The first question a Turkish company asks about the EU AI Act is “are we a provider or a deployer?” The second, asked a few minutes later, is “what is that in Turkish law?” The honest answer to the second question is that Türkiye has no AI statute in force, so there is no single place to look. What there is instead is a patchwork — product safety law, data protection law, labour law, consumer law, copyright — that already governs most of what the AI Act regulates, under different names and with different reach.
This page maps one onto the other. Each row takes a term or obligation from Regulation (EU) 2024/1689 as amended by the Digital Omnibus on AI (Regulation (EU) 2026/1744), names its nearest counterpart in Turkish law, and says where they differ. It is the AI counterpart to our US–Türkiye corporate law concordance and is built to be read alongside the AI Act document set and the readiness checklist. Two Turkish laws do most of the work and deserve naming up front: the Personal Data Protection Law (Law No. 6698, “KVKK”) and the Product Safety and Technical Regulations Law (Law No. 7223), which is the Turkish home of the CE-marking system the AI Act is built on.
Scope and actors
| AI Act term | Turkish counterpart | Where they differ |
|---|---|---|
| AI system (Art. 3(1)) | No statutory definition | KVKK regulates “processing”, which includes processing by “wholly or partly automated means” (Art. 3(1)(e)); the system itself is not a legal object. The comprehensive AI bill pending in Parliament (No. 2/2234, submitted June 2024) contains a definition, but it is not law. Until it is, the question “is this an AI system” has no Turkish legal answer; the question “does it process personal data” does. |
| Provider (Art. 3(3)) | İmalatçı (manufacturer) under Law No. 7223, Art. 3; often veri işleyen (processor) or an independent veri sorumlusu (controller) under KVKK | The AI Act’s provider is a product-safety concept: whoever develops the system and places it on the market under its own name. Law No. 7223 has the same figure, the manufacturer, with duties to draw up the technical file, run conformity assessment and affix the marking (Art. 7). Under KVKK the same company is classified by what it does with the data, not by what it built, so a provider can be a processor for one customer and a controller for its own model training. |
| Deployer (Art. 3(4)) | Veri sorumlusu (controller), KVKK Art. 3(1)(ı); the end user under Law No. 7223 | A company using an AI system under its authority is, for the personal data that flows through it, almost always the controller — the party that determines purposes and means. That is where the deployer’s Turkish obligations live: lawful basis, notice, security, data subject rights. Law No. 7223 gives the end user almost no duties; the AI Act gives the deployer several (see Art. 26 below). |
| Importer (Art. 3(6)) / Distributor (Art. 3(7)) | İthalatçı / Dağıtıcı, Law No. 7223, Art. 3, with duties in Arts. 9–10 | Near-identical concepts, because both laws descend from the EU’s New Legislative Framework. A Turkish distributor of a foreign AI product is already an economic operator under Law No. 7223 for any product covered by a technical regulation; AI systems as such are not yet the subject of a Turkish technical regulation. |
| Authorised representative (Art. 3(5), Art. 22) | Yetkili temsilci, Law No. 7223, Art. 3 and Art. 8 | Same concept: a person in the jurisdiction mandated in writing by the manufacturer. A Turkish provider selling a high-risk system into the EU needs one in the Union under the AI Act; a foreign provider selling regulated products into Türkiye needs one here under Law No. 7223. The two do not substitute for each other. |
| Operator (Art. 3(8)) | İktisadi işletmeci (economic operator), Law No. 7223, Art. 3(1)(f) | Both are umbrella terms for everyone in the supply chain. Law No. 7223’s list is manufacturer, authorised representative, importer, distributor and anyone else with obligations under a technical regulation; the AI Act adds product manufacturer and deployer. |
| Deployer becomes provider (Art. 25(1)) | Law No. 7223, Art. 11(1) | The AI Act treats a distributor, importer, deployer or third party as the provider if it puts its own name on a high-risk system, substantially modifies it, or changes its intended purpose so that it becomes high-risk. Law No. 7223 already says the same of importers and distributors who market a product under their own brand or modify it in a way that affects conformity (Art. 11). White-labelling a vendor’s model is the same act under both laws. |
| Extraterritorial scope (Art. 2(1)(a), (c)) | Law No. 7223, Art. 2(2) | The AI Act reaches a Turkish provider that places a system on the EU market, and a Turkish provider or deployer whose system’s output is used in the Union. In the other direction, Law No. 7223 deems products exported to EU Member States to have been placed on the Turkish market (Art. 2(2)) — a Turkish AI exporter is inside both regimes at once. How this plays out for a Turkish startup is the subject of Your Server Is in Turkey, Your Customer Is in Europe. |
The risk architecture
| AI Act term | Turkish counterpart | Where they differ |
|---|---|---|
| Prohibited practices (Art. 5) | No list; nearest are KVKK Art. 6 (special categories) and general personality rights, Civil Code Art. 24 | Türkiye has no catalogue of banned AI uses. Several of the Article 5 practices — emotion recognition at work, biometric categorisation, untargeted facial scraping — involve biometric or other special-category data, which KVKK Art. 6 prohibits processing except on the narrow grounds it lists. Manipulation and social scoring have no specific prohibition; they are attacked, if at all, through personality rights and the KVKK principles in Art. 4. |
| High-risk AI system (Art. 6, Annex III) | No risk tiering; sectoral rules only | Annex III’s list — employment, credit, education, essential services, biometrics, law enforcement — has no Turkish mirror. The nearest thing is sectoral: labour law for recruitment and monitoring, banking regulation for credit decisions, KVKK for everything that touches personal data. A Turkish company classifying its systems does so against the Annex, not against any domestic list. |
| Intended purpose / substantial modification (Art. 3(12), 3(23)) | Law No. 7223, Art. 7(1)(ç) and Art. 11 | The AI Act ties conformity to the purpose declared by the provider and reopens it on a change not foreseen in the initial assessment. Law No. 7223 requires the manufacturer to keep conformity current through changes to design and to the applicable rules, and treats a conformity-affecting modification by a distributor as making it the manufacturer. Same logic, different vocabulary. |
| Transparency obligations (Art. 50) | No general labelling duty; Consumer Protection Law Art. 61, Civil Code Arts. 24–25, KVKK Art. 10 | The AI Act requires people to be told they are dealing with a machine, synthetic content to be machine-readably marked, and deepfakes and AI-generated text on matters of public interest to be disclosed. Türkiye has no such duty in force. Two bills submitted in late 2025 would add labelling of AI-generated content to the Internet Law (No. 5651); until one passes, the tools are advertising law (adverts must be truthful, Consumer Law Art. 61), personality rights for deepfakes of real people, and the KVKK notice duty where personal data is processed. |
| General-purpose AI model (Art. 3(63), Arts. 53–55) | No concept; nearest are KVKK for training data and Law No. 5846 (FSEK) for copyright | Article 53 requires GPAI providers to keep technical documentation, give downstream providers integration information, adopt a copyright policy honouring rights reservations under the DSM Directive, and publish a training-content summary. Turkish copyright law has no text-and-data-mining exception at all, so training on protected works in Türkiye rests on licences or on the ordinary exceptions (quotation, Art. 35; personal use, Art. 38), which were not written for this. The Turkish question is not “did you publish a summary” but “did you have the right”. |
Provider obligations for high-risk systems
| AI Act term | Turkish counterpart | Where they differ |
|---|---|---|
| Risk management system (Art. 9) | KVKK Art. 12 (technical and organisational measures); Law No. 7223, Art. 5 (product must be safe) | Article 9 wants a continuous, documented, lifecycle risk process for the system. KVKK Art. 12 requires the controller to take every technical and administrative measure needed for an appropriate level of security — a security duty, not a system-risk duty. The AI Act’s process is broader; a company that runs it will find KVKK Art. 12 satisfied on the way. |
| Data and data governance (Art. 10) | KVKK Art. 4 (principles), Arts. 5–6 (legal bases), Art. 9 (transfers abroad) | Article 10 is about training, validation and testing datasets: relevance, representativeness, bias examination, gaps. KVKK is about lawfulness: a basis for each processing, accuracy, purpose limitation, minimisation. They overlap on accuracy and bias only partly — KVKK’s “accurate and where necessary up to date” (Art. 4(2)(b)) is a data-subject protection, not a model-quality standard. Both apply to the same dataset at once. |
| Technical documentation (Art. 11, Annex IV) | Teknik dosya, Law No. 7223, Art. 7(1)(b)–(c); kişisel veri işleme envanteri under KVKK | The technical file is a Law No. 7223 institution: drawn up before placing on the market and kept for at least ten years (Art. 7(1)(c)) — the same period as the AI Act’s Art. 18. KVKK’s processing inventory records what personal data is processed and why; it describes the data, not the system. Neither Turkish document is an Annex IV file, but a provider that has one can populate both. |
| Record-keeping / logs (Art. 12, Art. 19) | No general AI logging duty; sectoral retention rules | Article 12 requires high-risk systems to log events automatically; providers keep logs under their control for at least six months (Art. 19). Türkiye imposes logging by sector — hosting providers’ traffic records under Law No. 5651, financial-sector rules — and KVKK expects access logs as a security measure under Art. 12. There is no AI-specific logging duty. |
| Transparency and instructions for use (Art. 13) | Law No. 7223, Art. 7(1)(g)–(ğ); otherwise contract | Law No. 7223 already requires the manufacturer to give end users the information needed to avoid the product’s risks, in Turkish. For AI the practical vehicle is the vendor contract; what a deployer should demand is set out in the AI vendor contract playbook and in Buying an AI Tool, Not Building One. |
| Human oversight (Art. 14) | KVKK Art. 11(1)(g) | The AI Act requires the system to be designed so that natural persons can oversee, understand, override and stop it. KVKK gives the individual a right to object to a result produced against them exclusively through automated analysis — a right after the fact, not a design requirement. The two meet in the deployer’s process: the design must allow a human to act, and the human must actually be able to act when the objection arrives. See When the Model Decides About a Person. |
| Accuracy, robustness, cybersecurity (Art. 15) | KVKK Art. 12; Cybersecurity Law No. 7545 (2025) for the entities it covers | Turkish law addresses security, not accuracy. KVKK Art. 12 covers the personal data; the Cybersecurity Law adds obligations for the organisations within its scope. There is no Turkish standard for the accuracy or robustness of an automated system as such — a gap the AI Act fills for EU-facing systems and that contract has to fill for the rest. |
| Quality management system (Art. 17) | Law No. 7223, Art. 7(1)(ç); ISO/IEC 42001 (voluntary) | Law No. 7223 requires measures to keep serial production in conformity; it does not prescribe a documented QMS. The AI Act does, in detail. ISO/IEC 42001 is the voluntary standard most Turkish companies use to evidence one; certification is not a legal requirement under either law. |
| Conformity assessment, EU declaration of conformity, CE marking (Arts. 43, 47, 48) | Uygunluk değerlendirmesi, uygunluk beyanı, uygunluk işareti, Law No. 7223, Arts. 3 and 7(1)(b) | Türkiye applies the CE system through the customs union; the vocabulary in Law No. 7223 is the same as the EU’s. What is missing is an AI-specific technical regulation designating which systems need third-party assessment and by whom. A Turkish provider’s Annex III system therefore follows the AI Act’s route — mostly internal control — for the EU, and has no Turkish assessment route at all. |
| Registration in the EU database (Art. 49) | VERBİS, KVKK Art. 16 | Both are public registers, but of different things. The EU database lists high-risk AI systems; VERBİS lists data controllers and what they process. A Turkish deployer above the VERBİS thresholds is registered as a controller whether or not it uses AI; its AI systems appear nowhere. |
| Post-market monitoring (Art. 72) | Law No. 7223, Art. 7(1)(d) and (h) | Law No. 7223 already requires manufacturers to sample and test marketed products in proportion to their risk, keep records of complaints and non-conforming products, and take corrective action including withdrawal and recall. The AI Act asks for the same, as a documented plan proportionate to the system. |
| Serious incident reporting (Art. 73) | KVKK Art. 12(5) (data breach notification); Law No. 7223, Art. 18 (risk notification) | Article 73 reports run to the market surveillance authority within 15 days of awareness, 10 days for a death and 2 days for widespread infringements. KVKK Art. 12(5) is triggered only by unlawful acquisition of personal data and runs “as soon as possible” — the Board’s practice is 72 hours — to the Board and the affected persons. Law No. 7223 requires economic operators to notify the competent authority of products found to carry a risk. An AI incident can trigger any, all or none of these. |
Deployer obligations
| AI Act term | Turkish counterpart | Where they differ |
|---|---|---|
| Use in accordance with instructions; assign competent human oversight (Art. 26(1)–(2)) | KVKK Art. 12 (administrative measures); Turkish Commercial Code Arts. 367 and 375 (organisation of management) | Türkiye has no deployer-specific AI duty. What it has is a board that is responsible for how the company is organised and supervised, and a controller that must take administrative measures for data security. Assigning named, trained people to oversee a system is how both are evidenced. See The AI Decision Belongs to the Board. |
| Log retention by deployers (Art. 26(6)) | No equivalent | Deployers keep the logs under their control for at least six months unless other law says otherwise. No Turkish rule requires a user of an automated system to keep its logs; retention follows the deployer’s own KVKK retention and destruction policy, which will often be longer. |
| Inform workers’ representatives and affected workers (Art. 26(7)) | Labour Law Art. 22 (change to working conditions); Art. 75 (use of information about the employee) | Türkiye has no works councils and no statutory duty to inform workers before an AI system is deployed. What it has is stricter in a different place: a substantial change to working conditions is valid only if notified in writing and accepted by the employee within six working days (Art. 22), and the employer may use information it holds about an employee only lawfully and in good faith (Art. 75). Where a union is present, collective agreements may add consultation. See AI in the Workplace. |
| Inform natural persons subject to decisions (Art. 26(11)) | KVKK Art. 10 (notice duty) | KVKK’s notice at collection covers who the controller is, purposes, recipients, method and legal basis, and the data subject’s rights; it does not require saying that a decision will be made by an AI system. The AI Act does. A Turkish notice that adds one sentence about automated decision-making satisfies both. |
| Fundamental rights impact assessment (Art. 27) | No equivalent | KVKK has no mandatory data protection impact assessment, so there is no Turkish document into which an FRIA folds. Companies that run an FRIA for EU deployments produce a record that has no Turkish analogue and considerable evidentiary value under KVKK Art. 12 and the Commercial Code’s duty of care. |
| AI literacy (Art. 4) | No statute; KVKK Art. 12 practice, Occupational Health and Safety Law Art. 17 | Since the Omnibus, providers and deployers must take measures to support their staff’s AI literacy, without a guaranteed level. Türkiye has no such duty; training records are expected by the Board under Art. 12 and required for new technology under health and safety law. One training programme serves all three; see the AI literacy duty after the Omnibus. |
Rights, authorities and penalties
| AI Act term | Turkish counterpart | Where they differ |
|---|---|---|
| Right to lodge a complaint (Art. 85) | KVKK Arts. 13–14 | Any person may complain to a market surveillance authority under the AI Act. Under KVKK the individual must first apply to the controller, who has thirty days to answer (Art. 13), and may complain to the Board only after that route is exhausted (Art. 14(2)). Different authority, different sequence, and the Turkish route covers only personal data. |
| Right to explanation (Art. 86) | KVKK Art. 11(1)(b), (c), (g) | Article 86 gives a person subject to a high-risk decision the right to a clear and meaningful explanation of the system’s role and the main elements of the decision. KVKK gives the right to know whether and why data was processed and to object to a purely automated adverse result; it does not require an explanation of the decision’s logic. In practice a Turkish company answering an Art. 11 request about an automated decision is wise to give the Art. 86 explanation anyway. |
| National competent authority; AI Office (Arts. 64, 70) | No designated AI authority | The Personal Data Protection Board acts on the data side; the Ministry of Industry and Technology coordinates the AI Action Plan adopted by Presidential Circular 2026/9 (August 2026), which sets policy but binds no company directly. Product-safety authorities under Law No. 7223 would acquire jurisdiction only once an AI technical regulation exists. See what the Action Plan changes for companies. |
| Penalties (Art. 99) | KVKK Art. 18; Law No. 7223, Art. 20; Commercial Code Art. 553 | The AI Act’s ceilings are EUR 35 million or 7% of worldwide turnover for prohibited practices, EUR 15 million or 3% for most other breaches, EUR 7.5 million or 1% for false information, with SMEs paying the lower of the two. Turkish fines are fixed lira bands indexed annually — KVKK Art. 18 for notice, security and Board-order breaches, Law No. 7223 Art. 20 for product non-conformity — with no turnover-based ceiling. Directors’ personal liability under Commercial Code Art. 553 is the Turkish exposure that has no EU analogue. |
| Regulatory sandbox (Art. 57) | No AI sandbox; sectoral test environments only | Member States must have at least one AI sandbox operational by August 2027. Türkiye has sector-specific test regimes in finance and none for AI generally; the Action Plan contemplates them without creating any. |
| Staged application (Art. 113) | Nothing in force; three bills pending | Prohibitions and the literacy duty have applied since 2 February 2025, GPAI and governance provisions since 2 August 2025, the general body of the Act from 2 August 2026; the Omnibus moved the high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I) and gave generative systems placed on the market before 2 August 2026 until 2 December 2026 to mark synthetic content (Article 50 otherwise applies from 2 August 2026); it also added a prohibition on AI systems generating non-consensual intimate imagery and child sexual abuse material, applying from 2 December 2026. In Türkiye the comprehensive bill of 2024 and the two labelling bills of late 2025 await the plenary agenda. For a Turkish company the operative dates are the EU’s, because Article 2 reaches it. |
How to read the map
Three patterns run through the table. Where the AI Act is product safety law — providers, importers, technical files, conformity, marking, recall — Türkiye already has the same architecture in Law No. 7223, because both descend from the same EU framework; what is missing is the AI-specific technical regulation that would switch it on. Where the AI Act is data protection law — governance, oversight, notice, rights — KVKK covers the personal-data part of the ground, with a narrower notice, no impact assessment and a right to object rather than a right to an explanation. Where the AI Act is new — risk tiers, prohibited practices, labelling of synthetic content, GPAI duties, worker information — Türkiye has nothing in force and three bills pending.
The practical consequence for a Turkish company is that “AI Act compliance” and “Turkish compliance” are not two projects. The AI Act’s documents — the inventory, the classification memo, the technical file, the oversight design, the training record — are the evidence a Turkish regulator, customer or court will accept for the KVKK and Commercial Code duties that already apply. Building them once, for the stricter regime, is the efficient route; the AI Compliance Hub collects the material for doing so.
This concordance is for general information and is not legal advice. EU references are to Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744; Turkish references are to the laws named, as in force at publication. Application dates, thresholds and fine amounts should be checked against the current texts.
Sources. Regulation (EU) 2024/1689 (AI Act), Law No. 6698 on the Protection of Personal Data (KVKK), Product Safety and Technical Regulations Law No. 7223, Law No. 5651 on the Regulation of Publications on the Internet and Combating Crimes Committed by Means of Such Publications and Law No. 5846 on Intellectual and Artistic Works. Statute links open the official consolidated Turkish texts on mevzuat.gov.tr.
Author
-
View all postsMümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement. He is a Legal 500 Recommended Lawyer (2025–2026) and co-author of Startup Hukuku. Canonical profile: https://mumtazhacipasaoglu.com · Open-access legal guides: https://github.com/mumtazhpo
More from Vircon Insights
The Turkish Equivalent Of…: A US–Türkiye Corporate Law Concordance for Founders, Investors and Counsel
October 9, 2026Terms of Service for a Turkish SaaS: General Terms Control, Law No. 6563 and the B2B–B2C Line
October 3, 2026Raising Venture Capital as a Turkish Game Studio: Structure, IP and Investor Terms
October 1, 2026The Departing Founder's Shares: Structuring Good Leaver / Bad Leaver under Turkish Law
September 16, 2026Is a Term Sheet Binding? What a Letter of Intent Is Really Worth Under Turkish Law
September 3, 2026How SAFEs Work under Turkish Law: Discounts, Caps and the Limits of the TCC
September 2, 2026Related Practice Areas
Privacy & Cybersecurity
KVKK and GDPR compliance, breach response, cybersecurity governance.
View service →Corporate Law
Share transfers, capital increases, board structuring, governance.
View service →US Company Formations & Flip-Ups
Delaware C-Corp, flip-up structures, SAFE/convertible notes, 83(b).
View service →