On 25 June 2024, a draft Artificial Intelligence Law (Esas No. 2/2234) was introduced in the Turkish Grand National Assembly. Two years on, it remains in commission review — but it is the clearest signal of where Turkish AI regulation is heading, and it borrows its skeleton from the EU AI Act. Here is what a Turkey-connected company should take from it.
What the Draft takes from the EU AI Act
- A risk-based architecture. The Draft adopts the EU’s core idea: obligations scale with risk, and “high-risk” systems face registration and conformity assessment before and during use.
- Familiar principles. Security, transparency, fairness, accountability and privacy — the same vocabulary as the EU framework, applied to developers, users, importers and distributors.
- EU-style penalty tiers, in lira. Up to TRY 35 million or 7% of annual revenue for banned applications; TRY 15 million or 3% for compliance failures; TRY 7.5 million or 1.5% for supplying false information in inspections. The structure mirrors the AI Act’s fine architecture almost line by line.
What it leaves out
- No catalogue of high-risk uses. The Draft names the category but not the list. The EU’s Annex III specifies recruitment, credit, education, critical infrastructure and more; the Turkish text leaves classification to future secondary regulation — which means uncertainty for anyone planning today.
- Thin transparency mechanics. There is a transparency principle but no equivalent of the EU’s documentation, record-keeping and post-market monitoring machinery.
- Weaker automated-decision rights. The Draft does not replicate GDPR-style rights against solely automated decisions — though KVKK Article 11 already provides a partial Turkish answer.
- No dedicated regulator, no sandbox. Oversight rides on existing institutions, and there are no innovation provisions — no regulatory sandbox, no R&D incentives.
Regulation is not waiting for the Draft
While 2/2234 sits in commission, Turkish AI regulation is happening through other doors: a November 2025 draft amending the Turkish Penal Code targets AI-generated content and deepfake-related harms; the Personal Data Protection Authority (KVKK) is actively applying existing data-protection law to AI systems (see our analysis of the 2026/921 biometric decision); and sectoral regulators — banking, health, capital markets — are layering AI expectations into their own rulebooks.
What to do now
- Do not wait for the Turkish law. If you serve EU users, the EU AI Act already binds you on its own timeline — including the 2 August 2026 transparency obligations.
- Build to the stricter standard. A product that satisfies the AI Act will almost certainly satisfy 2/2234 in whatever form it passes; the reverse is not true.
- Treat KVKK as your operating AI regulator in Türkiye — automated decisions, biometrics and training data are already regulated territory.
- Watch the penal-code track. If your product generates or distributes synthetic media for the Turkish market, the AI-generated content rules may arrive before the framework law does.
We track both tracks — the framework Draft and the sectoral reality — in our AI & Algorithm Law practice.
Side by side: 2/2234 vs. the AI Act
| Dimension | Draft AI Law (2/2234) | EU AI Act |
|---|---|---|
| Status | In commission; no binding effect yet | In force; obligations phasing in since Feb 2025 |
| Architecture | Principle-based, risk-informed framework in a short text | Detailed risk tiers with annexes, conformity machinery, EU database |
| High-risk regime | Sketched, delegated to secondary regulation | Fully specified; postponed to Dec 2027 / Aug 2028 by the omnibus |
| Enforcement | To be designated; sector regulators fill the gap today | National authorities + AI Office for GPAI; fines up to 7% turnover |
| What binds a Turkish startup today | Nothing from the draft — but KVKK, TCK proposals and sector rules do | Everything already in force, if you target EU users |
Should we build to the Turkish draft or the AI Act?
Build to the AI Act: it is binding for EU-facing products now, and the Turkish draft borrows its architecture — AI Act compliance is forward-compatible with whatever Ankara enacts, rarely the reverse.
Could the draft change materially before enactment?
Yes — commission stage regularly rewrites scope and enforcement. Track the parliamentary file rather than summaries, and treat any product decision resting on the draft’s current text as provisional.
This week’s homework
Write the one-paragraph answer to “which regime governs us today?” for your own product — EU-facing features under the AI Act timeline, Turkish operations under KVKK and sector rules. If that paragraph doesn’t exist, this is the week it gets written.
This article is for general information only and does not constitute legal advice. It reflects the legislative position as of July 2026.
Author
-
View all postsMümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals — including crypto-asset infrastructure, fintech and games — bringing a former startup founder's perspective to every engagement.
If this is on your desk
Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.
Founder AcademyBook an intro callMore from Vircon Insights
Gaming Law in Türkiye: A Guide for Studios, Publishing Deals and Esports Teams
July 17, 2026Deepfakes and Synthetic Content: Building One Product for Ankara\u2019s Criminal Draft and Brussels\u2019 Labelling Rules
July 17, 2026You Didn't Train the Model — You Still Have AI Act Obligations: GPAI Rules for Companies Building on GPT, Claude and Llama
July 14, 2026The EU AI Act Was Postponed — Except the Part That Hits on 2 August
July 6, 2026Türkiye’s Crypto Advertising and Sweepstakes Rules: The Banned Pages of the Growth Playbook
July 16, 2026Türkiye’s DPA Publishes Its Agentic AI Guide: Reading Notes for Everyone Building or Deploying Agents
July 16, 2026Related Practice Areas
Privacy & Cybersecurity
KVKK and GDPR compliance, breach response, cybersecurity governance.
View service →Mergers & Acquisitions
End-to-end M&A: due diligence, structuring, documentation, negotiation.
View service →Startup Law
Incorporation, founder agreements, ESOP, term sheets, regulatory matters.
View service →