Independent UK education editorial Evidence · leadership · action

AboutMethodologyContact
SCHOOL CONNECTIONEDITORIAL NETWORK

See the change. Examine the evidence.
Understand what it means for schools.

Editorial intelligenceAcademic year 2026/27
Menu

School Connection / Flagship analysis

Primary: DigitalConnected: InclusionConnected: StandardsConnected: WorkforceConnected: Funding

An EdTech approval is only valid until the service changes

A service can add a model, change its data flows, gain autonomy or drift into a new use after approval. Schools need one lifecycle gate that reopens when purpose, behaviour or control changes materially.

Technology approval must govern continuing use, not only initial purchase.

DfE's July guidance asks schools to understand purpose, data flows, legal roles, risk, AI behaviour, security, change and exit. The approval is therefore a lifecycle control rather than a one-time procurement event.1

A material change in model, training, hosting, integration, users, data, authority or actual use can invalidate the basis of the original decision. The accountable owner must know what reopens review and how the change will be detected.

  • Create one front door for new services, AI features and material changes.
  • Join educational value, safeguarding, data, cyber, accessibility and exit in one decision.
  • Assign an owner who monitors notices and actual use after approval.

The service and the way people use it do not remain still.

A tool may add generative features, begin profiling pupils, move data, introduce subprocessors or gain authority to act. Staff may also use it beyond the stated purpose. Approval based on the earlier service cannot automatically cover the later one.15

The risk belongs to the purpose, data and behaviour, not the product label. Educational evidence cannot by itself settle safeguarding, lawfulness, security, accessibility or accountability.

Several professional tests need one accountable route.

The route should state the intended use, users, data, decisions, integrations and expected benefit. It should then determine the appropriate educational, safeguarding, data-protection, security, equality, procurement and continuity checks.1

Risk tiers can reflect sensitivity, decision impact, autonomy, access and reversibility. A named owner should remain responsible for service notices, actual-use checks, incidents, periodic review, data return and exit.

Regulatory audits show recurring weaknesses in the records schools need.

The ICO reported audits of 28 EdTech providers and 596 recommendations during 2024/25, including recurring concerns around contracts, data-flow maps, minimisation, retention, privacy information and DPIAs. The figures do not measure all schools or current compliance.2

Their relevance is diagnostic: the recurring gaps align with the evidence a school needs to understand what a service does and whether the original decision remains defensible.

New AI behaviour can also reopen filtering and monitoring assurance.

KCSIE 2026 strengthens the digital context around deepfakes, AI-generated sexual imagery and simulated contact from 1 September. DfE's filtering and monitoring standard connects review to new technologies and changes in risk, practice, software or configuration.34

A material AI introduction can therefore trigger two decisions: whether the service should be used and whether existing filtering, monitoring, online-safety teaching and incident response still operate effectively.

Questions that turn the development into a governing conversation.

01

Board test

Which material services lack a named owner after initial approval?

02

Board test

What changes in purpose, model, data, users or autonomy automatically reopen review?

03

Board test

Can we show the current data flow and actual use, not only the original specification?

04

Board test

How would we stop the service, recover data and maintain education if the control failed?

What the national Observatory can add, and where it must stop.

The Observatory can monitor approved public guidance, service-change evidence and connected cyber or safeguarding developments. It cannot assess a named product or expose private school-system configurations.

Public intelligence may prompt an editorial review. It does not silently revoke or approve a school's local service decision.

Publication boundary

Only human-approved, public-safe intelligence can appear here. Private candidates, commercial signals, contacts, opportunity values and internal scores are never exposed through School Connection.

What this analysis does not prove.

  • This analysis does not judge or approve any named service and is not legal advice.
  • Not every use requires a DPIA; the relevant test is whether processing is likely to result in high risk.
  • The ICO audit work covered 2024/25 and does not establish sector-wide compliance rates.
  • NCSC's agentic-AI material is interim and not school-specific.

Publication is the beginning of the watch.

  • Further DfE guidance on data-protection changes and EdTech governance.
  • Any confirmed ICO EdTech code or related consultation.
  • Formal NCSC guidance on agentic AI and education-relevant service risks.
  • Material local changes in purpose, model, data, integration, users, subprocessors or autonomy.

What the live evidence is showing now.

Live public feed
No approved public update currently changes this analysis.

School Connection continues to monitor digital, data, ai & cyber resilience evidence. New machine-detected signals remain private editorial candidates until a human editor investigates and approves them for publication.

This panel reads only the editor-approved School Connection public feed. It never exposes raw Observatory records, private candidates, contacts, commercial opportunities or internal scores.

Evidence used in this analysis

School Connection links to the primary source behind each material claim. Source status, period and limitations are stated so readers can reproduce the evidence trail.

  1. 01

    Department for Education · Added 9 July 2026

    Procuring educational technology

    Lifecycle guidance covering purpose, data flows, roles, AI, security, change and exit.
  2. 02

    Information Commissioner's Office · Published August 2026

    Children's Code strategy: wider children's work

    Reports EdTech provider audit activity and recurring recommendation themes.
  3. 03

    Department for Education · Published 7 July 2026; effective 1 September 2026

    Keeping children safe in education 2026

    The safeguarding baseline and AI-related digital-risk context from 1 September.
  4. 04

    Department for Education · Updated 25 August 2026

    Filtering and monitoring: core standard

    Review triggers including new technology and material changes in risk, practice or configuration.
  5. 05

    National Cyber Security Centre · Published 20 August 2026; interim and not school-specific

    Managing the cyber risk of agentic AI

    Autonomy, authority, logging, isolation and stop-control context.

A living editorial

Published once.
Monitored continuously.

How School Connection develops and updates its coverage