Artificial Intelligence Lawyer in Turkey
An artificial intelligence lawyer in Turkey advises businesses on the legal consequences of developing, buying, deploying and relying on AI systems under Turkish law and, where the business reaches Europe, under the EU AI Act.
AI rarely enters a company as a single decision. A software subscription is approved, a team starts drafting with a generative assistant, a model is connected to customer records, part of recruitment is automated, an AI feature appears inside an existing product. Each step looks operational on its own. Together they build a legal architecture that nobody in the business consciously designed, and that architecture is usually discovered from the outside, through a complaint, an audit question or a customer contract.
What law applies to artificial intelligence in Turkey when there is no comprehensive AI Act in force? The rules that attach to what the system actually does. Personal data, contract, intellectual property, consumer protection, employment, cybersecurity and civil liability all reach AI use cases through their own scope provisions. The absence of one statute does not produce an empty legal field; it produces a crowded one, with no single instrument to organise it.
When should a company speak to an AI lawyer in Turkey? Before deployment, before procurement, and before a use case expands into a process that touches people or money. Adoption is instant; exposure is cumulative. A tool switched on in an afternoon keeps generating prompts, outputs, transfers and decisions every day afterwards, and the record it leaves behind is the record the company will later have to explain.
Which is the bigger legal risk, the AI model or the way the company uses it? The use case, in most cases. The same commercial tool is low-risk when rewriting public marketing copy and legally sensitive when applied to employee files, health information, customer profiles or unsigned transaction documents. Legal classification follows the data and the decision, not the vendor’s product category.
Who inside a company usually decides its AI posture? Often nobody with the authority to decide it. The business most exposed to AI law is frequently the one that has never signed an AI contract, because its exposure was created by employees using public tools on their own initiative. The Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) addressed exactly this pattern in March 2026, describing use that develops outside any defined corporate strategy or policy.
⚖️ What Laws Apply to Artificial Intelligence in Turkey?
Turkey has no comprehensive artificial intelligence statute in force, and AI use is governed through the existing regimes according to what the system does. Three legislative proposals have been submitted to the Grand National Assembly of Türkiye (Türkiye Büyük Millet Meclisi) rather than one, and none has been enacted. A pending proposal indicates legislative interest. It does not create an obligation, and advice built on it would be advice built on something that does not yet exist.
The practical framework is use-case based. The Law on the Protection of Personal Data No. 6698 (Kişisel Verilerin Korunması Kanunu) applies wherever an AI system processes personal data. The Turkish Code of Obligations No. 6098 (Türk Borçlar Kanunu) shapes contractual and tort liability. The Law on Intellectual and Artistic Works No. 5846 (Fikir ve Sanat Eserleri Kanunu) governs copyright questions around training material and generated output. Consumer, employment, commercial and sector-specific rules enter according to the product, the data and the decision involved.
Policy direction has become considerably clearer in 2026. The Türkiye Artificial Intelligence Action Plan for 2026 to 2030 was put into force by Presidential Circular No. 2026/9, published in the Official Gazette (Resmî Gazete) No. 33344 dated 18 August 2026, and it replaces the National Artificial Intelligence Strategy for 2021 to 2025. The Plan is coordinated by the Ministry of Industry and Technology (Sanayi ve Teknoloji Bakanlığı) and organised around four official principles, “Fark Et, İstifade Et, Üret ve Yönet”, which translate roughly as recognise, benefit, produce and govern.
What that combination produces is a field with a great deal of law and no map. A company can be fully compliant with every instrument it knows about and still be exposed, because the instrument that applies to its AI use case belongs to a regime it never associated with technology. The legal task is to identify the activity, the data, the actors, the market and the consequence, then attach the rules that follow each of them.
⚖️ When Does a Business Need an AI Lawyer in Turkey?
A business needs AI legal review when artificial intelligence moves out of experimentation and into a process that affects data, people, contracts, money, rights or market access. The threshold has nothing to do with whether the company describes itself as a technology company. A manufacturer running predictive maintenance, an employer using a recruitment scoring tool and a retailer deploying a customer chatbot each generate materially different obligations, and none of them would appear on a list of AI businesses.
The useful first step is an inventory of use cases rather than a compliance programme. The inventory records the system, its business purpose, the provider, the users, the data categories, the processing location, the affected individuals, the role the system plays in decisions and where its output ends up. Without that map, a company reviews a vendor agreement while missing the employee data transfer underneath it, or publishes a privacy notice while missing the terms that govern who may reuse generated output.
Timing matters most in procurement. AI vendor terms allocate responsibility for training data, prompts, output, security incidents, model changes, availability and third-party claims, and they do it before anyone in the business has thought about those questions. Once the tool sits inside customer service, human resources or product development, renegotiating those points costs more than addressing them would have cost at signature, and in some cases the commercial moment for raising them has simply passed.
Cross-border businesses should keep two analyses separate. An Istanbul-based company can carry obligations under Law No. 6698 because it processes personal data locally while simultaneously facing EU AI Act questions because it places a system on the Union market or produces output intended for use there. Those are different questions with different answers, and merging them produces either unnecessary compliance work or an uncovered gap.
⚖️ AI Risk Is Usually Built Before Anyone Sees the Product
The quietest AI risks are created during design and procurement, in decisions that never look legal at the time they are taken. Training data is collected without a defined legal basis. Confidential material is pasted into a third-party model. A standard software agreement gives the vendor broader rights over inputs than the business realised it was granting. A workflow is automated without a human review point, because no one asked who would be answerable for the output.
For companies building AI, review begins with the provenance of data and code. Do the datasets contain personal data, copyrighted material or confidential information belonging to someone else. Do the licences permit training and commercial use, or only access. Do open-source components carry obligations that conflict with the intended distribution model. These questions have answers that are cheap to obtain early and expensive to obtain after a product has shipped.
For companies buying AI, the focus moves to vendor diligence and operational control. Counsel needs to know whether prompts are retained, whether customer data can be used to improve the provider’s models, where processing occurs, which subprocessors are involved, what audit rights exist, and how liability is allocated when the system produces an inaccurate or infringing result. Most of that sits in documents the business signed without legal review, because the subscription looked like software rather than like a data processing arrangement.
There is a further category that companies consistently underestimate: use that nobody procured at all. Employee-led adoption develops faster than governance, and it leaves no contract trail to review. That is the pattern the Personal Data Protection Authority described in its March 2026 material on generative AI tools in the workplace, and it is the reason an AI review that starts from the vendor list starts from an incomplete picture.

Not sure which AI systems your Turkish operation is already carrying obligations for?
A use-case review maps the systems, the data flows and the vendor terms before technical integration makes the structure difficult to change.
⚖️ AI and KVKK: Personal Data Does Not Stop Being Personal Data Inside a Model
The Law on the Protection of Personal Data No. 6698 applies to an AI system wherever the activity involves processing personal data within the scope of that statute. Technology does not create an exemption. Purpose limitation, proportionality, legal basis, transparency, retention, security and data subject rights all continue to apply, and they apply to the model’s inputs, its processing and its outputs separately.
Personal data can enter an AI system at three distinct points, and each point carries its own analysis. Training data may contain information about identifiable individuals. Prompts submitted by users routinely contain customer names, employee details or case facts. Output can produce information about a real person even where the system was never intended to process personal data, which means an output review is part of the compliance question rather than the end of it.
Cross-border processing adds a further layer that is frequently missed in AI deployments. Where an AI provider or one of its subprocessors handles personal data outside Turkey, the international transfer regime under Article 9 of Law No. 6698 applies to that arrangement. A continuous flow of prompts to infrastructure abroad is not an incidental transfer, and treating it as one is the most common structural error in AI procurement.
Automated decision-making deserves separate attention. Article 11 of Law No. 6698 gives a data subject the right to object to a result arising against the person from analysis of processed data exclusively through automated systems. If a scoring system produces an adverse outcome with no meaningful human involvement, that right is engaged; if a human reviews and can genuinely override the result, the analysis changes. The dividing line is the quality of the human step, not its presence on an organisation chart.
⚖️ What the Personal Data Protection Authority Has Actually Published on AI
The Personal Data Protection Authority has moved from general commentary to three specific AI publications in under five months, and each one addresses a different deployment pattern. Together they are the closest thing Turkey currently has to an applied AI compliance reference, and none of them is binding in the way a statute is binding.
The first is the Generative Artificial Intelligence and Personal Data Protection Guide, structured as fifteen questions, published on 24 November 2025. It evaluates personal data processing under Law No. 6698 across the generative AI lifecycle, and it addresses the controller and processor role question directly, which is the point where most vendor arrangements are misclassified.
The second is the Authority’s material on the use of generative AI tools in workplaces, published on 5 March 2026. It concerns publicly available third-party tools used by employees, and it names the governance problem explicitly as shadow AI, in Turkish “Gölge Yapay Zekâ”. The framing matters commercially, because a regulator that has named a phenomenon has signalled where it will look.
The third is the guide on agentic AI, published on 12 March 2026, which addresses systems that pursue objectives with varying degrees of autonomy rather than performing defined tasks. Its central observation is a legal one: a system that updates its own view of what data it needs can draw in datasets that were never contemplated at the outset, which strains purpose limitation and data minimisation at the same time. Where a company deploys agents with tool access, the Authority’s expectation is that human oversight is designed into the system rather than added afterwards.
None of these documents carries an administrative sanction of its own. Their value is predictive. They show the analytical framework the Authority intends to apply when an actual complaint or inspection arrives, and a company that has documented its position against that framework is in a materially different posture from one that has not.
⚖️ Shadow AI: When Employees Adopt AI Before the Company Does
Workplace AI risk arises in companies that have never purchased an AI system, because employees use public tools independently for drafting, translation, coding, research, customer replies and document analysis. The organisation does not know what information has left its controlled environment, which means it also cannot answer the first question any regulator or customer will ask.
A workable corporate AI policy separates approved tools from unapproved ones, defines prohibited input categories, sets review requirements for material outputs, and establishes an escalation route for suspected disclosure. A policy that exists only as a legal document changes nothing; it needs to be connected to access controls, procurement approval and training, because the behaviour it addresses is a convenience behaviour and convenience wins against documents.
Permission levels work better than blanket prohibitions. Public information, internal non-confidential material, personal data, special category personal data, source code, client information and trade secrets each justify a different rule, and a policy that treats them identically will either be ignored as unworkable or will block legitimate productivity. If the restriction does not match the actual risk of the data category, the policy fails in one direction or the other.
Confidential business information creates a separate problem from personal data, and it is the one most often overlooked. A prompt can contain an unpublished design, a pricing model, a negotiation position or a draft filing. Where the provider’s terms permit retention or reuse of inputs, the company has created a confidentiality exposure even though no personal data was involved and no data protection obligation was triggered.
⚖️ Automated Decisions, Recruitment and Performance Management
AI used to rank candidates, evaluate performance, recommend disciplinary action or influence termination sits at the intersection of data protection and employment law, and both regimes apply at once. Neither is satisfied by the other, and the vendor’s assurance that its model is fair is a technical statement, not a legal defence.
The data protection question runs through Article 11 of Law No. 6698. Where an adverse result against an individual arises from analysis carried out exclusively through automated systems, the objection right is engaged. Recruitment scoring is the clearest example, because the adverse result is a rejection and the analysis is frequently automated end to end, with the human step consisting of confirming a ranked list.
The employment question is separate and survives even where the data protection analysis is clean. A dismissal decision must be justifiable on its own merits under Turkish employment law, and a decision the employer cannot explain is difficult to defend regardless of how it was reached. If the employer cannot reconstruct why the system produced a particular output, the evidential problem arrives before the legal argument does. These questions belong with the firm’s labor law practice and, where individual disputes follow, with the employment law team.
Transparency obligations run alongside both. Candidates and employees are data subjects, and the information provided to them has to reflect what actually happens, including the role of automated analysis where it exists. A privacy notice drafted before the tool was introduced will not describe the processing that is now taking place, and updating it is usually the cheapest item on the remediation list.
⚖️ AI Vendor Agreements: The Contract Is Part of the Compliance System
An AI vendor agreement should allocate risk around data, output, model behaviour, security and change management, rather than treating the service as ordinary software. Standard software terms rarely answer whether prompts feed model improvement, who may reuse generated output, what happens when the underlying model is replaced, or who bears a third-party intellectual property claim arising from that output.
Data clauses need to identify the roles of the parties under Law No. 6698, the permitted purposes, retention periods, subprocessors, security commitments and the transfer route where processing occurs abroad. Where the arrangement involves a continuous flow of personal data outside Turkey, the appropriate safeguard has to be in place before the service starts, not documented afterwards when someone asks for it.
Output clauses require realistic allocation rather than absolute promises. Generative systems produce inaccurate and occasionally infringing material, and a vendor warranty that they will not is a warranty nobody can perform. A workable contract defines permitted use, requires human review for defined categories, restricts use in high-impact decisions, sets indemnity boundaries, and imposes notice and evidence preservation obligations when something goes wrong.
AI systems also change after signature, which distinguishes them from most licensed software. Model updates, new subprocessors, altered training practices and new features can shift the risk profile without any action by the customer. Change notification rights, audit mechanisms and a termination right tied to material change are therefore worth more than a detailed specification of the system as it existed on the day of signing. This work sits alongside contract drafting and commercial law, and disputes arising from these arrangements are handled through commercial contract disputes.
⚖️ Intellectual Property, Training Data and AI-Generated Output
AI intellectual property analysis separates three layers, because inputs, model assets and outputs each raise a different rights question. A company may have permission to access content without permission to train on it, may own proprietary code while depending on open-source components, and may receive generated output while the provider reserves broad rights to reuse it.
Under Turkish law, copyright questions are examined under the Law on Intellectual and Artistic Works No. 5846. That statute defines a work by reference to the characteristics of its author and defines the author as the person who creates the work, concepts drafted long before generative systems existed. Applying them to an AI-assisted output is a fact-specific exercise that turns on the extent of human creative contribution, and no general answer covers every output a company produces.
Does a Turkish company own what its AI tool generates? Not automatically, and ownership is the wrong first question. The first question is whether the output is protected at all, because unprotected material can be used but cannot be exclusively controlled, and a business model built on exclusivity in AI-generated assets needs that point resolved before launch rather than after a competitor copies the output.
Trade secret protection often matters more than copyright in practice. A prompt can carry a confidential formula, an internal memorandum, an unpublished design or a client strategy, and where the provider’s terms permit retention or reuse, the company has created a disclosure problem regardless of who owns the output. Businesses building proprietary AI should also review ownership across employees, contractors and development partners, which is addressed through the firm’s intellectual property practice.
⚖️ Who Is Liable When an AI System Gets It Wrong?
An AI system does not become the defendant because it produced the disputed output. Liability returns to the human and corporate actors that designed, supplied, integrated, instructed, deployed or relied on the system, together with the contracts and legal duties governing their conduct. The technology changes the evidence, not the parties.
Under Turkish private law, the Turkish Code of Obligations No. 6098 governs both contractual breach and tort-based claims, and the route depends on the relationship between the parties. A customer-facing hallucination, a defective automated recommendation and an internal decision-support error do not produce the same analysis, because in the first the company made a statement to a customer, in the second it acted on a recommendation, and in the third it made its own decision with imperfect assistance.
Consumer-facing deployments add the Law on Consumer Protection No. 6502 (Tüketicinin Korunması Hakkında Kanun). Where a chatbot describes a product incorrectly or automated content creates a misleading commercial impression, the obligations owed to the consumer belong to the business that made the statement. Labelling the output as AI-generated does not transfer that obligation to the vendor, and a disclaimer placed beneath a misleading statement does not cure the statement.
Evidence determines most outcomes here. Logs, prompt records, model versions, approval steps and human review records are what allow a company to reconstruct an incident months afterwards. A business that cannot show which system produced an output, on which version, and who approved the result, faces a factual problem before it reaches the legal argument, and the factual problem is usually the one that decides the matter.
⚖️ Does the EU AI Act Apply to a Company Established in Turkey?
The EU AI Act can apply to a company established in Turkey, because its territorial scope follows the market and the output rather than the place of incorporation. Article 2 of Regulation (EU) 2024/1689 covers, among others, third-country providers placing AI systems or general-purpose AI models on the Union market, and third-country providers and deployers where output produced by the system is used in the Union.
Scope has to be tested against the company’s role and its market path, not against its address. A Turkish developer selling an AI system into the European Union, a Turkish services business producing AI-generated output for an EU customer, and a Turkish subsidiary using an internal tool with no European connection occupy three different positions under the same Regulation. “Based in Turkey” answers none of them.
Role classification comes before obligation analysis. A company must first determine whether it is a provider, a deployer or another relevant operator, because the obligation sets differ substantially and applying the provider set to a deployer produces expensive work with no legal effect. A business that rebrands a third-party system under its own name may find that it has become a provider without intending to.
Does every Turkish company using a generative AI assistant need full EU AI Act compliance? No. The Regulation is role-dependent, use-dependent and scope-dependent, and most internal productivity use by a Turkish business with no European market path falls outside it entirely. The purpose of the analysis is to find the point where Turkish operations actually cross the European regulatory boundary, which for cross-border groups runs alongside regulatory compliance work.
⚖️ What the 2026 Amendment Delayed, and What It Did Not
The 2026 amendment to the EU AI Act postponed the high-risk obligations and left the transparency obligations in place, which means the duties currently binding a Turkish business with European exposure are the ones that were not delayed. Most commentary reports the delay. The commercially relevant half is the part that did not move.
Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It moved the obligations for stand-alone high-risk systems under Annex III to 2 December 2027, and the obligations for high-risk systems embedded in regulated products under Annex I to 2 August 2028. Those were the deadlines companies had been preparing for, and both moved by more than a year.
The general application date of Regulation (EU) 2024/1689 remained 2 August 2026, and the Article 50 transparency obligations applied from that date. Those duties include telling people when they are interacting with an AI system, labelling manipulated audiovisual content, and disclosing AI-generated text published to inform the public on matters of public interest. A Turkish company running a customer-facing chatbot for European users is inside that obligation now, not in 2027.
Two further dates fall in December 2026. The machine-readable marking requirement for synthetic content under Article 50(2) carries a grace period running to 2 December 2026, and new prohibited practices added by the amendment apply from the same date. Where a company relies on legacy systems placed on the market before the general application date, the transitional treatment depends on whether the system undergoes significant change afterwards, which makes the change management clause in the vendor contract a compliance instrument rather than an administrative one. The European Commission AI Act Service Desk maintains the consolidated implementation timeline.
⚖️ Türkiye’s AI Action Plan 2026-2030: Policy Direction, Not a Private-Sector Statute
The Türkiye Artificial Intelligence Action Plan for 2026 to 2030 is a national policy instrument addressed to public institutions, and it should not be described as though it created obligations for private companies. A circular directs the administration. It carries no administrative sanction for a private business and places no system into a legal risk category by naming one.
The Plan was presented publicly at the Türkiye Artificial Intelligence Summit on 13 June 2026 and put into force by Presidential Circular No. 2026/9, published in the Official Gazette No. 33344 dated 18 August 2026 and signed on 17 August 2026. It replaces the National Artificial Intelligence Strategy for 2021 to 2025, which had been brought into force by Circular No. 2021/18 published in the Official Gazette No. 31574 dated 20 August 2021.
The Plan is built on four official principles, “Fark Et, İstifade Et, Üret ve Yönet”, and rests on stated values of human-centred design, trustworthiness, ethical responsibility, digital sovereignty and sustainable development. Its objectives cover AI literacy, data and computing infrastructure, adoption across the public and private sectors, domestic technical capability, and a competitive and trustworthy AI ecosystem. Those are objectives for the state, and the coordination role sits with the Ministry of Industry and Technology.
What the Plan does change is the direction of supervisory capacity, and that is a reason to document governance now rather than later. A company that knows which AI systems it operates, what data those systems process, who owns each decision and which vendors are involved can adapt to a binding rule when one arrives. A company that does not will be assembling that map under a deadline, which is the expensive way to assemble it.
⚖️ Which Authority Will Supervise AI in Turkey?
Turkey has no single AI regulator today, and the most concrete signal about which authority a technology business will eventually deal with comes from parliament rather than from the executive. For a company deciding where to build its internal reporting lines, that signal is worth more than the individual policy objectives it sits alongside.
The final report of the Grand National Assembly’s Artificial Intelligence Research Commission, dated March 2026, proposes consolidating coordination and regulatory authority in this field under a single body, described as a Turkish artificial intelligence authority. The report also records an alternative that avoids creating a new institution: transforming the existing Cybersecurity Directorate (Siber Güvenlik Başkanlığı) so that it absorbs the artificial intelligence mandate. It further proposes ratification of the Council of Europe framework convention on artificial intelligence.
Neither option is in force, and a parliamentary commission report is not a source of obligation. Its practical value is directional. If the cybersecurity regulator absorbs the AI mandate, a company’s AI documentation and its cybersecurity documentation will eventually be read by the same authority, which is an argument for building them in a form that can be presented together.
In the meantime, supervision is distributed. The Personal Data Protection Authority is the active authority on AI questions today, on the basis of Law No. 6698 and three published AI documents within five months. Sectoral regulators reach AI use through their own frameworks where the deployment falls inside a regulated activity, and no authority currently holds a general AI mandate. For a foreign group, that means the correct question is not who regulates AI in Turkey, but which of several regulators reaches this specific use case.
⚖️ The Pending Bills: Three Proposals, None in Force
Three separate legislative proposals on artificial intelligence have been submitted to the Grand National Assembly of Türkiye, and treating any of them as current law is the most common error in AI commentary about Turkey. Their existence tells a company where legislative attention is concentrated. It does not tell a company what it must do.
The first was submitted on 25 June 2024 and registered under file number 2/2234. It proposes a general statutory framework covering principles such as safety, transparency, fairness, accountability and privacy, together with risk management and registration duties for high-risk systems. It remains before the relevant committees, with the Committee on Industry, Trade, Energy, Natural Resources, Information and Technology as the principal committee and the Justice Committee as the secondary committee.
Two further proposals followed in the second half of 2025, and both take a different approach: instead of a comprehensive framework, they attach artificial intelligence provisions to existing statutes, one through amendments to the criminal code and one through amendments to the internet publications regime. That difference in drafting technique matters more than the individual provisions, because it indicates that Turkey may regulate AI through targeted amendment rather than through a single framework law.
The practical rule for a business is unchanged while all three remain pending. Compliance obligations are drawn from instruments in force, and a proposal that has not been enacted creates no duty, no deadline and no category. Where a proposal would change a company’s position materially if enacted, the correct response is to track it and design for flexibility, not to comply with it in advance.
⚖️ AI Governance: What Should a Company Put in Place Now?
A practical AI governance programme starts with visibility, ownership and decision thresholds rather than with policy documents. The company should be able to say which AI systems are in use, who approved each of them, what data they receive, which decisions they influence and who can stop or override them. Governance fails when responsibility is distributed across information technology, legal, human resources and procurement with no single accountable process.
The AI inventory is most useful as a living register rather than as a one-off exercise. Useful fields include system name, vendor, business owner, purpose, user population, data categories, processing location, integration points, decision impact, human review requirement, contract date and next review date. That register is the factual base for legal classification, for vendor renegotiation and for any future audit, and assembling it is usually the single most valuable week of work in an AI programme.
Risk tiering should be grounded in the rules that actually govern the company. A Turkish business with no European market path can use a risk classification model without importing the EU AI Act categories, and doing so avoids the common outcome where a company declares a system high-risk under a regulation that does not apply to it, then finds it has created an obligation for itself that no authority imposed.
Prohibited uses need to be defined explicitly, because a policy that only describes good practice does not stop anything. Typical entries include entering special category personal data into unapproved public tools, uploading client-confidential documents, relying on unverified AI output for final legal or financial decisions, and permitting automated action above a defined impact threshold without human approval. The Personal Data Protection Authority’s March 2026 agentic AI guide points in the same direction, recommending that human oversight be integrated at the design stage. AI governance belongs inside broader corporate governance and corporate compliance structures, where board oversight, delegation and risk ownership already have a home.
⚖️ AI Legal Compliance Audit in Turkey
An AI legal compliance audit maps how a company actually uses artificial intelligence and tests each material use case against the rules that attach to it. It begins with the systems, data, contracts and decisions already inside the organisation, not with a generic list of every possible AI rule, because the generic list produces a document and the inventory produces a decision.
| Review area | Core question | Legal reference point | Typical output |
|---|---|---|---|
| AI inventory | Which systems are developed, bought or used, and by whom? | Internal, no statutory register | Use-case register and ownership map |
| Personal data | Does the system process personal data or send it abroad? | Law No. 6698, Article 9 | Gap analysis and transfer mechanism |
| Automated decisions | Does an adverse result arise from automated analysis alone? | Law No. 6698, Article 11 | Human review design |
| Vendor terms | Who controls prompts, output, retention and model improvement? | Law No. 6098 and contract | Contract revisions and change rights |
| Intellectual property | Are training inputs and generated outputs legally usable? | Law No. 5846 | Licensing and ownership controls |
| European exposure | Is the system placed on the EU market or its output used there? | Regulation (EU) 2024/1689, Article 2 | Role and applicability assessment |
| Transparency | Are users told they are interacting with AI, and is output labelled? | Article 50, applicable since 2 August 2026 | Interface and disclosure changes |
| Governance | Who approves, monitors and stops AI use? | Internal, informed by regulator guidance | AI policy and control matrix |
The audit should end with priorities rather than observations. A useful output separates immediate exposure, contract changes, policy work, technical controls, employee training and items that can simply be monitored, so that the business can sequence remediation by impact and implementation effort rather than working through a list in the order it was written.
Foreign companies entering Turkey can fold AI review into a wider corporate mandate, particularly where the Turkish subsidiary will inherit global AI tools, human resources systems, customer platforms and vendor contracts negotiated outside the Turkish legal environment. Where an acquisition is involved, the same questions belong in legal due diligence rather than in post-closing integration.
⚖️ Where AI Law Sits Beside Turkey’s Other Technology Statutes
Artificial intelligence questions in Turkey almost always sit on top of another technology regime, and the analysis is incomplete until that second regime has been identified. The AI layer supplies the use case; the underlying statute supplies the obligation, the regulator and the sanction.
This page addresses the legal treatment of artificial intelligence use cases. It does not cover the substance of the Cybersecurity Law No. 7545, the electronic commerce regime under Law No. 6563, or the content removal and platform liability framework under Law No. 5651, each of which has its own regulator, its own thresholds and its own timetables. Those regimes are dealt with separately in the firm’s work on information technology law in Turkey, and an AI deployment inside a connected industrial or platform environment usually needs both analyses rather than one.
The Istanbul context shapes which combination appears most often. Turkey’s technology exposure is concentrated among businesses that do not consider themselves technology companies: manufacturers with connected production systems, logistics operators with customer-facing tracking, hospitality groups with booking platforms, and Istanbul-based service businesses selling into European markets. When those companies add AI, they add it to an environment that is already regulated, which is why an AI review that ignores the existing stack tends to produce advice that cannot be implemented.
Group structure adds the final variable. Where the Turkish entity’s AI tools are procured and administered by a parent abroad, the obligations still attach locally while the ability to comply sits in another country. Closing that gap is a contractual exercise inside the group, and it belongs in the intra-group service agreement before an inspection or a customer audit makes the gap visible.
⚖️ How Oznur & Partners Approaches AI Legal Matters
AI legal work is most useful when it follows the technology’s actual lifecycle rather than treating artificial intelligence law as a single subject. The firm approaches AI matters through the Turkish disciplines that actually govern them: data protection, commercial contracts, corporate compliance, intellectual property, employment and dispute risk.
The starting point is factual. Counsel needs to know whether the client develops a model, integrates an interface, buys an enterprise tool, permits public generative AI, automates a decision or sells an AI-enabled product, because the same checklist cannot be applied meaningfully to those six situations. In practice the first session is usually spent establishing which of the six is actually happening, since companies frequently describe themselves as doing one and turn out to be doing three.
The second step is jurisdictional. Turkish law remains the core framework for Turkish operations, while a foreign parent, a European market path, an international data flow or a cross-border vendor adds a further layer. The objective is to find those connection points rather than to assume that every international rule applies because the technology itself is global.
The third step is implementation, and it is the step that distinguishes advice from documentation. Work typically produces contract amendments, an internal policy, transfer documentation under Article 9 of Law No. 6698, an ownership allocation for developed assets, approval thresholds, employee rules or dispute preparation. AI compliance becomes credible at the point where a legal conclusion changes a document, a control or a decision inside the business.
⚖️ Who We Work With
AI questions reach this firm through four recurring client profiles, and each one arrives with a different first problem. Identifying the profile early shortens the work, because the same statute produces different priorities depending on how the company touches the technology.
Foreign groups with a Turkish subsidiary form the first and largest profile. Their AI tools are chosen abroad and deployed locally, which makes the transfer analysis under Article 9 of Law No. 6698 the opening question and the intra-group agreement the eventual answer. Their second question is usually whether a European compliance programme covers the Turkish position, and it does not.
Product businesses building AI features form the second. Their questions concentrate on training data provenance, ownership of developed assets under Law No. 5846, and whether their market path brings them inside Regulation (EU) 2024/1689 as a provider. Startups and investor-backed companies in this group frequently need the analysis completed before a funding round rather than after it, which connects to the firm’s work on startup investment in Turkey.
Employers deploying AI in human resources form the third, and their exposure sits at the intersection of Article 11 of Law No. 6698 and Turkish employment law. Their most common request is a recruitment tool review, and the most common finding is that the human review step described in the policy does not match the human review step that actually occurs.
Regulated and payment-adjacent businesses form the fourth. For them the AI layer sits above an existing supervisory relationship, and sequencing determines what can launch and when. Where customer onboarding, identity verification or transaction monitoring is involved, the analysis extends into financial crime compliance, and where board-level ownership of the risk has to be documented, into corporate law.
⚖️ Related Legal Resources
🔹 Technology, data and regulation
Information Technology Law in Turkey covers the four statutes that AI deployments usually sit on top of, including the Cybersecurity Law No. 7545 and the post-2024 transfer regime under Article 9 of Law No. 6698.
Regulatory Compliance Lawyer addresses sector-facing obligations and inspection duties that attach where an AI use case falls inside a regulated activity.
MASAK Compliance in Turkey covers identity verification and transaction monitoring duties, which is where automated screening tools most often meet a supervisory framework.
🔹 Contracts and commercial risk
Turkish Contract Lawyer deals with the drafting of vendor, subscription and licensing terms, including change notification and termination rights tied to model updates.
Commercial Law covers risk allocation in technology transactions between businesses, including indemnity boundaries for third-party claims arising from generated output.
Commercial Contract Disputes in Turkey handles disputes arising from AI vendor arrangements, where the evidential question is usually which model version produced the disputed output.
🔹 People, assets and governance
Intellectual Property Law addresses software and generated output under the Law on Intellectual and Artistic Works No. 5846, together with trade secret protection for prompt content.
Labor Law covers workplace AI policies and AI-assisted personnel decisions, including the objection right under Article 11 of Law No. 6698.
Corporate Governance Lawyer in Turkey establishes the reporting lines that determine whether a Turkish entity can actually perform obligations attached to systems administered abroad.
Corporate Lawyer in Turkey provides cross-functional support for foreign businesses integrating inherited AI tools into a Turkish operation.
⚖️ The Question Is Not Whether Your Business Uses AI
The more useful question is where AI entered the business, and what changed when it did. A model may have changed the data flow. A chatbot may have changed who speaks to the customer. An automated score may have changed who makes a decision. A vendor term may have changed who can reuse confidential information. None of those changes announced itself as a legal event at the time.
Turkey’s AI framework is still forming, but no company is waiting in a legal vacuum while it forms. Existing Turkish law already reaches most AI use cases, the Personal Data Protection Authority is publishing increasingly specific guidance, the 2026-2030 Action Plan points toward risk-based governance and a consolidated supervisor, and the EU AI Act already binds businesses with the relevant European connection through obligations that took effect in August 2026.
Adoption is instant; exposure accumulates. Good AI compliance work does not slow the technology down. It makes visible the decisions a business has already taken by adopting it, while those decisions can still be changed.
Schedule a Legal Consultation
Whether your company is developing an AI product, deploying generative tools across business data, or bringing an AI-enabled service into the Turkish or European market, our technology and corporate lawyers in Istanbul can assess the structure before the risk becomes embedded in it.

