Türkiye’s Artificial Intelligence Action Plan (2026–2030) entered into force with Presidential Circular no. 2026/9, published in the Official Gazette of 18 August 2026, issue 33344. The circular is dated 17 August 2026 and assigns coordination of the plan to the Ministry of Industry and Technology. The plan replaces the National AI Strategy covering 2021–2025; it was first presented publicly at the Türkiye AI Summit on 13 June 2026.
This article is concerned not with the announcement but with its legal consequences: what an action plan brought into force by circular actually means for the private sector, which obligations it creates now, and which it merely signals.
First, a clarification: this is not a statute
A presidential circular is an instrument of internal direction addressed to public institutions. It imposes no direct obligation on companies, provides for no administrative sanction, and does not, by declaring an AI system “high-impact”, subject that system to a legal regime of its own. Türkiye still has no binding framework statute regulating artificial intelligence directly; the draft AI law numbered 2/2234 remains on the parliamentary agenda.
Even so, the plan can produce binding consequences for the private sector through three channels. The first is public procurement: documentation standards that public bodies apply to their own systems pass through contractually to the suppliers selling to them. The second is sectoral regulation: if the headings the plan points to are turned into secondary legislation by bodies such as the banking, capital markets, communications or health regulators, binding force arrives from there. The third is the legislative route: an action plan shapes the vocabulary and the priorities of the legislation that follows it.
The architecture of the plan
The plan rests on four axes representing four stages of AI maturity: Detect (awareness, human resources, the data ecosystem, the legal framework), Benefit (computing infrastructure, deployment across the public and private sectors), Produce (financing, domestic models, robotics, growth zones) and Govern (international investment, AI diplomacy, security and regulation). According to press coverage, each axis contains four actions, for a total of sixteen priority actions.
The circular lists the principles underlying the plan as human-centredness, reliability, ethical responsibility, digital sovereignty and sustainable development.
The plan in figures
The table below collects those of the plan’s publicly reported numerical targets that could be confirmed in more than one source. It is worth recalling that these amounts and dates are public policy objectives, not binding obligations.
| Heading | Target | Timeframe |
|---|---|---|
| AI literacy | Training for 5 million citizens | 2 years |
| Advanced specialists | 10,000 people | End of 2027 |
| Application professionals | 100,000 people | End of 2027 |
| Open public datasets | At least 2,000 datasets (National Data Library) | Plan period |
| Data centre capacity | At least 1 gigawatt | 2030 |
| Infrastructure investment | At least USD 10 billion of private investment mobilised | Plan period |
| Public investment programme | At least 2% allocated to AI projects | Plan period |
| Regulatory sandboxes | At least 5 priority sectors | Plan period |
Press coverage also refers to a National AI Research Fund of TRY 10 billion and an AI Growth Fund of TRY 15 billion, a “GPU for Everyone” access programme rising from 2 million GPU-hours a year to 20 million GPU-hours by the end of 2028, and AI vouchers for SMEs. For the detail of these items, the full text of the plan published by the Ministry of Industry and Technology should be consulted.
Four headings that matter to lawyers
The most operationally significant part of the plan is not the figures but the institutional and procedural headings. Four stand out.
1. Risk-based classification and algorithmic impact assessment
According to the reported content, the plan tiers AI systems by risk level: simple checklists for low-risk systems, short algorithmic impact assessments for medium-risk systems, and for high-impact systems a detailed assessment, publicly available model cards and a technical file to be submitted to the regulator. The high-impact domains listed include health, education, employment, social assistance, credit assessment, biometric identification, law enforcement and justice, together with systems that directly affect children or vulnerable groups.
This vocabulary deliberately overlaps with the architecture of the EU AI Act. For companies operating in Türkiye that also place products on the EU market, that is good news: the classification memo prepared for the AI Act and the accompanying technical file provide a largely reusable foundation on the Turkish side as well.
2. Regulatory sandboxes
The plan envisages regulatory sandboxes in at least five priority sectors: finance, health, energy, mobility and telecommunications. A sandbox works in two directions. It allows a product to be tested under supervision, with a limited user base and temporary exemptions; and, through the application file, the measurement plan and the exit criteria, it sets a de facto maturity threshold for the sector. The practical consequence for companies in these sectors is straightforward: whoever is ready when the sandbox calls open sits down with the regulator first.
3. Governance: who does what, and who imposes penalties
The institutional architecture has several layers. The National AI Council provides strategic direction and approves annual plans; a programme office within the Ministry of Industry and Technology monitors implementation; and the TÜBİTAK BİLGEM AI Institute supplies technical assessment capacity on security, robustness, bias, explainability and data protection. A National AI Ethics Board, to be established within the first year, is described as having an advisory, non-binding mandate.
Here is the point that matters for companies: binding enforcement power stays with the existing sectoral regulators, not with the new bodies. Supervisory and sanctioning authority in banking, health and communications remains where it is today. In other words, the first enforcement action you face because of an AI deployment will most likely come not from a text headed “AI legislation” but from the sectoral rules you are already subject to, and from the KVKK.
4. Data: open data, anonymisation and the KVKK overlap
The plan’s data axis covers publishing public datasets in machine-readable, openly licensed form, providing API access to high-value datasets, and defining “data product owner” roles within each institution. Anonymisation standards for open datasets are said to be under development.
This heading connects directly to the settled position of the Personal Data Protection Board that anonymisation and masking are not the same thing; the Board’s decision no. 2024/275 made that distinction concrete. Equally, the inclusion of biometric identification among the plan’s high-impact domains should be read alongside the Board’s case law that explicit consent does not displace the proportionality test.
What changes for companies today
No obligation arises directly and immediately. But the plan already has practical consequences for three company profiles.
- Technology companies selling to the public sector. If impact assessments and model cards are the target for newly deployed high-impact public systems, those documents will shortly become annexes to tenders and framework agreements. The provenance of your training data, your evaluation metrics, your known limitations and your human-oversight design should be written down now.
- Deployers in regulated sectors. In finance, health, energy, mobility and telecommunications, sandbox calls are worth tracking. Sandbox applications typically require a completed risk analysis, a measurement plan and an exit scenario; these are not documents that can be produced in three weeks.
- Companies supplying the EU. The EU AI Act already binds these companies today. The plan’s stated aim of an approach aligned with the EU framework while remaining sensitive to national priorities means, in the medium term, compliance with two regimes at once. The good news is that the document set is largely common; the bad news is the prospect of accounting to two separate regulators. For the detail, see our article for companies whose server is in Türkiye and whose customer is in Europe.
Six steps you can take now
- Build an inventory. Which AI systems are in use, in which process, on what data, and in place of whose decision? A company without an inventory cannot know which of its systems would count as high-impact.
- Run the high-impact test. If you touch health, education, employment, social assistance, credit assessment, biometric identification, law enforcement or justice, the plan’s heaviest documentation expectation is the one that will apply to you.
- Draft a model card. Purpose, scope, training data, performance, known limitations, human oversight and a contact channel. An honest one-page model card is worth more than a thirty-page file assembled after the fact.
- Attach the impact assessment to your KVKK processes. Rather than opening a separate file, keep it with the existing processing inventory, privacy notices and retention periods; the two regimes ask about the same facts under different names.
- Review your vendor contracts. If you have no right to documentation, version notifications and evaluation support from your model provider, you cannot discharge your own documentation duty. We have a separate guide on the clauses to look for in AI vendor contracts.
- Put the monitoring portal in your calendar. The plan’s progress and transparency portal, and the first progress report, will be the earliest reliable signal of which headings are actually being implemented.
Questions left open
The plan brings a level of conceptual detail one would not normally expect from an action plan. From the point of view of legal certainty, however, three questions remain open.
The first is definitional: it is not clear whether the criteria for a high-impact system will be derived from the list of domains or from a concrete threshold test. The second is whether the expectation of impact assessments and model cards will remain confined to public systems, and, if it extends to the private sector, through which legal instrument. The third is the plan’s relationship with draft law 2/2234 now before Parliament: will the draft be aligned with the plan’s vocabulary, or will the two texts proceed along separate tracks?
The answers will determine whether the plan is a signpost for companies or a de facto compliance timetable. You can follow developments through our AI Compliance Hub.
Sources
- Presidential Circular no. 2026/9, Official Gazette of 18 August 2026, issue 33344.
- Türkiye Artificial Intelligence Action Plan (2026–2030), Ministry of Industry and Technology.
- Press coverage of the plan: Anadolu Agency, Webrazzi, Aposto and BloombergHT (18 August 2026).
The numerical targets and procedural headings described here are compiled from the text of the circular published in the Official Gazette and from publicly available reporting on the plan. The inclusion of a target in this article does not mean that it creates a binding obligation for companies.
This article is provided for general information only and does not constitute legal advice. Please seek legal support for an assessment of any specific matter.
Author
-
View all postsMümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement.
If this is on your desk
Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.
Founder AcademyBook an intro callMore from Vircon Insights
Türkiye's First Official RWA Move: The Digital Precious Metals Communiqué Opens a Third Lane for Tokenization
August 11, 2026Türkiye’s Crypto Advertising and Sweepstakes Rules: The Banned Pages of the Growth Playbook
July 16, 2026Türkiye’s DPA Publishes Its Agentic AI Guide: Reading Notes for Everyone Building or Deploying Agents
July 16, 2026You Didn’t Train the Model, but You Still Have AI Act Obligations: GPAI Rules for Companies Building on GPT, Claude and Llama
July 14, 2026When the Algorithm Fixes the Price: Repricing Tools, Tacit Collusion and the Turkish Competition Authority’s 2026 Agenda
August 19, 2026Article 50 Is Live: The Two-Week Transparency Runbook for AI Products Serving EU Users
August 18, 2026Related Practice Areas
Privacy & Cybersecurity
KVKK and GDPR compliance, breach response, cybersecurity governance.
View service →Corporate Law
Share transfers, capital increases, board structuring, governance.
View service →Mergers & Acquisitions
End-to-end M&A: due diligence, structuring, documentation, negotiation.
View service →