A Turkish AI startup sold a hiring-assessment tool to companies in Europe. The product was good, sales were growing. Then a German customer added a single clause to the contract: “Document your compliance with the EU AI Act.” The team thought, “we’re in Turkey, why would an EU law bind us?” But the product was used in the EU, and hiring AI fell into the law’s “high-risk” category. The problem wasn’t geography; it was not knowing the law applies by market.
The EU AI Act (Regulation 2024/1689) is the world’s first comprehensive AI regulation and, much as KVKK did with GDPR years ago, it produces an effect that reaches beyond borders. Even if you aren’t established in the EU, you can fall within scope if your AI system is used in the EU market. In this piece, we cover the law’s logic and the steps a Turkish startup selling into the EU should take.
Why It Concerns You: Market-Based Application
This is a logic familiar from the KVKK + GDPR pairing: the law looks not at where the company is established, but at where the system is used. If your AI system’s output is used in the EU — your customer is there, your users are there — the obligations find you too. Access to the EU market is increasingly conditioned on compliance with these standards.
The Law’s Backbone: Risk-Based Classification
The EU AI Act doesn’t treat all AI systems alike; it builds four tiers by risk:
- Unacceptable risk (prohibited) — practices like social scoring and manipulative techniques are banned outright.
- High risk — areas such as hiring, credit, education, critical infrastructure, and biometric identification. This is where the weight of obligations sits.
- Limited risk — transparency obligations (e.g., telling users they’re interacting with an AI; labeling generated content).
- Minimal risk — most applications; no special burden.
Determining the correct tier is the first and most critical step, because all obligations derive from this classification.
If You’re a High-Risk System: The Obligations
If your product is in the high-risk category (hiring AI is a typical example), the law imposes concrete obligations: establish a risk-management system, ensure data governance and data quality, keep technical documentation and records, enable human oversight, ensure accuracy/robustness/cybersecurity, and meet transparency obligations. An impact assessment (including a fundamental-rights impact assessment — FRIA) is increasingly a central tool.
The Intersection with KVKK
The EU AI Act and KVKK are separate but interwoven regimes. If your AI system processes personal data, then alongside AI Act obligations, KVKK’s processing condition, right to object to automated decisions (art. 11(1)(g)), and transparency rules also apply. Building these two frameworks together serves both EU-market access and Turkish compliance at once — we cover that intersection in our piece on generative AI at work and KVKK.
A Checklist for a Turkish Startup Selling into the EU
- Determine the risk class — which tier is your system in? A high-risk area (hiring, credit, biometrics)?
- Prohibited-practice check — does the product in no way fall into the unacceptable-risk category?
- If high-risk, a compliance file — risk management, data governance, technical documentation, human oversight.
- Transparency — telling users they’re interacting with an AI; labeling generated content.
- Authorized representative — if you aren’t established in the EU, appointing an authorized representative may arise where required.
- KVKK compliance — if personal data is processed, a processing condition, automated decisions, and a privacy notice.
Treat Compliance as a Market Ticket, Not a Barrier
For a Turkish startup selling into Europe, the EU AI Act is not a wall but an entry ticket. The logic KVKK built years ago with GDPR now extends to AI: those who build compliance early enter the market early and safely. Determine your risk class and prepare your compliance file before opening the product to the EU — because if you wait until a customer asks for it in a contract annex, you’re already late.
Selling an AI product into the EU? Let’s set up your risk class and compliance file together. Schedule a call →
Frequently Asked Questions
Why does the EU AI Act bind me if I’m in Turkey?
The law applies by market; if your AI system is used in the EU, you fall within scope.
Where do the heaviest obligations sit?
In high-risk systems (hiring, credit, biometrics): risk management, data governance, documentation, and human oversight.
How does it relate to KVKK?
Separate but interwoven; if personal data is processed, KVKK rules apply at the same time.
Sources
- EU Artificial Intelligence Act (Regulation (EU) 2024/1689) — official portal: https://artificialintelligenceact.eu/
- EU AI Act — Turkish Directorate for EU Affairs: https://www.ab.gov.tr/ab-yapay-zeka-yasasi-yayimlandi_53836.html
- Vircon Legal — Generative AI at Work and KVKK: https://virconlegal.com/generative-ai-at-work-kvkk-compliance/
Role, trigger, duty — the extraterritorial map
| Your situation | AI Act role | Core duties today |
|---|---|---|
| You sell an AI product to EU customers from Türkiye | Provider placing on the EU market | Prohibited-practices screen, Article 50 disclosures, classification memo; EU authorised representative for high-risk when the regime lands |
| Your Turkish customers use outputs in the EU | Covered via output-use limb | Same screens — establishment is irrelevant |
| You build on GPT/Claude/Llama for an EU-facing feature | Deployer (or provider of your system) | Vendor documentation flow-down, transparency notices, human oversight where consequential |
| Türkiye-only product, no EU users, no EU output | Outside the Act | KVKK + Turkish sector rules still apply — and enterprise buyers ask anyway |
Does hosting in the EU alone trigger the Act?
No — the tests are placing on the market, putting into service, or output used in the Union. Hosting location matters for data-protection transfers, not for AI Act scope.
Do we need an EU legal presence?
Not for today’s duties; providers of high-risk systems will need an EU authorised representative when the postponed regime arrives — one more reason to classify early.
This week’s homework
Find your row in the table and write the classification memo for one flagship feature. If you land in row one or three, add the Article 50 inventory from our transparency runbook to the same file.
This article is for general information only and does not constitute legal advice. For a specific situation, please consult Vircon Legal.
Author
-
View all postsMümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals — including crypto-asset infrastructure, fintech and games — bringing a former startup founder's perspective to every engagement.
More from Vircon Insights
C-Corp or LLC? How Startup Founders Should Choose a US Entity
June 13, 2026The Token Is Easy, the Law Is Hard: Real-World Asset Tokenization (RWA) and Turkey
July 9, 2026What You Think Is "Just a Payment Feature" May Be a Loan: The Law of BNPL in Turkey
July 8, 2026Half the Deal Is Signed at Closing: Why Earn-Outs Trigger Disputes, and How to Prevent Them
July 3, 2026Notification Comes Earlier Than You Think: Turkey's New Merger-Control Thresholds and the Tech Exception
July 2, 2026The KVKK Compliance Audit: A Step-by-Step Guide to Measuring Your Data-Protection Health
June 25, 2026Related Practice Areas
Privacy & Cybersecurity
KVKK and GDPR compliance, breach response, cybersecurity governance.
View service →Mergers & Acquisitions
End-to-end M&A: due diligence, structuring, documentation, negotiation.
View service →Startup Law
Incorporation, founder agreements, ESOP, term sheets, regulatory matters.
View service →