What was announced

According to reports published in early September 2026, the programme targets all public employees. Training will be delivered by e-learning and made compulsory through institutions' HR systems. Its most striking feature is that it looks not only at whether the training was completed but at how well staff performed: learning outcomes will be monitored regularly, and those who succeed will receive level-based micro-credentials.

According to the announcement, the curriculum is organised around five core themes:

  • the basic concepts of artificial intelligence;
  • the safe use of generative AI tools;
  • personal-data protection;
  • awareness of misinformation and deepfake content;
  • principles of ethical use.

Alongside this general content, short practical modules tailored to staff members' duties and responsibilities will be offered. The aim, in other words, is for a tax inspector and a hospital administrator to build on the same foundation while learning different, job-specific practices.

Why this is a legal question

"AI literacy" sounds like a skills-development goal. Seen through a legal lens, however, an organisation training its staff on the risks of the technology they use is a direct part of its duty of care and its accountability. When a public official uploads an official document to a generative AI tool, relies on an AI output in assessing a citizen's application, or acts on a deepfake believing it to be genuine, the legal consequences of any resulting harm arise at both individual and institutional level.

Training therefore functions as a preventive measure in liability law. An institution that can document that it trained its staff on the risks and measured their competence has strong footing when institutional fault is assessed after a breach. Conversely, AI use rolled out without training makes debates about service fault — the administration's liability for failures in the running of a public service — all but inevitable.

The legal basis for making training mandatory

Turkish public-personnel law has long treated training as both a right and a duty. Civil Servants Law No. 657 devotes a dedicated part to training, charging institutions with preparing staff for their roles, keeping their knowledge current and raising their competence, and requiring employees to take part in the training programmes their institutions organise. Making AI literacy compulsory through HR systems therefore does not require a new statute; it applies an existing institutional duty to a new risk area.

The picture is more varied for employees outside the civil-service regime. Contracted staff, workers employed under the Labour Law and personnel of state-owned enterprises are subject to different rules, and their training obligations are mainly defined by their contracts, collective agreements and internal regulations. For the programme to reach "all public employees" in a legally consistent way, each institution will need to translate the obligation into the instruments that govern its own workforce.

Shadow AI: the gap between use and rules

The practical reason behind the programme is simple: in public administration, as in the private sector, the use of generative AI has run ahead of the rules. Staff draft letters, summarise reports, translate documents and prepare presentations with publicly available chatbots, often on personal accounts and without any institutional approval. This phenomenon, widely called "shadow AI," is not usually malicious; it stems from the desire to work faster. But every unapproved use is a blind spot for the institution: it cannot know which data left its systems, which outputs entered official files or which errors went unnoticed.

Banning such tools outright rarely works — use simply goes further underground. The more effective path is to make staff aware of the risks, offer approved alternatives and set clear rules. Literacy training is the first of those three steps, and its success will depend on whether the other two follow.

The European counterpart: Article 4 of the EU AI Act

The closest international counterpart to Turkey's move is Article 4 of the EU AI Act, headed "AI literacy." It requires providers and deployers of AI systems to take measures ensuring, to their best extent, a sufficient level of AI literacy among their staff and other persons operating the systems on their behalf. The obligation has applied since February 2025 and covers organisations using AI, public bodies included.

What stands out in the EU approach is that it defines literacy not as an abstract target but as an obligation that scales with context: staff members' technical knowledge, experience, education and training, and the context in which the system is used, must all be taken into account. The "role-based practical modules" and "level-based credentials" in Turkey's programme track that logic closely. Although Turkey is not an EU member, its dense economic and legal ties with the Union make that alignment valuable for future convergence.

Four legal risk areas for AI in the public sector

1. Personal-data protection

Public institutions are data controllers under Law No. 6698 on the Protection of Personal Data (KVKK). Entering citizens' information — let alone special categories of personal data — into generative AI tools raises serious problems under the data-security obligation, the purpose-limitation principle and, frequently, the rules on cross-border transfer. If a public chatbot's servers are abroad, every item of data entered may amount to a transfer outside Turkey. We examine the KVKK's approach to AI in training data: the KVKK and GDPR questions to settle first and in our guide to KVKK and AI governance. Our report on the Board's fine for AI-driven predictive profiling shows these risks are not abstract.

2. Confidentiality and state secrets

Public officials' duty to protect information learned in the course of their duties is reflected in both personnel legislation and criminal law. The Turkish Penal Code's offences of disclosing secrets relating to one's office and of unlawfully disclosing or obtaining personal data may come into play if official documents are uploaded to third-party AI services without control. Presidential Circular No. 2019/12 on information-security measures and the associated Information and Communication Security Guide are also important parts of this framework. The training's theme of "safe use of generative AI tools" targets exactly this "shadow AI" risk.

3. Administrative decision-making

Administrative acts must be lawful, reasoned and open to judicial review. An official who turns an AI output into a decision without questioning it creates risks under the duty to give reasons, the principle of equality and the prohibition of discrimination. Algorithmic bias in particular can systematically disadvantage certain groups. Ensuring that final decisions are made by humans and that outputs are critically evaluated should be one of the legally most important goals of literacy training. We covered judicial debate on the relationship between administrative law and algorithmic error in our report on the intersection of administrative law and AI.

4. Misinformation and deepfakes

Public institutions are prime targets for fraud and manipulation using fake voices and images. A transaction executed on a fake instruction imitating a senior manager's voice can cause both financial loss and severe legal consequences. That the training treats deepfake awareness as a stand-alone theme shows how concrete the risk has become for institutional security. We discussed legal tools for detecting synthetic content in our analysis of mandatory AI watermarking.

The legal significance of micro-credentials

The programme's level-based micro-credentials are more than a motivational device. They may acquire legal significance in several ways:

  • Proof of competence. It becomes possible to restrict the use of certain AI tools to staff holding the relevant level of credential — an authorisation model consistent with the EU's context-scaled approach to literacy.
  • Assessing liability. After a breach, whether the official had received the required training and at what level they were competent becomes a fact that can be weighed in both disciplinary proceedings and service-fault assessments.
  • The personal-data dimension. Performance measurements and credential records are themselves employees' personal data. Transparency is needed about why they are kept, for how long, and how they are used in career decisions.

The announcements give no detail on how credentials will affect appointment, promotion or assignment. Resolving that uncertainty in implementing rules matters for legal certainty and for staff buy-in.

What a strong curriculum should add

The five announced themes form a sound foundation. From a legal-risk perspective, several topics deserve explicit treatment within them:

  • Verification and "hallucinations." Generative models can produce fluent but false statements, including invented legal citations. Courts in several countries have sanctioned lawyers who filed briefs citing non-existent cases generated by AI — the 2023 Mata v. Avianca decision in New York is the best-known example. For public officials who cite legislation and case law in administrative acts, a verification habit is not optional.
  • Confidentiality of prompts. Staff should understand that what they type into a prompt can be stored, reviewed or used for training by the provider, depending on the service's terms.
  • Records and archives. AI-assisted drafts that become part of official files are subject to public-records and archiving rules. Institutions should decide which versions are kept and how AI involvement is documented.
  • Freedom of information. Under Law No. 4982 on the Right to Information, citizens may request information and documents held by public bodies. Institutions should expect questions about whether and how AI was used in decisions affecting the public.
  • Copyright and licences. The ownership of AI outputs and the licence terms of the tools used are unsettled questions; we discuss them in who owns the copyright of AI-generated images.
  • Bias and accessibility. Model performance may vary across languages, dialects and groups. Staff serving diverse citizens should know how to spot and correct uneven outputs.

Who else is in scope? Local government, state-owned enterprises and contractors

The reports describe the programme as covering all public employees, but public administration in Turkey is a broad ecosystem. Municipalities and their companies, universities, independent regulatory authorities and state-owned enterprises all use AI in their own ways, and some enjoy administrative or financial autonomy. Whether the programme will be applied uniformly across these bodies, or adopted by each through its own decisions, will shape its real reach.

Contractors are a further blind spot. Software vendors, call-centre operators and consultancy firms working for public bodies often handle the same data and systems as civil servants. A literacy programme that stops at the institution's payroll leaves a gap at the edges of the data flow. Procurement contracts can close it by requiring equivalent training and AI-use rules from suppliers.

Measuring success beyond completion rates

The programme's emphasis on performance rather than attendance is promising, but meaningful measurement will require indicators that reach beyond test scores. Useful signals include the share of AI use taking place on approved tools, the number of incidents reported internally and how quickly they are handled, the rate at which AI-assisted drafts are corrected during human review, and the outcome of periodic audits of data entered into external services. Publishing aggregated results would also strengthen public trust in the state's use of AI.

The link to the Action Plan

The programme was designed in line with the human-capital and public-capacity goals of the 2026–2030 Turkey AI Action Plan. We reviewed the Plan's legal framework in our study of Presidential Circular No. 2026/9 and its strategic direction in our analysis "The State's Smart Route." Training public staff can be read as one of the Plan's first concrete implementation steps: the spread of AI in government has to advance together with the competence of the people using it.

International examples

  • European Union: Article 4, discussed above, made literacy a binding obligation for all organisations using AI, without distinguishing public from private.
  • United Kingdom: the government published an AI Playbook bringing together principles for civil servants to use AI safely and effectively.
  • United States: Office of Management and Budget directions on federal agencies' use of AI call for AI governance within agencies and for building staff capacity.

The common thread is that training alone is not considered enough: literacy is treated as part of a governance system alongside approved-tool lists, data classification, use policies and incident-reporting mechanisms.

What institutions should do

The training programme is an important start, but institutions need internal rules to complement it:

  • A corporate AI use policy. A written policy defining which tools may be used for which purposes, what kinds of data must never be entered, and what happens in a breach. Our guide to a corporate AI use policy offers a framework that can be used directly.
  • An approved-tool list. Identifying tools that have passed a data-security assessment — ideally domestic or hosted in-house.
  • Data classification. Making it easy for staff to see which information is confidential, which is personal and which is public.
  • Human sign-off and logging. Requiring authorised staff to review AI-assisted drafts before they become final, and recording that process.
  • Incident reporting. An internal channel for rapidly reporting erroneous outputs, data leaks or deepfake attempts.

The citizen's perspective

Discussions of AI literacy usually focus on staff, but the ultimate beneficiaries are citizens. A person whose application is assessed with AI support has a legitimate interest in knowing that AI was involved, in receiving a decision whose reasons are understandable, and in being able to challenge it before a human. Those expectations already follow from general principles of administrative law — the duty to give reasons, the right to be heard and the right to judicial review — and from the KVKK's rules on decisions based solely on automated processing. Citizens who believe the administration has acted unfairly can also turn to the Ombudsman Institution (Kamu Denetçiliği Kurumu) in addition to the courts. Well-trained officials are the best guarantee that these rights work in practice: an official who understands how a model reaches its output is far better placed to explain a decision, spot an error and correct it before it harms anyone.

What to watch next

Three questions will determine the programme's impact. First, the implementation timetable and deadlines for completing training. Second, how micro-credentials will be tied to career and authorisation processes. Third, how far training will be backed at institutional level by use policies, approved-tool lists and data-security measures. A public administration that is trained but lacks rules reduces its risks only in part.

Frequently asked questions

Which public employees are covered?

According to the announcement, the programme targets all public employees, and training will be made mandatory through institutions' HR systems.

How will the training be delivered?

By e-learning. Alongside the core modules there will be short practical modules tailored to duties and responsibilities.

Is attendance enough?

No. According to the announcement, not just completion but performance will be monitored, and those who succeed will receive level-based micro-credentials.

Does completing the training shield an official from liability for an AI-related error?

No. Training is an important element in discharging the duty of care, but fault and liability are assessed separately in each case. If anything, the standard of care expected of trained staff is higher.

Can public officials use general tools such as ChatGPT?

That depends on the institution's use policy. Entering personal data, confidential information or the content of official correspondence into general-purpose tools hosted abroad carries serious risks under the KVKK and information-security rules.

How does this compare with the EU's AI literacy obligation?

The EU's Article 4 is a legal obligation on all providers and deployers; Turkey's programme is a public-sector training initiative. But both share a context-scaled logic in which literacy depends on role, experience and how the system is used.

Are training and credential records personal data?

Yes. Performance scores and credential levels relate to identifiable employees and are subject to the KVKK. Institutions should inform staff about how these records are used, who can access them and how long they are kept.

Do municipalities and state-owned enterprises have to take part?

The announcement refers to all public employees, but how the programme will apply to bodies with administrative or financial autonomy will depend on the implementing rules and on each body's own decisions.

Expert Opinion

This section reflects my personal assessment as the founder of this site and an AI ethics & compliance counsel.

In my view, mandatory AI literacy training for public staff is a well-timed and well-designed step. Well-timed, because generative AI tools entered public employees' daily work long before any formal policy did; unless that "shadow use" is managed, data leaks and flawed administrative acts are inevitable. Well-designed, because the programme measures performance rather than attendance and adopts a context-sensitive approach through role-based modules.

As a lawyer, however, I must stress one point: literacy is the start of a governance system, not the system itself. For trained staff to act correctly, they need written rules on which tools they may use with which data, approved-tool lists, human sign-off mechanisms and an incident-reporting channel. Otherwise training risks becoming a device that shifts responsibility from the institution to the individual: "you had the training, so the mistake is yours" must not be allowed to cover systemic gaps.

My advice to public institutions is to treat the programme as an occasion to draft corporate AI use policies. The alignment with Article 4 of the EU AI Act may also give Turkey a real advantage in future convergence. In government, AI's legitimacy will rest less on the power of the technology than on the competence of the people using it and on that use's fidelity to the law.

This article is for information only and does not constitute legal advice. Facts about the programme are based on press reports of 2 September 2026 (Memurlar.net); implementation details will be settled by official rules. The analysis and assessments are the author's own.