Skip to content
Meydan AI & Tech Law

Artificial Intelligence Law in Turkey

Legal content on artificial intelligence and technology law.

Artificial Intelligence Law in Turkey: A 2026 Legal Guide

Last updated: August 4, 2026

Artificial intelligence is not legally unregulated in Turkey. Although Turkey has not yet enacted a single comprehensive statute equivalent to the European Union Artificial Intelligence Act, the development, deployment and commercial use of AI systems are already governed by a combination of data protection, civil liability, consumer, intellectual property, internet, competition, employment and criminal law rules.

For international AI providers, technology companies and law firms, the central legal question is therefore not whether Turkish law applies to artificial intelligence. The real question is which body of Turkish law applies to a particular AI system, actor, dataset, output or harmful consequence.

This guide provides a practical overview of the Turkish legal framework applicable to artificial intelligence as of August 2026.

Key Takeaways

  • Turkey does not yet have a comprehensive AI statute in force, although several legislative proposals remain pending before the Turkish Parliament.
  • AI-related personal data processing is subject to Law No. 6698 on the Protection of Personal Data, commonly referred to as the KVKK.
  • Liability may arise under contract, tort, consumer protection, intellectual property, personality rights and sector-specific legislation.
  • Turkish companies may also fall within the scope of the EU AI Act when they place AI systems or general-purpose AI models on the EU market, use AI systems in the EU or generate outputs used in the EU.
  • Businesses should not wait for a dedicated Turkish AI Act before establishing AI governance, documentation and incident-response procedures.

1. Introduction

The use of artificial intelligence in Turkey has expanded across financial services, recruitment, healthcare, education, advertising, customer service, legal services, content production and public administration.

This expansion creates legal issues that do not fit neatly within a single category. A generative AI system may simultaneously process personal data, reproduce copyrighted material, produce misleading commercial content, interfere with personality rights and cause financial loss through an inaccurate output.

Turkish law generally approaches these disputes by examining:

  • the legal role of each participant;
  • the purpose for which the AI system was developed or deployed;
  • the degree of control exercised over the system;
  • the source and nature of the data used;
  • the foreseeability of the relevant risk;
  • contractual representations and limitations;
  • the precautions reasonably expected from the relevant actor; and
  • the connection between the AI system and the alleged damage.

The legal assessment is therefore fact-specific. Describing a service merely as an “AI platform” does not determine either its regulatory status or the allocation of liability.

For a detailed dispute-focused analysis, see Which Laws Govern AI-Related Disputes in Turkey?

2. Is There an AI Law in Turkey?

As of August 2026, Turkey has not enacted a single, horizontal and comprehensive artificial intelligence statute.

Several AI-related legislative proposals have nevertheless been submitted to the Grand National Assembly of Turkey. These proposals address issues such as ethical AI development, personal data protection, transparency, harmful synthetic content, platform responsibility and sectoral adaptation. The principal comprehensive AI proposal and subsequent AI-related amendment proposals remain under parliamentary consideration rather than forming part of the law currently in force.

The Turkish Parliament also established a Parliamentary Research Commission to examine the benefits and risks of artificial intelligence and the legal infrastructure required in this field. The Commission completed its research process and presented its report in early 2026. However, a parliamentary research report does not itself create directly enforceable obligations for private companies.

Accordingly, the Turkish AI framework currently consists of existing laws applied to new technological circumstances.

The most relevant legislation includes:

  • Law No. 6698 on the Protection of Personal Data;
  • the Turkish Code of Obligations;
  • the Turkish Civil Code;
  • Law No. 6502 on Consumer Protection;
  • Law No. 5846 on Intellectual and Artistic Works;
  • Law No. 5651 on Internet Publications;
  • the Turkish Commercial Code;
  • the Turkish Criminal Code;
  • employment legislation;
  • electronic commerce and advertising rules; and
  • sector-specific banking, insurance, healthcare, telecommunications and financial regulations.

The absence of a comprehensive AI statute should therefore not be interpreted as a regulatory exemption.

For a comparative assessment of possible national legislative approaches, see our analysis of five key provisions of Italy’s AI Law and their potential relevance to Turkey.

3. Data Protection and Artificial Intelligence

Personal data protection is currently one of the most developed areas of Turkish AI regulation.

Law No. 6698 applies whenever personal data are collected, recorded, analysed, enriched, transferred, stored or otherwise processed through an AI system. Depending on the circumstances, this may include:

  • training datasets;
  • user prompts;
  • uploaded documents;
  • voice and biometric data;
  • location information;
  • behavioural profiles;
  • customer-support records;
  • employee data;
  • model outputs associated with identifiable persons; and
  • data inferred by an AI system.

The Turkish Personal Data Protection Authority has expressly addressed generative AI and workplace AI use. Its guidance emphasises that AI systems should be developed and used in a human-centred, secure, responsible and legally compliant manner throughout their lifecycle.

Determining the Responsible Actor

A central issue is whether an organisation qualifies as a data controller, a data processor or, in some structures, an independent controller for a separate processing activity.

This analysis does not depend solely on the terminology used in a service agreement. It depends on which party determines:

  • why personal data are processed;
  • which categories of data are used;
  • how the AI system operates;
  • how long information is retained;
  • whether prompts or outputs are used for model improvement; and
  • with whom the data are shared.

A company using a third-party AI tool may remain responsible for the personal data entered into the system, even where the technical processing is performed by an external provider.

Processing Conditions and Core Principles

AI-related processing must satisfy an applicable processing condition under the KVKK. Explicit consent is not the only possible legal basis, but it cannot be treated as a universal solution for every AI operation.

The processing must also comply with the general principles of:

  • lawfulness and fairness;
  • accuracy and, where necessary, keeping data up to date;
  • processing for specified, explicit and legitimate purposes;
  • relevance, limitation and proportionality; and
  • retention only for the period required by the relevant purpose.

These requirements affect the design of datasets, prompt logging, model monitoring, data retention, access controls and output-review procedures.

Transparency

Individuals should receive intelligible information about the processing of their personal data. A generic privacy notice stating that data may be used for “technological purposes” will rarely provide sufficient clarity for a complex AI application.

The notice should explain, where applicable:

  • what data are collected;
  • whether the data are supplied directly or obtained from another source;
  • whether automated analysis is performed;
  • the purpose of the analysis;
  • the recipients of the information;
  • international transfers;
  • retention periods; and
  • the rights available to the individual.

Automated Analysis

Article 11 of the KVKK gives individuals the right to object where personal data are analysed exclusively through automated systems and a result arises against the individual.

This right is particularly relevant to AI systems used for recruitment, creditworthiness, fraud detection, insurance, employee monitoring, eligibility assessments and customer classification.

Organisations using AI in consequential decision-making should therefore maintain meaningful review procedures and should be able to explain how an adverse result was reached.

International Data Transfers

AI services frequently involve servers, cloud providers, support teams or model providers located outside Turkey.

The international transfer regime under Article 9 of the KVKK was substantially amended in 2024. The available mechanisms now include adequacy decisions, appropriate safeguards such as standard contractual clauses and binding corporate rules, and limited exceptional transfer grounds.

The Turkish Data Protection Authority has published separate standard contractual clauses for controller-to-controller, controller-to-processor, processor-to-processor and processor-to-controller transfers.

Using a global AI provider does not, by itself, establish compliance. The organisation must identify the transfer mechanism, the relevant parties, the destination, the data categories and any onward transfers.

4. AI Liability Under Turkish Law

Turkish law does not currently recognise an AI system as an independent legal person capable of bearing civil liability.

Claims must therefore be directed against one or more natural or legal persons connected to the development, supply, implementation, operation or use of the system.

Depending on the facts, these actors may include:

  • the AI developer;
  • the model provider;
  • the application provider;
  • the distributor;
  • the professional deployer;
  • the employer;
  • the platform operator;
  • the commercial user; or
  • the individual who instructed or misused the system.

Contractual Liability

Contractual liability may arise where an AI product or service fails to satisfy agreed specifications, service levels, security commitments, performance representations or professional obligations.

Relevant questions include:

  • What result was contractually promised?
  • Was the service described as autonomous, assistive or experimental?
  • Were material limitations clearly disclosed?
  • Was human review contractually required?
  • Did the provider undertake to comply with particular laws or technical standards?
  • Did the customer use the system outside the agreed scope?
  • Were liability exclusions individually negotiated and legally valid?

A contractual disclaimer stating that an AI system “may produce inaccurate results” will not necessarily eliminate liability where the provider made contradictory performance claims or failed to disclose a foreseeable and material risk.

Tort Liability

Article 49 of the Turkish Code of Obligations establishes the general principle that a person who causes damage through an unlawful and culpable act must compensate that damage.

In an AI dispute, this may require an assessment of:

  • the relevant duty of care;
  • whether the harm was foreseeable;
  • whether reasonable safeguards were implemented;
  • whether warnings were adequate;
  • whether the system was appropriately tested and monitored;
  • whether human intervention was required; and
  • whether the conduct caused the alleged loss.

The mere involvement of an AI system does not automatically establish fault. Equally, the complexity or opacity of a system does not automatically release the responsible company from its duty to manage foreseeable risks.

Consumer Protection

Where an AI-enabled product or digital service is offered to consumers, Law No. 6502 may apply.

A service may be considered defective where it does not possess the contractually agreed or objectively expected characteristics, does not provide the benefit reasonably expected by the consumer or contradicts statements made in advertising and promotional materials.

Consumer-facing AI providers should ensure that:

  • performance claims are supportable;
  • material limitations are disclosed before purchase;
  • automated recommendations are not presented as guaranteed outcomes;
  • subscription and cancellation terms are clear;
  • dark patterns are avoided; and
  • complaints can be reviewed by a human representative where appropriate.

5. Copyright, Training Data and AI-Generated Content

Copyright questions relating to artificial intelligence remain among the most legally unsettled areas in Turkey.

The principal statute is Law No. 5846 on Intellectual and Artistic Works.

Under the existing framework, a work must result from intellectual effort, bear the individual characteristics of its author, take a perceptible form and fall within a protected category. Turkish law describes the author as the person who creates the work.

Use of Copyrighted Material for AI Training

Turkey does not currently have an AI-specific statutory licensing framework in force governing the general use of copyrighted works for model training.

Depending on the technical process and material involved, the collection, reproduction, storage, adaptation or commercial use of protected works may engage the exclusive rights of authors and other right holders.

The analysis may turn on:

  • whether protected expression was reproduced;
  • whether the relevant material was lawfully accessed;
  • whether a statutory exception applies;
  • whether the use was commercial;
  • whether licensing terms restricted automated extraction;
  • whether the model retains or reproduces identifiable parts of a work; and
  • whether the output is substantially similar to protected expression.

Legislative proposals addressing digital copyright and the use of works in AI development have been submitted to Parliament, but these proposals remain under consideration and should not be treated as current law.

Ownership of AI-Generated Outputs

A fully autonomous output created without meaningful human intellectual contribution may face difficulty satisfying the existing authorship standard.

By contrast, copyright protection may be more plausible where a person exercises sufficiently individual and creative control over the selection, arrangement, editing or transformation of the final result.

The use of an AI tool does not automatically prevent protection. The central question is whether the final work reflects legally relevant human intellectual contribution rather than merely the independent operation of the system.

Companies should therefore document:

  • who designed the creative process;
  • who selected and refined prompts;
  • who chose among alternative outputs;
  • what human revisions were made;
  • which external materials were used; and
  • what rights were granted under the AI provider’s terms.

6. Deepfakes and Synthetic Content

Deepfakes and other synthetic content may engage several areas of Turkish law simultaneously.

Potential claims may arise from:

  • unlawful use of a person’s image or voice;
  • infringement of privacy or personality rights;
  • unlawful processing of biometric or other personal data;
  • defamation;
  • fraud or impersonation;
  • sexual or intimate synthetic content;
  • misleading advertising;
  • copyright infringement; and
  • manipulation of evidence.

Articles 24 and 25 of the Turkish Civil Code allow a person whose personality rights have been unlawfully infringed to seek judicial protection.

Depending on the case, remedies may include:

  • cessation of the infringement;
  • prevention of a threatened infringement;
  • removal or restriction of content;
  • correction or publication of a judgment;
  • pecuniary and non-pecuniary damages;
  • a complaint before the Personal Data Protection Authority; and
  • criminal proceedings where the relevant statutory elements are satisfied.

Synthetic content disputes require rapid evidence preservation. URLs, upload dates, account information, platform correspondence, original files, metadata and records demonstrating dissemination should be collected before content is deleted or altered.

For a detailed analysis of AI provider liability arising from synthetic sexual images, see Can an Artificial Intelligence Provider Be Sued for Synthetic Sexual Images?

7. Platform and Internet Regulation

AI-generated content distributed through websites, social networks, marketplaces and digital platforms may also fall within Turkey’s internet and platform regulation framework.

Law No. 5651 distinguishes between different online actors, including content providers, hosting providers, access providers and social network providers. The legal obligations of a business therefore depend partly on its actual technical and editorial role.

A platform that merely hosts user content may not be treated in the same manner as a business that creates, selects, recommends, promotes or materially modifies AI-generated content.

Relevant issues include:

  • notice and removal procedures;
  • preservation of traffic and transaction records;
  • responsiveness to judicial or administrative orders;
  • representation obligations applicable to certain platforms;
  • protection of personality rights;
  • content constituting a criminal offence;
  • advertising disclosures; and
  • the platform’s own role in generating or amplifying the content.

Terms of service should clearly regulate prohibited AI uses, impersonation, manipulated media, unlawful prompts, intellectual property complaints and repeat violations. However, contractual terms do not replace statutory obligations.

8. The EU AI Act and Turkish Companies

The EU AI Act is particularly important for Turkish companies that develop, supply or deploy AI systems connected to the European market.

The Act applies to public and private actors inside and outside the EU where they place an AI system or general-purpose AI model on the EU market, put an AI system into service in the EU, use it in the EU or, in specified circumstances, where the output of a system located outside the EU is used within the EU.

A Turkish company may therefore fall within the Act even if it has no subsidiary incorporated in an EU Member State.

Current Application Timeline

The EU AI Act entered into force on August 1, 2024 and became generally applicable on August 2, 2026, subject to phased application.

As of August 2026:

  • prohibited AI practices have applied since February 2, 2025;
  • governance provisions and obligations relating to general-purpose AI models have applied since August 2, 2025;
  • Article 50 transparency obligations apply from August 2, 2026;
  • rules for high-risk systems listed in Annex III will apply from December 2, 2027; and
  • rules for high-risk AI embedded in regulated products will apply from August 2, 2028.

The later high-risk dates result from the AI Omnibus, which entered into force on July 27, 2026.

Transparency Obligations

From August 2, 2026, relevant providers and deployers must comply with transparency requirements concerning certain interactive and generative AI systems.

These include obligations relating to:

  • informing users when they are interacting with an AI system;
  • machine-readable marking of AI-generated or manipulated outputs;
  • disclosure of deepfake content; and
  • disclosure of certain AI-generated text published to inform the public on matters of public interest.

The European Commission has also published guidelines and a voluntary Code of Practice to support compliance with these obligations. The statutory transparency duties remain legally binding even where an organisation does not sign the Code.

Turkish companies with EU-facing operations should therefore conduct a separate EU AI Act scope analysis rather than assuming that compliance with Turkish law alone is sufficient.

9. AI Litigation in Turkey

AI disputes in Turkey may involve civil courts, consumer authorities and courts, intellectual property courts, administrative proceedings, criminal investigations or sector-specific regulatory bodies.

The appropriate route depends on:

  • the status of the parties;
  • the legal nature of the claim;
  • the remedy requested;
  • the location of the relevant conduct;
  • contractual jurisdiction or arbitration clauses; and
  • whether an administrative decision is being challenged.

Evidence

AI litigation is heavily dependent on technical and documentary evidence.

Relevant evidence may include:

  • model and software versions;
  • prompts and system instructions;
  • input and output records;
  • timestamps;
  • audit logs;
  • training and testing documentation;
  • risk assessments;
  • human-review records;
  • incident reports;
  • API documentation;
  • content moderation decisions;
  • contractual documents;
  • privacy notices;
  • security records; and
  • internal communications.

A screenshot of an output may be insufficient where the opposing party disputes the prompt, context, system version or authenticity of the record.

Interim Measures and Evidence Preservation

Where online content, model logs or digital evidence may disappear, parties should consider urgent evidence-preservation measures.

Turkish civil procedure provides mechanisms including preliminary evidence proceedings and interim injunctions where the statutory requirements are satisfied. Courts may require a showing that obtaining the evidence later would become impossible or materially more difficult, or that delay would cause serious harm.

Technical expert evidence may also be necessary to determine how an AI system operated, whether an output was reproducible and whether the alleged harm resulted from the system, the user or an external factor.

10. Practical Checklist for Foreign AI Companies

Foreign AI companies operating in or offering services connected to Turkey should consider the following measures:

  1. Map the AI system and relevant actors.
    Identify the provider, developer, deployer, distributor, processor, controller and commercial user.
  2. Identify applicable Turkish legislation.
    Do not limit the assessment to data protection. Consider consumer, copyright, internet, advertising, employment, competition and sectoral rules.
  3. Review training and operational data.
    Establish the source, legal basis, quality and permitted use of each material dataset.
  4. Assess international data transfers.
    Identify where prompts, files, metadata, logs and support records are transmitted or accessed.
  5. Establish contractual responsibility.
    Define permitted uses, prohibited uses, security obligations, human review, audit rights, incident reporting and allocation of liability.
  6. Create meaningful transparency notices.
    Explain AI interaction, personal data use and material system limitations in clear language.
  7. Implement human oversight.
    Consequential decisions should not be treated as reliable merely because they were generated by a sophisticated model.
  8. Test foreseeable misuse and harmful outputs.
    Testing should cover discrimination, impersonation, security, privacy, hallucination, unlawful content and manipulation risks.
  9. Preserve documentation.
    Maintain version histories, testing records, risk assessments, incidents and remediation decisions.
  10. Establish a Turkish incident-response procedure.
    The procedure should address data breaches, harmful outputs, removal requests, regulatory notifications, evidence preservation and litigation risk.
  11. Assess EU AI Act exposure.
    Turkish law compliance does not exclude parallel obligations under the EU AI Act or other foreign legislation.
  12. Review the framework regularly.
    Turkish AI legislation is developing rapidly. Parliamentary proposals, regulatory guidance and sectoral requirements should be monitored.

11. Conclusion

Artificial intelligence is already subject to enforceable legal rules in Turkey, even though no comprehensive Turkish AI Act has yet entered into force.

The existing framework is fragmented but not empty. Depending on the system and its consequences, obligations may arise under personal data protection, contract, tort, consumer, copyright, personality rights, internet, competition, employment, criminal and sector-specific law.

For international companies, the safest approach is not to wait for a future AI statute. Effective compliance requires an actor-specific and use-case-specific assessment of the system’s full lifecycle, from data collection and model development to deployment, monitoring, outputs and incident response.

Companies that document decision-making, define responsibility, preserve human oversight and establish effective complaint and remediation mechanisms will be better positioned both to comply with Turkish law and to defend themselves in future AI-related disputes.


Legal Notice

This publication is intended to provide general information on Turkish law. It does not constitute legal advice and should not be relied upon as a substitute for advice concerning a specific transaction, product, investigation or dispute.

About Meydan AI & Tech Law

Meydan AI & Tech Law provides independent analysis of artificial intelligence, digital platforms, data protection and emerging technology regulation under Turkish law.

For professional enquiries concerning AI operations, regulatory assessments or disputes in Turkey, contact:

meydanhukuk@hotmail.com