A Comparative Legal Analysis of the UK Joint Committee on Human Rights Report and Turkish Bill No. 2/3358
Asutay Duhan Meydan
Attorney at Law
Abstract
Two recent parliamentary texts offer markedly different answers to the same regulatory problem: how legal responsibility should be allocated when artificial intelligence systems create risks that cannot be adequately addressed through rules designed for conventional software, online content or human decision-making.
On 14 September 2026, the UK Parliament’s Joint Committee on Human Rights published its report Human Rights and the Regulation of AI. The report does not constitute a bill. It recommends that the Government introduce dedicated AI legislation built around human-rights risk, lifecycle accountability, differentiated obligations across the AI supply chain, prior approval for high-risk systems, mandatory transparency, stronger rights for persons affected by automated decisions, an independent oversight body and statutory pre-release scrutiny of powerful AI models.
Turkey is proceeding from a different legislative starting point. Bill No. 2/3358, submitted to the Grand National Assembly of Turkey on 7 November 2025 and currently before parliamentary committees, would amend a series of existing statutes rather than create a self-contained AI Act. Its proposed amendments concern, among other matters, AI-generated unlawful content, developer and user responsibility, training-data transparency, hallucination controls, deepfake labelling, election security, cybersecurity testing and administrative sanctions.
The difference is therefore not merely one of regulatory intensity. It is architectural. Bill No. 2/3358 largely integrates AI into Turkey’s existing regimes governing internet content, criminal law, personal data, electronic communications and cybersecurity. The UK Committee proposes regulation of the AI lifecycle itself.
This article argues that the central comparative issue is where the law chooses to locate responsibility. Turkey’s proposal often attaches legal consequences to prohibited outputs, harmful uses and specific provider obligations. The UK report seeks to move responsibility upstream, toward the actors possessing the technical knowledge, economic capacity and practical control necessary to identify and mitigate risk before deployment.
That distinction may ultimately matter more than any individual prohibition.
1. The Two Texts Do Not Perform the Same Legal Function
The comparison must begin with a distinction that is easy to overlook.
The UK document is not proposed legislation. It is the Fourth Report of Session 2026–27 of the Joint Committee on Human Rights, published as HC 160 / HL Paper 56. It contains recommendations addressed to the Government, which has two months to respond. Among those recommendations is the adoption of an AI Bill.
Turkey already has a legislative proposal before Parliament. Bill No. 2/3358 is entitled Bazı Kanunlarda Değişiklik Yapılmasına İlişkin Kanun Teklifi — a Bill Amending Certain Laws. It was submitted on 7 November 2025 and remains before the Industry, Trade, Energy, Natural Resources, Information and Technology Committee, with the Justice Committee and Digital Media Committee acting as secondary committees.
This formal distinction produces a substantive one.
The UK Committee was free to design a regulatory architecture from the ground up. Bill No. 2/3358 instead attempts to insert AI-specific provisions into existing statutory structures. It proposes amendments to Law No. 5651 on internet publications, the Turkish Criminal Code, the Personal Data Protection Law, the Electronic Communications Law and the Cybersecurity Law.
Accordingly, the Turkish proposal frequently approaches AI through legal categories that already exist: content provider, access provider, social-network provider, criminal offender, data-security breach and cybersecurity obligation.
The UK report begins elsewhere. It treats the AI lifecycle and supply chain themselves as objects of regulation.
That is the first and most important divergence.
I. The First Fault Line: Harmful Content or the AI Lifecycle
Bill No. 2/3358 contains a broad definition of an “artificial intelligence system” and introduces several preventive duties. Yet much of its operative structure remains connected to consequences arising from AI-generated content or use.
The proposal would require removal or blocking within six hours of certain AI-generated content that violates personality rights, threatens public security or constitutes manipulated deepfake material. It would permit emergency access restrictions concerning AI content threatening public order or election security. Deepfake visual, audio or textual content would have to carry an explicit and non-removable indication stating that it was generated by artificial intelligence.
This is a recognisable extension of platform and internet-content regulation into AI.
The UK Committee takes a broader view. Its report states that existing UK law tends to operate most effectively at the point of deployment. The Committee considers this inadequate because the origin of a risk may lie considerably further upstream — in model architecture, training data, design decisions or development-stage safeguards. It therefore recommends proportionate obligations for actors throughout the AI lifecycle and supply chain.
That distinction can be expressed quite precisely.
Turkey’s proposal frequently regulates what an AI system produces or facilitates.
The UK model seeks additionally to regulate how an AI system came to possess the characteristics that made the harm possible.
The difference has substantial consequences for foundation-model providers.
Consider an enterprise in Turkey deploying a third-party large language model through an API. If the underlying model contains a risk embedded during training, the deploying enterprise may have neither access to the training data nor the technical capacity to alter the relevant model behaviour. A regulatory system focused predominantly on deployment can therefore place responsibility on an actor that may be legally visible but technically incapable of curing the source of the problem.
The UK Committee expressly identifies this difficulty. It concludes that actors with the greatest capacity to prevent harm will often be upstream developers, while risks can presently be passed down the contractual chain to actors unable to identify or remedy their source.
This is the point at which AI regulation begins to move beyond ordinary intermediary-liability doctrine.
II. The Second Fault Line: Liability Should Follow Control
The most consequential proposition in the UK report is not necessarily its recommendation for a new regulator or even its prior-approval regime. It is the underlying theory of responsibility.
The Committee recommends that due-diligence obligations should differ according to both:
- the actor’s position in the AI supply chain; and
- the nature and seriousness of the relevant risk.
It expressly suggests that the EU AI Act can provide a point of departure while emphasising that the resulting rules should be adapted to the United Kingdom.
This represents a control-based allocation of responsibility.
The relevant legal inquiry becomes not only whether an actor participated in the provision or deployment of an AI system, but what that actor knew, what it controlled, what risk it introduced and what measures it was technically capable of taking.
Turkey’s Bill contains elements pointing in the same direction, but without a comparable supply-chain taxonomy.
Article 6 of the proposal would impose duties on AI service providers to ensure transparency and auditability of training datasets, establish mechanisms against false and manipulative information, apply algorithmic controls to reduce hallucination risk, create human-approved oversight mechanisms for high-risk applications and conduct periodic cybersecurity vulnerability testing.
These are material obligations. They show that Bill No. 2/3358 is not purely a post-harm enforcement instrument.
What it does not yet establish, however, is a clear legal division between the foundation-model developer, model provider, downstream developer, integrator and deployer.
That omission matters commercially as much as doctrinally.
Modern AI products are rarely supplied through a linear relationship between one developer and one end user. Foundation models are integrated into other applications; systems may be fine-tuned by one entity, hosted by another, distributed through APIs and deployed within products designed by third parties. The UK Committee describes precisely this type of multi-layered supply chain.
A statutory term such as “service provider” can therefore become too broad if liability is not linked to control.
The provider capable of modifying model weights is not in the same legal position as a Turkish company merely purchasing API access.
The company controlling the training process is not in the same position as an enterprise customer controlling only prompts, retrieval data or user access.
The actor that creates a systemic risk should not automatically be equated with the actor through whose interface that risk becomes visible.
A mature AI liability regime must distinguish these functions.
III. The Third Fault Line: Ex Post Enforcement or Ex Ante Market Access
The UK report makes its sharpest departure from the Turkish proposal in relation to high-risk AI.
The Committee recommends that AI systems posing a high risk of human-rights harm should require prior approval before they are provided or deployed. It further recommends a testing, auditing and evaluation regime capable of preventing systems from entering the market, prohibiting their deployment or ordering their withdrawal where unacceptable risks are identified.
This changes the regulatory sequence.
Traditional enforcement generally follows this order:
deployment → harm or violation → investigation → sanction.
The model recommended by the Committee can add an earlier stage:
development → risk assessment → testing → regulatory approval → deployment → continuing supervision.
Bill No. 2/3358 does refer to “high-risk applications” and requires human-approved oversight mechanisms for them. Yet the proposal does not establish a general statutory classification of high-risk AI, specify the criteria by which systems enter that category or create a prior authorisation procedure.
The result is a notable drafting asymmetry.
The Turkish text contains a legal consequence for high-risk AI without yet constructing a complete legal category of high-risk AI.
That distinction would become particularly important in sectors such as healthcare, employment, credit scoring, insurance, biometric identification, education and public administration. Without statutory or secondary criteria determining what constitutes “high risk”, providers cannot determine the precise boundary of the enhanced obligation solely from the text.
The UK proposal is considerably more institutional in this respect. Its concept of high-risk AI is connected to due diligence, prior approval, regulator testing, human-rights impact and continuing supervision.
The regulatory concept therefore performs an organising function rather than appearing merely as an isolated standard.
IV. The Fourth Fault Line: Human Oversight Must Be Effective, Not Ceremonial
Both texts recognise the importance of human involvement.
The Turkish proposal requires “human-approved oversight mechanisms” in high-risk applications.
The UK report develops the issue further. Its broader approach to automated decision-making is concerned with whether a person affected by AI has sufficient information and procedural protection to understand and challenge a significant AI-assisted decision. It also places transparency duties across the lifecycle, including disclosure that AI is being used, a comprehensible explanation of its purpose and information concerning the source of data used by the system.
This highlights a broader problem with the expression “human in the loop”.
A human signature at the end of an automated process does not necessarily constitute meaningful human control.
The legal value of oversight depends on whether the human reviewer possesses:
access to relevant information, sufficient technical understanding, actual decision-making authority and a realistic ability to depart from the AI output.
Otherwise, human oversight may exist formally while algorithmic determination continues substantively.
This distinction is particularly important for administrative decision-making and regulated industries. In those contexts, the correct legal standard should not merely ask whether a human participated. It should examine whether effective human judgment remained available.
The UK report is closer to that substantive conception.
V. Turkey Is More Prescriptive in Several Areas
The comparative analysis should not be reduced to a conclusion that the UK model is simply broader and the Turkish model narrower.
In several respects, Bill No. 2/3358 is considerably more direct.
Hallucination
The proposal expressly requires AI service providers to implement algorithmic controls intended to reduce hallucination risk.
That is an unusual legislative choice.
The UK report deals with model reliability through risk assessment, testing, due diligence and oversight, but does not construct “hallucination” as an independent statutory compliance obligation. A search of the report itself reveals no corresponding standalone hallucination provision.
The Turkish provision is therefore more technologically specific.
Its difficulty lies elsewhere: the proposal does not define the standard by which compliance would be measured.
“Reducing” hallucination can describe an engineering objective, but legislation ultimately requires a standard capable of legal application.
The relevant questions concern matters such as the expected reliability level, the relevant use case, reasonable technical measures, known limitations and the distinction between a best-efforts obligation and an obligation to achieve a particular result.
Those details could be developed through secondary legislation, technical standards or regulatory guidance. Without such elaboration, however, the duty risks becoming broader in language than in enforceability.
Deepfakes
Turkey also proposes a concrete disclosure rule: synthetic visual, audio or textual content qualifying as deepfake would have to contain the statement “Generated by Artificial Intelligence”, in a clear, understandable and non-removable form. The proposal additionally provides administrative sanctions and access restrictions for violations.
The UK report favours mandatory transparency but does not prescribe the same fixed formulation.
Turkey therefore adopts a more rule-specific approach to synthetic media.
Election security
Bill No. 2/3358 expressly addresses AI-generated content threatening election security and empowers emergency intervention.
The UK report treats democracy as part of the broader human-rights framework, particularly through its connection to the Council of Europe AI Convention, but its regulatory architecture is not centred on an equivalent standalone election-content mechanism.
Thus, the Turkish proposal is narrower in overall architecture while being more prescriptive in several individual fields.
VI. Criminal Liability Is Where the Turkish Proposal Goes Furthest
Perhaps the most legally significant difference concerns criminal responsibility.
Article 2 of Bill No. 2/3358 proposes adding a paragraph to Article 125 of the Turkish Criminal Code. Under the proposed wording, a user who directs an AI system toward conduct constituting an offence under the Criminal Code would be treated as the perpetrator. It further provides that the sentence imposed on a developer whose design or training enables such offences would be increased by one half.
This provision deserves close scrutiny because it combines two different theories of responsibility.
The first is comparatively straightforward: AI does not displace the criminal responsibility of a human who intentionally employs it as an instrument to commit an offence.
The second is substantially more difficult. Developer liability requires a legal method for distinguishing ordinary technological capability from culpable contribution.
A general-purpose model may be technically capable of generating unlawful material despite extensive safeguards. The fact that criminal misuse is technologically possible cannot, by itself, establish the developer’s criminal responsibility.
Any workable interpretation would therefore have to engage traditional criminal-law concepts including mens rea, causation, foreseeability, contribution and the developer’s degree of control over the relevant risk.
The drafting raises another structural issue.
The proposed paragraph would be inserted into Article 125 of the Turkish Criminal Code, which regulates insult, while its wording refers more broadly to conduct constituting an offence “under this Law”.
That creates tension between the systematic location of the provision and the apparent breadth of its language.
The UK report does not recommend an equivalent general rule of enhanced criminal liability for AI developers. Its approach to upstream responsibility is principally built through due diligence, regulatory obligations, testing, market controls, accountability and remedies.
The contrast is striking.
Turkey contemplates reaching upstream through criminal law.
The UK Committee proposes reaching upstream primarily through regulatory law.
These are not interchangeable methods. Criminal liability demands far greater precision because legality and personal culpability operate as limiting principles.
VII. A Drafting Issue Already Visible in Bill No. 2/3358
The proposal also contains at least one apparent technical cross-reference problem.
Article 8 lists offences for which content removal or access-blocking mechanisms would apply and refers to:
“Threat (Article 28)”.
Under the Turkish Criminal Code, however, the offence of threat is governed by Article 106. Article 28 concerns coercion, violence, intimidation and threat as circumstances affecting criminal responsibility. Official Turkish materials likewise identify threat as the offence under Article 106.
The point is easily correctable during the parliamentary process, but it illustrates a broader concern.
AI legislation interacts simultaneously with criminal law, data protection, cybersecurity, internet law and administrative enforcement. Cross-references are not merely editorial matters. Errors can affect the scope of coercive powers and therefore require particular care.
There is also a more recent institutional development.
Law No. 7590, adopted on 24 July 2026 and published on 31 July 2026, transferred a series of statutory references and powers under Law No. 5651 from the Information and Communication Technologies Authority framework toward the Cybersecurity Presidency.
Bill No. 2/3358 predates those amendments and still assigns certain proposed AI powers expressly to the BTK.
If the proposal advances, its institutional references will therefore require reconciliation with the legislative changes enacted in 2026.
This is not a substantive objection to regulating AI. It is a necessary exercise in statutory coherence.
VIII. The Institutional Models Are Fundamentally Different
The Turkish proposal does not create a dedicated AI authority.
Instead, it distributes responsibility through existing institutions and statutory regimes, including internet regulation, telecommunications and cybersecurity.
The UK Committee recommends an independent AI oversight body established by statute, either through the creation of a new institution or expansion of an existing one. The body would possess powers relating to testing, evaluation, high-risk auditing, prohibition of deployment, market withdrawal and codes of practice.
It would also perform a function that is particularly important in AI regulation: system-wide learning.
The Committee considers an adverse-incident repository valuable because individual failures may reveal recurrent or systemic characteristics of models or model families.
That differs substantially from ordinary enforcement.
A regulator examining a single unlawful output asks whether a rule was breached.
An AI regulator examining incident patterns asks whether multiple apparently independent incidents reveal a common model-level defect.
The latter requires access to technical evidence across providers and sectors.
IX. Frontier Models Introduce a Separate Regulatory Layer
The UK report also distinguishes powerful foundation models from ordinary AI applications.
At present, engagement between developers and the UK AI Security Institute is largely voluntary, and AISI cannot compel access to models or prevent their release. The Committee recommends placing AISI on a statutory basis. Developers of powerful AI models would be required to submit new models and substantial new versions for review, evaluation and testing and provide technical specifications concerning model properties, training data and processes, intended use, safety and security testing and risk-control measures.
This constitutes a second level of regulation.
Application-level regulation asks whether AI is safe in a particular use.
Foundation-model regulation asks whether capabilities embedded in the model itself create risks before any particular downstream application is selected.
Bill No. 2/3358 does not presently make an equivalent structural distinction between general-purpose or frontier models and ordinary AI applications. Its statutory definition is broad enough to capture numerous forms of software within a common concept.
This may become increasingly significant.
As foundation models acquire greater autonomy, tool use and cross-domain capabilities, regulating only their downstream uses can leave the most consequential technical decisions outside the direct regulatory frame.
The UK Committee’s solution is to create regulation at both layers.
X. Human Rights Are Not Merely One Subject Among Others in the UK Model
The philosophical difference between the texts is also visible in their source of legal legitimacy.
The UK Committee places the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law at the centre of its analysis. The Convention establishes principles including human dignity, equality, privacy, transparency, accountability, reliability, procedural safeguards and iterative risk and impact assessment.
The United Kingdom signed the Convention on 5 September 2024. As of the Council of Europe’s September 2026 status table, Turkey had not yet signed it.
This does not mean that Turkey lacks existing human-rights obligations applicable to AI. The Constitution, the European Convention on Human Rights, data-protection law, criminal law and administrative law already apply to AI-related conduct where their conditions are satisfied.
The distinction concerns regulatory design.
The UK report begins with rights and then asks what institutional, procedural and technical duties are required to protect them throughout the lifecycle.
Bill No. 2/3358 begins more often from identified categories of misconduct — deepfakes, manipulation, unlawful content, discriminatory datasets, threats to public order, cybersecurity weaknesses — and attaches obligations and sanctions to those categories.
One model therefore moves primarily:
from rights → risk → duty → supervision.
The other moves more often:
from prohibited harm → responsible actor → intervention → sanction.
There is considerable overlap between the two, but the regulatory logic remains distinct.
XI. The Implications for Global AI Providers Are Substantial
For international providers operating across both jurisdictions, the important issue will not be whether there are “more” or “fewer” obligations.
It will be whether the obligations attach to the same corporate entity.
Under the lifecycle model proposed by the UK Committee, legal duties would be allocated according to an actor’s role in the AI supply chain and the seriousness of the relevant risk. A foundation-model developer might therefore face duties even where the immediate harmful interaction occurs through another company’s downstream product.
Bill No. 2/3358 already contemplates direct duties for developers and service providers, including training-data transparency, hallucination controls, cybersecurity testing and deepfake obligations. Yet it does not presently provide the same comprehensive role-based taxonomy.
For companies offering AI services into Turkey, this creates an important future compliance issue.
Contracts can distribute economic risk between provider and customer.
They cannot necessarily determine who bears a statutory obligation.
The central issue for future Turkish AI law will therefore be whether responsibility is attached by contractual status, by statutory label or by actual technical control over the relevant risk.
The UK report strongly favours the third approach.
That principle is especially significant for multinational providers because AI supply chains are global while enforcement remains territorial.
XII. A Regulatory Convergence Is Still Visible Beneath the Differences
Despite their structural differences, the texts are moving toward several common propositions.
Both recognise that AI transparency can no longer be treated as purely voluntary.
Both recognise that training data matter legally.
Both recognise discrimination as a system-level concern.
Both accept that high-risk applications require stronger oversight.
Both recognise cybersecurity as part of AI governance rather than an entirely separate technical discipline.
Both reject the proposition that general legal rules, without AI-specific obligations, will necessarily be sufficient for every category of risk.
The disagreement therefore lies less in the existence of AI regulation than in its architecture.
The emerging question is how far regulation should reach upstream.
Conclusion: AI Liability Is Becoming a Law of Control
The most important development visible in the UK report is a shift away from identifying responsibility solely at the point where an AI system causes visible harm.
AI regulation is beginning to follow control over risk.
That change is legally significant because AI systems divide causation across multiple actors.
A model developer can create a technical characteristic without determining the eventual use.
A downstream developer can materially modify a system without creating its foundation model.
A deployer can determine context without understanding all of the system’s internal characteristics.
A user can intentionally misuse a system despite safeguards imposed by every actor above it.
A legal framework that places all these actors into a single category will either over-regulate some or under-regulate others.
The Joint Committee’s proposed solution is differentiated lifecycle responsibility: legal obligations should be imposed at the stage at which risks can most effectively be identified and prevented. High-risk systems may require prior approval; powerful models may require pre-release scrutiny; developers, providers and deployers may bear different due-diligence duties; affected persons must receive sufficient transparency and procedural protection; and a specialist institution must be capable of observing risk across the market rather than case by case.
Turkey’s Bill No. 2/3358 takes another route. It contains several unusually concrete obligations — particularly on hallucination, deepfakes, election security, training-data transparency and developer responsibility — but integrates them into existing legal regimes rather than creating a comprehensive lifecycle framework. It also reaches further than the UK report in one sensitive respect by proposing explicit criminal-law consequences connected to AI developers.
The two texts therefore represent more than different national responses to the same technology.
They reveal two regulatory techniques.
One seeks to adapt existing law to AI-generated conduct.
The other seeks to make the architecture of AI development itself legally accountable.
For Turkey, the next stage of the legislative debate may ultimately turn on whether Bill No. 2/3358 remains a collection of AI-specific amendments or evolves toward a coherent system connecting risk classification, provider status, technical control, due diligence, market access, individual remedies and regulatory supervision.
That distinction will determine far more than compliance procedure.
It will determine where, in an AI supply chain, the law ultimately decides that responsibility begins.
Asutay Duhan Meydan
Attorney at Law
Meydan Law Office