Regulatory & Sectoral

Artificial Intelligence Law in Türkiye

Türkiye still has no dedicated AI statute, so AI risk is governed by existing data-protection, intellectual property, consumer and liability rules — layered, for anyone facing the European market, with the EU AI Act and its timetable as amended in July 2026.

Survey plate: a strict grid of cells with one aperture where four cells open into a clear square

Türkiye has no dedicated artificial-intelligence statute in force as at 25 July 2026. AI is governed instead by general law: the Personal Data Protection Law No. 6698 (KVKK), whose Article 11(1)(g) lets a data subject object to an adverse outcome produced by analysis carried out exclusively through automated systems; intellectual property; consumer and product law; and the Turkish Code of Obligations. For any business whose systems or outputs reach the European Union, the EU AI Act adds a second and directly binding layer, and its timetable was amended in July 2026.

That is the whole of the position, and it is worth stating plainly, because much of what circulates online as “Türkiye’s AI law” describes proposals that were never enacted. The absence of a single AI statute does not mean the absence of AI regulation. It means several regimes apply at once, and the burden of joining them up falls on your business.

Where Turkish AI Regulation Actually Stands

No Turkish statute regulates artificial intelligence as such. The consolidated official text of Law No. 6698 contains no occurrence of the term yapay zekâ and no AI-specific provision; its most recent amendment on the official amendment table is by Law No. 7499, which changed Articles 6, 9 and 18 and Provisional Article 3 with effect from 1 June 2024. The consolidated text of Law No. 5651, the internet publications statute, likewise contains no reference to artificial intelligence, deepfakes or synthetic media. Its two most recent amendments concern other subjects entirely: Law No. 7545 amended Article 10 with effect from 19 March 2025, and Law No. 7578 (Official Gazette of 1 May 2026, No. 33240) inserted digital-game definitions into Article 2 with effect from 1 May 2026 and added a new Additional Article 5 on age rating, local representation and parental controls, in force from 1 November 2026.

InstrumentStatus as at 25 July 2026What it does for AI
Law No. 6698 (KVKK)In force; last amended by Law No. 7499, 1 June 2024No AI provisions, but Art. 11(1)(g) governs purely automated decisions
Law No. 5651In force; last amended by Law No. 7578No AI provisions; no AI-labelling duty
Law No. 7545 (Cybersecurity Law)In force since 19 March 2025Cyberspace regulation; no AI provisions
Circular No. 2021/18Published 20 August 2021National AI Strategy 2021–2025; policy, not binding law
EU AI ActApplies extraterritoriallyBinds Turkish providers reaching the EU market

Türkiye’s AI policy instrument is administrative rather than legislative. The National Artificial Intelligence Strategy (2021–2025) was promulgated by Presidential Circular No. 2021/18, published in the Official Gazette of 20 August 2021, No. 31574. In Parliament, work is at the research stage rather than the enactment stage: the Grand National Assembly’s AI research commission, chaired by the Eskişehir deputy Fatih Dönmez, presented its report to the Speaker on 26 February 2026. Several private members’ bills on AI have been tabled and none has been enacted.

What this means for you: you cannot point to one checklist and declare yourself compliant, and you should not build a compliance programme around a bill that has not passed. A single AI deployment can simultaneously raise a data question, an IP question and a liability question, and each must be answered under its own body of law.

Article 11(1)(g): The One In-Force Rule on Automated Decisions

The single most operationally important Turkish provision for AI sits in the data law, not in any technology statute. Under Article 11(1)(g) of Law No. 6698, every data subject has the right to object to an adverse outcome arising from the analysis of their data carried out exclusively through automated systems. The provision has not been amended since enactment, and it is the principal in-force Turkish rule touching automated and AI-driven decision-making.

Its reach is wider than it first appears. A lender scoring loan applicants, a retailer profiling customers, an insurer pricing a policy, or an HR team screening CVs with an algorithm are all processing personal data through automated analysis, and all of them can face an objection if the outcome is adverse to the individual. The practical response is architectural rather than legal: build a route by which a human can review and, where appropriate, override the model, and keep a record showing that the route exists and is used.

Everything else that governs the data side of an AI system is ordinary personal data protection law — a lawful basis for each processing activity, transparency in clear and accessible language, data minimisation and purpose limitation, and compliant safeguards where models, vendors or cloud infrastructure sit abroad. The differences between KVKK and the GDPR matter here, and they are set out in our guide to KVKK for foreign companies.

If your AI system touches personal data, treat compliance as a data-protection project first and an “AI project” second. In Türkiye, the fastest route to a fine is not a novel AI theory of harm, it is an ordinary KVKK breach hidden inside a clever model.


What the Regulator Has Actually Published on AI

The Personal Data Protection Authority has not made rules on AI, but it has published three documents that show how it thinks about these systems:

  • Recommendations on the Protection of Personal Data in the Field of Artificial Intelligence — KVKK Publication No. 76, edition dated April 2025, addressed to developers, manufacturers and service providers and to decision-makers.
  • Generative Artificial Intelligence and Personal Data Protection: A Guide in 15 Questions — published on the Authority’s website on 24 November 2025, printed as Publication No. 113. It covers content generation, the lifecycle of generative models, use cases and risks, assesses the resulting processing under Law No. 6698, and addresses what individuals — and parents of children using these tools — should watch for.
  • Agentic AI — an announcement and accompanying assessment published on 12 March 2026, covering what agentic systems are, the functions of AI agents, use cases, risks and data-protection considerations across the lifecycle.

None of these is binding. All three are worth reading before a deployment, because they are the closest thing Türkiye has to a supervisory position on AI, and a documented decision that follows them is materially easier to defend than one that does not.

The Cybersecurity Law No. 7545 Is Not an AI Law

This point is worth making expressly, because Law No. 7545 is regularly and wrongly presented as Türkiye’s AI legislation. It is a cybersecurity statute. It was adopted on 12 March 2025 and published in — and, under its Article 20, in force from — the Official Gazette of 19 March 2025, No. 32846. Its stated purpose under Article 1 is the detection and elimination of existing and potential internal and external threats to all elements constituting the national power of the Republic of Türkiye in cyberspace. Article 2 extends it to public institutions, public professional organisations, and natural and legal persons and unincorporated organisations present, operating or providing services in cyberspace. It establishes a Cybersecurity Board and confers powers on the Cybersecurity Directorate. Its consolidated official text contains no occurrence of the term yapay zekâ.

It nonetheless matters to anyone running AI infrastructure, because an AI system operating in cyberspace is squarely within its scope and its sanctions are severe. Article 16 carries criminal penalties including one to three years’ imprisonment plus a judicial fine of 500 to 1,500 days for withholding information, documents, software, data or hardware from authorised bodies or inspectors; two to four years plus 1,000 to 2,000 days for operating without the required approval, authorisation or permit; four to eight years for breach of the confidentiality duty; three to five years for making leaked personal or critical-public-service institutional data accessible, sharing it or offering it for sale without consent; two to five years for fabricating or spreading false claims of a data leak in order to create alarm or to target institutions or persons; and eight to twelve years for cyber-attacks on elements of Türkiye’s national power in cyberspace, rising to ten to fifteen years for disseminating, transmitting or offering for sale data so obtained. Under Article 16(7) these are increased by one third where the offence is committed by a public official, by one half where committed by more than one person, and by between one half and double where committed within the activity of an organisation.

The administrative fine bands sit in Article 16(10) and (11). As enacted on 19 March 2025 they run from TRY 1,000,000 to TRY 10,000,000 for failure to discharge the duties in Article 7(1)(b) and (c), and from TRY 10,000,000 to TRY 100,000,000 for failure to discharge the duties in Article 18. A breach of Article 8(4) attracts TRY 100,000 to TRY 1,000,000, rising, where the breach is by a commercial company, to up to 5% of the gross sales revenue shown in its audited annual financial statements and in any event not less than TRY 100,000. Article 17(2) adds that where one person is found to have committed several of the Law’s administrative offences before a sanction decision is issued, a single fine is imposed increased by up to double, and that where a benefit was obtained or a loss caused, the fine may be no less than three and no more than five times that benefit or loss.

Those lira figures should not be read as current-year figures. Under Article 17(7) of the Misdemeanours Law No. 5326, administrative fines expressed as fixed sums are increased at the start of each calendar year by the revaluation rate announced under the Tax Procedure Law No. 213, so the band in force for the year in question has to be checked for that year. The turnover-based element is a proportional fine and falls outside that annual revaluation.

Two further points of structure. A transitional provision of the Law provides that the regulations governing its implementation were to be brought into force within one year — that is, by 19 March 2026 — with existing rules not contrary to the Law continuing to apply until then. And Article 19(3) of Law No. 7545 is itself the instrument that amended Article 10 of Law No. 5651 with effect from 19 March 2025.

Do not read Law No. 7545 as an AI code. Read it as the reason your AI infrastructure needs the same security, authorisation and incident discipline as the rest of your estate — with criminal, not merely administrative, consequences attached.

The EU AI Act and the July 2026 Change of Timetable

Even without a Turkish AI law, the EU AI Act binds Turkish businesses. Regulation (EU) 2024/1689 applies to providers placing AI systems or general-purpose AI models on the EU market irrespective of whether they are established in the Union or in a third country, and it reaches providers and deployers outside the EU where an AI system’s output is used within the Union. No EU establishment is needed for the obligations to bite.

The baseline dates are these. The Regulation entered into force on 1 August 2024. The prohibited-practices and AI-literacy provisions applied from 2 February 2025. The governance rules and the general-purpose AI model obligations applied from 2 August 2025. General application follows on 2 August 2026.

The high-risk timetable then changed. Regulation (EU) 2026/1744 of 8 July 2026, amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence — the “Digital Omnibus on AI” — was published in the Official Journal on 24 July 2026 and enters into force on the third day following publication. It postpones the application of Chapter III, Sections 1, 2 and 3:

  • to 2 December 2027 for the Annex III use-case high-risk systems; and
  • to 2 August 2028 for systems classified as high-risk under Article 6(1), the Annex I product-embedded ones.
EU AI Act milestoneDate
Entry into force1 August 2024
Prohibited practices; AI literacy2 February 2025
Governance rules; general-purpose AI models2 August 2025
General application, including Art. 50 transparency2 August 2026
Annex III high-risk obligations (as postponed)2 December 2027
Article 6(1) / Annex I high-risk obligations (as postponed)2 August 2028

The commercially significant point is what was not postponed. Article 50 — the transparency obligations for providers and deployers of certain AI systems, including the marking of AI-generated or manipulated content — keeps its original application date. The amending Regulation modifies Article 50(7) to remove certain Commission implementing-act empowerments and adds a four-month transitional period, limited to the marking obligation in Article 50(2), for providers of generative AI systems that had already placed those systems on the market before 2 August 2026. A Turkish company that reads the omnibus as a general reprieve and stops work on disclosure and content-marking is reading it wrongly.

For a Turkish business the practical first step is unchanged: list every product or service in which an AI system’s output could reach an EU user, then classify each against the Act’s tiers. Most systems will land in the minimal-risk category and need little more than good documentation. Discovering late that a flagship product is high-risk under EU rules forces an expensive redesign that early classification would have avoided — and the postponed dates are a scheduling opportunity, not a cancellation.

Allocating Liability for AI

When an AI system causes harm in Türkiye, responsibility is shared among the developer, operator and user, and sometimes a distributor. Claims typically rest on:

  • Contract — the relationships between developer, operator and users are usually contractual; well-drafted clauses are the first line of defence.
  • Product liability — where an AI-enabled product is treated as defective under the Consumer Protection Law (No. 6502).
  • Tort — fault-based claims under the Turkish Code of Obligations (No. 6098), though attributing fault to an autonomous system is difficult.
  • Regulatory breach — most often a data-protection or intellectual property violation.

Open questions remain around the burden of proof, the attribution of fault in autonomous systems, and the applicable standard of care. A claimant may struggle to prove exactly how an opaque model produced a harmful output, and the courts have limited precedent to draw on. Until these questions are settled by legislation or case law, the contract is where liability is really decided, and the logs are what decide the contract dispute.

Do not assume a court will untangle AI liability for you. If your agreements are silent on who owns the risk when the model is wrong, you have not avoided the question, you have simply left it to be answered against you.

Businesses can reduce exposure well before any dispute:

  • Documentation — record how the system was built, tested and validated, so you can evidence the correctness and integrity of inputs and outputs if challenged.
  • Human oversight — build the review route that Article 11(1)(g) presupposes, and make sure a person can actually intervene in high-stakes decisions.
  • Governance — adopt internal policies on transparent and accountable AI use, and assign clear ownership of AI risk within the organisation.
  • Contracts — allocate responsibility, IP and indemnities expressly across every vendor and customer relationship, in your commercial contracts as well as your AI-specific agreements.
  • Sector rules — regulated fields such as health carry their own authorisation and record-keeping duties that apply to an AI tool exactly as they apply to any other.
  • Insurance — consider specialised liability cover for errors, bias or discrimination.

Taken together, these measures do more than reduce liability. They give you the paper trail that turns a defensible decision into a provable one, which is often the difference between resolving a dispute quickly and litigating it for years.

How we help

We advise Turkish and international clients across the AI lifecycle:

  • AI governance and KVKK compliance — policies, data-protection impact assessments, automated-decision review routes and privacy safeguards.
  • Intellectual property — protecting models, datasets and AI output, and settling ownership before disputes arise.
  • EU AI Act readiness — classifying systems against the tiers, and scheduling Article 50 transparency work and postponed high-risk work to the correct dates.
  • Cybersecurity compliance — assessing obligations and exposure under Law No. 7545 for AI infrastructure operating in cyberspace.
  • Contracts and licensing — drafting development, data-sharing and service agreements that allocate risk.
  • Liability and dispute resolution — assessing exposure and acting in AI-related disputes.

AI regulation in Türkiye will keep moving, and the shape of that movement is now reasonably clear: a research report before Parliament, a regulator publishing guidance faster than the legislature publishes law, and an EU regime that already binds anyone selling into Europe. Businesses that build compliance in from the start adapt far more cheaply than those forced to react to a statute after it appears.


How an AI compliance project works

  1. 01

    Map your AI systems

    We inventory every AI use case, the personal data it touches, where the model and infrastructure sit, and where the outputs are used.

  2. 02

    KVKK compliance check

    We confirm a lawful basis for each processing activity, test the position against Article 11(1)(g) on purely automated decisions, and document impact assessments where needed.

  3. 03

    EU AI Act classification

    EU-facing systems are mapped against the Act's tiers and its revised timetable, so that Article 50 transparency work is not left until the deadline while high-risk work is scheduled to the postponed dates.

  4. 04

    Contract and governance layer

    We draft or revise agreements and internal policies so liability, intellectual property, logging and human oversight are allocated expressly.

  5. 05

    Monitor and adapt

    Turkish and EU rules are both moving. We keep documentation, guardrails and contracts aligned as legislation, regulator guidance and implementing rules land.

Frequently asked questions

Does Türkiye have a dedicated AI law in 2026?

No. As at 25 July 2026 there is no dedicated artificial-intelligence statute in force in Türkiye. The three digital statutes usually cited in this context — Law No. 6698 on the Protection of Personal Data, Law No. 5651 on internet publications, and Law No. 7545, the Cybersecurity Law — contain no AI-specific provisions, and the term "yapay zekâ" does not appear in any of their consolidated official texts. Türkiye's AI policy instrument is administrative rather than legislative: the National Artificial Intelligence Strategy for 2021–2025, promulgated by Presidential Circular No. 2021/18 (Official Gazette of 20 August 2021, No. 31574). Parliamentary work is at the research stage — the Grand National Assembly's AI research commission presented its report to the Speaker on 26 February 2026 — and although several private members' bills on AI have been tabled, none has been enacted.

Does Turkish law require AI-generated content to be labelled?

No. There is no labelling duty for AI-generated, synthetic or manipulated content under Turkish law as at 25 July 2026. Law No. 5651, the statute that would ordinarily carry such an obligation, contains no reference to artificial intelligence, deepfakes or synthetic media anywhere in its consolidated official text. Its two most recent amendments do not concern AI: Law No. 7545 amended Article 10 with effect from 19 March 2025, and Law No. 7578 (Official Gazette of 1 May 2026, No. 33240) inserted digital-game definitions into Article 2 with effect from 1 May 2026 and added a new Additional Article 5 on age rating, local representation and parental controls for game platforms, in force from 1 November 2026. Proposals for a mandatory AI label circulate widely online, but no such duty has been enacted. A Turkish company whose content reaches EU users should nevertheless plan for Article 50 of the EU AI Act, which does require certain AI-generated or manipulated content to be marked.

Is the Cybersecurity Law No. 7545 Türkiye's AI law?

No, and the confusion is worth clearing up because it recurs. Law No. 7545, the Cybersecurity Law, was adopted on 12 March 2025 and published in — and entered into force from — the Official Gazette of 19 March 2025, No. 32846. Its stated purpose under Article 1 is the detection and elimination of existing and potential internal and external threats to all elements constituting the national power of the Republic of Türkiye in cyberspace; Article 2 extends it to public institutions, public professional organisations, and natural and legal persons and unincorporated organisations present, operating or providing services in cyberspace. It establishes a Cybersecurity Board and confers powers on the Cybersecurity Directorate. It contains no occurrence of the term "yapay zekâ" and imposes no AI-specific obligation. That said, an AI system deployed in cyberspace is not outside its scope, so security, authorisation and reporting duties can apply to AI infrastructure like any other.

Does the EU AI Act apply to Turkish companies?

It can, and no EU establishment is required. Regulation (EU) 2024/1689 applies to providers placing AI systems or general-purpose AI models on the EU market irrespective of whether they are established in the Union or in a third country, and it reaches deployers and providers outside the EU where an AI system's output is used within the Union. A Turkish developer selling into the EU, or serving EU customers, can therefore fall within its risk-based obligations. The Regulation entered into force on 1 August 2024; the prohibited-practices and AI-literacy provisions applied from 2 February 2025; the governance rules and general-purpose AI model obligations from 2 August 2025; and general application follows on 2 August 2026.

What changed in the EU AI Act timetable in July 2026?

The high-risk timetable moved. Regulation (EU) 2026/1744 of 8 July 2026 — the "Digital Omnibus on AI", amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 — was published in the Official Journal on 24 July 2026 and enters into force on the third day following publication. It postpones the application of Chapter III, Sections 1, 2 and 3 to 2 December 2027 for the Annex III use-case high-risk systems, and to 2 August 2028 for systems classified as high-risk under Article 6(1), that is the Annex I product-embedded ones. It is important not to over-read this: the Act as a whole has not been delayed. Article 50, which carries the transparency obligations for providers and deployers of certain AI systems including the marking of AI-generated or manipulated content, was not postponed. The amending Regulation modifies Article 50(7) to remove certain Commission implementing-act empowerments and adds a four-month transitional period, limited to the marking obligation in Article 50(2), for providers of generative AI systems that had already placed those systems on the market before 2 August 2026.

Can we train AI on personal data under Turkish law?

Only with a lawful basis under Law No. 6698. You need explicit consent or another statutory ground, transparency towards data subjects, data minimisation and purpose limitation, and compliant safeguards for cross-border transfers where models, vendors or infrastructure sit abroad. Article 11(1)(g) is directly relevant: a data subject may object to an adverse outcome produced by analysis carried out exclusively through automated systems, which means a purely automated training-and-scoring pipeline needs a human-review route and a documented rationale. The Personal Data Protection Authority has published three non-binding documents on the subject — recommendations on data protection in the field of AI (Publication No. 76, April 2025), a generative-AI guide in fifteen questions published on 24 November 2025 (Publication No. 113), and an assessment of agentic AI published on 12 March 2026. They do not create obligations, but they show how the Board frames the lifecycle of these systems.

Who is liable when an AI system causes damage in Türkiye?

Liability is allocated among the developer, operator and user under contract, product-liability and tort principles in the Turkish Code of Obligations (No. 6098) and the Consumer Protection Law (No. 6502). The party held responsible is usually the one that failed to exercise reasonable care or placed a defective product on the market. Because no Turkish statute assigns responsibility for autonomous systems, and because a claimant faces real difficulty proving how an opaque model produced a harmful output, the contract is where liability is actually settled. Agreements that pre-allocate responsibility, define the standard of care and set evidence and logging duties are worth more in practice than any argument about the state of the law.

Who owns the output an AI system generates?

Ownership is not automatic and depends on your contracts and on general intellectual property principles. Turkish copyright law is built around human authorship, so purely machine-generated output may not attract standard protection. Trade-secret and contractual protection often does more work than copyright here. In practice, ownership and licensing of models, datasets, weights and outputs should be settled expressly in the relevant development, data-sharing or service agreement, together with the question of what rights the provider retains over inputs submitted to the system.