Türkiye does not yet have a single comprehensive horizontal AI statute comparable to the EU AI Act, but artificial intelligence is already subject to existing Turkish laws governing areas such as personal data, contracts and liability, intellectual property, consumer protection, employment and regulated sectors. The Türkiye Artificial Intelligence Action Plan (2026–2030), placed within the governmental policy framework through Presidential Circular No. 2026/9, marks a new phase by signalling movement towards a more trustworthy, risk-sensitive and accountable AI governance environment. Businesses should therefore distinguish carefully between existing binding law, regulatory guidance, emerging policy and regulatory direction, and prudent corporate governance when assessing their AI-related obligations and risks. Personal data protection is already a central compliance consideration, with Law No. 6698 applying where AI systems process personal data and the Turkish Personal Data Protection Authority providing additional guidance specifically addressing artificial intelligence and generative AI. Companies using third-party AI and cloud services should also assess vendor contracts, cross-border data flows, intellectual property and trade-secret exposure, cybersecurity, human oversight and the allocation of responsibility for AI-supported decisions. Turkish companies with EU-facing activities may additionally fall within the territorial scope of the EU AI Act, requiring a separate assessment that should not be confused with the EU framework’s broader influence on Türkiye’s emerging risk-based regulatory approach. Rather than waiting for future AI legislation, organisations can strengthen regulatory readiness by identifying and classifying their AI systems, mapping data flows, reviewing providers and contracts, establishing meaningful human oversight, documenting material decisions and training employees in responsible AI use. Bıçak Law Firm assists Turkish and international businesses with AI legal risk assessments, governance frameworks, KVKK compliance, AI and technology contracts, cross-border data issues, intellectual property and trade-secret protection, internal AI policies and the interaction between Turkish requirements and international regulatory frameworks such as the EU AI Act.
Artificial Intelligence Law and Regulation in Türkiye
1. AI Law in Türkiye: Where Does the Law Stand in 2026?
Türkiye does not currently have a single comprehensive horizontal statute regulating artificial intelligence in the manner of the European Union’s AI Act. This does not mean, however, that the development, procurement or use of AI systems falls outside the law. Depending on the technology, data involved, sector, contractual relationships and consequences of its use, AI may already be subject to binding Turkish legislation concerning personal data, contracts and civil liability, consumer protection, intellectual property, employment, competition, criminal law and regulated industries.
At the same time, Türkiye’s AI governance framework has entered a new phase. The Türkiye Artificial Intelligence Action Plan (2026–2030) establishes a policy direction towards trustworthy AI, stronger data governance, security, standards and risk-sensitive regulation. Official government materials describe the Plan as structured around four axes – Recognise, Benefit, Produce and Govern (Fark Et, İstifade Et, Üret ve Yönet) – supported by 16 actions. The legal landscape should therefore be understood through distinct layers: existing binding law, AI-specific policy and emerging regulation, regulatory guidance, and prudent corporate governance. Keeping these categories separate is essential when determining what organisations must do today and what they should prepare for next.
2. From the 2021–2025 Strategy to the 2026–2030 AI Action Plan
Türkiye’s present approach builds on the National Artificial Intelligence Strategy 2021–2025, which established the earlier national framework for developing AI capabilities, skills, institutional capacity and responsible use. The policy framework has now moved into a new phase. The Türkiye Artificial Intelligence Action Plan (2026–2030) was announced in June 2026 and subsequently addressed through Presidential Circular No. 2026/9, dated 17 August 2026 and published in the Official Gazette on 18 August 2026. The Ministry of Industry and Technology now lists the 2026–2030 Plan among Türkiye’s current strategy documents.
2.1. The Legal Status of the 2026/9 Presidential Circular and Action Plan
A critical distinction must be maintained: the Presidential Circular, the Action Plan and binding AI legislation are not interchangeable concepts. The Action Plan establishes policy priorities and indicates the direction in which Türkiye’s AI governance framework is expected to develop. It should not be described as if Türkiye had thereby enacted an EU AI Act-style horizontal statute imposing all contemplated requirements directly on private organisations. For businesses, existing legislation determines present binding obligations, while the Action Plan provides an important roadmap for the regulatory environment towards which Türkiye is moving.
2.2. Türkiye’s 2026–2030 AI Action Plan: The Emerging Regulatory Direction
The Action Plan approaches artificial intelligence as an economic, technological and governance issue. From a legal perspective, its importance lies principally in the direction of future regulation rather than the creation of immediately applicable horizontal statutory duties.
2.3. Risk-Proportionate AI Governance
A central feature is movement towards a risk-sensitive legal and ethical framework, under which regulatory expectations may differ according to the risks associated with particular AI systems, uses and impacts. For businesses, this suggests that future requirements may increasingly depend on what a system does, the context in which it is deployed, the interests it can affect and the seriousness of potential harm. This should not yet be characterised as a completed Turkish equivalent of the EU AI Act.
2.4. Trustworthy AI, Standards and Regulatory Sandboxes
The Plan connects AI governance with trust, safety, data governance, standards and sector-specific implementation. It also envisages regulatory experimentation, including sandbox mechanisms, as part of the developing ecosystem. This indicates that Türkiye’s future AI framework may develop through a combination of legislation, sectoral rules, standards, guidance and supervisory practices rather than exclusively through a single AI statute.
2.5. Algorithmic Impact Assessment
The Action Plan also incorporates algorithmic impact assessment into Türkiye’s emerging AI-governance vocabulary. Such assessments can provide a structured method for identifying and documenting potential effects on individuals, organisations and society. Its inclusion is significant, but it does not by itself establish a general statutory obligation requiring every organisation in Türkiye to conduct an algorithmic impact assessment today. It instead signals movement towards more risk-based, documented and accountable governance.
3. Existing Turkish Laws Applicable to Artificial Intelligence
The absence of a horizontal AI statute does not remove AI from Türkiye’s existing legal framework.
3.1. Contracts, Tort and Liability
Agreements for developing, licensing, procuring or deploying AI may address performance, confidentiality, intellectual property, data use, warranties and allocation of risk. Where AI-related activity causes legally recognised damage, liability must be assessed under the applicable rules and facts rather than on the assumption that the technology itself is an autonomous bearer of legal responsibility.
3.2. Consumer and Product-Related Risks
AI-enabled products and consumer-facing services may engage rules concerning consumer transactions, misleading practices, safety, conformity and applicable sector-specific requirements.
3.3. Criminal Law and Unlawful Use
Existing criminal offences may apply where AI facilitates fraud, impersonation, unlawful interference with information systems or other prohibited conduct. Use of AI as an instrument does not itself create a separate criminal-law regime.
3.4. Employment, Competition and Sectoral Regulation
AI-assisted recruitment, workplace decisions, pricing, customer profiling, healthcare, insurance, financial services and other regulated activities may simultaneously engage employment, competition, data protection, consumer and sector-specific rules. The practical question is therefore not simply whether Türkiye has an “AI Act,” but which binding laws already apply to the particular AI use case.
4. AI, Generative AI and Personal Data Protection
Personal data protection is one area in which binding Turkish law already directly affects AI. Where an AI system processes personal data, Personal Data Protection Law No. 6698 (KVKK) and applicable secondary legislation may apply regardless of whether the technology is labelled AI, machine learning or generative AI. The Personal Data Protection Authority has supplemented this binding framework with AI-specific guidance. Its 2021 AI recommendations remain relevant, while the Guide on Generative Artificial Intelligence and the Protection of Personal Data (in 15 Questions), published on 24 November 2025, specifically considers personal-data processing throughout the lifecycle of generative AI systems. These materials are important regulatory guidance but should not be presented as if every recommendation were an independently enacted statutory obligation.
4.1. Training Data, Prompts, Inputs and Outputs
Personal-data exposure may arise at several points. Training datasets can contain information relating to identifiable individuals; users may enter personal information into prompts; uploaded documents may contain employee, customer or client data; and generated outputs may reproduce or infer personal information. Organisations should therefore understand both what information users submit to AI systems and what providers may subsequently do with it.
4.2. Data Minimisation, Transparency and Lawful Processing
AI does not displace the general requirements governing personal-data processing. Organisations should determine the legal basis and purpose of processing, assess whether the data used are necessary and proportionate, address transparency and retention, and implement appropriate safeguards.
4.3. Sensitive Data and Cross-Border Transfers
Additional scrutiny is necessary where AI processes special categories of personal data. Third-party generative AI and cloud services may also create international-transfer issues. Organisations should understand where data are processed, whether providers retain or reuse them, which subprocessors are involved and whether the applicable Turkish rules governing transfers abroad are engaged. AI governance and data governance are therefore increasingly inseparable.
5. Intellectual Property, Copyright and Trade Secrets
Generative AI also interacts with copyrighted works, software, proprietary datasets, confidential information and trade secrets. Training or developing AI using protected material can raise questions concerning the rights necessary for reproduction or other uses. The analysis may depend on the material, source, acts undertaken, applicable licences and relevant limitations or exceptions. Content being publicly accessible does not necessarily mean that it is free for unrestricted AI training or commercial reuse. AI-generated outputs create different questions, including whether protection exists, the significance of human contribution and whether outputs reproduce protected third-party material. Businesses should therefore avoid assuming that AI-generated text, images, code or other commercially significant outputs necessarily come with clear and unrestricted rights. An immediate corporate risk also arises when employees place source code, client material, internal legal documents, pricing information, unpublished inventions or commercial strategies into external AI systems. Companies should establish rules identifying approved AI tools, permitted information and prohibited inputs.
6. AI Contracts, Cloud Services and Third-Party Providers
For many organisations, AI risk arises not from developing models but from procuring or integrating third-party AI systems.
6.1. Vendor Due Diligence
Organisations should understand what a service does, what data it receives, where information is processed and stored, whether inputs are retained or used for training, which subprocessors are involved and what security arrangements apply. Due diligence should be proportionate: an internal productivity tool does not necessarily require the same assessment as an AI system processing sensitive information or supporting consequential decisions.
6.2. Contractual Allocation of AI Risk
Depending on the service, contracts may need to address permitted data use, confidentiality, model training, IP, security, incident notification, audit or information rights, subcontracting, warranties, liability, termination and data deletion or return. Outsourcing an AI function does not automatically outsource the customer’s own legal responsibilities.
6.3. Cloud and Cross-Border Data
Cloud AI may create international issues even where users are located in Türkiye. Personal-data transfers must be assessed under applicable KVKK requirements, while confidentiality, trade secrets, cybersecurity and sectoral restrictions may create additional considerations.
7. Liability, Automated Decisions and Human Oversight
When an AI-supported process causes harm or an unlawful result, stating that “the AI made the decision” does not resolve responsibility. An AI value chain may involve developers, providers, cloud services, integrating companies and professional or employee users. Responsibility depends on applicable law, contractual relationships, the function of the system and the degree of control exercised by the relevant actors.
Human oversight should therefore be substantive rather than ceremonial. For higher-impact uses, organisations should determine who reviews AI recommendations, what information the reviewer receives, whether an output can genuinely be challenged or overridden and how significant decisions are documented. The appropriate level of oversight depends on the system and consequences of error; there is not presently a single statutory human-oversight rule applying identically to every AI system used in Türkiye.
8. AI Governance as a Board-Level Legal Risk
As AI becomes embedded in core operations, governance should not be treated exclusively as an IT issue. AI can simultaneously affect personal data, confidential information, IP, employment, customers, cybersecurity and regulatory compliance. A governance framework may therefore include an AI inventory, assigned accountability, risk classification, approval procedures, vendor and data assessments, human oversight, documentation, monitoring and escalation mechanisms. Three categories should remain distinct. Some measures derive from existing binding law. Others reflect the emerging policy and regulatory direction. Others constitute prudent corporate governance even where no AI-specific statute currently mandates a particular procedure. For boards and senior management, the central questions become: Where is AI being used? What consequences can it produce? Who is accountable? And can the organisation demonstrate how material risks are being managed?
9. The EU AI Act and Why It Matters for Turkish Companies
The EU Artificial Intelligence Act, Regulation (EU) 2024/1689, is relevant to Turkish businesses in two legally distinct ways. First, the Regulation itself can apply to certain operators established outside the EU. Depending on the circumstances, this can include providers placing AI systems on the EU market or putting them into service in the Union and providers or deployers outside the EU where an AI system’s output is used in the Union. A Turkish company may therefore require an EU AI Act assessment where, for example, it supplies an AI system into the EU market, participates in an EU-facing AI product or service chain or otherwise falls within the Regulation’s territorial scope. Mere use of AI by a company in Türkiye does not by itself establish EU AI Act applicability.
9.1. The EU AI Act Application Timeline
The AI Act is now law. Article 113 provides a general application date of 2 August 2026, while particular provisions have different dates: Chapters I and II applied from 2 February 2025, specified governance and general-purpose AI provisions from 2 August 2025, and Article 6(1) and corresponding obligations from 2 August 2027. Businesses should therefore check the provision and AI category concerned rather than treating the Act as having one uniform compliance date.
9.2. EU Influence on Türkiye’s Emerging Framework
Separately, the European risk-based regulatory model is relevant to the direction of Türkiye’s emerging framework. This regulatory influence does not mean that EU requirements automatically become Turkish law. Companies operating across Türkiye and the EU may consequently require parallel but distinct assessments: one under Turkish law and Türkiye’s developing framework, and another under the EU AI Act where its scope requirements are met.
10. Regulatory Sandboxes, Standards and Sector-Specific AI Rules
Türkiye’s AI framework may increasingly develop through regulatory experimentation, standards, guidance and sector-specific implementation alongside generally applicable law. The risks presented by an internal productivity tool differ materially from AI deployed in healthcare, finance, insurance, employment, telecommunications or other high-impact or regulated environments. Existing licensing, professional, safety, cybersecurity, data-protection and supervisory requirements may therefore apply independently of future AI-specific measures. Regulatory sandboxes can also provide controlled environments for testing innovative applications while legal and technical risks are assessed. Their existence should not be interpreted as a general exemption from otherwise applicable law; their legal effect depends on the particular framework and competent authority. The key question is therefore not only “Is this AI?” but “In which activity and regulatory environment is this AI being used?”
11. What Should Companies Using AI in Türkiye Do Now?
Companies do not need to wait for future AI legislation before establishing a proportionate compliance framework.
11.1. Build an AI Inventory
Identify which AI systems are used, for what purposes, by whom and with what data—including employee use of publicly accessible generative AI tools. The KVKK has specifically highlighted workplace use of third-party generative AI where adoption may occur without a defined organisational strategy or policy.
11.2. Classify Use Cases and Legal Risks
Assess the data processed, persons affected, degree of automation and potential consequences, with particular attention to employment, customers, sensitive information, regulated activities and consequential decisions.
11.3. Map Data and Conduct Privacy Assessments
Understand what information enters the system, where it goes, who receives it, how long it is retained and whether international transfers occur.
11.4. Review AI Vendors and Contracts
Assess provider data practices, training rights, security, subprocessors, IP, incident notification, liability and termination arrangements.
11.5. Protect IP, Confidential Information and Trade Secrets
Define approved tools and establish clear restrictions on uploading sensitive corporate or third-party information.
11.6. Establish Human Oversight and Accountability
Identify who approves material deployments, reviews significant recommendations and has authority to override or suspend systems.
11.7. Document, Monitor and Escalate
Maintain proportionate records of significant systems, assessments and approvals and establish procedures for problematic outcomes or incidents.
11.8. Train Employees
Employees should understand approved tools, privacy and confidentiality restrictions, verification of AI outputs, IP concerns and when human review or escalation is required.
12. Preparing for Türkiye’s Emerging Risk-Based AI Framework
Future readiness does not require companies to predict legislation that has not yet been enacted. A more durable strategy is to build capabilities that are useful under existing law and adaptable to future regulation: AI identification and classification, impact assessment, documentation, human oversight, vendor governance, monitoring and auditability. The objective is not premature compliance with hypothetical requirements, but regulatory adaptability. Organisations that understand where AI is deployed, what data and third parties are involved, who is accountable and how significant risks are managed will be better positioned as Türkiye’s framework develops.
13. How Bıçak Law Firm Supports AI Governance and Compliance
Bıçak Law Firm advises businesses on the interconnected legal issues arising from the development, procurement and use of artificial intelligence in Türkiye. Depending on the organisation and use case, our work may include AI legal risk assessments and governance frameworks, internal AI policies, KVKK and privacy assessments, AI vendor and technology contracts, cross-border data issues, intellectual property and trade-secret protection, employee-use policies, human-oversight arrangements and sector-specific regulatory analysis. We also advise international businesses on the interaction between Turkish requirements and cross-border frameworks, including circumstances in which the EU AI Act may require a separate assessment for Türkiye-based companies with EU-facing activities.
14. Frequently Asked Questions
14.1. Does Türkiye have an AI Act?
As of August 2026, Türkiye has not enacted a single comprehensive horizontal AI statute equivalent to the EU AI Act. AI is nevertheless already governed by existing Turkish laws depending on the use case, while the 2026–2030 Action Plan indicates the direction of an emerging risk-sensitive framework.
14.2. Is the 2026–2030 AI Action Plan legally binding?
The 2026/9 Presidential Circular, the Action Plan and legislation imposing specific obligations on businesses must be distinguished. The Circular places the Action Plan within the governmental policy framework, while the Plan establishes priorities and regulatory direction. Its contemplated future mechanisms should not automatically be treated as statutory duties applicable to every private organisation today.
14.3. Does the KVKK apply to generative AI?
Yes, where generative AI involves processing personal data, Law No. 6698 may apply. This can concern training materials, prompts, uploaded documents and, depending on the circumstances, outputs. The KVKK has also published specific regulatory guidance addressing generative AI and personal-data protection.
14.4. Does the EU AI Act apply to Turkish companies?
Potentially. Establishment in Türkiye neither automatically brings a company within the Regulation nor automatically excludes it. Turkish companies with relevant EU-facing AI systems, products, services or outputs should assess the AI Act’s territorial scope and their role in the relevant value chain.
14.5. What should a company in Türkiye do before deploying AI?
A proportionate assessment should identify the system’s purpose, data, providers, affected persons and consequences. Depending on the risk, this may involve privacy review, vendor due diligence, contractual safeguards, IP and trade-secret controls, security measures, human oversight, internal approval and documentation.
15. Conclusion: From AI Adoption to Responsible AI Governance
Türkiye’s AI landscape has moved beyond the question of whether artificial intelligence is legally relevant. Existing Turkish law already governs many aspects of AI development and use, while the 2026–2030 Action Plan signals movement towards a more structured, trustworthy and risk-sensitive governance environment. The appropriate corporate response is neither to wait for future legislation nor to treat every policy objective as an existing legal obligation. Organisations should instead combine compliance with binding law, proportionate AI risk assessment, effective data and vendor governance, protection of intellectual property and confidential information, meaningful human oversight and documented accountability. As AI becomes more deeply embedded in business operations, responsible AI governance will increasingly form part of the legal infrastructure that enables organisations to innovate while managing regulatory, commercial and operational risk.






Comments
No comments yet.