Your model made a call and someone was harmed; a wrong triage suggestion, a scoring error that cascaded, generated content that defamed. The next 72 hours decide whether this becomes an engineering story or a legal one. AI incidents now live inside three overlapping regimes, and the companies that handle them well have decided the workflow before the pager goes off.
Regime one: AI Act serious-incident reporting
For high-risk systems, Article 73 requires providers to report serious incidents; death, serious harm to health, serious and irreversible disruption of critical infrastructure, or infringements of fundamental-rights obligations; to market surveillance authorities on short statutory clocks once the causal link is established or reasonably likely. The obligations mature with the high-risk timeline (December 2027 for Annex III after the omnibus), but the institutional muscle (detection, triage, causal assessment, reporting decision) takes longer to build than a template does. Deployers feed this system too: they must inform providers and authorities of incidents they observe.
Regime two: KVKK breach discipline
Many AI incidents are simultaneously data incidents; a model leaking training data, a prompt-injection exfiltration, transcripts exposed. KVKK’s breach practice expects notification to the Authority without delay (the Board’s 72-hour reflex) and to affected persons. If your incident response plan was written for infrastructure breaches only, model-layer scenarios (leakage via outputs, poisoning, injection) belong in it now (our glossary: prompt injection).
Regime three: civil liability, rewritten
The EU’s revised Product Liability Directive explicitly covers software and AI systems: defectiveness can arise from what the system learned after deployment, from failure to supply updates, and disclosure duties in litigation ease the claimant’s evidentiary path. Combined with Turkish general tort and product-safety principles for the home market, the practical exposure is this: your logs are the evidence, and the absence of logs reads worse than a defect. Contract chains matter equally; the indemnity and cooperation clauses from our GPAI piece are what stand between a vendor’s model error and your balance sheet.
The pre-incident package (build in one quarter)
- Incident taxonomy: define what counts as an AI incident for you; harm-touching outputs, rights-touching decisions, data-touching failures; with severity tiers.
- Logging fit for causation: inputs, model/version, key parameters, outputs, human overrides; retention matched to liability windows.
- A dual-clock playbook: KVKK 72-hour lane and AI Act reporting lane in one flowchart, with counsel in the loop at the classification step; because reports are admissions and silence is worse; the sequencing needs judgement.
- Kill-switch and rollback rehearsed: the mitigation authorities ask about first is whether you could stop the system, and how fast you did.
- Comms discipline: one voice, no premature causal statements, customer notification templates pre-approved.
When the incident involves a vendor’s model, hour one includes invoking the contractual cooperation clause; if your contract lacks one, that is a today problem, not an incident-day discovery.
Sources. Regulation (EU) 2024/1689 (AI Act) and Law No. 6698 on the Protection of Personal Data (KVKK). Statute links open the official consolidated Turkish texts on mevzuat.gov.tr.
This article is for general information only and does not constitute legal advice. It reflects the position as of July 2026.
Author
-
View all postsMümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement. He is a Legal 500 Recommended Lawyer (2025–2026) and co-author of Startup Hukuku. Canonical profile: https://mumtazhacipasaoglu.com · Open-access legal guides: https://github.com/mumtazhpo
More from Vircon Insights
Will Insurance Pay When the Model Is Wrong? E&O, Cyber and Product Liability for AI Companies
August 28, 2026Three Ways to Move Up the IPO Queue: Türkiye's New Priority Criteria
September 1, 2026Whose Voice Is It Anyway? Voice Cloning Under Turkish Personality Rights, KVKK Biometrics and FSEK
August 26, 2026The Regulator Will See You Now: How Startups Get Into the AI Act Sandboxes (Deadline Moved to August 2027)
August 25, 2026Every Prompt Is a Border Crossing: Sending Personal Data to Model APIs Under KVKK’s 2024 Transfer Regime
August 21, 2026Synthetic Data Is Not a Legal Loophole: When "Fake" Data Is Still Personal Data
August 20, 2026Related Practice Areas
Privacy & Cybersecurity
KVKK and GDPR compliance, breach response, cybersecurity governance.
View service →Corporate Law
Share transfers, capital increases, board structuring, governance.
View service →ICOs, Crypto & Blockchain
Crypto-asset regulation, token offerings, exchange and custody licensing.
View service →