Skip to content
September 6, 2026 · English

Risks for AI Providers in Turkey Insights on Bill No. 2/3358

By Av. Asutay Duhan Meydan / Attorney at Law
7 September 2026

Turkey is considering a legislative proposal that could materially alter the regulatory exposure of artificial intelligence providers operating in the country.

Bill No. 2/3358, submitted to the Grand National Assembly of Turkey on 7 November 2025, does not establish a standalone “AI Act”. Instead, it proposes targeted amendments to five existing statutes: Law No. 5651 on Internet Publications, the Turkish Criminal Code No. 5237, the Personal Data Protection Law No. 6698, the Electronic Communications Law No. 5809, and the Cybersecurity Law No. 7545. As of 7 September 2026, the bill remains before the parliamentary committees and has not entered into force.

For AI providers, the most significant aspect of the proposal is not the amount of the administrative fines. It is the creation of a regulatory architecture capable, in different circumstances, of producing content removal, access blocking, provider-level blocking or temporary suspension of operations.

The bill also reaches beyond output moderation. It regulates training datasets, hallucination controls, content verification, human oversight and cybersecurity testing, while introducing potential criminal exposure connected to the design and training of AI systems.

This article examines each provision of the bill from the perspective of an AI provider offering services in Turkey, with particular emphasis on service availability and access-blocking risk.


1. Access-Risk Ranking of the Bill

The provisions do not create the same type of risk. Some expressly authorise blocking. Others create obligations which may ultimately result in suspension or make an AI provider more vulnerable to enforcement under Turkey’s existing internet-control framework.

RankBill ArticleLaw AffectedPrincipal EffectAccess / Availability Risk
1Article 6Cybersecurity Law No. 7545, Art. 7AI-specific technical duties; temporary suspension for serious violationsCRITICAL
2Article 7Law No. 5651, proposed Additional Art. 5Deepfake labelling; blocking for systematic violationsCRITICAL / CONDITIONAL
3Article 5Electronic Communications Law No. 5809, Art. 6Emergency BTK blocking of AI contentVERY HIGH
4Article 8Law No. 5651, Art. 8(1)Expansion of criminal-content blocking catalogueVERY HIGH
5Article 3Law No. 5651, proposed Art. 8(18)Six-hour removal/blocking; joint responsibility of developersHIGH
6Article 9Law No. 5651, Art. 8/AExtends criminal-law exposure to social networks where AI operatesHIGH, BUT CONDITIONAL
7Article 10Entry into forceImmediate effectiveness upon publicationMEDIUM / INDIRECT
8Article 2Turkish Criminal Code No. 5237, Art. 125Developer criminal exposure arising from AI design/trainingLOW DIRECT / HIGH LIABILITY
9Article 4Personal Data Protection Law No. 6698, Art. 12Dataset legitimacy, anonymity and non-discriminationLOW DIRECT
10Article 1Law No. 5651, Art. 2Broad statutory definition of an AI systemLOW DIRECT / SCOPE MULTIPLIER
11Article 11Execution by the PresidentNONE BY ITSELF

The distinction between content-level blocking and provider-level unavailability is essential. Not every provision authorising access blocking necessarily permits Turkey to block an entire AI service. Nevertheless, several provisions could, either expressly or through interaction with the existing architecture of Law No. 5651, create that result.


2. Article 1 — The Definition That Determines Who Enters the Regulatory Perimeter

Article 1 would amend Article 2 of Law No. 5651 by introducing a statutory definition of an “artificial intelligence system”.

The proposed definition is broad. It covers software, models, algorithms or programming structures that process data and autonomously or semi-autonomously generate output, make decisions, provide recommendations or take actions through technologies including machine learning, deep learning and artificial neural networks.

There is no direct blocking power in Article 1.

Its significance lies elsewhere: it establishes the perimeter within which the subsequent obligations operate. A broad definition increases the likelihood that not only foundation-model providers, but also AI-enabled search engines, recommendation systems, integrated assistants and other algorithmic services may fall within the proposed framework.

Access risk: Low directly; significant as a scope multiplier.


3. Article 2 — Criminal Liability Linked to AI Design and Training

Article 2 would add a new paragraph to Article 125 of the Turkish Criminal Code, currently the offence of insult.

The proposal provides that a user who directs an AI system towards conduct constituting an offence is to be regarded as the perpetrator. More significantly for providers, it states that the penalty applicable to a developer who, through the design or training of the system, enables the commission of such offences is to be increased by one half.

This does not itself authorise blocking.

It does, however, create potentially serious developer-side exposure because concepts such as “enabling” an offence through design or training are not technically or legally defined. The proposal does not explain whether the relevant threshold is intentional design, knowledge, foreseeable misuse, insufficient safeguards, or merely the technical capacity of a model to generate unlawful output.

There is also an important drafting issue. Although the provision is inserted into Article 125 of the Criminal Code, its language refers more generally to acts constituting offences “under this law”. The relationship between the provision’s location and its apparently wider wording would require substantial clarification.

For AI companies, this provision makes safety-by-design and training governance potentially relevant to criminal-law exposure, rather than merely regulatory compliance.

Access risk: Low directly; provider liability risk: High.


4. Article 3 — Six-Hour Blocking and Joint Responsibility of AI Developers

Article 3 would add a new paragraph 18 to Article 8 of Law No. 5651.

It targets AI-generated content that:

  • violates personality rights;
  • threatens public security; or
  • has been falsely manipulated through deepfake technology.

The proposed rule requires access-blocking and content-removal measures to be implemented within six hours. More unusually, the bill provides that access providers and developers of AI systems are jointly responsible for this obligation.

This is significant because the developer may have no control over the location at which an output is subsequently published.

A user could, for example, generate content through an AI system, download it and republish it on a third-party platform. Yet the proposed wording brings the AI developer into the same statutory responsibility structure as the access provider.

The proposal does not clearly explain how an AI developer is expected to remove content hosted outside its technical infrastructure, nor does Article 3 independently define the sanction specifically applicable to a developer unable to comply.

For providers, this means a rapid notice-and-action architecture may become indispensable.

Access risk: High, principally at content level.


5. Article 4 — Training Dataset Governance Under the Personal Data Protection Law

Article 4 would amend Article 12 of the Personal Data Protection Law No. 6698.

AI datasets would be required to comply with principles of anonymity, non-discrimination and legitimacy, while use of discriminatory datasets would be treated as a data-security violation.

There is no express blocking mechanism.

Nevertheless, this provision could materially affect AI training and data governance in Turkey. Providers relying on large-scale scraped datasets may need to demonstrate a considerably stronger compliance trail concerning personal data, anonymisation and dataset provenance.

The term “legitimacy” is particularly important because it is not defined in the proposed provision.

The bill should not, however, be read as creating a copyright licensing requirement for AI training. It neither amends Turkey’s copyright legislation nor introduces a fair-use, text-and-data-mining or AI-training exception. Accordingly, training-data compliance under Article 4 would not itself resolve copyright entitlement.

Access risk: Low; training and data-governance risk: High.


6. Article 5 — Emergency BTK Power to Block AI Content

Article 5 is one of the proposal’s clearest access-control provisions.

It would amend Article 6 of the Electronic Communications Law No. 5809 by granting the Information and Communication Technologies Authority (BTK) authority to issue an emergency access-blocking decision concerning AI content that threatens:

  • public order; or
  • election security.

Violation may also result in an administrative fine of up to TRY 10 million.

The drafting is strikingly concise. The proposed provision itself does not establish a detailed threshold, procedural test or express judicial-confirmation mechanism comparable to some of the procedures found in Law No. 5651.

Terms such as “public order” and “election security” can cover a wide spectrum of generative-AI activity, particularly during politically sensitive periods.

The provision appears primarily directed at AI content rather than automatic blocking of the AI service itself. Nevertheless, providers distributing the disputed content through their own interfaces may face immediate operational pressure to disable outputs, features or access pathways in Turkey.

Access risk: Very High.


7. Article 6 — The Highest Provider-Level Availability Risk

Article 6 would amend Article 7 of the Cybersecurity Law No. 7545 and impose direct technical obligations on AI service providers.

They would be required to:

  1. ensure the transparency and auditability of training datasets;
  2. establish content-verification mechanisms designed to prevent false and manipulative information;
  3. implement algorithmic controls to reduce hallucination risk;
  4. develop human-approval mechanisms for high-risk applications; and
  5. conduct periodic cybersecurity vulnerability testing.

Failure to comply may result in an administrative fine of up to TRY 5 million.

The critical sentence follows:

serious violations threatening public order may result in a temporary suspension of activity.

This is not technically the same legal instrument as an “access-blocking order”. It is potentially more consequential.

A temporary suspension could operate as a regulatory prohibition on providing the relevant service in Turkey. Depending on implementation, the commercial result may therefore be equivalent to provider-level unavailability.

The provision is also remarkable because it turns matters traditionally associated with model quality into statutory compliance duties. Hallucination reduction, information verification and training-data auditability would no longer be merely internal engineering objectives.

The central legal question will be the standard against which compliance is measured. A duty to “reduce” hallucination is fundamentally different from a duty to eliminate it. The bill does not define the required technical threshold.

For providers, Article 6 is therefore arguably the most consequential provision in the entire proposal.

Access / service-continuity risk: Critical.


8. Article 7 — Deepfake Labelling and Potential Provider-Level Blocking

Article 7 would introduce Additional Article 5 to Law No. 5651.

Where visual, audio or textual content is falsely generated through AI systems as a deepfake, the content would have to carry a clear, understandable and non-removable statement indicating that it was “Generated by Artificial Intelligence”.

Failure to comply may result in fines between TRY 500,000 and TRY 5 million for content providers and/or developers.

The provision then escalates significantly:

where the violation is committed systematically and intentionally, access to the content provider may be blocked.

Additionally, content of this nature that disrupts public order, harms personality rights or serves political-manipulation purposes must be promptly made inaccessible, with a criminal complaint where necessary. BTK would receive monitoring, supervision and guideline-making powers.

The distinction between a developer and a content provider is crucial here.

Developers are expressly exposed to administrative fines. Provider-level blocking, however, is textually directed at the “content provider”. Accordingly, an AI company would face the strongest blocking exposure under this clause where it is also characterised as the relevant content provider under Law No. 5651.

For generative-AI businesses, this provision makes content provenance and synthetic-content labelling a service-availability issue, not merely a transparency issue.

Access risk: Critical where the AI provider qualifies as the content provider; otherwise Very High compliance risk.


9. Article 8 — Expansion of Law No. 5651’s Criminal Blocking Catalogue

Article 8 would amend Article 8(1) of Law No. 5651, the existing statutory catalogue under which internet content may be removed and/or access may be blocked where sufficient suspicion exists that the publication constitutes specified offences.

The proposal adds:

  • insult, under Turkish Criminal Code Article 125;
  • threat; and
  • crimes against humanity, under Article 77.

This is important because existing Article 8 already provides a mature enforcement architecture. Decisions may be issued during investigations and prosecutions, and certain administrative blocking powers are also available. Existing Article 8(17) further provides that blocking should ordinarily be directed at the offending URL or section, but the entire website may be blocked where content-level blocking is technically impossible or insufficient to prevent the violation.

Accordingly, expanding the Article 8 catalogue potentially expands not only the number of removable AI outputs, but also the circumstances in which site-wide blocking can become legally possible under the existing machinery of Law No. 5651.

There is also a notable drafting defect. The bill identifies “threat” as Article 28 of the Turkish Criminal Code. Article 28 is not the substantive offence of threat; the offence is regulated under Article 106. Article 28 concerns coercion, violence, intimidation and threat as circumstances affecting criminal responsibility.

Given that Article 8 concerns a measure capable of restricting access to internet services, this discrepancy is not minor. The principle of legal certainty requires the relevant offence to be identified with precision.

Access risk: Very High.


10. Article 9 — AI Operating Through Social Network Providers

Article 9 would add a new paragraph to Article 8/A of Law No. 5651.

It provides that, for matters listed in Article 8(1), the relevant provisions of the Turkish Criminal Code will also apply to the social network provider on which the relevant AI operates.

This provision is particularly relevant to AI products integrated into social networks.

Its practical exposure may therefore differ between:

  • a standalone AI chatbot;
  • an AI assistant embedded within a social media platform; and
  • an AI system operated by the social network provider itself.

Article 9 does not independently create a new blocking order. However, its placement in Article 8/A matters. Existing Article 8/A is Turkey’s urgent blocking mechanism for circumstances including national security, public order, prevention of crime and public safety. It already permits rapid content removal and access blocking, and in certain circumstances allows blocking of an entire website when URL-level restriction cannot prevent the violation.

Article 9 therefore increases legal exposure within an already powerful enforcement environment.

Access risk: High for AI integrated into social networks; materially lower for providers outside that classification.


11. Articles 10 and 11 — No Transition Period

Article 10 provides that the law would enter into force on the date of publication. Article 11 provides that its provisions would be executed by the President.

Article 11 does not independently create access risk.

Article 10, however, is operationally important because the bill contains no statutory grace period.

If enacted in its present form, providers could theoretically face obligations concerning deepfake labelling, training-data auditability, hallucination controls, human oversight and rapid removal from the date of publication.

For a global foundation-model provider, implementing those requirements is not necessarily a same-day technical exercise.

Article 10 access risk: Medium indirectly because it accelerates exposure.
Article 11 access risk: None independently.


What Does the Bill Mean for AI Providers Operating in Turkey?

Taken as a whole, Bill No. 2/3358 represents a shift from traditional internet regulation towards model-level regulatory responsibility.

Under the proposal, an AI provider may potentially be scrutinised not only for what is published on its service, but also for:

  • how the model was designed;
  • how it was trained;
  • the datasets used for training;
  • whether those datasets are auditable;
  • whether the system generates false or manipulative information;
  • whether hallucination risk has been sufficiently reduced;
  • whether high-risk outputs are subject to human control;
  • whether deepfake outputs are permanently labelled;
  • and how quickly unlawful outputs can be disabled.

The most significant provider risk is therefore service continuity.

Articles 5, 7 and 8 contemplate access-blocking mechanisms. Article 3 imposes a six-hour response architecture and extends responsibility directly to AI developers. Most importantly, Article 6 introduces temporary suspension of activity for serious violations threatening public order.

The bill accordingly creates three escalating levels of enforcement:

content removal → access blocking → suspension of the AI service’s activity.

That structure should matter to every international AI company serving users in Turkey.


What Should AI Providers Prepare For?

If the proposal advances, providers offering AI services in Turkey should begin examining at least the following areas.

First, regulatory classification must be mapped precisely. A company may be treated differently depending on whether it is characterised as an AI developer, service provider, content provider, access provider or social network provider. Several of the bill’s most severe consequences turn on those classifications.

Second, providers need a Turkey-specific rapid response protocol. Article 3’s six-hour deadline and the emergency powers contemplated elsewhere in the proposal make a conventional global trust-and-safety queue potentially insufficient.

Third, synthetic-content provenance should be technically auditable. Providers capable of producing images, audio, video or text that may fall within the proposal’s broad deepfake concept should evaluate durable labelling, metadata, watermarking and provenance systems.

Fourth, political and election-related AI risk requires separate treatment. Article 5 expressly connects emergency blocking powers with election security, while Article 7 refers to political manipulation. Providers should therefore expect heightened enforcement exposure around elections.

Fifth, training-data governance must be documentable. Article 6 does not merely demand responsible training; it calls for transparency and auditability. Providers should be able to establish dataset lineage, governance controls and the relationship between data protection requirements and model training.

Sixth, model-quality controls should generate evidence. If hallucination reduction and prevention of manipulative information become legal duties, it will no longer be sufficient merely to state that safety systems exist. Providers may need evidence of testing, evaluations, mitigation measures, incident response and continuous improvement.

Finally, business-continuity planning is necessary. Providers should consider whether individual functions, modalities or model endpoints can be geo-restricted without disabling the entire service. Where regulators object to one category of output, technical granularity may become the difference between a limited intervention and service-wide unavailability.


Conclusion

Bill No. 2/3358 is still a proposal. It should not be described as current Turkish AI law, and none of the new duties or sanctions discussed above is presently in force. The official parliamentary record continues to list the bill as pending before the relevant committees.

Nevertheless, the proposal deserves considerably more attention from international AI providers than its monetary penalties alone might suggest.

Its most consequential feature is the combination of AI-specific technical obligations with Turkey’s existing access-blocking infrastructure.

The bill would potentially connect model training, hallucination control, synthetic-content labelling, election integrity, public-order regulation and criminal liability to mechanisms capable of limiting the availability of AI services in Turkey.

For providers, the critical question is therefore no longer simply:

“Can this output create legal liability?”

Under the proposed framework, the more important question may become:

“Can failures at the model, training or content-governance level ultimately affect our ability to continue providing the service in Turkey?”

Under several provisions of Bill No. 2/3358, the answer could be yes.

Av. Asutay Duhan Meydan
Meydan AI Law

Primary source: Grand National Assembly of Turkey, 28th Legislative Term, Bill No. 2/3358, Bill on Amendments to Certain Laws. Official TBMM legislative record | Official bill text (PDF)