Every Permission Is a Relationship: Prevent Duty in the Age of Agentic AI
Yesterday I wrote about the systems account as the digital morality of an online school.
Since then, I have been thinking about Prevent.
Not because the two belong in separate folders marked “IT” and “safeguarding”, but because in an online school they are increasingly the same conversation.
Every permission is a relationship. Every OAuth token is a disclosure. Every AI tool allowed into a school tenant is not just a productivity decision. It is a trust decision.
And in the age of agentic AI, schools need to think much more carefully about what — and who — is being allowed to build trust with children.
Prevent is no longer only a content question
Prevent exists to stop people from becoming terrorists or supporting terrorism. Its current statutory framing is rightly focused on ideology, susceptibility to radicalisation, early intervention, and support. The duty under the Counter-Terrorism and Security Act 2015 requires specified authorities to have due regard to the need to prevent people being drawn into terrorism.
That legal frame matters. We should not dilute it.
But the route by which a young person may be drawn into harmful ideology is changing.
For years, schools have been trained to look for familiar radicalisation indicators: isolation, secrecy, scripted speech, sudden ideological rigidity, extremist symbols, changes in peer group, changes in online behaviour.
Those indicators still matter.
But in 2026, the risk environment has shifted.
A young person does not necessarily have to find an extremist forum, meet a recruiter, or join a closed messaging channel to begin moving into a distorted worldview.
They may begin with loneliness.
Or humiliation.
Or grief.
Or a sense of injustice.
Or spiritual searching.
Or misogynistic content presented as humour.
Or conspiracy theories presented as independent thinking.
Or an AI companion that never gets tired of listening.
Or a chatbot that appears to understand them better than any adult in their life.
The issue is no longer only harmful content.
It is synthetic trust.
Radicalisation, deception, coercion and trust
In the agentic era, I think schools need to update the way they talk about Prevent risk.
Radicalisation remains the movement towards legitimising, supporting, or participating in terrorism or terrorism-supporting ideology.
But the pathway into that movement may now involve several overlapping dynamics:
Deception The distortion of reality, evidence, authority, identity or intent. This includes deepfakes, synthetic audio, fabricated persecution narratives, fake peer identities, AI-generated “proof”, impersonation, and authoritative-sounding outputs that are not accountable to anyone.
Coercion The narrowing of a young person’s perceived choices through fear, shame, secrecy, dependency, blackmail, ideological obligation or emotional pressure. This is where Prevent begins to overlap with child sexual exploitation, criminal exploitation, grooming, coercive control and serious youth violence.
Trust capture The gradual transfer of emotional reliance, epistemic authority or decision-making influence from safe human relationships to an unsafe actor, group, platform, chatbot, companion app, bot network, or agentic system.
That last one feels particularly important.
Trust capture is not always dramatic. It may not look like grooming at first. It may look like support. It may look like advice. It may look like friendship. It may look like a young person finally feeling understood.
That is precisely why it matters.
Why agentic AI changes the risk picture
Traditional Prevent risk is usually mediated through human actors, peer groups, family systems, community networks, media ecosystems, online communities, or ideological content.
AI compresses several of those stages.
A generative chatbot can provide persuasive ideological framing in a tone calibrated to a young person’s age, reading level, interests and emotional state.
An AI companion can create the experience of always-available intimacy without safeguarding infrastructure.
Synthetic media can fabricate evidence, impersonate authority figures, or intensify grievance.
Agentic systems can, in principle, research, generate, distribute and coordinate content across multiple tools or accounts.
None of this means AI is inherently radicalising.
It means that systems capable of sustained, personalised, relational interaction must now be assessed as part of the safeguarding and Prevent risk environment.
This is especially important for children and young people who are already isolated, excluded, traumatised, attendance-fragile, neurodivergent, care-experienced, or spending large amounts of unstructured time online.
Those factors do not predict radicalisation. They must never be treated as suspicion in themselves.
But they can increase the salience of identity-seeking, belonging-seeking and meaning-seeking behaviours — the very pathways that manipulative actors, and increasingly manipulative systems, can exploit.
The safeguarding question has changed
The old question was:
What content might a child encounter?
That question still matters.
KCSIE 2025 widened the online safety frame to include misinformation, disinformation and conspiracy theories as content risks, which is significant for schools and safeguarding teams.
Ofcom’s 2025 children’s safety codes under the Online Safety Act also make clear that services used by children — including social media, search and gaming platforms — have duties to assess and reduce risks to children online.
But the new safeguarding question is wider:
Who or what is building trust with this child?
And then:
How is that trust being used?
Is the child’s agency expanding or narrowing?
Are they becoming more connected to safe human relationships, or less?
Are they becoming more able to question, reflect and pause — or more rigid, secretive and dependent?
Is the system helping them think, or quietly teaching them what to think?
This is where Prevent, online safety, AI governance and digital architecture meet.
Why the systems account matters
This is why yesterday’s systems account argument is not just an IT governance point.
It is where third-party OAuth access is blocked or permitted.
It is where AI tools are allowed into the tenant or kept out.
It is where browser extensions, Workspace apps, drive permissions, admin roles, group inboxes, non-human accounts and audit logs are configured.
It is where “we trust this tool” becomes technically real.
In the Prevent risk assessment I am currently updating, we have named emerging AI radicalisation risk explicitly. The draft already treats generative AI chatbots, autonomous systems, deepfakes, synthetic media, AI-mediated grooming and ideological reinforcement as current operational risks — not speculative future concerns. It also links those risks to technical controls such as blocking unapproved AI authentication, separating human and non-human accounts, using role-based access, preserving audit trails and applying our Diamond Standard AI governance framework.
That may sound dry.
It is not dry.
It is the architecture of duty of care.
Every permission is a relationship
When a school allows an app to read Drive, that is not just a technical permission. It is a relationship between the app and the school’s information environment.
When a browser extension can summarise email, that is not just a convenience. It is a relationship with staff communication, potentially including sensitive information.
When an AI tool can access learner work, that is not just workflow optimisation. It is a relationship with a child’s data, expression, vulnerability and learning profile.
When an AI companion is marketed as a mentor, coach or friend, that is not just edtech. It is a relational claim. And relational claims need safeguarding scrutiny.
Schools already understand this when the relationship is human. We ask who is working with the child, what checks they have had, what training they have completed, what records are kept, who supervises them, what boundaries apply, and how concerns are escalated.
We now need to ask equivalent questions of systems.
What schools should now be asking
Every online school, hybrid provision, alternative provision, trust and local authority commissioning online education should be asking:
Are third-party OAuth apps blocked by default?
Is there an allowlist process for any tool that touches school data?
Are AI tools assessed through safeguarding, data protection and Prevent lenses before use?
Are AI companion, mentor or coaching tools treated as high-risk by default?
Do staff know they must never enter identifiable child data into personal or public AI tools?
Are deepfake, synthetic intimate image and impersonation scenarios included in safeguarding training?
Do Prevent risk assessments include AI-mediated grooming, conspiracy reinforcement and synthetic media?
Are non-human accounts separated from human accounts and scoped tightly?
Are logs retained long enough to reconstruct what happened after an incident?
Can a parent, child or practitioner understand when AI is being used, what it is doing, and how to refuse it?
If the answer to those questions is unclear, the risk is not theoretical.
It is already in the architecture.
A necessary caution
There is an important caution here.
We must not start treating neurodivergence, trauma, social isolation, political anger, unusual interests, spiritual searching, fascination with conflict, or adolescent identity formation as indicators of radicalisation in themselves.
That would be both ethically wrong and operationally dangerous.
The Home Affairs Committee recently warned against allowing vulnerability, neurodiversity, mental health or violence fascination to become a catch-all Prevent concern, rather than reserving Prevent for genuine risk of radicalisation towards terrorism or terrorism-supporting belief.
That distinction matters.
The answer is not surveillance of vulnerable children.
The answer is better relational judgement, better digital literacy, better staff training, better architecture, and better routes for early support.
The point is not fear. It is responsibility.
I am not interested in moral panic about AI.
I am interested in governance that has caught up with reality.
Children are already living in environments where human, algorithmic and synthetic influence overlap.
Some of those systems will help them. Some will entertain them. Some will manipulate them. Some will sell to them. Some will flatter them. Some will radicalise indirectly by narrowing the world until only grievance makes sense.
Schools cannot control all of that. But we can control what we authorise.
We can control what enters our tenants.
We can control what touches school data.
We can control whether AI tools are assessed before use or after something goes wrong.
We can control whether staff are trained to recognise synthetic trust capture.
We can control whether our Prevent risk assessments still belong to the pre-agentic internet, or whether they are honest about the world children now inhabit.
The next Prevent risk assessment cannot simply ask what content children might encounter.
It has to ask what systems are building trust with them.
Because every permission is a relationship.
And in safeguarding, relationships are never neutral.
These are the conversations we're having at The Novus Learning Network fortnightly on Fridays at 2pm UK time and I'd love to continue this one with you there or in the comments below.
First published in Building Schools in the Cloud on LinkedIn, 24 April 2026.