Skip to content
August 2, 2026 · English

Which Laws Govern AI-Related Disputes in Turkey/ Türkiye?

An Assessment of Turkish Law in the Absence of a Specific Artificial Intelligence Act, with Reference to the EU AI Act and the Italian Model

Av. Asutay Duhan Meydan
Meydan AI & Tech Law

The use of artificial intelligence systems in assessing credit applications, selecting job candidates, supporting decisions in healthcare, imitating the images and voices of real persons, or training models on copyright-protected materials gives rise to forms of legal dispute that were not specifically contemplated when traditional legal rules were enacted.

Türkiye has not yet enacted a horizontal and comprehensive statute specifically regulating artificial intelligence. The Artificial Intelligence Bill dated 24 June 2024 and registered under file number 2/2234 remains under consideration before the relevant committee of the Grand National Assembly of Türkiye as of August 2026.

This does not, however, mean that harm caused by artificial intelligence falls outside the legal order. Existing Turkish law is capable of addressing a substantial proportion of AI-related disputes through the rules governing personal data protection, personality rights, contractual liability, tort, consumer protection, intellectual property, employment and criminal liability.

The principal difficulty is not the complete absence of applicable rules. Rather, it lies in the fragmented nature of the legal framework, the uncertainty surrounding the allocation of responsibility among providers, users, platforms and developers, and the particular difficulty faced by injured parties in proving fault and causation in cases involving opaque algorithmic systems.

For a comprehensive overview of the applicable legal framework, see our 2026 guide to Artificial Intelligence Law in Turkey.

Does the Absence of an Artificial Intelligence Act Create a Legal Vacuum?

Private law and criminal law provide different answers to this question.

Under Article 1 of the Turkish Civil Code, a judge must first apply the applicable statutory provisions. Where no directly applicable statutory rule exists, the judge may refer to customary law and, in the absence of such custom, decide the matter in accordance with the rule that the judge would have enacted had the judge acted as the legislature. Accordingly, the absence of a provision specifically addressing artificial intelligence does not require a private law dispute to remain unresolved.

The position is more restrictive in criminal law. Under the principle of legality set out in Article 2 of the Turkish Criminal Code, conduct that is not expressly defined as a criminal offence cannot be punished. Existing offences cannot be extended by analogy in order to create a new category of “AI offence.”

This distinction is particularly important in relation to deepfakes, wholly synthetic sexual content and AI-generated false evidence. Conduct may constitute an unlawful interference with personality rights and therefore be restrained or give rise to compensation under private law, while at the same time remaining outside criminal liability where the constituent elements of an existing offence are not satisfied.

Automated Credit and Insurance Decisions

Consider a bank that uses an artificial intelligence system to assess not only an applicant’s income, but also the applicant’s place of residence, consumer habits, health-related information and online behaviour. The application is rejected, yet the bank is unable to explain the basis on which the decision was reached.

The first applicable statute would be the Turkish Personal Data Protection Law No. 6698.

Article 4 of the PDPL requires personal data to be processed lawfully and fairly, accurately and, where necessary, kept up to date, for specified and legitimate purposes, and in a manner that is relevant, limited and proportionate to the purposes for which the data are processed. Processing must be based on one of the lawful grounds set out in Article 5 and, where special categories of personal data are involved, Article 6.

Article 10 requires the data subject to be informed of the processing activity. More importantly, Article 11(1)(g) grants the data subject the right to object to a result arising against the person through the analysis of personal data exclusively by automated systems. Where unlawful processing causes damage, the data subject may also seek compensation.

Where a contractual banking or service relationship exists, Article 112 of the Turkish Code of Obligations concerning contractual non-performance may apply. Even in the absence of a contract, liability may arise under Article 49 of the TCO on tortious conduct. Where an unlawful algorithmic assessment causes damage to a person’s commercial reputation, financial prospects or personality rights, non-pecuniary damages may also be claimed under Article 58.

Within the European Union, such systems are not addressed solely through data protection law. The EU AI Act classifies certain systems used to assess creditworthiness, evaluate risks in life and health insurance, and determine access to essential public services as high-risk systems. Such systems are subject to obligations concerning risk management, technical documentation, record-keeping, data governance and human oversight.

The AI Act does not, however, constitute a general compensation statute. The GDPR, consumer law and national rules on civil liability continue to apply.

The principal deficiency in Türkiye is therefore not that algorithmic decisions are wholly unregulated. It is that procedural safeguards enabling an individual to understand the logic of the decision, challenge it meaningfully and request genuine human review are not set out with sufficient clarity.

Algorithmic Discrimination in Recruitment

An AI system trained on historical data in which predominantly male candidates were hired may systematically assign lower scores to female applicants. Similarly, age, disability, health status or place of residence may operate as indirect proxies for discriminatory treatment.

Under Turkish law, such disputes must first be assessed under the equality principle in Article 10 of the Constitution, the employer’s duty of equal treatment under Article 5 of Labour Law No. 4857, and Law No. 6701 on the Human Rights and Equality Institution of Türkiye.

Where CVs, educational records, photographs, personality assessments or video interviews are analysed by an AI system, the PDPL also applies. A data controller cannot avoid liability merely by stating that the decision was produced by an automated system.

Article 122 of the Turkish Criminal Code, which regulates hate and discrimination, cannot be applied to every instance of algorithmic bias. Criminal liability requires the discriminatory motive and the material elements specified by the provision to be established in the particular case. A defective dataset or an inadequately supervised model may give rise to employment or civil liability without necessarily constituting a criminal offence.

The EU AI Act classifies many AI systems used for recruitment, candidate selection, employee performance assessment, promotion and dismissal as high-risk systems. The European approach does not generally prohibit the use of such systems. It seeks instead to ensure that they are assessed in advance, made subject to appropriate controls and kept under meaningful human supervision.

Deepfakes and Non-Consensual Synthetic Images

Consider a case in which a person’s face is placed onto sexually explicit material through the use of artificial intelligence and the resulting image or video is disseminated through social media. No genuine photograph or recording of that nature may ever have existed.

Under Turkish private law, the fact that the image is synthetic rather than authentic does not prevent the existence of an interference with personality rights.

Under Article 24 of the Turkish Civil Code, a person may seek protection against unlawful attacks directed at private life, honour, reputation, image or sexual identity. Article 25 allows the person to seek prevention of a threatened attack, cessation of an ongoing attack, a declaration of unlawfulness and, where appropriate, publication or notification of the judgment.

Where damage has occurred, pecuniary and non-pecuniary compensation may be claimed under Articles 49 and 58 of the Turkish Code of Obligations. Where the person’s face, voice or biometric characteristics render the person identifiable, the PDPL may also apply.

From a criminal law perspective, the circumstances may give rise to offences such as insult, threat, blackmail, violation of privacy or unlawful dissemination of personal data.

A significant legal difficulty nevertheless arises as to whether a wholly synthetic image may be treated as a genuine image relating to a person’s private life for the purposes of Article 134 of the Turkish Criminal Code. Existing offences may have been drafted on the assumption that an authentic image or recording has been obtained or disclosed. Under the principle of legality in Article 2 of the Criminal Code, those provisions cannot be extended without limit.

Article 50 of the EU AI Act introduces transparency obligations requiring disclosure that deepfake images, audio or video have been artificially generated or manipulated. The AI Act does not, however, create a general criminal offence of producing or disseminating deepfake content.

Italy has adopted a more direct approach. Law No. 132 of 23 September 2025 supplements the EU AI Act through national rules concerning user protection, professional use, the judiciary, copyright and criminal law.

Under the Italian framework, the non-consensual dissemination of AI-generated or manipulated images, audio or video capable of misleading others as to their authenticity and causing unjust harm is specifically criminalised. The Italian approach therefore exposes one of the most significant gaps in Turkish criminal law: the fact that synthetic content is not based on a genuine recording does not reduce the harm caused to the victim, yet it may make the application of existing offences more difficult.

Voice Cloning and AI-Assisted Fraud

The cloning of a company director’s voice in order to instruct an accounting employee to make an urgent transfer is a classic example of artificial intelligence operating as the instrument of the offence rather than as the subject of liability.

Under Turkish law, such conduct may fall within the offence of fraud under Article 157 of the Turkish Criminal Code or, depending on the circumstances, aggravated fraud under Article 158. Where unlawful access to information systems has occurred, Articles 243 and following concerning cyber offences may apply. Where a false document has been created, the provisions on forgery of official or private documents may also be relevant.

Criminal responsibility does not attach to the artificial intelligence system. It attaches to the person who uses the system to engage in fraudulent conduct.

Turkish law does not currently recognise the use of artificial intelligence as a general aggravating circumstance applicable across criminal offences. Future legislation may nevertheless consider how the use of AI should affect sentencing where it makes deception exceptionally difficult to detect, enables the targeting of a large number of victims or materially aggravates the resulting harm.

False Information Generated About Individuals

Consider a chatbot that falsely states that a doctor, lawyer or businessperson with no criminal record has previously been convicted of an offence.

In such a case, protection may be sought under Articles 24 and 25 of the Turkish Civil Code, while pecuniary and non-pecuniary damages may be claimed under Articles 49 and 58 of the Turkish Code of Obligations. Where the output involves the processing of data relating to an identifiable individual, the principles of accuracy and currency under the PDPL may also apply.

Liability cannot, however, be allocated automatically.

The following factors would need to be examined:

  • the prompt provided by the user;
  • the safety measures implemented by the model provider;
  • whether the system repeatedly generated the same false statement;
  • whether the provider was notified of the false information;
  • whether the information was corrected following notification;
  • the role of the platform in disseminating the content; and
  • the causal link between the model output and the damage sustained.

The principal difficulty in such cases lies in the injured person’s lack of access to information concerning the model’s training, the data relied upon in producing the response and the safety mechanisms that failed. Accordingly, debates concerning algorithmic liability concern not only substantive rules of liability, but also access to evidence and the allocation of the burden of proof.

Training Data and Copyright

The unauthorised use of books, articles, photographs or software protected by copyright for the training of an AI model is one of the most contested fields of artificial intelligence law.

Under Turkish law, the matter must primarily be assessed under Law No. 5846 on Intellectual and Artistic Works. The author’s rights of adaptation, reproduction, distribution, performance and communication to the public must be taken into account. The technical reproduction of works during training, their inclusion in datasets and the reproduction of distinctive elements of a work in model outputs may raise separate legal questions.

The fact that material is publicly accessible on the internet does not mean that it may automatically be used as training data. Conversely, the mere fact that a work has been used in model training does not necessarily establish infringement without an examination of the particular circumstances.

The lawful basis of access, licence terms, the nature of any reproduction, the availability of text and data mining exceptions, the degree of similarity between the output and the protected work, and the commercial nature of the use must be assessed separately.

The human-centred concept of authorship under Turkish copyright law is also relevant to AI-generated works. Artificial intelligence cannot, under the current legal structure, be recognised as an independent author. However, where the human user exercises a sufficient degree of selection, arrangement, revision, direction and creative control, the resulting work may potentially qualify as a product of human intellectual effort.

Italian Law No. 132/2025 expressly places human contribution at the centre of copyright protection. Works created with the assistance of artificial intelligence may receive protection only where they remain the result of the author’s intellectual effort.

Bodily Injury Caused by a Defective AI System

Where an AI-supported diagnostic system used in a hospital fails to identify signs of a serious illness, or an industrial AI system issues an incorrect command that causes injury to a worker, several liability regimes may apply concurrently.

Under the Turkish Code of Obligations, liability may arise under Article 49 concerning tort, Article 112 concerning breach of contract, Article 66 concerning the liability of an employer for employees and, depending on the circumstances, Article 71 concerning liability for activities presenting a significant danger.

In consumer transactions, the provisions of Consumer Protection Law No. 6502 concerning defective goods and defective services may apply. Where AI forms part of the safety component of a physical product, Law No. 7223 on Product Safety and Technical Regulations may also become relevant.

It remains insufficiently clear under Turkish law whether independent software supplied solely through an online API or cloud service should in every case be treated as a “product” for the purposes of traditional product liability.

Where death or injury occurs, criminal liability may be considered under Articles 85 and 89 of the Turkish Criminal Code concerning negligent homicide and negligent injury. This requires proof that an identifiable natural person breached a duty of care, that the result was foreseeable, and that a causal link existed between the conduct and the harm.

A developer, manager or medical professional cannot be held criminally responsible merely because an AI system produced an erroneous result. Criminal liability must be based on the individual’s degree of control, knowledge, duty of care and fault.

Use of Artificial Intelligence by Legal and Other Professionals

Where a lawyer uploads confidential client documents to an openly available generative AI system or includes fictitious judicial decisions generated by that system in a pleading without verification, the absence of a specific AI statute does not prevent the application of existing professional rules.

Article 34 of the Attorneyship Law requires lawyers to perform their duties with care, accuracy and integrity, while Article 36 imposes a duty of professional secrecy. The processing and possible international transfer of personal data contained in a case file are also subject to the PDPL. Where the client suffers damage, contractual and disciplinary liability may arise.

The same principle applies to physicians, accountants, engineers and other regulated professionals. A professional cannot avoid responsibility for review and verification by arguing that the relevant conclusion was generated by an AI system.

Italian Law No. 132/2025 adopts the principle that AI used in professional activities must remain instrumental and supportive, while the core of the service must remain the product of human intellectual work. It also requires disclosure to the client in relation to material uses of AI.

A comparable Turkish rule should not require disclosure of every spelling or formatting tool. It should instead focus on uses involving the transfer of personal data, the generation of professional opinions, diagnostic assessments or the substantial influence of AI on the service provided.

Artificial Intelligence in Judicial Proceedings and Synthetic Evidence

Artificial intelligence may offer substantial benefits in file classification, anonymisation, case-law research and deadline management. The assessment of evidence, interpretation of the law and delivery of judgment must nevertheless remain functions of the judge.

Under Turkish law, this conclusion may be derived from Articles 36, 138 and 141 of the Constitution; Articles 27, 199 and 297 of the Code of Civil Procedure; and Articles 217 and 230 of the Code of Criminal Procedure.

There is, however, no specific statute expressly regulating judicial use of AI, requiring the system used to be recorded, requiring notification to the parties, mandating review of known system limitations or requiring disclosure of the extent to which an algorithmic recommendation influenced the judgment.

Italy has expressly provided that the interpretation and application of law, assessment of facts and evidence, and delivery of judicial decisions remain exclusively with the judge. The Italian model does not exclude AI from the administration of justice. Rather, it confines the technology to the role of a supporting tool and prevents it from replacing judicial authority.

Where AI-generated audio or video is submitted to a court as genuine evidence, offences such as forgery, false accusation, fabrication of an offence or fraud may apply depending on the circumstances.

Can Artificial Intelligence Itself Bear Criminal Responsibility?

Artificial intelligence is not an independent offender under Turkish criminal law.

Under Article 20 of the Turkish Criminal Code, criminal responsibility is personal. Liability must therefore be attributed to natural persons who use the AI system, manage it, knowingly cause the harmful result, or fail to prevent the result despite being under a legal duty to do so.

In relation to legal persons, criminal punishment does not ordinarily apply. Security measures and administrative sanctions may nevertheless be imposed where expressly provided by law.

The fact that an AI system causes a harmful result is not, by itself, sufficient to render the developer, provider or manager criminally liable. The material and mental elements of an existing offence, intent or negligence where legally recognised, the individual’s actual control over the system, and causation must each be established.

Accordingly, the relevant criminal-law question is not whether “the AI committed an offence,” but rather which natural person breached which duty and thereby caused the constituent elements of which offence to be fulfilled.

What Are the European Union and Italy Doing?

The EU AI Act establishes a preventive and risk-based framework for AI systems placed on the market or put into service. It regulates prohibited practices, high-risk systems, general-purpose AI models, technical documentation, transparency and human oversight.

It does not replace civil law, criminal law, employment law, data protection or consumer law.

An AI-related dispute in Europe is therefore not resolved by reference to the AI Act alone. The GDPR, the Digital Services Act, product liability rules, national criminal codes and domestic private law continue to operate alongside it.

Italian Law No. 132 of 23 September 2025 complements the EU AI Act in specific areas of the domestic legal order. It entered into force on 10 October 2025 and is to be interpreted consistently with the EU AI Act.

The principal distinction in the Italian approach is that it moves beyond general risk regulation and adopts specific national rules concerning professional activity, judicial functions, copyright and criminal law.

Does Türkiye Need an Entirely New Liability System?

A substantial proportion of AI-related disputes in Türkiye can be addressed through existing law. The analysis will nevertheless often require the simultaneous application of the PDPL, the Turkish Civil Code, the Turkish Code of Obligations, the Turkish Criminal Code, copyright law, labour law, consumer law and sector-specific legislation.

Türkiye therefore does not necessarily need a new regime that replaces the existing law of liability. What is needed is a complementary statute that connects existing rules within the context of AI relationships.

Such legislation should clarify, in particular:

  • the allocation of responsibility among AI providers, developers, deployers, platforms and end users;
  • human oversight in high-risk systems;
  • the requirement to provide reasons for automated decisions and the right to human reconsideration;
  • access to model logs and technical documentation;
  • the allocation or reversal of the burden of proof in algorithmic harm cases;
  • the origin of training data and the rights of affected right holders;
  • the status of independent software under product liability law;
  • clear criminal provisions concerning non-consensual and harmful deepfake content; and
  • the limits of AI use in judicial and professional activities.

Conclusion

The absence of a comprehensive AI-specific statute in Türkiye does not mean that AI-related disputes arise in a legal vacuum.

Automated decisions may be assessed under the PDPL and the law of obligations; discrimination under employment and equality law; deepfakes under personality rights and existing criminal provisions; training data under copyright law; defective goods and services under consumer and liability law; and professional uses of AI under professional duties and standards of care.

The existing framework nevertheless suffers from three principal weaknesses: fragmentation, uncertainty in the allocation of responsibility and evidential difficulty.

The EU AI Act establishes a preventive framework that regulates systems according to their level of risk before harm occurs. Italy supplements that framework with national provisions relating to professional activity, the judiciary, copyright and criminal law.

The appropriate approach for Türkiye is not to reproduce foreign legislation in its entirety. The existing institutions of Turkish law should be preserved, while legislation should clearly determine how those institutions apply to AI systems, who is responsible under which circumstances, and what evidence an injured party may use to enforce legal rights.

The central problem in artificial intelligence law is not that no applicable law exists, but that existing laws do not, on their own, provide sufficient clarity when confronted with algorithmic decision-making, technical opacity and multi-actor structures of responsibility.