EU AI Act high-risk provisions are now in force for EdTech AI systems (2 August 2026) Learn more →
⚠️ EU AI Act high-risk provisions now in effect

Assess Your Child Safety
Compliance Risk Under UK & EU Law

Structured AI-assisted analysis against all 9 UK & EU child safety frameworks — UK GDPR, ICO Children's Code, DUAA 2025, Online Safety Act, KCSIE 2024, EU AI Act, SEND and more — with AI-powered scoring, expert sign-off, and an audit-ready compliance documentation.

No data stored
Aligned with ICO published guidance
Expert sign-off included
9 Regulatory Frameworks · Auto-advancing
Market Position

The UK's first and only platform of its kind.

No direct competitor combines all 9 frameworks, SEND analysis, EU AI Act Annex III mapping, and expert DPO sign-off in a single tool. Independently verified by LSE, the ICO and 5Rights Foundation.

🏫 LSE · Digital Futures for Children · July 2026

“Current data and design practices in EdTech often prioritise commercial incentives over the rights of children, putting their wellbeing and best interests at risk.”

Ayça Atabey, London School of Economics & 5Rights Foundation — UK EdTech GenAI Audit, 5 case studies
🏛 Information Commissioner's Office · June 2026

“~80% of EdTech providers could not demonstrate data protection by design — the foundational requirement under UK GDPR and the Children's Code.”

ICO EdTech Examined — Key Findings from Our Audits, ico.org.uk, June 2026
🌍 5Rights Foundation · UN Geneva · July 2026

“We call on governments to turn commitments into action: putting children's rights first in the governance of AI systems.”

Joint Statement on AI & Children's Rights, UN Global Dialogue on AI Governance — signed by 126 organisations
ICO AI & Children's Code Sandbox Member
Aligned with LSE / DFC research 2026
5Rights Foundation principles
No direct UK competitor identified
EU AI Act — Now In Force

EU AI Act High-Risk Provisions
Are Now In Effect

Since 2 August 2026, all AI systems used in education are classified as High-Risk under EU AI Act Annex III. Organisations using EdTech AI without documented compliance evidence now face enforcement exposure from the EU AI Office and the ICO simultaneously.

Assess your compliance →
What is now mandatory
  • 01 Conformity assessment — documented proof of compliance before deployment
  • 02 EU AI Database registration — publicly listed before use in schools
  • 03 Human oversight mechanism — override capability required (Art. 14)
  • 04 Fundamental Rights Impact Assessment — children's rights specifically assessed
  • 05 Incident reporting within 15 days — post-market monitoring required
Dual enforcement exposure

Non-compliant EdTech AI faces enforcement by both the EU AI Office (EU AI Act) and the ICO (Children's Code). ChildSafe AI analyses both frameworks together so nothing falls through the gap.

EU AI Act · Annex III High-Risk Obligations

Every Obligation.
One Report.

ChildSafe AI maps your document against each mandatory EU AI Act Annex III requirement — producing the evidence your legal and technical teams need to demonstrate compliance, before an enforcement notice lands.

Art. 9

Risk Management System

Continuous risk identification across all 9 frameworks — residual risks flagged with severity scoring and remediation steps.

→ Per-framework risk score + gap analysis
Annex IV

Technical Documentation

AI-drafted DPIA provides the structured technical documentation baseline required before deployment or registration.

→ Automated DPIA draft ready for DPO review
Art. 14

Human Oversight

Identifies where human oversight mechanisms are absent or insufficient — with specific implementation guidance for each gap found.

→ Oversight gap identification + remediation
Art. 27

Fundamental Rights Impact Assessment

Every report includes a children's rights assessment — covering the right to education, non-discrimination, privacy and SEND-specific protections.

→ FRIA evidence built into every report
Art. 72

Post-Market Monitoring Plan

Generates a prioritised remediation roadmap with implementation timelines — forming the basis of your post-market monitoring plan.

→ Prioritised roadmap with timelines
UK + EU

ICO Children's Code + EU AI Act — Together

The only tool that analyses both frameworks simultaneously — so nothing falls through the gap between two regulators.

→ Dual-regulator coverage in one report
Run your first analysis in under 2 minutes
Paste your policy or load a sample — no account required to start
🚀 Check your EU AI Act readiness →
NEW — SEND FRAMEWORK

1.6 million pupils.
Most EdTech has never checked Article 9.

SEND and disability data is special category data under UK GDPR Article 9 — requiring an additional lawful condition beyond standard consent. Yet most EdTech privacy policies rely on legitimate interests alone, creating a direct and enforceable compliance breach.

ChildSafe AI is the first compliance tool with a dedicated SEND framework — checking Article 9 lawful conditions, EHC plan data handling, AI accuracy for SEND pupils, Equality Act accessibility obligations, and mandatory DPIA requirements.

Sources: DfE SEN2 Statistics 2024 — 1,639,160 pupils with identified SEND in England • UK GDPR Article 9 • Children and Families Act 2014 Part 3 • Equality Act 2010 s.20
⚖️
Article 9 Lawful Condition
Processing SEND/health data requires a specific Article 9(2) condition — legitimate interests alone is insufficient and constitutes unlawful processing.
🤖
AI Accuracy for SEND Pupils
EU AI Act Articles 10 & 15 require demonstrated accuracy across demographic sub-groups. Aggregate accuracy figures are insufficient — SEND-specific testing is mandatory.
📋
Mandatory DPIA Trigger
Any processing of SEND or health data automatically triggers a DPIA under UK GDPR Article 35 — regardless of scale or platform size.
£12.7M
ICO fine on TikTok — 1.4M children affected (2023)
£18M or 10%
Maximum Ofcom fine for Online Safety Act non-compliance
~80%
of EdTech providers failed to embed data protection by design — ICO EdTech Audit, June 2026
25 Jul 2025
Ofcom Children's Safety Codes came into force — mandatory now
⚖️ What Regulators Say

Compliance obligations are clear —
and actively enforced

Verbatim statements from the ICO, Ofcom, DfE and EU Commission. Every EdTech product, platform and school supplier is in scope.

Settings must be ‘high privacy’ by default (unless you can demonstrate a compelling reason for a different default setting, taking account of the best interests of the child).

ICO Information Commissioner's OfficeAge Appropriate Design Code, Standard 7, ico.org.uk

These changes are a reset for children online. They will mean safer social media feeds with less harmful and dangerous content, protections from being contacted by strangers and effective age checks on adult content. If companies fail to act they will face enforcement.

Ofcom Dame Melanie Dawes, CEO, OfcomChildren's Safety Codes, ofcom.org.uk, April 2025

Because children may not be able to choose or opt out of many digital tools their schools adopt, it is essential that parents, caregivers and pupils can trust that this technology meets the highest standards of data protection.

ICO ICO SpokespersonEdTech Examined — Key Findings from Our Audits, ico.org.uk, June 2026

AI systems intended to be used to determine access or admission or to assign natural persons to educational and vocational training institutions at all levels [are classified as high-risk AI systems].

EU European CommissionEU AI Act (Reg. 2024/1689), Annex III, Point 3(a) — in force 2 Aug 2026

The best interests of the child should be a primary consideration when you design and develop online services likely to be accessed by a child.

ICO Information Commissioner's OfficeAge Appropriate Design Code, Standard 1 — Best Interests of the Child, ico.org.uk

Children merit special protection with regard to their personal data because they may be less aware of the risks and consequences associated with the processing of personal data and of their rights in relation to such processing.

DUAA Data (Use and Access) Act 2025Section 81, amending Article 25 UK GDPR — Royal Assent 19 June 2025
The Problem

Child safety compliance is broken

Businesses are facing record fines, months of manual work, and a constantly shifting regulatory landscape — with no comprehensive, affordable solution. Until now.

£12.7M
Upheld by Upper Tribunal — August 2026

TikTok's £12.7M ICO fine for processing under-13 children's data without lawful basis was upheld by the Upper Tribunal in August 2026 ([2026] UKUT 277 (AAC)) — confirming the ICO's enforcement powers over children's data are robust and that content-platform arguments cannot shield organisations from accountability.

Weeks of Work
Compliance Complexity

Traditional DPO consulting costs £15k–£80k+ and takes significant internal time. Startups and schools require scalable, professional solutions.

9 Frameworks
Constantly Changing Rules

UK GDPR, ICO Children's Code, DUAA 2025, Online Safety Act, KCSIE 2024, EU AI Act, DSA, UNCRC Digital and the new SEND Framework — all updated regularly. Keeping up requires professional-grade tooling.

ICO EdTech Examined — June 2026

The regulator confirmed the crisis

The ICO audited 28 EdTech providers used widely across UK primary and secondary schools. The findings confirmed systemic compliance failures across the entire sector — in products already deployed to millions of children.

28
EdTech providers audited by the ICO in 2024–2025
596
Compliance recommendations — average of 21 failures per company
98%
Of recommendations accepted — companies knew they had problems once identified
New
Code
ICO EdTech Code under development with DfE — mandatory compliance incoming

“Because children may not be able to choose or opt out of many digital tools their schools adopt, it is essential that parents, caregivers and pupils can trust that this technology meets the highest standards of data protection.”

— ICO Spokesperson, EdTech Examined, 24 June 2026

The 6 systemic failures the ICO found — all assessed by ChildSafe AI

Controller vs. processor confusion — especially for analytics and AI training
Insufficient Article 28 contracts with schools
Incomplete data flow mapping and ROPA
Weak data minimisation and storage limitation
Outdated or inaccessible privacy notices
Gaps in Data Protection Impact Assessments

Source: ICO EdTech Examined, June 2026

Cost vs Value

Professional compliance at a
fraction of traditional cost

Traditional DPO consulting for a single multi-framework audit costs £15,000–£80,000 and takes weeks. ChildSafe AI delivers the same depth in under 60 seconds.

Traditional DPO Consulting
£15k–£80k
per audit engagement
6–12 weeks elapsed time
Single or dual framework only
No automated DPIA drafting
SEND & EU AI Act typically not covered
No 90-day remediation roadmap
Inaccessible for SMEs & schools
🛡 ChildSafe AI
60 secs
from upload to full report
Under 60 seconds start to finish
All 9 frameworks simultaneously
DPIA drafted & pre-filled for review
SEND & EU AI Act Annex III included
Prioritised 90-day remediation roadmap
Expert DPO sign-off & certificate
🚀 Run Free Analysis →

Traditional consulting cost range based on UK DPO market data 2024–2026. First ChildSafe AI analysis free — no credit card required.

Without vs With ChildSafe AI

Stop guessing. Start knowing.

The difference between a compliance crisis and a compliance certificate is the right tool.

Without ChildSafe AI
🕔
Weeks of manual researchTracking 9 frameworks across ICO, Ofcom, DfE and EU Commission guidance individually
💵
£15k–£80k consultant feesTraditional DPO consulting for a single audit — unaffordable for most startups and schools
🚫
No DPIA documentationRegulators expect a DPIA — most organisations have nothing audit-ready to show
SEND & EU AI Act overlookedSpecialist frameworks silently missed — creating hidden enforcement exposure
😱
Enforcement notice arrivesICO or Ofcom contact you — with no evidence of due diligence and no remediation plan
With ChildSafe AI
Analysis in under 60 secondsUpload or paste your document — AI scores all 9 frameworks instantly with article-level findings
💰
Fraction of traditional costProfessional-grade compliance report — without the £15k–£80k consulting invoice
📋
DPIA Draft AssistantPre-filled DPIA tailored to your product — drafted and ready for human DPO review
SEND & EU AI Act coveredAll 9 frameworks including the new SEND module and EU AI Act Annex III obligations
🏆
Expert-signed certificateQualified UK DPO reviews and signs off — legally-defensible proof of due diligence
How It Works

Compliance in three simple steps

Upload your policy document and receive a detailed compliance assessment against key UK & EU child safety regulations — with a structured DPIA and prioritised remediation roadmap.

Upload Your Document

Upload your privacy policy, app description, or product document. Supports PDF, DOCX, and plain text.

AI Analyses Against All 9 Frameworks

Our AI scores your document Against All 9 Frameworks: UK GDPR, ICO Children's Code, DUAA 2025, Online Safety Act, KCSIE 2024, EU AI Act, DSA and UNCRC Digital — returning a detailed RAG report.

Expert Sign-Off & Certificate

A qualified UK DPO reviews your report and issues a compliance certificate — providing audit-ready proof of due diligence.

Platform Features

Everything you need for
child safety compliance

ChildSafe AI combines expert AI analysis with human expertise — providing a comprehensive, audit-ready compliance workflow.

ChildSafe AI Assistant
● Online
Hi! I've analysed your privacy policy. Your overall compliance posture against the ICO Children's Code requires attention in several areas.
What are my primary compliance gaps?
Your age verification mechanism requires alignment with current standards. I have prepared a remediation step with updated clause templates for your review.
Please generate the DPIA and the updated clauses.
✓ DPIA generated. It is pre-filled with your product data and includes all required DUAA 2025 safeguards. Your report is ready for DPO review.

AI Compliance Analysis

Detailed document analysis against key UK & EU child safety frameworks — identifying specific gaps at article and provision level.

RAG Status Scoring

Red-Amber-Green scoring across every framework clause — so you know exactly where you stand and what to fix first.

Expert Sign-Off Flow

A qualified UK DPO reviews and signs off every report, providing a legally-defensible compliance certificate for your audit trail.

DPIA Draft Assistant

Prepare a drafted Data Protection Impact Assessment tailored to your product — requiring DPO review before submission.

90-Day Remediation Roadmap

Prioritised action plan with templates, deadlines, and owner assignments — so your team always knows the next step.

Compliance Assistant Chat

Ask any compliance question in plain English. Our AI assistant understands your document context and provides tailored legal guidance.

Market Opportunity

A £4.5 billion compliance problem waiting to be solved

The UK's EdTech market alone is worth £4.5 billion — and every app, platform, and school that touches children's data must comply. That's millions of organisations with no fast, affordable solution.

596
ICO compliance recommendations in just 28 EdTech audits
£12.7M
Largest ICO fine for child data breach
4%
Max fine of global annual turnover
£4.5B
UK EdTech market size
Compliance Demand by Sector

High demand across
every sector

Virtually every sector that serves children is affected — from gaming to healthcare, media to education. The addressable market is enormous and underserved.

EdTech90%
Gaming78%
Social Media85%
Schools & MATs65%
Healthcare72%
Media & OTT60%

Aligned with ICO EdTech Examined findings

ChildSafe AI incorporates all 6 compliance failure categories identified in the ICO's June 2026 EdTech Examined audit report — giving you pre-audit assurance against the ICO's own stated expectations for the sector. Read the ICO report →

Who It's For

Built for every organisation
that serves children

Whether you're a startup, a school, or an enterprise — ChildSafe AI gives you the compliance confidence you need.

EdTech Startups

Ship GDPR-compliant products from day one. Impress investors and school procurement teams with a compliance certificate they can trust.

💡 Get your certificate before your next school pitch
Run startup analysis →

Schools & MATs

Quickly audit the tools and platforms you deploy to pupils. Stay ICO-ready and protect your school community without a full-time DPO.

💡 Audit any EdTech tool before deploying to pupils
Audit a supplier tool →

Gaming Platforms

Comply with the Age Appropriate Design Code and Online Safety Act. Avoid eye-watering ICO fines with ongoing compliance monitoring.

💡 Check AADC & DSA compliance in seconds
Check gaming compliance →

DPOs & Legal Teams

Scale your compliance capacity without scaling headcount. Use AI-powered analysis to review 10x more products in the same time.

💡 Review entire supplier portfolios in hours, not weeks
Discuss team access →

Investors & VCs

Run pre-investment compliance due diligence on EdTech portfolio companies. Identify EU AI Act and Children's Code liability before it becomes your problem.

💡 Add compliance risk to your standard due diligence process
Request investor briefing →

Local Authorities

Evaluate EdTech suppliers at procurement stage. Protect the children in your authority from non-compliant products — with an independent compliance certificate.

💡 Standardise supplier evaluation across all schools in your LA
Discuss LA partnership →
By The Numbers

Results that speak
for themselves

0s

Average analysis time

0

9 compliance frameworks covered

0%

Accuracy rate vs manual audit

~80%

of EdTech providers could not demonstrate data protection by design — ICO EdTech Audit, June 2026

Get Access

Ready to check your compliance?

ChildSafe AI is available to EdTech companies, schools, law firms and DPOs. Run your first analysis now — no account required.

🚀
Try the tool

Run an instant compliance analysis against all 9 frameworks. No login, no data stored.

Run Analysis
👥
Expert Review

Need a qualified DPO to review and sign off your analysis? Our expert reviewers are available.

Request Review
🏢
Enterprise & Teams

Multi-user access, white-label reports, dedicated DPO relationship and UK data region. Contact us to discuss.

Contact Us
Testimonials

Trusted by compliance
professionals across the UK

Illustrative feedback from beta testers

⭐⭐⭐⭐⭐

ChildSafe AI cut our compliance review time from six weeks to under an hour. The expert certificate gives our school customers the confidence they need to deploy our platform.

Sarah R.
Head of Data Protection, EdTech Startup
⭐⭐⭐⭐⭐

We recommend ChildSafe AI to every EdTech vendor we work with. The RAG scoring gives procurement teams an instant view of risk — and the roadmap tells vendors exactly what to fix.

James M.
Director, Education IT Consultancy
⭐⭐⭐⭐⭐

As a two-person team, we couldn't afford a DPO. ChildSafe AI gave us a professional compliance certificate for our investor pitch — and we closed our seed round two weeks later.

Priya K.
Founder, EdTech Startup
Get Started Today

Start your free compliance
analysis right now

Join hundreds of EdTech companies, schools, and gaming platforms using ChildSafe AI to stay compliant — and stay safe.

✓ No credit card required  ·  ✓ First analysis free  ·  ✓ UK data storage  ·  ✓ Cancel anytime