What happened
On 1 October 2026 the Official Gazette (No. 33387) published two presidential decisions under the heading "Atama Kararları" (appointment decisions), both dated 30 September, that between them staff the top of Türkiye's Cybersecurity Presidency (Siber Güvenlik Başkanlığı). Decision 2026/321 filled the Presidency's two deputy-head posts, its Directorates-General for Management Services, Digital State, Cyber Defence and Ecosystem Development, and the post of First Legal Counsel.
Decision 2026/322 is narrower, and for anyone following AI law it matters more. It assigns Osman Gazi Güçlütürk, described in the decision as a Dr. Öğretim Üyesi (faculty member) at Galatasaray University, to the vacant Kamu Yapay Zekâ Genel Müdürlüğü, the Directorate-General for Public AI. The decision cites Article 38 of Higher Education Law No. 2547 and Articles 2 and 3 of Presidential Decree No. 3. Article 38 is the provision that allows university teaching staff to be assigned to posts in other public bodies, which is why Decision 2026/322 uses the verb görevlendirilmiştir (has been assigned), whereas Decision 2026/321 uses atanmıştır (has been appointed). In other words, the post is filled by assignment from a university position rather than by an ordinary civil-service appointment.
Six days later, on 7 October, the Minister of Industry and Technology, Mehmet Fatih Kacır, spoke at a symposium at Bahçeşehir University entitled "Kurumlarda Yapay Zeka: Güvenlik, Etik, Entegrasyon ve Ekonomik Değer" (AI in organisations: security, ethics, integration and economic value). According to press reports, he set out the governance side of the 2026–2030 AI Action Plan: a National AI Ethics Board, assessment of likely impacts before AI systems are deployed in health, education and employment, and regulatory sandboxes in priority sectors. We could not find a ministry press release for the speech. The account below relies on reports carried by Memurlar.net, credited to İhlas News Agency, and by Kamudanhaber.
Read together, the two events show Türkiye's AI governance at an awkward midpoint: one institution exists in law and now has a head; the others have been announced, but no legal instrument has yet created them.
How the Directorate came to exist
The Directorate is the end point of a chain of presidential decrees.
- 8 January 2025. Presidential Decree No. 177 (Official Gazette No. 32776) created the Cybersecurity Presidency as a body attached to the Presidency of the Republic, with public legal personality and its own budget. Its original remit was cybersecurity only. Its three directorates-general were Cyber Defence, Cyber Resilience and Ecosystem Development.
- 19 March 2025. Cybersecurity Law No. 7545 (Official Gazette No. 32846) gave the Presidency its statutory duties. Article 5 of the Law covers the protection of critical infrastructure, standards, testing and certification, audit and sanctions.
- 28 March 2025. Presidential Decree No. 183 (Official Gazette No. 32855) closed the Presidency's Digital Transformation Office, which had until then led the government's digital-transformation and public-sector AI agenda. Article 23 of the same decree added a new duty to the Cybersecurity Presidency: "to lead the digital transformation of the public sector and AI applications in the public sector" and to mediate the delivery of e-Devlet services. That is the moment the public-sector AI remit moved.
- 25 December 2025. Presidential Decree No. 192 (Official Gazette No. 33118) rewrote the Presidency's duties and created the Public AI Directorate-General, alongside a Digital State Directorate-General, a Management Services Directorate-General and a Strategy Development Department. It also provided for three deputy heads and allowed the Presidency to establish companies in Türkiye or abroad by presidential decision. The staffing table grew from 135 posts in Decree No. 177 to 204, and the number of director-general posts from three to six.
Both stages were challenged before the Constitutional Court by opposition members of parliament, and both challenges failed. In E.2025/47, K.2025/119 (3 June 2025, published in Official Gazette No. 33046 on 13 October 2025) the Court rejected the annulment request against Article 7(2) and the staffing provisions of Decree No. 177. In E.2026/18, K.2026/26 (12 February 2026, published in Official Gazette No. 33260 on 21 May 2026) it rejected the request against the staffing table as reorganised by Decree No. 192. In the second, the majority held that reorganising the posts of a public legal person concerns its organisational structure and falls within the executive's decree-making competence. Parts of both rulings were adopted by majority, with four members dissenting, but the structure has survived constitutional review.
What the mandate actually says
The AI duties that Decree No. 192 added to Article 4 of Decree No. 177 are worth reading in full, because they determine what this body can do to anyone outside government:
- (l) carrying out legislative work on AI applications in the public sector, contributing to national AI policy, strategy and action plans and to the alignment of national legislation with international regulation, and taking part in ecosystem development;
- (m) setting principles, procedures and standards for data governance, covering the life of data "from creation to destruction", in the context of the digital state and public-sector use of AI;
- (n) leading public-sector AI applications: identifying requirements together with the institutions concerned, building a shared data space, setting quality criteria and standards for the data to be used, and "granting conformity" to them.
Two other new duties sit close by. Under (i), the Presidency sets the principles, procedures and standards for the administrative, financial and technical features of the IT products, services and systems that public institutions procure or develop. Under (j), it sets project-management standards for public IT projects and gives the Presidency of Strategy and Budget an opinion on their financial and technical aspects.
Three points follow. First, these duties belong to the Presidency, not to the Directorate. Article 7(2) of Decree No. 177 leaves the duties of each service unit to a regulation that the Presidency issues itself. We have not located a published regulation dividing the work between the Public AI Directorate and the Digital State Directorate, whose remits overlap on data governance and e-Devlet. Until one appears, the Directorate's exact boundaries are an internal matter.
Second, the powers point inwards. They bind public institutions and shape how the state buys and uses AI. Nothing in Decree No. 192 places a direct obligation on a private company.
Third, the inward-facing powers are nonetheless where the commercial impact will come from. The power to set standards for IT systems that public bodies procure, together with the power to set data-quality standards for public AI applications and grant conformity to them, gives the Presidency a gatekeeping role over the public AI market without any new statute.
What the minister announced on 7 October
According to the press reports, Mr Kacır described the Action Plan as built on four axes, "Fark Et, İstifade Et, Üret ve Yönet" (Notice, Benefit, Produce, Govern), with 16 actions. The governance elements were these:
- A National AI Ethics Board ("Ulusal Yapay Zeka Etik Kurulu"). It is meant to guide developers and institutions on protecting privacy, preventing discrimination and child safety, and to turn shared principles into practical guides.
- Pre-deployment impact assessment. His words were "Kamu olarak", meaning "as the public sector": in areas such as health, education and employment that directly affect citizens' lives, "we will base ourselves on assessing the likely impacts of systems before they are put into use." Human oversight and technical security testing are to form part of that process.
- Regulatory sandboxes ("düzenleyici deney alanları") in priority sectors, where entrepreneurs can test innovations "under safe and predictable conditions". Reports mention health, energy and smart manufacturing among the priority areas.
- A National Data Library opening at least 2,000 public datasets.
He also said: "Hiçbir algoritma, insanın ahlaki ve hukuki sorumluluğunu ortadan kaldıramaz" (no algorithm can remove a human being's moral and legal responsibility). Other targets included 10,000 advanced AI specialists and 100,000 practitioners by 2030 and at least 1 GW of data-centre capacity.
The wording on impact assessment matters. "Kamu olarak" is a commitment about the state's own use of AI, not a duty on private developers, and the body that will run that use is the Cybersecurity Presidency and its Public AI Directorate.
Earlier reporting on the plan fills in the architecture. An Anadolu Agency report of 27 August, carried by İstanbul Ticaret Gazetesi, describes a National AI Board chaired by the President to approve priorities and annual implementation plans; a Programme Office running a progress and transparency portal, with the Public AI Directorate among its members; and the Ethics Board, drawn from the public sector, industry, academia and civil society, which is to provide ethical guidance and publish practical guides. According to the report, the Ethics Board will not hold binding powers: "binding oversight and sanctioning powers will be exercised by the relevant sectoral regulators". Its establishment is targeted within one year.
What exists in law, and what is still a plan
In force now:
- the Cybersecurity Presidency and its Public AI Directorate-General, under Decree No. 177 as amended by Decrees No. 183 and No. 192, and Cybersecurity Law No. 7545;
- Presidential Circular 2026/9 (Official Gazette No. 33344, 18 August 2026) on the 2026–2030 AI Action Plan, which instructs public institutions to carry out the duties the Plan assigns them;
- Presidential Circular 2026/11 (Official Gazette No. 33375, 19 September 2026) on the 2030 National Smart Cities Strategy and Action Plan;
- the existing horizontal law that already governs AI use, above all the Personal Data Protection Law No. 6698.
Announced but not yet created:
- the National AI Ethics Board, for which we have found no establishing instrument;
- the National AI Board and the Programme Office, which are described in the plan and in reporting but have not, as far as we can find, been set up by decree or decision;
- pre-deployment impact assessment, for which there is as yet no published methodology, scope or legal instrument;
- regulatory sandboxes, for which no AI-specific legal basis has been published;
- a framework AI law. According to press reports of the 2027–2029 Medium-Term Programme, national AI legislation work is to be conducted "with EU alignment in mind". That is a policy commitment, not a bill.
Two legal points sit behind that list. A circular (genelge) is an internal instruction to the administration: it can direct ministries and agencies, but it cannot by itself impose duties on private parties or create a body with powers over them. And a programme document cannot suspend a statutory obligation, so an AI sandbox testing personal-data uses will still operate inside Law No. 6698 unless a statute provides otherwise. Until the instruments exist, these are commitments of policy, not rules anyone can be held to.
We covered the Action Plan's publication on 18 August. Circular 2026/9 puts into effect a plan coordinated by the Ministry of Industry and Technology; the Cybersecurity Presidency is the body with standing legal powers over public-sector AI.
On 23 September we noted that municipalities were being told to deploy AI. Circular 2026/11, coordinated by the Ministry of Environment, Urbanisation and Climate Change, lists "AI-supported decision-making mechanisms" among its priorities. Add the AI literacy programme for public servants we reported on 2 September, and the pattern is clear. Türkiye's first regulated AI user is the state itself, and the rules are being written from the inside out.
What this means for companies
For businesses that do not sell to the public sector, nothing changed this fortnight. For those that do, the direction is visible even if the detail is not.
Procurement will carry the rules. The Presidency's duty under Article 4(1)(i) of Decree No. 177 to set standards for the IT products, services and systems that public bodies procure is the most likely route by which AI requirements reach vendors. Expect them to appear as technical specifications, qualification criteria and contract clauses, not as a regulation addressed to the market.
Data will be the first battleground. The duties under (m) and (n) concern data governance across the life of data, shared data spaces and data-quality standards, with a power to grant conformity. Vendors whose systems train or run on public data should expect questions about provenance, quality, retention and deletion beyond ordinary procurement checks.
Impact assessment will flow down. If public bodies are to assess AI systems before deploying them in health, education and employment, they cannot do so without information from the supplier: what the system does, how it was tested, how bias was measured, where human oversight sits, what is logged. Contracts will allocate that burden.
Security is already law. Under Article 5(1)(ı) of Law No. 7545 the Presidency sets technical criteria for the cybersecurity products and services used in public institutions and critical infrastructure, and for the businesses that supply them. Article 4(1)(d) states a preference for domestic products in cybersecurity work. An AI system is not automatically a cybersecurity product, but one authority now sits over both, and requirements are likely to converge.
KVKK does not step aside. None of this displaces Law No. 6698. Personal data processed by public-sector AI remains subject to it, including the Article 9 rules on transfers abroad where a foreign-hosted model is involved.
For private deployers, soft law is coming. If the Ethics Board publishes guides on fairness, explainability, data provenance and human oversight, they will bind no one. In practice, however, they will become the benchmark against which "appropriate" conduct is measured, in the same way that KVKK guidance shapes enforcement under Article 12 of Law No. 6698. Sectoral regulators keep the binding powers.
In practical terms, organisations that supply or plan to supply AI to public bodies should:
- document data provenance and data-quality controls for each system now, before a tender asks for them;
- prepare a standard technical dossier covering intended purpose, testing, bias evaluation, human-oversight design and logging;
- review security posture against the requirements the Presidency already applies under Law No. 7545;
- check personal-data flows, including any transfer abroad, against Law No. 6698.
How it compares: Korea and the EU
South Korea built its institutions by statute. The AI Basic Act (Law No. 20676, promulgated 21 January 2025, in force 22 January 2026) provides for a National AI Strategy Committee of up to 60 members, chaired by the President (Article 7, as amended on 20 January 2026), an AI Policy Center designated by the Ministry of Science and ICT (Article 11) and an AI Safety Institute operated by the Ministry (Article 12), and gives the Ministry powers to investigate (Article 40) and to impose fines of up to KRW 30 million (Article 43).
On impact assessment the Korean model is instructive. Article 35(1) makes assessing the impact of high-impact AI on fundamental rights only an effort duty for businesses. Article 35(2), however, requires state bodies that intend to use high-impact AI to give priority to products and services that have been assessed. Korea wrote into law the procurement lever that Türkiye holds only through the Presidency's standard-setting duties and a ministerial statement. And Türkiye's planned National AI Board resembles Korea's committee, except that Korea's exists by statute and Türkiye's, so far, in a plan.
The European Union is a less direct comparison, and should be drawn carefully. The European AI Office was created by a Commission Decision of 24 January 2024 inside the Commission. The AI Act anchors it in Article 64, gives it supervisory powers chiefly over general-purpose AI models (Articles 88 to 94) and sets up a European AI Board of Member State representatives in Article 65. The AI Office supervises market actors; Türkiye's Public AI Directorate does not. Its closer counterparts are government digital agencies. The EU does offer one useful parallel. Article 27 of the AI Act requires deployers that are bodies governed by public law, or private entities providing public services, to carry out a fundamental-rights impact assessment before using certain high-risk systems. That is the same idea as Mr Kacır's "Kamu olarak" commitment, but in the EU it is binding law. Article 57 of the Act requires each Member State to establish AI regulatory sandboxes, with a legal basis Türkiye has yet to provide.
What to watch next
- A Presidency regulation allocating duties to the Public AI Directorate, and any first standards under Articles 4(1)(i), (m) and (n) of Decree No. 177.
- The instrument that creates the National AI Ethics Board, and whether it is a presidential decree, a decision or a ministerial act. That choice will say a lot about its weight.
- Whether the pre-deployment assessment acquires a methodology, a list of covered systems and an owner, and whether it stays confined to the state's own use.
- The legal basis chosen for the sandboxes, and how they interact with KVKK.
- Any draft framework AI law following the Medium-Term Programme commitment.
Frequently asked questions
Does Türkiye now have an AI regulator?
Not in the sense of a body with powers over the market. The Cybersecurity Presidency, through its Public AI Directorate, has legal duties over AI used by the public sector. Binding powers over private AI use remain with existing regulators, such as KVKK, the Competition Authority and the sectoral authorities, under their own laws.
Has the National AI Ethics Board been established?
No. It has been announced, and the plan's description presents it as advisory, with a target of establishment within a year. We have found no instrument creating it.
Will private companies have to carry out AI impact assessments?
Not under anything currently in force. The commitment the minister described concerns AI used by the public sector in health, education and employment. Suppliers to that sector should still expect to provide the information such assessments require.
Why does a public-sector AI unit sit inside a cybersecurity agency?
Because of how the remit moved. When Decree No. 183 closed the Digital Transformation Office in March 2025, the duty to lead public-sector AI and to mediate e-Devlet services was given to the Cybersecurity Presidency. Decree No. 192 then turned the Presidency into both a cybersecurity authority and the state's digital-government body, and created the Public AI Directorate within it.
Burhan Doğuş Ayparlar's View
This section sets out my personal assessment as the founder of this site and an attorney at law (Türkiye).
I think the activation of this Directorate, created by decree last December and now staffed, is the most consequential institutional development in Turkish AI governance this year. It is easy to miss, because it arrived as a decree and an assignment decision rather than as a law.
The Turkish debate has long been framed around one question: when will there be an AI law, and will it look like the EU AI Act? That misses what is happening. The state is building rules for its own use of AI first, through decrees, circulars and standard-setting powers that need no parliamentary vote. The Presidency's power to set standards for the IT systems public bodies buy, and to grant conformity on data quality for public AI, is a real lever over a large market. For many companies it will matter more in the next two years than any draft bill.
That approach has advantages. The state should get its own house in order before it tells others how to behave, and an impact-assessment duty that starts with the public sector's use of AI in health, education and employment is aimed at exactly the decisions where people have least choice. The minister's line that no algorithm removes human moral and legal responsibility is also the right principle, and the one administrative courts will apply in any case.
My concerns are about form, not direction. An ethics board without an establishing instrument, an impact assessment without a methodology and sandboxes without a legal basis are intentions. If the Ethics Board is to be advisory, as the plan describes, its value will depend on whether its guides are published, reasoned and actually used by the sectoral regulators that hold the binding powers. I would also like to see the Public AI Directorate's standards published and consulted on, not issued as internal administrative regulations.
The Korean comparison is instructive here. Korea put the procurement preference for assessed high-impact AI into its statute. Türkiye could reach a similar result through the Presidency's existing standard-setting powers, without waiting for a framework law. If it does, and does so transparently, it will have built the most practical part of an AI governance regime before the legislative debate is even settled.
This article is for information only and does not constitute legal advice. It is based on the Official Gazette of 1 October 2026 (No. 33387), Presidential Decrees No. 177, 183 and 192, Cybersecurity Law No. 7545, Presidential Circulars 2026/9 and 2026/11, the Constitutional Court decisions cited (whose outcome we confirmed from the published decision texts as reproduced in legal databases), the Korean AI Basic Act as published on the National Law Information Center, and press reports of the Minister of Industry and Technology's remarks of 7 October 2026. We could not locate a ministry release for those remarks, and statements attributed to the minister rely on press reports. Information about the person assigned to the Directorate is limited to what the Official Gazette decision states. The description of the National AI Board, Programme Office and Ethics Board relies on Anadolu Agency reporting of 27 August 2026, and the Medium-Term Programme commitment on press reports; we have not reviewed the full Action Plan document or the Programme text. Statements about Turkish law are general in nature; specific cases require individual assessment. The analysis and assessments are the author's own.