🔴Illinois HB 3773IN EFFECTUp to ~$70K/violation|🔴Texas TRAIGA (HB 149)IN EFFECTAG-enforced|🔴Utah AI Policy ActIN EFFECT$2,500/violation|⚠️Colorado AI Act (SB 205)Jan 1, 2027AG-enforced|⚠️California SB 942Aug 2, 2026$5K/day|⚠️EU AI Act Art. 50Aug 2, 2026€35M or 7% revenue|⚠️New York RAISE ActJan 1, 2027AG civil penalties|
European Union · EU AI ActNo AI-specific statute — general data protection, competition and consumer law apply

Türkiye AI Compliance Checklist

Step-by-step actions every business serving customers in this country must take to meet EU AI Act and local rules.

Deadline: No AI-specific compliance deadline, because there is no AI-specific statute. The duties that reach AI systems are the standing ones under Law No. 6698, in force since its publication in the Resmî Gazete on 7 April 2016.Penalty: No AI-specific penalty exists in Turkish law. Penalty amounts under Laws 6698, 4054 and 6502 are deliberately NOT quoted here: the operative penalty articles were not read at source in this pass, and Turkish administrative fines are revalued annually, so a figure carried from a secondary source would be both unsourced and out of date. The enforcement corpus holds 8 Turkish matters decided under these statutes.

How AI law works in Türkiye

Türkiye has no artificial-intelligence act. What binds an AI deployer is general law, and this is the legal basis under which the eight Turkish matters already in the enforcement corpus were decided. Law No. 6698, the Kişisel Verilerin Korunması Kanunu, was adopted on 24 March 2016 and published in Resmî Gazete No. 29677 on 7 April 2016; it is the statute the Kişisel Verileri Koruma Kurumu (KVKK) acts under, and it governs the personal data an AI system is trained on and processes. Law No. 4054 on the Protection of Competition, published in Resmî Gazete No. 22140 on 13 December 1994, is the route an algorithmic-pricing or self-preferencing matter takes before the Rekabet Kurumu. Law No. 6502 on Consumer Protection, published in Resmî Gazete No. 28835 on 28 November 2013, is the Reklam Kurulu's statute and the parent of the advertising rules that carry Türkiye's AI-disclosure obligation. Platform and ranking systems are additionally reached by Law No. 5651 on internet publications and Law No. 6563 on electronic commerce. Every date and gazette number above is lifted verbatim from the header block of the consolidated text published by the Cumhurbaşkanlığı Mevzuat Bilgi Sistemi. ⚠️ These statutes are AI-RELEVANT, not AI-specific, and the distinction matters: none of them mentions artificial intelligence, and presenting them as Türkiye's AI regime would overstate what the country has enacted.

Applicable laws

  • 📜 Kişisel Verilerin Korunması Kanunu No. 6698 (Personal Data Protection Law)
  • 📜 Rekabetin Korunması Hakkında Kanun No. 4054 (Protection of Competition Law)
  • 📜 Tüketicinin Korunması Hakkında Kanun No. 6502 (Consumer Protection Law)

An EU AI Act compliance checklist for Türkiye businesses begins with system identification and inventory. Document every AI system your organization deploys or relies on — include third-party tools (marketing automation, recommendation engines, fraud detection, hiring assessments, content moderation), internal models, and any system that makes automated decisions affecting EU residents. For each system, record: what it does, what data it uses, whether it qualifies as high-risk under the EU AI Act, and whether you built it or procured it from a vendor. This inventory is the compliance foundation — you cannot manage risk for systems you have not documented.

Step two is risk-level assessment and documentation obligation. For each system in your inventory, determine whether it meets the EU AI Act's definition of high-risk. High-risk categories include: systems used in hiring, promotion, performance monitoring, or firing; systems used for benefits eligibility (loans, insurance, social services); systems used in law enforcement, criminal risk assessment, or immigration; systems used for biometric identification or facial recognition; and systems that materially impact legal rights or safety. If a system is high-risk, you must complete a documented conformity assessment before it goes into production, addressing bias testing, model explainability, data-quality assessment, and human-oversight design. If the system has already deployed and is high-risk, you must complete this assessment immediately and prepare remediation.

Step three is transparency and user-rights implementation. For limited-risk systems (chatbots, transparent AI tools), you must disclose to end users that they are interacting with AI and provide information about the system's capabilities and limitations. For high-risk systems, you must go further: provide clear, accessible notice to individuals subject to AI decisions, explain how the AI system works, disclose the personal data being used, and provide a mechanism for individuals to request human review or appeal the AI decision. In Türkiye, this transparency obligation is enforceable directly by end users — a failure to provide required disclosures creates both regulatory exposure and private civil liability for breach of individual rights.

Step four is ongoing monitoring and human-oversight deployment. For high-risk systems, you must establish a process by which individuals can escalate AI-driven decisions to a human decision-maker with authority to override and provide a substantive review. This human-review process must be monitored: log every escalation, review escalation patterns monthly to identify when the AI system is consistently overridden (a sign of miscalibration), and retrain the model if needed. You must also maintain audit logs of every high-risk AI decision for at least three years, capturing inputs, model version, confidence scores, and reviewer notes. These logs are evidence of compliance and a key defense against penalty allegations.

Step five is governance, vendor management, and readiness for inspection. Designate a compliance owner and establish a schedule for annual risk re-assessment and bias re-testing of high-risk systems. If you use third-party AI vendors, review their documentation of conformity assessment, bias testing, and data-protection practices — if they cannot provide it, treat the deployment as high-risk and conduct assessment yourself. Maintain a written compliance manual describing your AI systems, how you assess and mitigate risk, how you handle human review, and how you meet transparency obligations. This manual is both an operational guide and evidence of good-faith compliance — regulators and private litigants will ask for it. By August 2, 2026, your organization should be prepared for a regulatory inspection covering all high-risk systems.

The Türkiye AI compliance checklist

Disclosure & transparency

Notify Türkiye users when AI is part of a consequential decision affecting them, in plain language and before the decision is final.
Label AI-generated text, image, audio, or video content (Article 50, EU AI Act) where a reasonable person could be misled.
Maintain an internal register of all AI systems serving Türkiye users, including purpose, model, and risk classification.
Publish a public-facing AI usage statement on your website covering Türkiye.

Risk classification & assessment

Classify each AI system against Türkiye's national framework. Where rules are sector-specific, layer applicable EU/UK obligations on top.
Run a Data Protection Impact Assessment (DPIA) under GDPR Article 35 / equivalent for any system that profiles or makes automated decisions about people.
Document training data sources, validation, and testing — regulators in Türkiye can request the technical file.
Implement bias / fairness testing across protected categories (race, gender, age, disability, religion).

Governance & accountability

Designate an EU representative if your business is established outside the EU (EU AI Act Art. 22 / GDPR Art. 27).
Cooperate with the local supervisory authority — for Türkiye this is typically the national DPA plus an AI-specific competent authority.
Adopt an AI acceptable-use policy and require staff acknowledgement.
Stand up an incident-response procedure: within 72h GDPR breach window, plus EU AI Act serious-incident reporting.

Technical controls

Apply data minimization to all prompts/inputs sent to AI vendors.
Sign a DPA + EU AI Act compliance addendum with every AI vendor.
Enable detailed audit logging for AI-assisted decisions.
Build a contestation / human-review path for adverse automated decisions, satisfying GDPR Art. 22.

More Türkiye resources

💰 AI Law Fines & Penalties📋 AI Compliance Requirements📖 AI Compliance Guide AI Law Deadlines← All Türkiye resources

Other countries

Germany (EU)France (EU)Netherlands (EU)Spain (EU)Italy (EU)Sweden (EU)
Editorial standards

Anchored to the primary government source (statute, bill text, or agency rule) and verified directly against it · Last verified Sep 2, 2026. See our methodology.

Primary sources · Türkiye
  • mevzuat.gov.trhttps://www.mevzuat.gov.tr/mevzuat?MevzuatNo=6698&MevzuatTur=1&MevzuatTertip=5
  • mevzuat.gov.trhttps://www.mevzuat.gov.tr/mevzuat?MevzuatNo=4054&MevzuatTur=1&MevzuatTertip=5
  • mevzuat.gov.trhttps://www.mevzuat.gov.tr/mevzuat?MevzuatNo=6502&MevzuatTur=1&MevzuatTertip=5