Your model made a call and someone was harmed; a wrong triage suggestion, a scoring error that cascaded, generated content that defamed. The next 72 hours decide whether this becomes an engineering story or a legal one. AI incidents now live inside three overlapping regimes, and the companies that handle them well have decided the workflow before the pager goes off.
Regime one: AI Act serious-incident reporting
For high-risk systems, Article 73 requires providers to report serious incidents; death, serious harm to health, serious and irreversible disruption of critical infrastructure, or infringements of fundamental-rights obligations; to market surveillance authorities on short statutory clocks once the causal link is established or reasonably likely. The obligations mature with the high-risk timeline (December 2027 for Annex III after the omnibus), but the institutional muscle (detection, triage, causal assessment, reporting decision) takes longer to build than a template does. Deployers feed this system too: they must inform providers and authorities of incidents they observe.
Regime two: KVKK breach discipline
Many AI incidents are simultaneously data incidents; a model leaking training data, a prompt-injection exfiltration, transcripts exposed. KVKK’s breach practice expects notification to the Authority without delay (the Board’s 72-hour reflex) and to affected persons. If your incident response plan was written for infrastructure breaches only, model-layer scenarios (leakage via outputs, poisoning, injection) belong in it now (our glossary: prompt injection).
Regime three: civil liability, rewritten
The EU’s revised Product Liability Directive explicitly covers software and AI systems: defectiveness can arise from what the system learned after deployment, from failure to supply updates, and disclosure duties in litigation ease the claimant’s evidentiary path. Combined with Turkish general tort and product-safety principles for the home market, the practical exposure is this: your logs are the evidence, and the absence of logs reads worse than a defect. Contract chains matter equally; the indemnity and cooperation clauses from our GPAI piece are what stand between a vendor’s model error and your balance sheet.
The pre-incident package (build in one quarter)
- Incident taxonomy: define what counts as an AI incident for you; harm-touching outputs, rights-touching decisions, data-touching failures; with severity tiers.
- Logging fit for causation: inputs, model/version, key parameters, outputs, human overrides; retention matched to liability windows.
- A dual-clock playbook: KVKK 72-hour lane and AI Act reporting lane in one flowchart, with counsel in the loop at the classification step; because reports are admissions and silence is worse; the sequencing needs judgement.
- Kill-switch and rollback rehearsed: the mitigation authorities ask about first is whether you could stop the system, and how fast you did.
- Comms discipline: one voice, no premature causal statements, customer notification templates pre-approved.
When the incident involves a vendor’s model, hour one includes invoking the contractual cooperation clause; if your contract lacks one, that is a today problem, not an incident-day discovery.
This article is for general information only and does not constitute legal advice. It reflects the position as of July 2026.
Author
-
View all postsMümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement.
If this is on your desk
Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.
Founder AcademyBook an intro callMore from Vircon Insights
You Didn’t Train the Model, but You Still Have AI Act Obligations: GPAI Rules for Companies Building on GPT, Claude and Llama
July 14, 2026The Classification Memo: How to Map Your Product to the AI Act in One Afternoon
July 30, 2026AI Credit Scoring: The Four-Floor Compliance Stack for Fintechs (KVKK, BDDK, AI Act, Discrimination)
July 23, 2026Deepfakes and Synthetic Content: Building One Product for Ankara’s Criminal Draft and Brussels’ Labelling Rules
July 17, 2026Türkiye Raises the Fintech Capital Bar Again: New Minimum Equity Floors for Payment and E-Money Institutions
August 7, 2026Türkiye's DPA Governs by Principle Decision: What the Accident Data and Guest ID Rulings Tell Product Teams
August 5, 2026Related Practice Areas
Privacy & Cybersecurity
KVKK and GDPR compliance, breach response, cybersecurity governance.
View service →Corporate Law
Share transfers, capital increases, board structuring, governance.
View service →ICOs, Crypto & Blockchain
Crypto-asset regulation, token offerings, exchange and custody licensing.
View service →