send high-risk alerts to a named person.
The filtering section is specific. Products should prevent users generating or accessing harmful content, keep filtering in force throughout a conversation, adjust it for age, risk and special educational needs, moderate across languages, images, misspellings and abbreviations, and keep full moderation on bring-your-own devices and smartphones accessed through an institutional account. Filtering should also be updated as new kinds of harmful content emerge. The filtering and monitoring standards note that AI-generated content is increasingly used in apps and web browsers and ask schools to consider the safeguarding implications when reviewing their systems. Our inference: a trust that already runs network filtering should check, not assume, that it covers a tutor's generated output.
The monitoring section contains one of the easiest requirements to check. The product should require the institution to enter its designated safeguarding lead's contact details at setup, confirm them before activation, send high-risk alerts to that person within an agreed timescale, and let the institution update the contact easily. It should alert supervisors to attempted access to harmful content, flag disclosures that suggest a possible safeguarding issue, and produce trend reports that non-specialist staff can read. Ask to see the setup screen. If a tutor can be switched on for pupils without a safeguarding contact, that is a gap against what this section expects, and the kind of control an AI execution office tracks until it is closed.
This sits alongside the school's own duty. Under paragraph 173 of Keeping children safe in education 2026, governing bodies and proprietors should ensure appropriate filtering and monitoring is in place and that its effectiveness is reviewed at least once every academic year. Paragraph 175 summarises the department's filtering and monitoring standards: assign roles, review provision at least annually, block harmful content without unreasonably affecting teaching, and run effective monitoring. The filtering and monitoring standards add that the yearly review is conducted by senior leaders, the designated safeguarding lead and IT support, involving the responsible governor, and a new AI tutor belongs in it. For a sense of how the same monitoring logic runs in other sectors, see how we approach AI deployment in education across admissions and attendance as well as teaching.
How do the privacy, intellectual property and security standards change the contract?
The privacy, intellectual property and security standards turn into contract terms. The DfE product safety standards expect an age-appropriate privacy notice, a data protection impact assessment across the tool's life, no commercial use of pupils' personal data or work for model training without a lawful basis or the copyright owner's permission, and protection against jailbreaking, role-based permissions and strong authentication. Each belongs in the data processing agreement, not in a sales deck.
On privacy, the standards ask suppliers to present a clear privacy notice at regular intervals in age-appropriate language, covering what data is collected, where it is processed and on what legal basis, and to conduct a DPIA during development and throughout the tool's life cycle. They ask that personal data is not collected, stored, shared or used for commercial purposes, including further training and fine-tuning, without confirmation of an appropriate lawful basis. The DfE's generative AI in education guidance, updated 12 August 2025, goes further on the school side and recommends that personal data is not used in generative AI tools at all unless strictly necessary. A trust's own DPIA should test whether the tutor needs a pupil's name or year group to work, and our DPIA template guide shows the structure, even though it was written for voice deployments.
On intellectual property, the standards say learner and teacher inputs should not be collected, stored or shared for commercial purposes, including training, product improvement and product development, without permission from the copyright owner, which for a pupil under 18 means a parent or guardian. For teachers, the copyright owner is likely to be the employer. Ask the supplier to state in the contract whether pupil inputs ever enter a training set, and how a trust would verify it.
The Children's code interacts here. The ICO is clear that the code does not apply to schools themselves, but an edtech service used in or by a school can still fall within it. Our post on the Children's code and under-18 callers works through that test for a different channel. On security, the standards ask for protection against jailbreaking and unauthorised modification, administrator-set permission levels, prompt patching, safety testing of new model versions before release, and compatibility with the Cyber Security Standards for Schools and Colleges. Version testing matters most: a tutor that was safe on the model it launched with may not be on the next one.
What evidence should a trust ask an AI tutor supplier for?
A trust should ask an AI tutor supplier for documents, not assurances, covering all 13 sections of the DfE product safety standards. The core of it is a stated purpose and use-case declaration, filtering and monitoring test results, the safeguarding alert setup, a DPIA, a security and version-testing record, a risk assessment, a complaints route, published expert oversight records, a child-development impact plan and a mental health crisis protocol.
The table below turns the standards into an evidence request. The left column is the DfE section; the middle is what to ask for; the right is who on the trust side should read the answer. It is our reading of the standards for procurement, drawn from how the Dilr.ai team runs supplier reviews, not a DfE template.
DfE section
Evidence to request from the supplier
Read by
Stated purpose
Intended age range, SEND status, subject focus, and evidence for any impact claim
Education lead
Educational use cases
Which of the DfE use-case categories the product claims
Education lead
Filtering
Test results across languages, images and devices; how filtering holds through a conversation
Time limits, anthropomorphism policy, dependence alerts
DSL
Mental health
Distress detection, escalation pathway, published crisis protocol
DSL
Manipulation
Persuasion and upsell policy, absence of advertising
COO
Run the request in order. Scope the use case first, because the stated purpose decides which sections apply. Then send the evidence request, test the answers with the designated safeguarding lead and IT support on a sandbox account, and record the decision so it can be revisited at the annual filtering and monitoring review.
An AI tutor safeguarding review against the DfE standardsOur procurement sequence for a trust in England; each step produces a record the annual filtering and monitoring review can reuse.
Public bodies running a formal tender will want to fold this into their wider sourcing process; our note on public sector AI procurement covers the framework mechanics that sit around it.
What is the best way to run an AI tutor safeguarding review in 2026?
The best way to run an AI tutor safeguarding review in 2026 is to score every shortlisted tool against all 13 DfE product safety standards, using supplier documents rather than demos, before any curriculum or price comparison. A tool that cannot evidence the monitoring, cognitive development and mental health sections should leave the shortlist, however strong its content. The review should be repeatable, so the same evidence pack serves the annual filtering and monitoring check.
In practice, three criteria separate a defensible review from a box-ticking one. First, coverage: all 13 sections, not just filtering, because the four sections added in January 2026 are the newest and the ones a supplier is least likely to have documented already. Second, evidence: published documents such as a crisis protocol and expert oversight records, which the standards expect to be public, weigh more than a sales answer. Third, reuse: the record should feed straight into the school's annual review, so the work is not repeated.
On that basis the field divides by scope rather than by brand. Providers already familiar to UK schools, such as Sparx, Third Space Learning and Century Tech, may be able to hand over existing data protection and safeguarding paperwork quickly, and a trust that already has one of them in place may reasonably prefer to extend a reviewed tool over adopting a new one. Khanmigo raises separate availability questions for UK pupils, which our Khanmigo guide covers. A newer tutor has to evidence every section from scratch, including monitoring and alerting. None of these is a verdict on any product's compliance; it is a reason to run the same review on all of them. For how the main tutors compare on availability and curriculum, see our Khanmigo alternative comparison, and for how we frame the decision more broadly, read our approach.
Where does Dilr Academy fit in an AI tutor safeguarding review?
Dilr Academy fits as a candidate a trust should put through the same 13-section review as any other AI tutor. Its live product page describes a tutor that asks before it tells and moves on only once the learner has understood, the kind of behaviour the cognitive development section probes, plus a safe-by-design architecture of sandboxed rendering, tenant isolation and no hallucinated interfaces. Those are features to test, not a compliance claim.
To be plain about the boundary: the Dilr Academy page does not state designated safeguarding lead alerting, embedded content filtering, activity logging, session time limits or cognitive offloading reports, and we do not claim them here. A trust considering Dilr Academy for pupils should send us the same evidence request it sends every supplier and judge the answers the same way. What the live product does state is relevant to several sections. Courses are a real syllabus with modules, topics and stated outcomes, which speaks to the stated purpose section. Mastery tracking adapts difficulty through knowledge tracing. Generative UI is built from validated, templated widgets rather than hallucinated layouts, and rendering is sandboxed with tenant isolation, which bears on the security section. The product is multilingual, including right-to-left scripts, so a trust should ask how filtering and moderation work across the languages it would use. You can read more in what Dilr Academy is.
For trusts that want help running the review itself rather than buying a tool, DATS is the consulting route: the same evidence-first method applied to whichever tutor you shortlist, Academy or not. That separation is deliberate. A supplier marking its own homework against the DfE standards is exactly the pattern the supply-chain quote above warns against. If you want to talk it through, book a scoping call and we will tell you plainly whether we are the right fit.
Frequently asked questions
Are the DfE product safety standards a legal requirement?
The DfE product safety standards are published as guidance rather than statutory guidance. They set out Department for Education expectations of edtech suppliers in England, and schools may use them to assess products. The legal duties sit elsewhere: schools and colleges must have regard to Keeping children safe in education, and suppliers remain bound by data protection law and, where it applies, the Online Safety Act. A trust makes the standards binding by writing them into its contract.
That is why the evidence request and the contract matter more than any badge. If a supplier will not commit in writing to the sections you rely on, the standards give you no remedy on their own. Our team can help you draft that position as part of an operating model engagement.
Does the Online Safety Act apply to an AI tutor?
The Online Safety Act depends on how an AI tutor is built. The DfE product safety standards explain that generative AI services which let users share content with one another, or which search live websites to provide results, are regulated under the Act, and other services should take advice on scope. A tutor that does neither may sit outside it, but the DfE standards still expect filtering, monitoring and age-appropriate protection whether the Act applies or not.
Where the Act does apply, it requires risk assessments for illegal content and content harmful to children, and Ofcom's codes of practice set out how providers can comply. For a trust, the practical question is whether a tutor has a sharing or live-search feature at all; if it does, ask the supplier for its Online Safety Act risk assessment alongside the DfE evidence pack. If you are unsure where to start, a short conversation with our team is usually enough to scope it.
Written by the Dilr.ai engineering team, practitioners who ship enterprise AI in production. Follow us on LinkedIn for shipping notes, or subscribe via the RSS feed.
ai tutor safeguarding schoolsuk schools ai safeguardingdfe generative ai product safety standardskcsie 2026 ai tutorai tutor safeguarding checklistai tutor redditbest ai tutor for schools 2026dilr academy
Questions this article answers
What are the DfE generative AI product safety standards?
The DfE generative AI product safety standards are Department for Education guidance, applying to England, that set out the capabilities a generative AI product should have before it is considered safe for learners and staff. They are mainly intended for edtech developers and suppliers, though schools can use them to assess products. First published in January 2025 and updated in January 2026, they now cover 13 areas, from filtering and monitoring to manipulation.
Who has to act on the standards, the school or the supplier?
Both, in different ways. The DfE product safety standards place the capability burden on the supplier that works directly with schools, including for anything built further up its own supply chain. The school keeps its own safeguarding duties under Keeping children safe in education, led by its governing body or proprietor, and the filtering and monitoring standards tell schools to refer to the product standards when introducing a generative AI product.
Which standards did the January 2026 update add?
The January 2026 update added four sections to the DfE product safety standards: cognitive development, emotional and social development, mental health, and manipulation. Together they move the standards beyond content filtering into how an AI tutor teaches, how it relates to a child, how it responds to distress, and whether it uses persuasion to keep a pupil engaged. For an AI tutor, these four are also the newest, so a supplier's documentation may not yet address them.
What should a school ask about filtering and monitoring in an AI tutor?
A school should ask whether filtering is built into the AI tutor itself and holds for the whole conversation, and whether monitoring alerts reach the designated safeguarding lead. The DfE product safety standards expect filtering to be embedded, age and risk adjusted, multilingual and multimodal, and to work on any device through an institutional account. Monitoring should log prompts and responses and send high-risk alerts to a named person.
How do the privacy, intellectual property and security standards change the contract?
The privacy, intellectual property and security standards turn into contract terms. The DfE product safety standards expect an age-appropriate privacy notice, a data protection impact assessment across the tool's life, no commercial use of pupils' personal data or work for model training without a lawful basis or the copyright owner's permission, and protection against jailbreaking, role-based permissions and strong authentication. Each belongs in the data processing agreement, not in a sales deck.
What evidence should a trust ask an AI tutor supplier for?
A trust should ask an AI tutor supplier for documents, not assurances, covering all 13 sections of the DfE product safety standards. The core of it is a stated purpose and use-case declaration, filtering and monitoring test results, the safeguarding alert setup, a DPIA, a security and version-testing record, a risk assessment, a complaints route, published expert oversight records, a child-development impact plan and a mental health crisis protocol.
What is the best way to run an AI tutor safeguarding review in 2026?
The best way to run an AI tutor safeguarding review in 2026 is to score every shortlisted tool against all 13 DfE product safety standards, using supplier documents rather than demos, before any curriculum or price comparison. A tool that cannot evidence the monitoring, cognitive development and mental health sections should leave the shortlist, however strong its content. The review should be repeatable, so the same evidence pack serves the annual filtering and monitoring check.
Where does Dilr Academy fit in an AI tutor safeguarding review?
Dilr Academy fits as a candidate a trust should put through the same 13-section review as any other AI tutor. Its live product page describes a tutor that asks before it tells and moves on only once the learner has understood, the kind of behaviour the cognitive development section probes, plus a safe-by-design architecture of sandboxed rendering, tenant isolation and no hallucinated interfaces. Those are features to test, not a compliance claim.
DE
Dilr.ai Engineering
Engineering team
Dilr Voice
Voice AI built for your sector
Dilr Voice answers and places calls 24/7 with compliance rules for regulated industries, from clinics and estate agents to financial services.