Skip to content
August 6, 2026 · English

EU AI Act in Turkey: Five Critical Legal Gaps

How the Absence of an Equivalent Framework Creates Structural Risks Under Turkish Law

Av. Asutay Duhan Meydan
Meydan AI & Tech Law

Introduction

EU AI Act in Turkey ;

The debate concerning the EU AI Act in Turkey is no longer merely a matter of comparative law. It raises a direct question about whether the Turkish legal system possesses sufficient preventive safeguards for artificial intelligence systems capable of affecting employment, credit, insurance, public services, personal data and access to justice.

The absence of a comprehensive artificial intelligence statute in Turkey does not mean that artificial intelligence operates outside the legal order.

Depending on the facts of a particular case, the use of an AI system may already be governed by the Turkish Personal Data Protection Law No. 6698, the Turkish Civil Code, the Turkish Code of Obligations, consumer law, employment law, intellectual property law, criminal law and sector-specific regulations.

The principal problem is therefore not the complete absence of applicable law. It is the absence of a horizontal and binding legal framework capable of regulating an AI system before it causes harm.

As of August 2026, Turkey has not enacted a statute equivalent to the European Union Artificial Intelligence Act. The principal Artificial Intelligence Bill, submitted to the Grand National Assembly of Turkey on 24 June 2024 under file number 2/2234, remains before the relevant parliamentary committees. The Parliamentary Research Commission on Artificial Intelligence completed its work and submitted its report in February 2026, but a parliamentary research report does not itself create enforceable duties for AI providers, deployers or public authorities.

The position within the European Union has developed considerably. Regulation (EU) 2024/1689 entered into force on 1 August 2024 and became generally applicable on 2 August 2026. Regulation (EU) 2026/1744, known as the AI Omnibus, entered into force on 27 July 2026 and amended several provisions and application dates while preserving the central risk-based structure of the EU AI Act. In particular, the application of the principal high-risk system obligations was postponed until 2 December 2027 for systems listed in Annex III and until 2 August 2028 for AI systems embedded in certain regulated products.

These postponements do not alter the central legal distinction between the European and Turkish approaches. The EU AI Act establishes an ex ante governance system. It determines which uses are prohibited, which systems are high-risk, what documentation must be maintained, which risks must be assessed and what information must be provided before or during deployment.

Turkish law, by contrast, currently operates primarily through fragmented and predominantly ex post mechanisms. It intervenes after personal data have been unlawfully processed, after a discriminatory decision has been made, after a person’s image has been manipulated or after a defective AI-supported service has caused damage.

This difference creates five structural risks for the Turkish legal system.

Why the EU AI Act in Turkey Matters

The absence of the EU AI Act in Turkey creates a structural gap between existing legal remedies and the preventive regulation of artificial intelligence systems. Turkish law may respond after harm occurs, but it does not yet provide a comprehensive framework governing prohibited practices, high-risk systems, transparency obligations and the rights of affected individuals.

1. The Absence of a Horizontal Prohibition on Intrinsically Abusive AI Practices

Article 5 of the EU AI Act does not merely regulate harmful outcomes. It prohibits certain AI practices because the practices themselves are considered incompatible with human dignity, autonomy, equality and other fundamental rights.

The prohibited practices include AI systems that materially manipulate human behaviour, exploit vulnerabilities arising from age, disability or social and economic circumstances, produce unlawful forms of social scoring, predict criminality solely through profiling, create facial-recognition databases through untargeted scraping, infer emotions in workplaces or educational institutions and categorise individuals through biometric data in order to infer sensitive characteristics.

The 2026 AI Omnibus extended Article 5 further. It introduced specific prohibitions relating to AI systems used to generate or manipulate realistic non-consensual intimate material involving identifiable persons and systems used to generate or manipulate child sexual abuse material. These new provisions will apply from 2 December 2026. The amendment also places responsibility on providers where the generation of such material is a reasonably foreseeable and reproducible outcome and reasonable technical safeguards have not been implemented.

A Turkish scenario

Consider an AI application made available to users in Turkey. The application allows a user to upload an ordinary photograph of a real person and generate a realistic nude image of that person.

The provider may argue that it did not create or distribute the final image, that the output was generated following a user request and that the service is merely a general-purpose image tool.

The person depicted may rely on personality rights under Articles 24 and 25 of the Turkish Civil Code, request the prevention or cessation of the interference and seek compensation under the Turkish Code of Obligations. Personal data legislation may also apply where the image or other identifiable information has been processed unlawfully. Depending on the particular content and manner of distribution, criminal provisions may become relevant.

However, these remedies do not answer the prior regulatory question:

Should a provider be legally permitted to place an AI system on the Turkish market where the generation of realistic non-consensual intimate content is an intended, foreseeable or reproducible use of that system?

Turkish law does not currently provide a horizontal AI-specific prohibition directed at the placing on the market, putting into service or operation of such a system.

The result is a shift of the legal burden from the provider to the victim. The victim must identify the relevant actor, establish the unlawful interference, locate the content, preserve evidence, demonstrate damage and seek removal or compensation after the harm has already occurred.

The EU model intervenes at an earlier stage. It examines not only the individual output but also the design, intended purpose, foreseeable misuse, preventive safeguards and distribution strategy of the AI system.

The absence of an equivalent rule in Turkey creates three consequences:

First, providers may not be under a clear legal obligation to prevent foreseeable forms of severe AI-enabled abuse.

Second, administrative authorities may lack an explicit legal basis to prohibit or withdraw the AI system itself rather than addressing individual outputs one by one.

Third, civil and criminal liability may remain dependent on conventional statutory categories that were not drafted to regulate the placing on the market of an AI capability capable of generating harm at scale.

This distinction is significant. Regulating a harmful image is not the same as regulating the system that repeatedly and predictably generates such images.

2. The Absence of Mandatory Lifecycle Safeguards for High-Risk AI Systems

The second structural gap concerns high-risk AI systems.

The EU AI Act classifies certain systems as high-risk because their use may substantially affect access to employment, education, credit, insurance, healthcare, public benefits, justice and other essential areas.

Annex III includes, among other systems, AI used to analyse and filter job applications, evaluate employees, determine access to educational institutions, assess creditworthiness, price life and health insurance, determine access to public assistance and support judicial decision-making.

Articles 8 to 15 establish a lifecycle compliance structure for these systems. Depending on the system, providers must implement risk-management processes, data-governance measures, technical documentation, automatic record-keeping, information for deployers, human oversight, accuracy, robustness and cybersecurity safeguards.

Article 10 is particularly important. It requires training, validation and testing datasets to be relevant, sufficiently representative and, to the greatest extent possible, complete and free from errors. Providers must examine potential biases, identify shortcomings and adopt measures to prevent or mitigate discriminatory effects.

A Turkish scenario

Assume that a Turkish insurance company uses an AI system to assess applications for life insurance.

The model analyses the applicant’s age, place of residence, occupation, purchasing habits and inferred health risks. The training dataset contains disproportionately negative historical outcomes for applicants from particular regions or socioeconomic groups.

The system assigns a high-risk score and offers either an excessively high premium or no coverage at all.

The applicant may attempt to rely on the PDPL, contractual principles, consumer law or general anti-discrimination rules. Article 11 of the PDPL grants a data subject the right to object where the analysis of personal data exclusively through automated systems produces an adverse result.

Nevertheless, the following questions remain unresolved:

Was the dataset tested for regional or socioeconomic bias?

Was the model validated for the Turkish population in which it was deployed?

Were performance thresholds determined before deployment?

Were inaccurate or discriminatory outcomes logged?

Was a qualified person authorised to disregard the model’s recommendation?

Was the system tested against foreseeable misuse or data drift?

Which actor was responsible: the model developer, the foreign provider, the local integrator or the insurance company?

Turkish personal data law can regulate the lawfulness of personal data processing. It does not, by itself, establish a complete product- and system-governance regime covering the technical quality, documentation, performance, human oversight and cybersecurity of every high-risk AI system.

The Turkish Personal Data Protection Authority has issued recommendations calling for privacy impact assessments, human-rights-based risk analysis, data quality, accountability and human intervention. These recommendations demonstrate that the underlying risks are recognised. They do not, however, constitute a general statutory conformity regime equivalent to Articles 8 to 15 of the EU AI Act.

The practical consequence appears most clearly during litigation.

A claimant may suspect that an algorithmic system produced a discriminatory or inaccurate result but may have no access to:

  • the version of the model used on the relevant date;
  • the training and validation methodology;
  • the variables that materially influenced the outcome;
  • system logs;
  • known error rates;
  • bias testing;
  • internal incident reports; or
  • human-oversight records.

Without mandatory documentation and record-keeping, the substantive right to claim compensation may exist while the evidence required to prove the claim remains exclusively within the control of the provider or deployer.

The lack of high-risk system rules therefore creates not only a regulatory problem but also an evidential problem.

3. The Absence of a Fundamental-Rights Impact Assessment Before Public-Sector Deployment

Article 27 of the EU AI Act requires certain public bodies, entities providing public services and specified private deployers to conduct a fundamental-rights impact assessment before deploying a high-risk AI system.

The assessment must identify the context in which the system will be used, the persons and groups likely to be affected, the specific risks of harm, the applicable human-oversight measures and the arrangements to be followed if those risks materialise. The deployer must also identify internal governance and complaint mechanisms.

This obligation is broader than an ordinary technical procurement assessment.

It requires the public authority to consider not merely whether the system works, but whether its use is compatible with equality, human dignity, privacy, access to public services, due process and effective remedies.

A Turkish scenario

Assume that a municipality introduces an AI system to identify applications that may involve social-assistance fraud.

The system assigns risk scores by analysing household information, address history, previous applications, utility consumption, family composition and other available records.

Applicants with high scores are subjected to additional inspections, delayed payments or the suspension of benefits.

Under Turkish administrative law, an affected person may challenge the final administrative act. Article 125 of the Constitution provides that recourse to judicial review is available against acts and actions of the administration, while Article 36 protects access to courts and the right to a fair trial.

However, judicial review takes place after the system has been procured, integrated and used.

Without a mandatory AI-specific impact assessment, the administrative authority may never have been legally required to document:

  • why an AI system was necessary;
  • whether a less intrusive alternative was available;
  • which groups were likely to be disproportionately affected;
  • whether historical data contained discriminatory patterns;
  • how false-positive outcomes would be corrected;
  • whether human officials could override the score;
  • how affected persons would be informed; and
  • how complaints would be investigated.

This absence directly affects judicial review.

A court cannot effectively assess proportionality, equality or misuse of administrative discretion where the administration itself has not created a record of the system’s intended purpose, risks, limitations and oversight structure.

The public authority may also depend on a private technology provider. The authority may possess the final score but not the technical information necessary to explain how that score was produced.

The result is a fragmented chain of responsibility:

The public authority may state that it relied on the provider’s system.

The provider may state that the final decision was made by the public authority.

The system integrator may state that it merely implemented the model according to contractual instructions.

Article 27 seeks to prevent this structure from becoming a mechanism through which responsibility disappears. It places a direct obligation on the deployer to examine the effect of the system within the specific institutional and social context in which it will be used.

Turkey currently has no equivalent horizontal obligation applicable to public-sector deployments of high-risk AI.

4. The Absence of Mandatory Transparency and Traceability for Synthetic Content

Article 50 of the EU AI Act addresses a different category of risk: deception caused by interaction with AI systems and synthetic content.

Providers of systems intended to interact directly with natural persons must generally ensure that individuals are informed that they are interacting with an AI system.

Providers of AI systems generating synthetic audio, image, video or text content must ensure that outputs are marked in a machine-readable and detectable format.

Deployers of systems producing deepfakes must disclose that the content has been artificially generated or manipulated. Similar disclosure obligations apply to AI-generated text published for the purpose of informing the public on matters of public interest, subject to specified exceptions. These transparency obligations became applicable on 2 August 2026.

A Turkish scenario

Shortly before an election, a realistic video appears online showing a candidate apparently making statements that were never made.

The video is shared through several anonymous accounts, copied across platforms and incorporated into news commentary before its authenticity can be established.

Turkish law may provide remedies where the content infringes personality rights, contains criminally unlawful material, processes personal data unlawfully, misleads consumers or constitutes another recognised legal violation.

The principal difficulty is that the legal system must first determine that the content is artificial.

Without machine-readable provenance information or a mandatory disclosure rule:

  • platforms may be unable to identify the synthetic origin quickly;
  • affected persons may struggle to prove manipulation;
  • courts may require expert examination;
  • copies may lose contextual information;
  • the original generator may remain unidentified; and
  • interim measures may be delayed while the content continues to circulate.

The same problem may arise outside elections.

An AI-generated voice recording may be used to impersonate a company director.

An AI-generated medical expert may promote an unsafe product.

A customer may receive financial advice from a chatbot without understanding that no human professional reviewed the advice.

A synthetic video may be submitted as evidence in civil or criminal proceedings.

The Turkish legal system may assess the unlawfulness of each act. It does not currently impose a general technical obligation requiring AI-generated content to carry detectable provenance information.

This creates an important distinction:

Existing law may regulate what may lawfully be said or shown. It does not necessarily regulate whether the artificial origin of the content must remain technically detectable.

The absence of provenance rules affects not only individual rights but also the evidential system.

As synthetic content becomes more realistic, the legal question will no longer be limited to whether a particular recording is false. Courts will increasingly need reliable mechanisms for determining the origin, integrity and modification history of digital material.

Article 50 attempts to establish part of that infrastructure at the point of generation and deployment. Turkish law currently addresses the problem primarily after the synthetic content has entered circulation.

5. The Absence of an AI-Specific Right to Explanation

Article 86 of the EU AI Act grants an affected person the right to obtain a clear and meaningful explanation where a decision is based on the output of a specified high-risk AI system and produces legal effects or similarly significantly affects that person’s health, safety or fundamental rights.

The explanation must address the role of the AI system in the decision-making process and the principal elements of the decision.

Turkish law already contains an important but narrower protection.

Article 11(1)(g) of the PDPL allows a person to object where the analysis of personal data exclusively through automated systems produces an adverse result. The data subject may also request information regarding the processing and seek compensation where unlawful processing causes damage.

The wording “exclusively through automated systems” is critical.

A Turkish scenario

Assume that an employer uses an AI system to rank 5,000 job applicants.

The system analyses CVs, language patterns, video interviews and psychometric indicators. It assigns each applicant a score. A human resources employee reviews only the highest-ranked candidates and rejects the remainder.

A rejected applicant requests an explanation.

The employer states that the final decision was not exclusively automated because a human employee formally approved the result.

The technology provider states that the model and scoring methodology constitute confidential commercial information.

The applicant receives no meaningful information about why the application was rejected.

This is not merely a transparency problem. It is a problem of access to justice.

To challenge discriminatory treatment, breach of contract, unlawful data processing or another legal violation, the applicant must identify the factual basis of the adverse decision.

Where the institution provides only a generic statement such as “your application did not meet our criteria,” the applicant cannot determine whether the result was influenced by age, gender, disability, location, language, education, inferred personality or an inaccurate correlation contained in the model.

The formal presence of a human decision-maker should not automatically eliminate accountability where that person merely approves the AI output without independent examination.

Article 86 is significant because it focuses on the actual role of the AI system in the decision-making process. It does not treat a nominal human signature as conclusive evidence that the decision was genuinely human.

Turkish law currently lacks an AI-specific procedural mechanism determining:

  • the minimum content of an explanation;
  • which actor must provide it;
  • the period within which it must be provided;
  • the extent to which system logs must be preserved;
  • how commercial secrecy should be balanced against the right to an effective remedy;
  • and what consequence follows where the deployer cannot explain the decision.

Without such rules, the right to challenge an algorithmic decision risks becoming theoretical.

A person cannot effectively contest a decision without knowing that AI was used, what role it performed and which principal factors influenced the outcome.

The Broader Consequence: Two Levels of AI Protection

The absence of an EU AI Act–equivalent framework also creates a cross-border asymmetry.

Article 2 of the EU AI Act applies to providers placing AI systems or general-purpose AI models on the EU market even where those providers are established outside the European Union. It may also apply to providers and deployers located in third countries where the output produced by the AI system is used within the Union.

A Turkish technology company may therefore become subject to EU AI Act obligations when serving European customers while remaining outside an equivalent horizontal regime for the same system when it is used exclusively in Turkey.

This may create two versions of the same service:

  • an EU-facing version containing documentation, transparency, risk-management and complaint procedures; and
  • a domestic version operating without equivalent safeguards.

The result is not merely a difference in corporate compliance. It is a difference in the level of legal protection afforded to affected persons.

A person located in the European Union may benefit from AI-specific transparency, explanation and governance rules, while a person affected by the same model in Turkey may be required to construct a claim through several fragmented areas of law.

What Should Turkey Adopt?

Turkey does not need to reproduce every provision of the EU AI Act word for word.

A future Turkish AI statute should be adapted to the institutions, procedural rules and liability principles of Turkish law. It should nevertheless address the five structural gaps identified above.

First, certain AI practices should be expressly prohibited. The prohibition should apply not only to individual users but also to providers that intentionally or foreseeably make severely harmful AI capabilities available without adequate safeguards.

Second, AI systems used in employment, credit, insurance, healthcare, education, public services and justice should be subjected to binding risk-management, documentation, logging, data-quality and human-oversight obligations.

Third, public bodies should be required to conduct and preserve fundamental-rights impact assessments before deploying high-risk AI systems.

Fourth, synthetic content should be subject to technically effective provenance and disclosure requirements, particularly in relation to deepfakes, public-interest information and impersonation.

Fifth, persons significantly affected by AI-supported decisions should have a clear right to know that AI was used and to receive a meaningful explanation capable of supporting an administrative or judicial challenge.

These obligations should not replace existing Turkish law. They should operate alongside the PDPL, civil liability, consumer protection, employment law, intellectual property law, administrative law and criminal law.

The function of a Turkish AI statute should be to connect those existing fields and provide rules addressing the specific characteristics of algorithmic systems: technical opacity, autonomous or semi-autonomous operation, scalable harm, multiple actors and evidential asymmetry.

Conclusion

The absence of a comprehensive AI statute in Turkey does not create an absolute legal vacuum.

A person harmed by an AI system may still rely on personal data protection, personality rights, contractual liability, tort, consumer law, employment law, intellectual property or criminal law.

The weakness lies elsewhere.

Existing Turkish law generally evaluates the legality of an act after a decision has been made, content has been generated or damage has occurred. It does not yet provide a comprehensive and binding system governing which AI practices may never be used, which systems must be tested before deployment, what records must be maintained, what public authorities must assess and what explanations must be given to affected persons.

The five most significant gaps concern:

  1. prohibited AI practices;
  2. high-risk system safeguards;
  3. fundamental-rights impact assessments;
  4. synthetic-content transparency; and
  5. the right to explanation.

These are not merely technical compliance requirements.

They determine whether a person can know that an AI system affected them, understand how the system operated, identify the responsible actor, obtain the relevant evidence and effectively enforce their rights.

The principal legal risk for Turkey is therefore not that courts will be completely unable to apply existing law.

It is that the law will intervene only after the harm has materialised, while the information required to establish responsibility remains under the exclusive control of the provider, deployer or public authority.

A legal system that regulates only the harmful output, but not the design, deployment and governance of the system producing that output, will remain structurally incomplete in the age of artificial intelligence.