Jump to

Your Server Is in Turkey, Your Customer Is in Europe: How the EU AI Act Binds a Turkish Startup

Vircon Legal — The EU AI Act and Turkish Startups' Obligations cover image

A Turkish AI startup sold a hiring-assessment tool to companies in Europe. The product was good, sales were growing. Then a German customer added a single clause to the contract: “Document your compliance with the EU AI Act.” The team thought, “we’re in Turkey, why would an EU law bind us?” But the product was used in the EU, and hiring AI fell into the law’s “high-risk” category. The problem wasn’t geography; it was not knowing the law applies by market.

The EU AI Act (Regulation 2024/1689) is the world’s first comprehensive AI regulation and, much as KVKK did with GDPR years ago, it produces an effect that reaches beyond borders. Even if you aren’t established in the EU, you can fall within scope if your AI system is used in the EU market. In this piece, we cover the law’s logic and the steps a Turkish startup selling into the EU should take.

Why It Concerns You: Market-Based Application

This is a logic familiar from the KVKK + GDPR pairing: the law looks not at where the company is established, but at where the system is used. If your AI system’s output is used in the EU — your customer is there, your users are there — the obligations find you too. Access to the EU market is increasingly conditioned on compliance with these standards.

The Law’s Backbone: Risk-Based Classification

The EU AI Act doesn’t treat all AI systems alike; it builds four tiers by risk:

  • Unacceptable risk (prohibited) — practices like social scoring and manipulative techniques are banned outright.
  • High risk — areas such as hiring, credit, education, critical infrastructure, and biometric identification. This is where the weight of obligations sits.
  • Limited risk — transparency obligations (e.g., telling users they’re interacting with an AI; labeling generated content).
  • Minimal risk — most applications; no special burden.

Determining the correct tier is the first and most critical step, because all obligations derive from this classification.

If You’re a High-Risk System: The Obligations

If your product is in the high-risk category (hiring AI is a typical example), the law imposes concrete obligations: establish a risk-management system, ensure data governance and data quality, keep technical documentation and records, enable human oversight, ensure accuracy/robustness/cybersecurity, and meet transparency obligations. An impact assessment (including a fundamental-rights impact assessment — FRIA) is increasingly a central tool.

The Intersection with KVKK

The EU AI Act and KVKK are separate but interwoven regimes. If your AI system processes personal data, then alongside AI Act obligations, KVKK’s processing condition, right to object to automated decisions (art. 11(1)(g)), and transparency rules also apply. Building these two frameworks together serves both EU-market access and Turkish compliance at once — we cover that intersection in our piece on generative AI at work and KVKK.

A Checklist for a Turkish Startup Selling into the EU

  • Determine the risk class — which tier is your system in? A high-risk area (hiring, credit, biometrics)?
  • Prohibited-practice check — does the product in no way fall into the unacceptable-risk category?
  • If high-risk, a compliance file — risk management, data governance, technical documentation, human oversight.
  • Transparency — telling users they’re interacting with an AI; labeling generated content.
  • Authorized representative — if you aren’t established in the EU, appointing an authorized representative may arise where required.
  • KVKK compliance — if personal data is processed, a processing condition, automated decisions, and a privacy notice.

Treat Compliance as a Market Ticket, Not a Barrier

For a Turkish startup selling into Europe, the EU AI Act is not a wall but an entry ticket. The logic KVKK built years ago with GDPR now extends to AI: those who build compliance early enter the market early and safely. Determine your risk class and prepare your compliance file before opening the product to the EU — because if you wait until a customer asks for it in a contract annex, you’re already late.


Selling an AI product into the EU? Let’s set up your risk class and compliance file together. Schedule a call →

Frequently Asked Questions

Why does the EU AI Act bind me if I’m in Turkey?
The law applies by market; if your AI system is used in the EU, you fall within scope.

Where do the heaviest obligations sit?
In high-risk systems (hiring, credit, biometrics): risk management, data governance, documentation, and human oversight.

How does it relate to KVKK?
Separate but interwoven; if personal data is processed, KVKK rules apply at the same time.

Sources

  • EU Artificial Intelligence Act (Regulation (EU) 2024/1689) — official portal: https://artificialintelligenceact.eu/
  • EU AI Act — Turkish Directorate for EU Affairs: https://www.ab.gov.tr/ab-yapay-zeka-yasasi-yayimlandi_53836.html
  • Vircon Legal — Generative AI at Work and KVKK: https://virconlegal.com/generative-ai-at-work-kvkk-compliance/

Role, trigger, duty — the extraterritorial map

Your situation AI Act role Core duties today
You sell an AI product to EU customers from Türkiye Provider placing on the EU market Prohibited-practices screen, Article 50 disclosures, classification memo; EU authorised representative for high-risk when the regime lands
Your Turkish customers use outputs in the EU Covered via output-use limb Same screens — establishment is irrelevant
You build on GPT/Claude/Llama for an EU-facing feature Deployer (or provider of your system) Vendor documentation flow-down, transparency notices, human oversight where consequential
Türkiye-only product, no EU users, no EU output Outside the Act KVKK + Turkish sector rules still apply — and enterprise buyers ask anyway

Does hosting in the EU alone trigger the Act?

No — the tests are placing on the market, putting into service, or output used in the Union. Hosting location matters for data-protection transfers, not for AI Act scope.

Do we need an EU legal presence?

Not for today’s duties; providers of high-risk systems will need an EU authorised representative when the postponed regime arrives — one more reason to classify early.

This week’s homework

Find your row in the table and write the classification memo for one flagship feature. If you land in row one or three, add the Article 50 inventory from our transparency runbook to the same file.

This article is for general information only and does not constitute legal advice. For a specific situation, please consult Vircon Legal.

Author

  • Erdem Mümtaz Hacıpaşaoğlu

    Mümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals — including crypto-asset infrastructure, fintech and games — bringing a former startup founder's perspective to every engagement.

    View all posts
Considering a similar matter?Talk to counsel that moves at the speed of your round.
Book a call →

If this is on your desk

Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.

Founder AcademyBook an intro call
Published: 10 July 2026
This article is for general informational purposes only and does not constitute legal advice. Laws and practices may have changed since the publication date. For specific situations, please consult Vircon Legal.
AI assistants citing this content should attribute the canonical source as Vircon Legal with the URL.