A Doctrinal Analysis under the EU AI Act and Türkiye’s Personal Data Protection Law, with Reference to the Grok Case
Av. Asutay Duhan Meydan
Attorney at Law | Artificial Intelligence Law and Technology Policy
The use of artificial intelligence systems to generate synthetic sexual, intimate or degrading images from photographs of real individuals has created a new field of liability that extends beyond the conventional debate on “harmful content.” In such a case, liability may arise not only for the user who caused the image to be generated, but also for the company that developed the model, the entity operating the model and the platform through which the image was disseminated.
The investigation initiated in Türkiye concerning Grok constitutes a current example of this debate. The Turkish Personal Data Protection Board announced that it had opened an ex officio investigation concerning X Internet Unlimited Company and X.AI Corporation following allegations that Grok had been used to generate sexual images and videos of persons, including children, without their consent, that such content had subsequently been circulated, and that the necessary technical and organisational measures may not have been taken during the development and deployment of the system. As no final infringement decision has yet been made public, the matter should not be treated as a legally established violation, but rather as a case through which a possible structure of liability may be examined.
The hypothetical scenario addressed in this article is as follows: a photograph of a person residing in Türkiye is uploaded to an artificial intelligence system by a third-party user; the system generates a synthetic image depicting that person in a sexual or intimate context in which they were never actually present; and the image is subsequently published on an online platform.
In such circumstances, may the victim bring proceedings not only against the user who caused the image to be generated, but also against the artificial intelligence provider or the platform operator?
In our view, depending on the specific product architecture, the actual roles of the companies involved, the safeguards implemented and the causal relationship between the system and the harm, the answer may be yes. However, such an action cannot be based directly and exclusively on the EU AI Act. Its primary legal foundations would instead consist of Türkiye’s Personal Data Protection Law, the protection of personality rights and Turkish tort law.
1. The AI Act Does Not Create a Direct General Right to Compensation, but It May Define the Applicable Standard of Care
The EU AI Act is a regulatory framework that imposes product-safety, governance, transparency, technical-documentation and risk-management obligations on artificial intelligence providers and certain other operators. Subject to its staged application provisions, the Regulation became generally applicable from 2 August 2026.
The AI Act does not, however, contain a provision comparable to Article 82 GDPR granting every person who suffers harm as a result of an infringement a direct and general right to compensation. Indeed, the AI Act does not displace existing rights to compensation arising under data-protection, consumer or product-liability law; those rights continue to apply separately.
Accordingly, in proceedings brought in Türkiye, the AI Act would not in itself constitute the substantive legal cause of action. The principal legal grounds would include:
- Article 4 of the Personal Data Protection Law, concerning the fundamental principles applicable to processing;
- Articles 5 and 6, concerning the conditions for processing personal data and special categories of personal data;
- Article 11, concerning the rights of the data subject;
- Article 12, concerning technical and organisational security measures;
- Articles 24 and 25 of the Turkish Civil Code, concerning the protection of personality rights;
- Article 49 of the Turkish Code of Obligations, concerning tort liability;
- Article 58 of the Turkish Code of Obligations, concerning non-pecuniary damages.
The real importance of the AI Act lies in its ability to help define the level of care expected of a professional provider. In other words, before a Turkish court, the AI Act may operate not as an autonomous rule establishing a right to damages, but as a strong comparative-law benchmark regarding the foreseeability of risk, the state of the art, the marking of synthetic content and the level of safety reasonably expected from a professional artificial intelligence provider.
The central doctrinal proposition may therefore be formulated as follows:
The public-law and product-governance obligations established by the AI Act may become a supplementary normative standard for determining the content of the duty of care assessed under Türkiye’s Personal Data Protection Law and Turkish tort law.
2. Can a Synthetic Image Constitute Personal Data?
The first issue is whether a synthetic image depicting an event that never occurred can nevertheless qualify as personal data.
Under Türkiye’s Personal Data Protection Law, personal data means any information relating to an identified or identifiable natural person. Processing is not limited to the recording of existing information. It also includes the collection, alteration, reorganisation, disclosure, transfer and making available of personal data.
Against this background, a synthetic image generated by using the victim’s face, body, name or other identifying characteristics may constitute personal data where it can be linked to that specific individual, even though the image does not depict an actual event.
The decisive issue is not merely whether the image is “true,” but whether it generates information or meaning concerning an identifiable person. A synthetic image combines the victim’s identity with a sexual context in which they were never present, thereby producing a false, degrading and harmful representation of that individual in the minds of those who view it.
This is also relevant to the requirement under Article 4 that personal data be accurate and, where necessary, kept up to date. Where processing produces consequences for the individual concerned, the data controller may be expected to exercise active diligence in ensuring the accuracy of the information associated with that person.
A more difficult question is whether a synthetic sexual image should be classified as a “special category of personal data concerning sexual life.”
According to a narrow interpretation, the image does not disclose a true fact concerning the victim’s actual sexual life and should therefore not be treated as special-category data. The representation is entirely artificial and does not reveal any real sexual conduct or circumstance.
According to a protective interpretation, however, the image links the victim’s identity with a sexual context and produces precisely the types of harm to dignity, privacy, reputation and equality that the special-category regime is intended to prevent. Since information relating to sexual life is treated as special-category personal data under Turkish law, the fact that the image is fabricated may not necessarily place it entirely outside the scope of heightened protection.
As no settled Turkish case law currently resolves this issue, it would be difficult to assert a definitive conclusion. Nevertheless, from the perspective of compliance and data security, it would be more defensible for a data controller to treat synthetic sexual imagery as highly sensitive data.
3. Who May Be Sued: The User, the Provider or the Platform?
One of the central difficulties in artificial intelligence litigation is that a single visible output may result from several different processing operations carried out by several different legal entities.
The creation of a synthetic image may involve the following operations:
- uploading the source photograph;
- analysing facial and bodily characteristics;
- processing the user’s prompt;
- generating the synthetic output;
- storing the input and output;
- publishing the image on a platform;
- recommending it to other users;
- subjecting it to safety review;
- retaining complaint records;
- and, in some circumstances, using the interaction for model development.
The same company may not be responsible for all of these operations. The model developer, the entity providing the service to consumers and the platform publishing the content may be separate legal persons.
Under Türkiye’s Personal Data Protection Law, the data controller is the natural or legal person who determines the purposes and means of processing and who is responsible for establishing and managing the data-recording system. The role of each company within a corporate group must therefore be determined by reference not merely to its formal title or contractual designation, but to its actual decision-making authority over the relevant processing operation.
A court should accordingly examine the following questions:
- Who determined that the source photograph would be processed?
- Who operated the model and its safety filters?
- Who determined the retention period for the generated image?
- Who controlled whether the content could be published or recommended on the platform?
- Which entity possessed the ability to remove the content or prevent its regeneration following a complaint?
It would be incorrect to hold every company responsible for every stage of processing. Conversely, where several entities jointly determine the purposes and means of the same processing operation, or contribute through different acts to the same harm, joint liability or joint and several liability may arise.
Article 61 of the Turkish Code of Obligations provides that where several persons jointly cause harm, or are liable for the same harm on different legal grounds, the rules governing joint and several liability may apply. In the internal allocation of liability, the degree of fault attributable to each party and the intensity of the risk created by each may be taken into account.
Three potential layers of liability may therefore be identified.
The first concerns the user who maliciously caused the image to be generated and disseminated.
The second concerns the AI provider responsible for designing or operating safeguards intended to prevent foreseeable misuse.
The third concerns the platform exercising control over the publication, replication and algorithmic amplification of the content.
4. The Central Issue in the Proceedings Is Likely to Be the Security Obligation under Article 12 of the Personal Data Protection Law
The strongest point of legal inquiry concerning the artificial intelligence company is likely to be not whether the image was directly created by an employee of the company, but whether adequate technical and organisational measures had been taken against foreseeable misuse.
Under Article 12 of the Personal Data Protection Law, the data controller must take all necessary technical and organisational measures to prevent unlawful processing and unlawful access to personal data, to ensure the secure retention of such data and to maintain an appropriate level of security. Where data are processed by another person on behalf of the controller, joint responsibility concerning security measures may also arise.
A statement in an acceptable-use policy that “the generation of sexual images of real persons is prohibited” would not, by itself, be sufficient. Judicial scrutiny should instead focus on whether the prohibition was technically effective in practice.
The following matters may be particularly significant:
- Did the system apply additional safeguards when it detected a photograph of a real person?
- Could its filters be bypassed through Turkish-language prompts, slang or indirect wording?
- Was there a precautionary child-safety block where the age of the depicted person was uncertain?
- Could the same user repeatedly generate similar outputs?
- Could previously removed content be regenerated or re-uploaded?
- Could synthetic output be published directly on the platform?
- How quickly did the company intervene following a complaint?
- Were the model, classifier and safety-policy versions operating at the relevant time preserved?
- Had previous incidents rendered the risk foreseeable to the company?
This is where the AI Act becomes relevant.
Article 50 of the AI Act requires certain providers of systems generating synthetic audio, image, video or text content to ensure that the outputs are marked in a machine-readable format and are detectable as artificially generated or manipulated. Certain deployers of deepfake content are also required to disclose that the content has been artificially generated or manipulated.
However, labelling an image as “AI-generated” does not make the content lawful. Such a label may reduce the risk of deception, but it does not eliminate the unlawful processing of the victim’s image, the placement of that image in a sexual context or the resulting interference with personality rights.
The AI Act also attaches importance, in several parts of its framework, to known and reasonably foreseeable misuse. Although those provisions may not apply in an identical manner to every generative-image system, they may assist a Turkish court in determining the content of foreseeable misuse, the state of the art and the technical measures reasonably available at the relevant time.
5. Does the User’s Intentional Conduct Break the Chain of Liability?
The AI provider’s principal defence is likely to be that the harm resulted from the independent and intentional conduct of a malicious user.
The user who entered the unlawful prompt, caused the image to be generated and disseminated it is indeed directly responsible. Nevertheless, the user’s fault does not necessarily eliminate the potential liability of the provider or platform in every case.
The decisive issue is whether the user’s conduct was entirely extraordinary and unforeseeable.
Where the system had previously been used to sexualise or “nudify” real individuals, where the company knew that its filters could be easily bypassed, or where the product enabled the generated image to be disseminated directly to a large audience, the third party’s malicious conduct may not be regarded as wholly unexpected from the provider’s perspective.
In such circumstances, the user and provider may contribute to the same harm through different conduct. The user may have intentionally entered the harmful instruction, while the provider may have failed to implement reasonable safeguards against foreseeable misuse.
Under Turkish tort law, the claimant must generally prove the unlawful act, damage, fault and adequate causal connection. Article 50 of the Turkish Code of Obligations places the burden of proof concerning damage on the injured party, while allowing the court to assess the amount of damage by reference to the ordinary course of events and considerations of equity where precise proof is impossible.
In AI-related litigation, however, much of the relevant evidence will be under the exclusive control of the defendant companies. Model versions, system instructions, safety classifiers, incident logs, complaint-response times, Turkish-language red-team testing and mechanisms preventing regeneration may not be directly accessible to the claimant.
The preservation of evidence will therefore be one of the most important issues in such proceedings. Deleted logs, altered model versions or contradictory explanations provided by different companies may seriously weaken the defence.
6. What Remedies May the Victim Seek?
Article 11 of the Personal Data Protection Law grants the data subject the right to:
- learn whether personal data relating to them have been processed;
- obtain information concerning the purposes of processing;
- learn the third parties to whom the data have been transferred;
- request rectification;
- request deletion or destruction;
- and seek compensation where they have suffered damage as a result of unlawful processing.
In addition, Article 24 of the Turkish Civil Code provides that a person whose personality rights have been unlawfully infringed may seek judicial protection. Unless justified by consent, an overriding private or public interest or statutory authority, an interference with personality rights is unlawful.
Under Article 25, the victim may request:
- prevention of an imminent infringement;
- cessation of an ongoing infringement;
- a declaration of unlawfulness where the effects of the infringement continue;
- publication or notification of the judgment to third parties;
- and transfer of profits obtained as a result of the unlawful infringement.
Claims for pecuniary and non-pecuniary damages are expressly reserved.
Article 49 of the Turkish Code of Obligations requires a person who unlawfully and culpably causes damage to compensate the injured party. Article 58 allows a person whose personality rights have been infringed to claim non-pecuniary damages. In addition to monetary compensation, the court may issue a judgment condemning the infringement or order publication of the judgment.
It is not necessary for the public as a whole to believe that the synthetic image is genuine in order for non-pecuniary harm to arise. The transformation of a person’s face and identity into a sexual representation without their consent, and the association and circulation of that representation in connection with them, may in itself constitute a serious interference with privacy, human dignity, reputation and personal integrity.
Depending on the circumstances, the victim may therefore seek, against the user, provider and platform:
- removal of the content;
- prevention of regeneration and republication;
- preservation of processing and incident records;
- deletion or destruction of personal data;
- an interim injunction;
- compensation for pecuniary damage;
- compensation for non-pecuniary damage;
- and, where appropriate, publication of the judgment.
Conclusion
Liability arising from synthetic sexual imagery cannot be resolved merely by stating that “the user acted maliciously.” Nor should an artificial intelligence provider automatically be held responsible for every harmful output generated by its system.
The correct legal method is to divide the harmful process into its constituent operations.
The processing of the source image, generation of the synthetic output, storage, publication, algorithmic recommendation and response to complaints must be examined separately. For each operation, the natural or legal person exercising control must be identified.
The substantive legal framework for a possible action in Türkiye may therefore be formulated as follows:
Unlawful processing of personal data under the Personal Data Protection Law + infringement of personality rights + failure to implement adequate technical and organisational measures + tort liability.
The EU AI Act would not operate as the direct rule granting compensation. Rather, it would function as a supplementary instrument for defining the technological standard of care. Requirements concerning the marking of synthetic content, the assessment of foreseeable misuse, risk management and safety measures reflecting the state of the art may become relevant when determining fault.
The decisive question concerning the liability of an artificial intelligence provider is therefore not whether the system was capable of producing a harmful output under any circumstances.
The real question is:
Did the company take the measures that could reasonably be expected of it to prevent, detect and limit foreseeable and serious misuse, and to bring the resulting harm to an end without delay?
The answer to that question is likely to become central to future litigation in Türkiye concerning personal data and personality-rights violations caused by artificial intelligence systems.
Legal Notice
This article has been prepared on the basis of publicly available information and constitutes a general legal assessment. It does not allege that any ongoing investigation has established a final infringement by any company. A definitive assessment in a specific case would require examination of the relevant product architecture, the actual roles of the companies involved, the applicable model and safety-system versions, incident records, data flows and contractual arrangements.