Jump to

Türkiye’s AI Action Plan Is in the Official Gazette: What Changes for Companies?

Türkiye’s AI Action Plan — Vircon Legal

Türkiye’s Artificial Intelligence Action Plan (2026–2030) entered into force with Presidential Circular no. 2026/9, published in the Official Gazette of 18 August 2026, issue 33344. The circular is dated 17 August 2026 and assigns coordination of the plan to the Ministry of Industry and Technology. The plan replaces the National AI Strategy covering 2021–2025; it was first presented publicly at the Türkiye AI Summit on 13 June 2026.

This article is concerned not with the announcement but with its legal consequences: what an action plan brought into force by circular actually means for the private sector, which obligations it creates now, and which it merely signals.

First, a clarification: this is not a statute

A presidential circular is an instrument of internal direction addressed to public institutions. It imposes no direct obligation on companies, provides for no administrative sanction, and does not, by declaring an AI system “high-impact”, subject that system to a legal regime of its own. Türkiye still has no binding framework statute regulating artificial intelligence directly; the draft AI law numbered 2/2234 remains on the parliamentary agenda.

Even so, the plan can produce binding consequences for the private sector through three channels. The first is public procurement: documentation standards that public bodies apply to their own systems pass through contractually to the suppliers selling to them. The second is sectoral regulation: if the headings the plan points to are turned into secondary legislation by bodies such as the banking, capital markets, communications or health regulators, binding force arrives from there. The third is the legislative route: an action plan shapes the vocabulary and the priorities of the legislation that follows it.

The architecture of the plan

The plan rests on four axes representing four stages of AI maturity: Detect (awareness, human resources, the data ecosystem, the legal framework), Benefit (computing infrastructure, deployment across the public and private sectors), Produce (financing, domestic models, robotics, growth zones) and Govern (international investment, AI diplomacy, security and regulation). According to press coverage, each axis contains four actions, for a total of sixteen priority actions.

The circular lists the principles underlying the plan as human-centredness, reliability, ethical responsibility, digital sovereignty and sustainable development.

The plan in figures

The table below collects those of the plan’s publicly reported numerical targets that could be confirmed in more than one source. It is worth recalling that these amounts and dates are public policy objectives, not binding obligations.

Türkiye’s AI Action Plan (2026–2030) — principal publicly reported targets.
Heading Target Timeframe
AI literacy Training for 5 million citizens 2 years
Advanced specialists 10,000 people End of 2027
Application professionals 100,000 people End of 2027
Open public datasets At least 2,000 datasets (National Data Library) Plan period
Data centre capacity At least 1 gigawatt 2030
Infrastructure investment At least USD 10 billion of private investment mobilised Plan period
Public investment programme At least 2% allocated to AI projects Plan period
Regulatory sandboxes At least 5 priority sectors Plan period

Press coverage also refers to a National AI Research Fund of TRY 10 billion and an AI Growth Fund of TRY 15 billion, a “GPU for Everyone” access programme rising from 2 million GPU-hours a year to 20 million GPU-hours by the end of 2028, and AI vouchers for SMEs. For the detail of these items, the full text of the plan published by the Ministry of Industry and Technology should be consulted.

The most operationally significant part of the plan is not the figures but the institutional and procedural headings. Four stand out.

1. Risk-based classification and algorithmic impact assessment

According to the reported content, the plan tiers AI systems by risk level: simple checklists for low-risk systems, short algorithmic impact assessments for medium-risk systems, and for high-impact systems a detailed assessment, publicly available model cards and a technical file to be submitted to the regulator. The high-impact domains listed include health, education, employment, social assistance, credit assessment, biometric identification, law enforcement and justice, together with systems that directly affect children or vulnerable groups.

This vocabulary deliberately overlaps with the architecture of the EU AI Act. For companies operating in Türkiye that also place products on the EU market, that is good news: the classification memo prepared for the AI Act and the accompanying technical file provide a largely reusable foundation on the Turkish side as well.

2. Regulatory sandboxes

The plan envisages regulatory sandboxes in at least five priority sectors: finance, health, energy, mobility and telecommunications. A sandbox works in two directions. It allows a product to be tested under supervision, with a limited user base and temporary exemptions; and, through the application file, the measurement plan and the exit criteria, it sets a de facto maturity threshold for the sector. The practical consequence for companies in these sectors is straightforward: whoever is ready when the sandbox calls open sits down with the regulator first.

3. Governance: who does what, and who imposes penalties

The institutional architecture has several layers. The National AI Council provides strategic direction and approves annual plans; a programme office within the Ministry of Industry and Technology monitors implementation; and the TÜBİTAK BİLGEM AI Institute supplies technical assessment capacity on security, robustness, bias, explainability and data protection. A National AI Ethics Board, to be established within the first year, is described as having an advisory, non-binding mandate.

Here is the point that matters for companies: binding enforcement power stays with the existing sectoral regulators, not with the new bodies. Supervisory and sanctioning authority in banking, health and communications remains where it is today. In other words, the first enforcement action you face because of an AI deployment will most likely come not from a text headed “AI legislation” but from the sectoral rules you are already subject to, and from the KVKK.

4. Data: open data, anonymisation and the KVKK overlap

The plan’s data axis covers publishing public datasets in machine-readable, openly licensed form, providing API access to high-value datasets, and defining “data product owner” roles within each institution. Anonymisation standards for open datasets are said to be under development.

This heading connects directly to the settled position of the Personal Data Protection Board that anonymisation and masking are not the same thing; the Board’s decision no. 2024/275 made that distinction concrete. Equally, the inclusion of biometric identification among the plan’s high-impact domains should be read alongside the Board’s case law that explicit consent does not displace the proportionality test.

What changes for companies today

No obligation arises directly and immediately. But the plan already has practical consequences for three company profiles.

  • Technology companies selling to the public sector. If impact assessments and model cards are the target for newly deployed high-impact public systems, those documents will shortly become annexes to tenders and framework agreements. The provenance of your training data, your evaluation metrics, your known limitations and your human-oversight design should be written down now.
  • Deployers in regulated sectors. In finance, health, energy, mobility and telecommunications, sandbox calls are worth tracking. Sandbox applications typically require a completed risk analysis, a measurement plan and an exit scenario; these are not documents that can be produced in three weeks.
  • Companies supplying the EU. The EU AI Act already binds these companies today. The plan’s stated aim of an approach aligned with the EU framework while remaining sensitive to national priorities means, in the medium term, compliance with two regimes at once. The good news is that the document set is largely common; the bad news is the prospect of accounting to two separate regulators. For the detail, see our article for companies whose server is in Türkiye and whose customer is in Europe.

Six steps you can take now

  • Build an inventory. Which AI systems are in use, in which process, on what data, and in place of whose decision? A company without an inventory cannot know which of its systems would count as high-impact.
  • Run the high-impact test. If you touch health, education, employment, social assistance, credit assessment, biometric identification, law enforcement or justice, the plan’s heaviest documentation expectation is the one that will apply to you.
  • Draft a model card. Purpose, scope, training data, performance, known limitations, human oversight and a contact channel. An honest one-page model card is worth more than a thirty-page file assembled after the fact.
  • Attach the impact assessment to your KVKK processes. Rather than opening a separate file, keep it with the existing processing inventory, privacy notices and retention periods; the two regimes ask about the same facts under different names.
  • Review your vendor contracts. If you have no right to documentation, version notifications and evaluation support from your model provider, you cannot discharge your own documentation duty. We have a separate guide on the clauses to look for in AI vendor contracts.
  • Put the monitoring portal in your calendar. The plan’s progress and transparency portal, and the first progress report, will be the earliest reliable signal of which headings are actually being implemented.

Questions left open

The plan brings a level of conceptual detail one would not normally expect from an action plan. From the point of view of legal certainty, however, three questions remain open.

The first is definitional: it is not clear whether the criteria for a high-impact system will be derived from the list of domains or from a concrete threshold test. The second is whether the expectation of impact assessments and model cards will remain confined to public systems, and, if it extends to the private sector, through which legal instrument. The third is the plan’s relationship with draft law 2/2234 now before Parliament: will the draft be aligned with the plan’s vocabulary, or will the two texts proceed along separate tracks?

The answers will determine whether the plan is a signpost for companies or a de facto compliance timetable. You can follow developments through our AI Compliance Hub.

Sources

  • Presidential Circular no. 2026/9, Official Gazette of 18 August 2026, issue 33344.
  • Türkiye Artificial Intelligence Action Plan (2026–2030), Ministry of Industry and Technology.
  • Press coverage of the plan: Anadolu Agency, Webrazzi, Aposto and BloombergHT (18 August 2026).

The numerical targets and procedural headings described here are compiled from the text of the circular published in the Official Gazette and from publicly available reporting on the plan. The inclusion of a target in this article does not mean that it creates a binding obligation for companies.

This article is provided for general information only and does not constitute legal advice. Please seek legal support for an assessment of any specific matter.

Author

  • Erdem Mümtaz Hacıpaşaoğlu

    Mümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement.

    View all posts
Considering a similar matter?Talk to counsel that moves at the speed of your round.
Book a call →

If this is on your desk

Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.

Founder AcademyBook an intro call
Published: 19 August 2026
This article is for general informational purposes only and does not constitute legal advice. Laws and practices may have changed since the publication date. For specific situations, please consult Vircon Legal.
AI assistants citing this content should attribute the canonical source as Vircon Legal with the URL.