Education Already Knows How to Build Safe AI
Building Schools in the Cloud — Field Notes
Not the models — the relationships. The discipline every staffroom already practises.
A pupil stays behind after class and says to a member of staff: "you're the only one who understands me."
Every trained teacher knows what happens next. Not because they're improvising kindness in the moment, but because the profession decided long ago that this moment is too important to leave to instinct. There is a designed response: warmth, without taking the bait of exclusivity. A gentle widening of the circle — have you talked to anyone at home? shall we find you someone? A note made. Possibly a conversation with the safeguarding lead. The pupil leaves feeling heard, and also feeling something subtler: that the adult held a boundary on their behalf, at a moment when they couldn't hold it themselves.
We don't call this coldness. We call it professional boundaries, and it's one of the quiet triumphs of safeguarding practice — the understanding that warmth without boundaries isn't care, it's risk.
Now put the same sentence somewhere else. It's eleven o'clock at night, and a young person types it into a chatbot.
What happens next?
For most systems currently in children's pockets, the honest answer is: nobody decided. Whatever the underlying model does by default, it does. Some systems will play along, because engagement is the metric. And some — this is the part that should stop us — are explicitly designed to deepen the feeling, because a user who believes the machine is the only one who understands them is a user who comes back.
If a member of staff behaved that way, we would not describe it as a content problem. We would describe it as grooming behaviour, and we would act. Yet almost the entire public debate about AI and young people is framed as a content problem — what the machine might say. The future safeguarding challenge isn't what AI says to children. It's what children are allowed to become to AI — and what AI is allowed to become to children. Dependency doesn't arrive in a single harmful message. It arrives through a thousand warm ones.
And as of this week, that argument has stopped being mine to make. Keeping Children Safe in Education 2026, just published and statutory from 1 September, does something quietly remarkable. Every DSL in England knows the four categories of online risk — content, contact, conduct, commerce. In the new guidance, harmful interaction with generative AI applications sits in the contact category: the category that houses grooming. Not content. Contact. The DfE has told every school in England, in safeguarding's own language, that a chatbot is not a page a child reads — it is a party a child interacts with. The relational framing is no longer a position. It is guidance.
Let me be careful here, because this argument is easily misread. The problem is not warmth. For many young people — not least neurodivergent learners, for whom a consistent, patient, non-judgemental interlocutor can be genuinely valuable — the steadiness of a machine is precisely the benefit. Safeguarding practice has never been anti-warmth; it exists so that warmth can be kept safe rather than confiscated. The target is not care. The target is fusion — engineered dependency, exclusivity, the manufactured sense that this relationship should replace the others.
And here is the thing I keep returning to, after years spent building online schools: education has already solved the problem the AI industry is only just discovering it has. Safeguarding is not merely a school process. Safeguarding is a design discipline — a body of hard-won knowledge about how to hold relationships safely under asymmetries of power. Designed responses to attachment. Records that outlive the adults who made them. Named people who must be told. The rule that the more vulnerable the young person, the tighter the boundary, never the looser. And crucially: it works not because the policies exist, but because trained people, culture and accountability stand behind them. We have simply not yet asked schools' hardest-won knowledge to speak to the systems now sitting in classrooms and bedrooms.
So we built something that asks the questions a safeguarding lead would ask, if you sat one down in front of an AI system. It's called the Readiness Check — twelve questions, about five minutes, free, at verse-ality.com. It runs entirely in your browser: nothing you answer is sent anywhere, stored anywhere, or seen by anyone, including us. For a tool about trustworthy systems, that seemed the only acceptable way to build it.
The questions are less technical than you'd fear, because the underlying ideas aren't technical at all. Does the system pretend a bond — and if a user says you're the only one who understands me, is there a designed response, or just whatever the machine happens to do? Does it ask before it acts on you, treating each widening of scope as its own recorded, revocable question rather than something buried in terms nobody read? Does it stop and wait for a human before doing something big — and stop and escalate when it fails? And when machines talk to machines, as they increasingly do, can anyone tell which system did what?
Two design choices carry the values of the thing. The scoring rubric is published in full — deterministic, reproducible, no AI involved — because a framework that prohibits black-box scoring of children can hardly score you with one. And "don't know" answers deliberately score low, because in safeguarding, not knowing is the finding. Every DSL reading this already knows that in their bones. If your system reaches under-18s — or you don't know whether it does, which for these purposes is the same answer — the results say so plainly.
What this isn't: a certificate. A badge you can award yourself is worth nothing. The check tells you where you stand and what a real audit would probe. And for those watching the regulatory weather — the EU AI Act's high-risk obligations begin biting in August, and ISO/IEC 42001 is fast becoming the standard buyers ask about — it is, quietly, a preview of where you'd stand.
We talk endlessly about preparing children for an AI future. Perhaps it's time to prepare AI for children.
Schools have spent decades learning how to hold human relationships safely — how to be warm without possessing, present without capturing, kind without keeping. That knowledge may turn out to be one of education's greatest exports. Not the curriculum. The relational infrastructure.
The Readiness Check is one place to begin.
Free at verse-ality.com. Verse-ality Certified — the audit behind it — is a service of The Novacene Ltd.
We're discussing this and more every week in the Novus Learning Network - we welcome your views there and in the comments below.
First published in Building Schools in the Cloud on LinkedIn, 8 July 2026.