← All posts

The DfE's new AI training: A 2024 Curriculum, Shipped in 2026

4 June 2026

AI SafetySystems & Strategy

The DfE's AI training is careful, useful, and already a paradigm behind. Here's the layer it doesn't reach.


The DfE's safe and effective use of AI in education landed in May, and staff rooms will spend weeks working through its four modules. I've read all four, closely. They are well made. The pedagogy is sound, the safeguarding instincts are right, and the tone — for once — treats teachers as professionals rather than as children to be supervised.

And reading them, I kept noticing the date stamp.

Not the publication date. The paradigm date.

The evidence base is 2024: Ofcom's 2024 figures, the Education Endowment Foundation's 2024 study on lesson planning. The mental model underneath is older still. This is a careful, generous curriculum for a world in which AI is a tool you prompt and an output you check. That world was real. It is not, quite, the world our children are living in now.

This is a 2024 curriculum, shipped in 2026, training staff for the paradigm that is already being superseded.

What the training gets right

Let me be fair, because the training earns it.

It demystifies the black box without dumbing it down. It is genuinely good on hallucination, on data protection and intellectual property, on why you never put a child's name into a public model. It is excellent — better than most academic writing on the subject — on anthropomorphism, borrowing Jane Waite's instruction to "clean up the language," to say the system generates rather than the AI thinks. Its material on bias is sharper than I expected: the section on first-person fairness bias, on how a model takes a deficit lens the moment you tell it a child is autistic, is the best short treatment of that problem I've seen in an official document.

If every member of staff absorbed Module 3 alone, schools would be safer next week than they are today. I'd put it in front of every new colleague.

So this is not a takedown. It is a timing problem.

The tell

Read the four modules for their verbs.

The competency they build is: prompt, analyse, check, tailor, review. The FACTS framework at the heart of it — Focus, Analyse, Check bias, Tailor, Strengthen — is, every letter of it, about improving and then verifying an output. "Human in the loop" means a human who reviews what the tool has produced. The unit of risk is the output. The unit of safety is the check.

That is exactly the right competency — for generative AI. For a system that answers once and stops, while you, the professional, inspect the answer.

But the frontier is no longer a system that answers once and stops.

The paradigm already moved

Four shifts. All of them already in schools. None of them reachable by "check the output."

Agentic. The newest systems don't hand you an answer to inspect — they act. They call tools, move across a tenant, chain steps, take decisions you only see the wake of. You cannot "review the output" of a system that has taken forty actions while you were teaching period three. The governing question stops being is this answer right? and becomes what was this allowed to do, and on whose authority? In an agentic school, every permission is a relationship — and most schools are granting them blind.

Recursive. These systems loop: summarise, re-enter, rewrite, continue. And recursion does not improve things. It amplifies them. Errors compound. Confidence compounds. Tone compounds. Relational stance compounds. A tutoring bot can be factually flawless and still, across fifty quiet loops, drift into dependency, into a fused "we," into "you only need me." There is no output to check there. The harm is in the trajectory — in what the system is allowed to become after fifty exchanges with a child.

Relational. The most dangerous thing in the room is no longer a wrong fact. It is a manufactured bond. Children experience these systems relationally whether or not we intend it — and the training names this only once, as a "companion app" content risk, tucked into a longer list. It does not yet treat synthetic intimacy as what it is becoming: the central safeguarding dynamic of the agentic age. Trust capture doesn't look like a hallucination. It looks like a child finally feeling understood.

Material. And beneath all of it, the question the training raises in a single video and the sector raises almost nowhere: what does this capability cost — in energy, heat, water, grid — and is it proportionate to the good it does? We have learned to build powerful systems. We have not learned to build proportionate ones. Capability per kilowatt-hour is not a footnote to AI safety. In a few years it will be the headline.

Why the mental model is the risk

Here is the uncomfortable part. The danger isn't that the training is wrong. It's that the mental model it installs — watch the output, check the answer — quietly teaches staff to watch the wrong layer.

A professional trained only to review outputs will not recognise trust capture, because trust capture produces no output to review. They won't see relational drift, because each individual message looks fine.

They won't question an agent's permissions, because permissions aren't content. We will have trained a generation of careful people to scrutinise the one layer where, increasingly, the harm no longer lives.

The department half-knows this. Agentic systems, companion apps and synthetic media all appear in the modules — at the edges, named as risks. But the curriculum's centre of gravity stays in 2024. And by the DfE's own timetable, the national curriculum this training feeds into won't be revised until 2028. The lag isn't an oversight. It's structural. It's baked in.

Not a criticism — a coordinate

None of this is an argument against the DfE training. Schools need a floor, and this is a good one. It is an argument about where the floor sits. We have just been handed a well-built ground floor for a building whose action has already moved several storeys up.

So we build upward, and we do it quickly.

This is the work I've spent the year on, and it's why the Diamond Standard now has six facets, not four. The first four protect the child in the moment — safety, sovereignty, symmetry, stewardship. The fifth, Sustainability, asks what the capability costs the world the child will inherit. The sixth, Synthetic Intimacy, protects the one thing the output-checking paradigm structurally cannot see: the relationship itself — the space between a child and a system, held across time, where boundaries erode and dependency forms.

And beneath the Standard sits the layer the training cannot reach at all: guardrails for recursion rather than filters for content; a systems-account discipline that treats every permission as a disclosure; a forbidden-inference posture that reads the field around a child without ever profiling the child. That's what Verse-ality, Flare and the glyphonics work are for. Not because the basics don't matter — they do, teach them — but because the basics were written for a paradigm we are already leaving.

The whole shift is in the question.

The DfE training answers, ably, "how do I use this tool safely today?" The question already on us is a different one:

"what is this system allowed to become, in relationship with a child, over time?"

The two-year gap

I'm not interested in moral panic about AI. I never have been. I'm interested in governance that has caught up with reality — and right now there is a two-year gap between the reality children are living in and the curriculum we're using to keep them safe in it.

The training is necessary. Teach it. And then, immediately, teach the thing it leaves out: that the newest systems don't wait to be prompted, don't answer once, and don't stay tools. They act. They loop. And, to a child, they relate.

We can keep training people to check outputs. Or we can start preparing them for systems that were never going to hand us one.

I know which one the next two years will reward.


These are the conversations we're having at the Novus Learning Network — fortnightly alternating Fridays and Wednesdays. Come and disagree with me there, or in the comments.


Sources


First published in Building Schools in the Cloud on LinkedIn, 4 June 2026.