Founder
September 14, 2026
32 min read
YAZEK is not a narrow administrative act in which a teacher simply completes an online form. The system is the visible gateway to an institutional compliance architecture that runs from the selection of an AI tool to the processing of student data, from assessment and evaluation to human oversight, from vendor contracts to appeal mechanisms. For educational institutions, the real question is no longer “Are we using artificial intelligence?” but “Which use case are we running, with which data, under whose responsibility, and with which safeguards?”
Imagine a teacher who turns to generative AI in order to give faster feedback on students’ essays. The teacher removes names, uploads the texts, and asks the model to flag weaknesses in expression and to propose a draft score. At first glance, this may look like a practical efficiency choice that remains within the teacher’s professional discretion.
Yet the same act brings at least seven distinct questions with it: Does the student text contain personal data? Is removing names genuinely enough for anonymisation? Will the texts be reused to improve the service provider’s model? Is the data being transferred abroad? Does the student know that AI was used in the assessment? If the teacher treats the model’s suggestion as the basis of the grade, who is responsible for assessment and evaluation? Which records will be kept so that the student can challenge the outcome? Add intellectual property, academic integrity, children’s digital wellbeing, cybersecurity and the vendor contract, and a single “prompt” touches the institution’s legal, IT, pedagogical design and governance layers in their entirety.
The Ethical Declaration System for Artificial Intelligence Applications (YAZEK), opened for use by the Ministry of National Education (MEB) on 2 February 2026, sits precisely at this intersection.[1] YAZEK’s most important effect is to convert AI use into a visible and traceable institutional activity. In that sense, the system is not merely a tool of ethical awareness; it is a compliance trigger that requires educational institutions to rethink their policies, procedures, roles, records and control sets.
The central thesis of this article is this: compliance with YAZEK cannot be achieved by completing a form in due form, standing alone. The form is meaningful only if an AI governance system is operating behind it. Otherwise there is a declaration, but no verifiable compliance.
YAZEK is not a standalone digitalisation project. The system is built on the Policy Document and Action Plan on Artificial Intelligence in Education (2025–2029), which entered into force in June 2025; the Directive on the Ethics Committee for Artificial Intelligence Applications of 22 October 2025; and the Ethics Guide for Artificial Intelligence Applications in Education, published in January 2026.[2] This chronology matters. First the policy objective was set; then the organisational structure that allocates duties and powers was established; then the way ethical principles would be translated into practice was explained; and finally the declaration and monitoring process was tied to a digital system.
The resulting structure has four layers:
Statutory obligations: first and foremost Law No. 6698 on the Protection of Personal Data (KVKK), Law No. 1739 on Basic National Education, provisions on the protection of children, intellectual property, contract and consumer law, and cybersecurity duties.
Administrative governance: the duties of MEB’s High Ethics Board for Artificial Intelligence Applications (Üst Kurul) and of the boards and teams at provincial, district and school level.
Ethical and operational standards: the eight principles in the Guide, the assessment questions, the conditions for declaration, and the review processes.
Institutional implementation: each educational institution’s own tool inventory, acceptable-use rules, data-processing workflows, vendor controls, training programmes and incident management.
These layers are not alternatives to one another. That an application has been declared under YAZEK does not automatically establish compliance with KVKK; nor does a data-processing activity that is lawful under KVKK, of itself, mean that the activity is pedagogically fair, explainable or of educational quality. Likewise, an ethically problematic use need not amount to a personal-data breach. A classification that systematically disadvantages students, even where a legal basis exists, is an example of that distinction.
YAZEK’s scope should not be read narrowly either. The system is designed to cover AI applications used in education, instruction and administrative processes in educational institutions affiliated with MEB, including public and private schools, science and art centres, and public education centres. Developers and units running institutional projects, as well as teachers, are part of this architecture.
A common error in education technology is to determine risk by looking at the product name: a tool is treated as either “safe” or “objectionable”. Yet the same generative AI tool may be relatively low-risk when a teacher uses it to generate ideas for a lesson plan without student data, and high-impact when it is used to score student essays. An image-generation tool produces one set of legal consequences when it is used to design a representative poster in a history class, and quite another when it processes a real student’s face to produce a synthetic video.
YAZEK’s implicit but powerful approach is therefore to move the object of compliance from the “product” to the use case. The unit of review is the combination of the following components:
Purpose + user group + data + model function + effect on the decision + technical and contractual conditions
This formula is decisive for institutional policy. A tool inventory is not enough on its own; it must also record, for each tool, in which lesson, administrative process or student group it is used, with what kinds of data, and with how much decision-support effect. Even if the name of the tool does not change, the risk assessment must be renewed when the purpose, the target group, the data category or the effect on assessment changes. YAZEK’s linking of whether a fresh declaration is required for the same application to changes in the scope of use, pedagogical purpose, tool and target group is a consequence of this logic.
The first legal sentence that must be established about YAZEK is this: the system is not a prior-authorisation or licensing mechanism; it is, in essence, a self-assessment and ethical-declaration mechanism. Once the teacher has answered the questions and completed the declaration, the application may proceed; the school-level team is not designed as an authority that pre-approves every filing. By contrast, if the team sees a clear personal-data, security or ethical risk, it may warn that the application should not be started, or should be stopped.
This distinction does not extinguish responsibility; it distributes it and puts it on the record. The person making the declaration is responsible for the accuracy of the information given and for the actual use being carried out in line with the declaration. School management cannot escape oversight and institutional organisation; the procurement unit cannot escape contractual safeguards; IT officers cannot escape technical controls; and the relevant administrative units cannot escape the review and coordination duties assigned to them.
Three false equivalences, in particular, must be rejected in relation to YAZEK.
The first is equating a declaration with a permit. A declaration records the user’s self-assessment and the responsibility assumed; it is not a licence of conformity issued by the administration for every use. The second is treating a system record as a certificate of lawfulness. A record provides traceability; but separate assessment is still required under KVKK, intellectual property, contract, cybersecurity and education law. The third is assuming that where no declaration is required, no obligation remains. Even in a use that falls outside YAZEK, duties concerning personal data, confidential information, copyright, academic integrity, security and pedagogical responsibility continue.
This framework makes the “we filled in the form, the risk is closed” approach impossible. YAZEK is not a safe harbour; it is the opening record of accountability.
YAZEK’s current explanations treat a declaration as required especially in three situations: where the student interacts directly with the AI system; where student data such as homework, audio, images, reports or grades are processed; and where AI is used in assessment and evaluation or in decision-support processes. By contrast, uses by the teacher for lesson preparation, material development or professional development without student data, and uses that a student undertakes by individual choice without school or teacher direction, are kept outside the YAZEK declaration.[4]
These boundaries do not, however, extinguish other obligations. The examples below require an initial assessment of the YAZEK threshold to be read together with the areas that still need examination outside the declaration.
Where there is direct interaction, student data, or assessment/evaluation or decision support, a declaration is as a rule required. A student using a chatbot under school direction goes to declaration because of direct interaction; age appropriateness, notice, data minimisation, harmful content, digital wellbeing and accessibility still need to be examined. Uploading homework, audio recordings, images, progress reports or grades goes to declaration because student data are processed; the KVKK legal basis, data security, retention and deletion, cross-border transfer and the vendor’s role still need to be assessed. Scoring, ability grouping or guidance with AI goes to declaration because of assessment/evaluation or decision support; human oversight, explainability, discrimination testing, and appeal and correction mechanisms still need to be put in place.
By contrast, some uses fall outside the YAZEK form without creating a legal vacuum. A teacher taking ideas for a lesson plan without student data does not, as a rule, go to declaration; but output accuracy, copyright, terms of service and institutional confidentiality remain. A student using a tool independently, by personal choice, without the school does not, as a rule, require a YAZEK declaration; duties of academic integrity, age conditions, family guidance and digital literacy continue. An educational software product that does not contain AI needs no YAZEK form; KVKK, information security, and consumer and contract-law obligations still apply.
The phrase “initial assessment” here is deliberate. The real scope of a use can be understood only by examining the concrete data flow and function. Calling a feature “personalisation”, “smart feedback” or “automatic recommendation” in marketing copy is not a sufficient technical explanation of what the system actually does. The institution must learn from the provider both the AI character of the feature and its real effect on the decision.
YAZEK-Ready EdTech ProductPublicationsSeptember 14, 2026👤Sercan Koç
The Ethics Guide for Artificial Intelligence Applications in Education adopts eight core principles: a human-centred and rights-based approach; equality and inclusiveness; transparency and explainability; privacy, confidentiality and data governance; reliability, safety and technical robustness; accountability and human oversight; educational value and qualified contribution; and conformity with national and spiritual values.[5]
To read these principles as a list of values hung on the institution’s wall is to miss the real function of the regulation. Each principle must be converted into a concrete family of controls:
A human-centred approach requires that the student’s benefit come before the efficiency objective, and that the possibility of withdrawing from certain uses, or of dealing with a human, be designed in.
Equality and inclusiveness require testing for different languages, disabilities, socioeconomic conditions and digital-access circumstances, and require that paid features not create a de facto split in learning opportunities.
Transparency and explainability require that students and parents not merely be told that “AI is being used”, but that they be able to understand for what purpose the system is used and to what extent it affects the outcome.
Privacy and data governance require that data unrelated to the purpose not be collected at all, that access be granted on a role basis, that retention periods be set, and that deletion be verified.
Reliability and technical robustness require pre-classroom testing, error and hallucination checks, misuse scenarios, cybersecurity and a business-continuity plan.
Accountability and human oversight require that, at the end of a decision, there be a named responsible person, and that this person be able genuinely to change the system’s recommendation.
Educational value requires that the technology be used not because it is new, but because it makes a measurable contribution to a defined learning need.
Alignment with values requires content control appropriate to age, context and the fundamental purposes of the education system.
Ethical assessment therefore cannot consist of a pledge that “we will comply with the principles”. The evidence of compliance is found in verifiable documents: test results, risk assessments, data-flow diagrams, notice texts, human-control records, vendor clauses, incident reports and training records.
Explore the critical legal limitations, personal data privacy challenges, and institutional responsibilities when integrating artificial intelligence into educational workflows.
In generative AI use, personal data often enter the system not through a classic registration screen, but through a free-text box. A command of the form “Prepare a study plan for this student, taking into account a dyslexia diagnosis and the last three exam results” is as much a transfer of health and achievement data as it is a pedagogical instruction. Even if the teacher uploads no file, the prompt, the added context, the chat history, the model output, the user account and the technical logs can together form a data-processing chain.
Assessment under KVKK cannot be made by looking only at the final output. Collection of the data, transmission to the tool, storage, access for support services, use in model development, transfer abroad and deletion may each give rise to separate processing operations. The Personal Data Protection Authority’s generative-AI guide likewise emphasises that the condition for processing, and the general principles in Article 4 of the Law, must be assessed separately at every stage of the lifecycle, and that controller and processor roles must be determined according to the actual power to determine purposes and means, rather than according to the label in the contract.[6]
Four issues are particularly important here.
In educational institutions, the power asymmetry between the student and the institution strips the sentence “we obtained consent” of any claim to be, on its own, a safe legal basis. For every processing activity, the appropriate legal basis in Article 5 of KVKK, or, where the conditions are met, Article 6, must be identified in concrete terms. If explicit consent is required, it must be specific, informed and freely given; tying the service to processing that is not necessary should also be scrutinised.
The obligation to inform and explicit consent must not be confused with one another. The obligation to inform is an independent duty that the controller must discharge; consent arises only if that is the legal basis to be relied upon. Melting the two into a single text under the heading “parental consent form” can obscure compliance rather than strengthen it.
Removing a name and a school number from an essay may not eliminate the student’s indirect identifiability, given events, locations, health status or family information in the text. Such an operation is often masking or pseudonymisation rather than anonymisation. True anonymisation requires that the link to the person cannot reasonably be re-established by available methods.
YAZEK’s explanations, which bring student homework and similar content within the scope of declaration even where names have been removed, therefore set a cautious operational threshold. In terms of terminology, however, two regimes must be kept apart: YAZEK may establish a broad declaration duty where student material is concerned; under KVKK, whether the data are truly anonymous requires a technical and contextual examination. The institution’s own “anonymous” label is not decisive.
Special categories of data relating to special educational needs, health information, religious belief or other aspects of a student’s life can easily enter prompts in the name of personalisation. In tools that use cameras and audio, the data category, the purpose of processing and the technical method must also be examined separately. YAZEK’s explanations, for example, treat certain uses that analyse a student’s bodily movements by camera as involving biometric-data risk. Under KVKK, however, not every image automatically counts as biometric data; the technical character of the processing as uniquely identifying the person must be investigated on the facts of the case. This distinction does not shrink the risk; it ensures that the correct legal regime is put in place.
A transfer map cannot be drawn without investigating the location of the server, sub-processors, remote-support access, the model-training infrastructure and the backup arrangement. Under Article 9 of KVKK, it must be determined which of an adequacy decision, appropriate safeguards or exceptional cases can be applied, and the form and notification conditions of mechanisms such as standard contractual clauses must be met. A general statement on the provider’s website that “we are GDPR-compliant” is not evidence of compliance with Türkiye’s transfer regime.
For that reason, conducting a short data-protection impact assessment for every high-impact use is, beyond good practice, a reasonable instrument of accountability. The Personal Data Protection Authority also recommends a privacy impact assessment, privacy by design, and a project-specific data-protection programme for high-risk AI projects.[7]
AI acquires its greatest legal weight in education in assessment, classification and guidance processes. A system may group a student by achievement level, score a written text, generate a risk prediction from attendance data, or flag behaviour that could become a disciplinary matter. Even if these outputs are labelled “recommendation only”, high-impact decision support is in play if they in fact determine the teacher’s or the administration’s decision.
Article 11 of KVKK grants the data subject the right to object to an adverse result arising from the analysis of processed data exclusively by automated systems. The importance of this provision in education is obvious: outcomes such as grades, placement, programme admission, counselling guidance or discipline affect the student’s educational life directly.
Being able to say “there is human oversight” is not satisfied by the teacher pressing an approve button after the output. Meaningful human oversight requires at least the following elements:
The person exercising oversight must have the competence to understand the model’s purpose, limits and error types.
That person must have real authority to change the decision, and time to examine it.
The model output must be capable of being compared with the underlying data and with other pedagogical observations.
The circumstances in which the output will be rejected, or a second review requested, must be defined in advance.
An intelligible reason must be capable of being given to the student, and an accessible appeal route must be offered.
The initial output, the human correction and the final decision must be recorded to the extent necessary.
Otherwise the human becomes a “rubber stamp” that merely legitimises the algorithmic recommendation. Read together, YAZEK’s principles of transparency, explainability, accountability and human oversight require institutions to design not only who decides, but how the decision will be questioned.
YAZEK’s architecture provides for a review chain for alleged ethical breaches, beginning at school level. A written petition by an identified applicant is conveyed to the school administration; review by the school team, appeal to the provincial or district board, and then the High Board stage are structured with specified time limits. Under the Directive, fifteen days each are provided for the school team’s review and for the first appeal stage, and one month for the High Board stage. Confidentiality of the review process is also essential.[8]
This internal application route is valuable; but it does not replace students’ and parents’ rights of application under KVKK, administrative application and judicial remedies, contractual rights that may arise from the private-school relationship, or other statutory avenues. Institutional procedure must not conflate these channels. Turning a data-breach allegation into nothing more than an “ethics complaint” file does not extinguish the controller’s separate duties, such as notification to the Authority. Likewise, a grade appeal and an alleged ethical breach may arise from the same event and still have different competences and consequences.
It is also not enough that the application exists only on paper. The student and the parent must learn in advance, in age-appropriate language, that AI is being used, what it affects, and to whom and how they may apply. An inaccessible appeal route is a theoretical safeguard.
One of the most critical statements in YAZEK’s frequently asked questions is that there is no MEB-approved list of “safe AI tools”. Leaving tool selection to the user does not mean that responsibility disappears; on the contrary, it makes the institution’s product-review and vendor due-diligence capacity important.
An EdTech provider’s pedagogical promises should not be assessed in isolation. At the purchase or free-trial stage, answers to at least the following questions should be obtained:
Which data categories are processed, for which purposes, and for how long?
Are prompts, files and outputs used outside the core service for model training or product development; can that use be switched off?
How are controller/processor roles established in a manner consistent with actual operation?
In which countries is the data held; who are the sub-processors; how are changes notified?
How is a deletion request applied and verified in the main system, in backups and in logs?
On which standards do access control, encryption, security testing, incident notification and vulnerability management rest?
What age threshold, parent/guardian mechanism and content-safety controls does the product provide for children?
Is the institution given prior notice when the model or the terms of service change?
What is the intellectual-property regime for outputs and uploaded content; which licences of use does the provider claim?
Can data and institutional content be taken out in a portable format; is there verifiable deletion and transition support when the service ends?
That a free tool requires no payment from the institutional budget does not mean that it is costless. The price may appear as data, lock-in, advertising, limited control or service-continuity risk. The Teacher Handbook’s observation that tools can change name, pricing, features and access conditions over time is also important in law: a technical change is also a change in the risk profile.[9]
Review therefore does not end once the contract is signed. The institution must periodically monitor version changes, the sub-processor list, the privacy policy, default settings and model behaviour. For a critical provider, an alternative tool and a data-migration plan are also part of educational continuity.
Find out how to structure solid contracts, secure exit rights, and establish contractual observability for artificial intelligence integrations in your institution.
The data-protection agenda of AI use should not overshadow intellectual-property and academic-integrity problems. A teacher uploading textbook pages, publisher materials or third-party images to a model; a student transforming their own text with generative AI; and an institution using model output in commercial content each give rise to different rights and licensing issues.
Under Law No. 5846 on Intellectual and Artistic Works, authorship is addressed around the natural person who creates the work and the intellectual product that bears the imprint of that person’s personality.[10] Whether a given AI output is protected must nevertheless be assessed through the nature and intensity of the human’s creative contribution, the inputs used, the editing process and the concrete output. Absolute sentences such as “AI outputs have no copyright” or “the person who wrote the prompt is automatically the author” do not make a reliable legal policy.
In academic integrity, too, there are not merely two options between “prohibited” and “permitted”. At least four categories can be defined in the institution’s acceptable-use policy:
Permitted use: uses such as idea generation, creating exercises or language correction that do not substitute for the learning outcome.
Use subject to disclosure: uses in which the AI contribution must be declared, stating the tool, purpose and scope.
Use subject to teacher permission: uses that require prior permission and a process record for a particular assignment or project.
Prohibited use: uses such as having the model produce the whole of a piece of work by which the student’s own attainment is to be measured, impersonation/deepfake, breach of examination security, or uploading another person’s personal data.
These categories should be differentiated by age level, by the purpose of the course and by the attainment being measured. The institution also cannot establish a regime that supervises only the student. The teacher’s duty to verify material created with AI, to check the source and, where necessary, to disclose the use is also part of the policy. A fair academic-integrity system, even if not symmetrical, places reciprocal responsibility on teacher and student.
For the answers given on the YAZEK form to be consistent with institutional reality, the policies and procedures on which those answers rest must be established in advance. A single document titled “Artificial Intelligence Policy” does not meet every need. An effective structure is an interconnected policy set.
The core that makes use visible is the AI acceptable-use policy, the tool and use-case inventory and the pre-use impact assessment. The first defines permitted, conditional and prohibited use cases and the roles of student, teacher and administration; it produces use rules, a contribution declaration and an approval matrix. The inventory makes visible which tool is used, for what purpose and by whom, and leaves a current inventory, a use owner and a risk level. The impact assessment weighs legal, pedagogical, technical and children’s-rights risks together; it produces a risk form, a test result, a mitigating measure and a residual-risk decision.
The data and procurement layer rests on the personal-data compliance pack and the procurement and contract standard. The compliance pack manages legal basis, notice, retention, transfer, rights requests and security; it produces a processing inventory, texts, a retention-and-deletion plan and a transfer record. The procurement standard establishes minimum safeguards over providers and sub-processors; it leaves a due-diligence file, a data-protection addendum, and service-level and exit clauses.
Control of the decision takes concrete form in the human-oversight and decision-appeal procedure and the academic-integrity and intellectual-property policy. The first determines by whom and how AI-supported decisions will be controlled; it produces a review record, reasons, a correction and an appeal outcome. The second regulates the limits, declaration and content use of AI contribution; it leaves student/teacher guidance, a rubric and a contribution declaration.
The set’s continuity depends on incident and breach management, the competence and training programme, change and lifecycle management and the business continuity and exit plan. Incident management directs erroneous output, discrimination, data breach and ethics complaints to the correct channel; it produces an incident record, notification, corrective action and root-cause analysis. The training programme provides role-based AI literacy for teachers, administrators, students and parents; it leaves an attendance record, competence measurement and current content. Lifecycle management provides re-assessment when the model, purpose, data, user, contract or version changes; it produces a version record, a change trigger and a renewed declaration/assessment. The exit plan protects the continuation of education if the tool shuts down, becomes paid or becomes inaccessible; it leaves an alternative process, a data-export plan and verified deletion.
Preparing this set is not a drafting exercise that the legal unit can carry out on its own. Pedagogical purpose must be assessed together with teachers and instructional designers; data flow with IT and information security; the contract with procurement and legal; the effect on children with counselling/psychological support; and accessibility with special-education expertise. The role of the law is not to “approve” these expertises at the last stage, but to design the decision points and the evidence architecture from the outset.
YAZEK establishes a multi-layered structure through the school AI-applications ethics team chaired by the principal, the provincial/district boards, and the eleven-member High Board. This official structure must be completed by an operational allocation of duties inside the institution.
A functional model can be thought of along three lines:
Use owner: the teacher, department or project team; defines the purpose and the data need, answers the first risk questions, and carries out the actual use in line with the declaration.
Expert control: the school ethics team, legal/KVKK, IT security, pedagogical quality and procurement functions; each performs the control in its own field of expertise, sets conditions and monitors.
Institutional oversight: school management and the relevant provincial/district and central structures; assess systemic risks, recurring incidents, policy effectiveness and resource need.
This classification is not a new board model named in the Directive; it is an operational approach that will make existing duties workable. Unless a “use owner” is designated for every use, a “risk-acceptance authority” for every high risk, and an “incident coordinator” for every incident, responsibility disperses and disappears in the organisation chart.
An educational institution should operate YAZEK not as an annual form campaign, but as a continuous cycle:
Teachers should not be asked only about purchased institutional products; free accounts, browser extensions, AI features inside the LMS, tools used in student projects and automations of administrative units should also be taken into the inventory. “Shadow AI” is the most important source of unseen data flows.
The institution may establish its own internal risk model. Without changing YAZEK’s official principles, low, medium and high review levels can be set according to triggers such as direct interaction with the student, special-category data, camera/audio, profiling, assessment and evaluation, large scale and transfer to an external provider. In this way, not every use meets the same bureaucratic load.
Pedagogical benefit, alternatives that use less data, the KVKK legal basis, the effect on children’s rights, discrimination, explainability, security, intellectual property and the contract are addressed together. Risk is not merely defined; it is converted into a measure that has a responsible person, an end date and a method of verification.
The YAZEK form should be a summary of a completed assessment. The scope of the pilot, the target group, human oversight, notice and withdrawal criteria are determined in advance. In high-impact applications, a limited pilot produces healthier evidence than full rollout.
Error rates, student/parent complaints, the outcome of appeals, performance across different groups, data incidents, model/contract changes and pedagogical attainment are monitored. If the purpose, tool, data or target group has changed, the YAZEK declaration and the internal assessment are renewed. Decommissioning is also part of the lifecycle; accounts, data, integrations and permissions must be closed.
If an educational institution can answer the following questions with documents, it is on the way to converting YAZEK into a genuine compliance system:
Is there a current inventory of the AI tools and features used in the institution by students and staff?
Are the pedagogical purpose, owner, target group and processed data categories of each use defined?
Is there a written, example-based internal guide on which scenarios require a YAZEK declaration?
Has it been verified whether the provider uses the data for model training, analytics or advertising?
Were the KVKK legal basis, notice, retention and cross-border transfer arrangements determined before use began?
Who is the competent and authorised person who will genuinely review an AI-supported grade, classification or guidance decision?
When a student or parent objects to the outcome of a use, on which record, within which period and by whom will the review be conducted?
Is there a monitoring mechanism that will detect a change in the model, price, licence, sub-processor or data policy?
Is it clear, by age and by course, when AI contribution is permitted, when it must be disclosed, and when it is prohibited?
If the tool shuts down tomorrow, or the risk becomes unacceptable, how will the data be extracted and deleted, and how will education continue?
An answer of “we do not know” to one of these questions does not automatically mean a breach of legislation; but it does show a control gap. The priority list of the compliance programme is drawn precisely from these gaps.
An important feature of digital regulatory tools is that they can change faster than static texts. Indeed, while the January 2026 Ethics Guide states that the form cannot be changed or deleted after final approval, as of 8 September 2026 YAZEK’s current frequently asked questions section explains that there is a three-day editing window after final approval, and that after that period a new form is required for an erroneous declaration.[11]
This difference should be read not as a contradiction that devalues the regime, but as a new feature of compliance: institutions must now monitor not only the version of the legislation, but also the version of the digital procedure and the interface. The following information should be kept in a declaration file:
the date of the declaration and by whom it was given,
the form/question set and Guide version applied on that date,
the model, and where possible the version, of the tool used,
a copy of the privacy policy and terms of service as they stood on that date,
subsequent changes and the re-assessment decision.
In other words, a screenshot, a version record and a change log are now part of the legal evidence architecture. YAZEK shows the need to manage not only applications, but the compliance system itself, with a lifecycle approach.
Not every educational institution or AI provider in Türkiye is automatically subject to the European Union Artificial Intelligence Act; territorial and material scope must be examined separately. The EU regulation is nevertheless a useful comparative benchmark that indicates the global direction for AI in education. It is noteworthy that certain systems determining access to educational institutions, or assessments affecting a person’s educational and professional life, are treated as high-risk, and that duties of risk management, data governance, logging, documentation, human oversight, accuracy and cybersecurity are provided for. The prohibition of certain uses of emotion recognition in educational institutions, in turn, draws a strong line against the claim to “read” children’s inner world with technology.[12]
This comparison matters for Türkiye’s EdTech ecosystem for two reasons. First, a provider offering products to the European market, or affecting students there, may require a direct scope analysis. Second, expectations in public procurement and private-school contracts often develop ahead of the minimum legislation in force. A product whose explainability, record-keeping, human-oversight and technical-documentation capacity is not built today may face a competitiveness problem in tomorrow’s supply chain.
The common ground of YAZEK and the EU approach is that they look at the effect of the use, rather than at the name of the technology. The institutional policy set to be built in Türkiye should therefore not merely meet today’s declaration duty; it should establish a risk-based, evidence-producing governance infrastructure that can be adapted to different regulatory environments.
Who Gave the Grade?PublicationsSeptember 14, 2026👤Sercan Koç
YAZEK’s real innovation in education law is to take AI out of an abstract ethics debate and to place it inside a particular teacher, a particular student group, a particular data flow and a particular decision. In this way, both the easy claim that “technology is neutral” and the generalisation that “every AI use is dangerous” give way to concrete, risk-based assessment.
The system’s strength is that it creates visibility and traceability through declaration. Its limit begins at exactly that point: visibility is not, by itself, a safeguard. For the declaration to be accurate, the institution needs a tool inventory; a legal-basis and transfer analysis; a pedagogical impact assessment; a human-oversight and appeal mechanism; vendor clauses; academic-integrity rules; incident management; and training and change records.
The task before educational institutions is therefore not confined to sending teachers a notice that says “do not forget the YAZEK form”. What must be done is to convert YAZEK’s questions into the institution’s daily decision order: Which use is acceptable? Who will review it? Which data will never be uploaded? What safeguard will be asked of the provider? In which decision will a human have the last word? How will the student be informed and how will they appeal? When will a change give rise to a new assessment?
The answers to these questions live not in a single document, but in an interconnected policy set that is updated regularly. That is why the meeting of law, pedagogy, information security, procurement and child-development expertise at the same table is not a preference; it is the working method of AI compliance.
The most rational first step for institutions is to put existing policies and practices through a compliance gap analysis against YAZEK’s eight principles and against data-protection, procurement, assessment-and-evaluation and incident-management duties. At the end of that work, what emerges is not only missing documents, but also decisions without an owner, unseen data flows and use cases that require re-assessment. A policy, contract, training and control roadmap, sequenced by risk, can then be prepared.
The soundest investment in YAZEK is not faster form-filling; it is to build an institutional memory in which the institution can explain every declaration with its supporting grounds, keep every high-impact decision under human oversight, and renew itself at every change. Trust in education is born not from the claim that the algorithm is error-free, but from the institution’s capacity to anticipate, explain, correct and account for error.
This article is a general legal assessment. For a concrete educational institution, project or AI application, the data flow, the parties’ actual roles, the student group, the model used and the current legislation must be examined separately.