On 25 June 2024, a draft Artificial Intelligence Law (Esas No. 2/2234) was introduced in the Turkish Grand National Assembly. Two years on, it remains in commission review, but it is the clearest signal of where Turkish AI regulation is heading, and it borrows its skeleton from the EU AI Act. Here is what a Turkey-connected company should take from it.
What the Draft takes from the EU AI Act
- A risk-based architecture. The Draft adopts the EU’s core idea: obligations scale with risk, and “high-risk” systems face registration and conformity assessment before and during use.
- Familiar principles. Security, transparency, fairness, accountability and privacy: the same vocabulary as the EU framework, applied to developers, users, importers and distributors.
- EU-style penalty tiers, in lira. Up to TRY 35 million or 7% of annual revenue for banned applications; TRY 15 million or 3% for compliance failures; TRY 7.5 million or 1.5% for supplying false information in inspections. The structure mirrors the AI Act’s fine architecture almost line by line.
What it leaves out
- No catalogue of high-risk uses. The Draft names the category but not the list. The EU’s Annex III specifies recruitment, credit, education, critical infrastructure and more; the Turkish text leaves classification to future secondary regulation, which means uncertainty for anyone planning today.
- Thin transparency mechanics. There is a transparency principle but no equivalent of the EU’s documentation, record-keeping and post-market monitoring machinery.
- Weaker automated-decision rights. The Draft does not replicate GDPR-style rights against solely automated decisions: though KVKK Article 11 already provides a partial Turkish answer.
- No dedicated regulator, no sandbox. Oversight rides on existing institutions, and there are no innovation provisions: no regulatory sandbox, no R&D incentives.
Regulation is not waiting for the Draft
While 2/2234 sits in commission, Turkish AI regulation is happening through other doors: a November 2025 draft amending the Turkish Penal Code targets AI-generated content and deepfake-related harms; the Personal Data Protection Authority (KVKK) is actively applying existing data-protection law to AI systems (see our analysis of the 2026/921 biometric decision); and sectoral regulators: banking, health, capital markets: are layering AI expectations into their own rulebooks.
What to do now
- Do not wait for the Turkish law. If you serve EU users, the EU AI Act already binds you on its own timeline: including the 2 August 2026 transparency obligations.
- Build to the stricter standard. A product that satisfies the AI Act will almost certainly satisfy 2/2234 in whatever form it passes; the reverse is not true.
- Treat KVKK as your operating AI regulator in Türkiye: automated decisions, biometrics and training data are already regulated territory.
- Watch the penal-code track. If your product generates or distributes synthetic media for the Turkish market, the AI-generated content rules may arrive before the framework law does.
We track both tracks: the framework Draft and the sectoral reality: in our AI & Algorithm Law practice.
Side by side: 2/2234 vs. the AI Act
| Dimension | Draft AI Law (2/2234) | EU AI Act |
|---|---|---|
| Status | In commission; no binding effect yet | In force; obligations phasing in since Feb 2025 |
| Architecture | Principle-based, risk-informed framework in a short text | Detailed risk tiers with annexes, conformity machinery, EU database |
| High-risk regime | Sketched, delegated to secondary regulation | Fully specified; postponed to Dec 2027 / Aug 2028 by the omnibus |
| Enforcement | To be designated; sector regulators fill the gap today | National authorities + AI Office for GPAI; fines up to 7% turnover |
| What binds a Turkish startup today | Nothing from the draft, but KVKK, TCK proposals and sector rules do | Everything already in force, if you target EU users |
Should we build to the Turkish draft or the AI Act?
Build to the AI Act: it is binding for EU-facing products now, and the Turkish draft borrows its architecture: AI Act compliance is forward-compatible with whatever Ankara enacts, rarely the reverse.
Could the draft change materially before enactment?
Yes: commission stage regularly rewrites scope and enforcement. Track the parliamentary file rather than summaries, and treat any product decision resting on the draft’s current text as provisional.
This week’s homework
Write the one-paragraph answer to “which regime governs us today?” for your own product: EU-facing features under the AI Act timeline, Turkish operations under KVKK and sector rules. If that paragraph doesn’t exist, this is the week it gets written.
Sources. Regulation (EU) 2024/1689 (AI Act), Regulation (EU) 2016/679 (GDPR), Law No. 6698 on the Protection of Personal Data (KVKK) and Turkish Penal Code No. 5237. Statute links open the official consolidated Turkish texts on mevzuat.gov.tr.
This article is for general information only and does not constitute legal advice. It reflects the legislative position as of July 2026.
Author
-
View all postsMümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement. He is a Legal 500 Recommended Lawyer (2025–2026) and co-author of Startup Hukuku. Canonical profile: https://mumtazhacipasaoglu.com · Open-access legal guides: https://github.com/mumtazhpo
More from Vircon Insights
Three Ways to Move Up the IPO Queue: Türkiye's New Priority Criteria
September 1, 2026The Regulator Will See You Now: How Startups Get Into the AI Act Sandboxes (Deadline Moved to August 2027)
August 25, 2026A 12-Month Cap on Off-Exchange Share Sales: Rebuilding the Post-IPO Exit Plan
September 1, 2026English Is No Longer the Exception on KAP: The Process to Build Before 1 October 2026
August 31, 2026Your Users Are Younger Than Your Terms Say: Children, Age Assurance and AI Products
August 31, 2026Will Insurance Pay When the Model Is Wrong? E&O, Cyber and Product Liability for AI Companies
August 28, 2026Related Practice Areas
Privacy & Cybersecurity
KVKK and GDPR compliance, breach response, cybersecurity governance.
View service →Mergers & Acquisitions
End-to-end M&A: due diligence, structuring, documentation, negotiation.
View service →Startup Law
Incorporation, founder agreements, ESOP, term sheets, regulatory matters.
View service →