Filtering and Monitoring in 2026: Is Your Safeguarding Practice Keeping Up With the Technology?
For years, schools and colleges have been told that appropriate filtering and monitoring is an essential part of safeguarding children online but in 2026, the question is changing.
It is no longer enough to ask:
"Do we have filtering and monitoring?"
We need to be asking:
"Does it actually work in the digital environment our children and young people are using today?"
The Department for Education's updated filtering and monitoring standards, alongside Keeping Children Safe in Education (KCSIE) 2026, strengthen expectations around how schools and colleges assure themselves that their systems are effective and with AI-generated content, apps, mobile devices, personalised feeds and increasingly dynamic online environments, this is an area where safeguarding leaders cannot afford to stand still.
What's changing?
KCSIE 2026 strengthens the expectation that governing bodies and proprietors ensure filtering and monitoring arrangements are reviewed for effectiveness at least once every academic year. That review should include checks that filtering works appropriately across internet-connected devices and relevant locations, with those checks recorded.
This matters, because having filtering software installed is not the same as knowing that children are being effectively protected.
AI has changed the safeguarding landscape
One of the most significant developments is the increased recognition of generative AI and dynamic content. Traditional filtering systems were largely designed around websites, URLs and categories but children's online experiences increasingly involve content that is generated, personalised or delivered dynamically. AI tools can create text, images and other material in real time.
A platform itself might be permitted while individual content within it presents a safeguarding risk.
Schools and colleges therefore need to understand whether their current filtering and monitoring arrangements can respond effectively to:
generative AI;
dynamic and personalised content;
app-based activity;
mobile technology;
content generated within otherwise permitted platforms; and
changing patterns of online behaviour.
The question is no longer simply:
"Is this website blocked?"
It is:
"What can a child access, generate, receive or experience once they are inside the platform?"
Filtering must work in the real world
The updated expectations also reinforce the importance of testing filtering across the actual environment in which technology is used.
That means considering different:
Devices.
Locations.
User profiles.
Applications.
Networks and configurations.
Schools and colleges should understand what their system blocks and allows and whether protections continue to work when school-managed devices are taken off-site. They should also consider their approach to Bring Your Own Device arrangements and ensure new devices and services are appropriately protected before being distributed or introduced. A system working perfectly on a staff desktop connected to the school network tells us very little about the experience of a student using a different device, application or configuration.
One filtering profile does not fit everyone
Another important principle is proportionality. Filtering should protect children from harmful and inappropriate content without unnecessarily restricting teaching and learning.
The DfE standards are clear that settings should not simply apply one blanket filtering profile to everybody. As a minimum, staff and students should have different profiles, with settings considering their particular context and risk.
That requires safeguarding judgement.
Age matters.
SEND may matter.
English as an additional language may matter.
The way technology is used within the setting matters.
Known safeguarding incidents and contextual risks matter.
And the digital resilience and needs of the children themselves matter.
Appropriate filtering should therefore be informed by the safeguarding profile of your actual learners, not simply by the product you have purchased.
Monitoring is not just an IT responsibility
This is perhaps the message we would most like safeguarding leaders to take away.
Filtering and monitoring is safeguarding. It cannot sit solely with the IT department or an external technology provider.
The DSL brings safeguarding expertise. IT professionals bring technical expertise. Senior leaders bring operational responsibility. Governors and proprietors provide strategic oversight and assurance. Effective arrangements require those people to work together.
The DSL is responsible for safeguarding and child protection matters identified through monitoring, while governing bodies and proprietors retain overall strategic responsibility for ensuring appropriate arrangements are in place.
That makes this a governance issue as much as a technology issue.
Can you evidence that your system works?
KCSIE 2026 and the updated DfE standards reinforce an important move from having systems to assuring their effectiveness.
Checks should be recorded.
Settings should be able to evidence:
when a check took place;
who carried it out;
what was tested;
what the outcome was; and
what action was taken as a result.
This provides something incredibly important: an audit trail of safeguarding assurance.
Because if a serious incident occurs, knowing the name of your filtering provider is unlikely to be enough. Leaders should be able to demonstrate how they knew the system was appropriate and effective for their setting.
What should DSLs and safeguarding leaders do now?
With KCSIE 2026 coming into force on 1 September 2026, now is the time to test your arrangements.
Ask:
When did we last formally review our filtering and monitoring provision?
Who was involved?
Did the DSL, IT, senior leadership and governance all contribute?
Have we tested filtering across different devices, user groups and locations?
Do we understand what happens on school-managed devices when they are used away from the setting?
Can our systems respond appropriately to app-based, dynamic and AI-generated content?
Do we understand the limitations of our current technology?
How quickly are monitoring alerts reviewed and safeguarding concerns acted upon?
Do staff understand what they should report if filtering or monitoring appears ineffective?
Can governors evidence appropriate scrutiny and assurance?
And importantly:
When was the last time somebody actually tested whether what we think is happening is really happening?
Beyond compliance
Online safeguarding moves quickly, the platforms change, the technology changes, the content changes, the risks change and increasingly, the way content reaches children changes too. A filtering and monitoring system purchased several years ago cannot simply be assumed to remain appropriate because the contract is still running. Safeguarding leaders need to understand the technology, challenge its limitations and ensure arrangements reflect the children and young people they are responsible for today.
Because the question isn't:
"Have we bought a filtering and monitoring system?"
The question is:
"Can we evidence that it is actually keeping children safer?"
That is the difference between compliance and safeguarding assurance.
RLB Safeguarding supports schools, colleges and education providers with safeguarding audits, Prevent, online safeguarding, DSL development, training, governance and strategic safeguarding assurance. Book your free consultation here
Resources
Important Updates to Keeping Children Safe In Education 2026
Meeting digital and technology standards in schools and colleges
Schools given advice on image safety to keep ahead of threat from AI blackmailers