Trackers
Trackers

AI Regulation in Turkey: 2026 Update

AI regulation in Turkey is evolving rapidly. The country has moved from a soft-law approach - relying on existing sectoral rules and voluntary guidelines - toward a more structured legislative framework that places direct obligations on developers, deployers, and importers of AI systems. For international businesses operating in or entering the Turkish market, understanding this framework is no longer optional. This guide covers the current regulatory landscape, the key authorities involved, sector-specific rules, compliance obligations, and the practical steps companies should take to stay ahead.

The current state of AI regulation in Turkey

Turkey does not yet have a single, consolidated AI Act equivalent to the European Union';s framework. Instead, ai regulation turkey is currently built on a layered combination of existing legislation, presidential strategy documents, and sector-specific guidance issued by independent regulators. This layered structure means that compliance obligations depend heavily on the industry in which an AI system is deployed.

The most significant overarching document is Turkey';s National Artificial Intelligence Strategy, which sets out the government';s ambitions for AI development, adoption, and governance. The strategy identifies priority sectors - including health, agriculture, transport, and finance - and calls for the development of binding legal instruments to govern high-risk AI applications. While the strategy itself is not law, it has driven concrete regulatory action across multiple ministries and agencies.

The Personal Data Protection Law (KVKK), which closely mirrors the EU';s GDPR, applies directly to AI systems that process personal data. Any AI application that profiles individuals, makes automated decisions, or uses personal data for training purposes must comply with KVKK requirements. This includes obtaining valid legal bases for processing, implementing data minimisation principles, and - critically - respecting the right of data subjects not to be subjected to decisions based solely on automated processing. The Personal Data Protection Authority (KVKK Kurumu) enforces these rules and has issued guidance specifically addressing automated decision-making.

The Turkish Commercial Code and the Law on Electronic Commerce also carry indirect relevance for AI-powered commercial platforms, particularly those using algorithmic pricing, automated contracting, or AI-driven recommendation systems. Businesses using such tools in consumer-facing contexts must ensure compliance with consumer protection rules administered by the Ministry of Trade.

Key regulatory authorities and their roles

Several authorities share responsibility for AI oversight in Turkey, and understanding which body governs which domain is essential for any compliance programme.

The Personal Data Protection Authority (KVKK Kurumu) is the primary regulator for AI systems that involve personal data processing. It has the power to investigate, impose administrative fines, and order the suspension of data processing activities. Its guidance on automated decision-making is directly relevant to AI developers and deployers working with Turkish user data.

The Information and Communication Technologies Authority (BTK) regulates digital infrastructure, online platforms, and telecommunications. BTK has become increasingly active in overseeing AI-driven content moderation, algorithmic recommendation systems, and the use of AI by social media platforms operating in Turkey. Platforms above certain user thresholds are required to appoint local representatives and comply with content-related obligations that increasingly intersect with AI governance.

The Banking Regulation and Supervision Agency (BDDK) and the Capital Markets Board (SPK) govern AI use in financial services. Both regulators have issued guidance requiring financial institutions to maintain explainability and auditability of AI-driven credit scoring, fraud detection, and investment advisory systems. Institutions must be able to demonstrate to regulators how an AI system reached a particular decision.

The Health Ministry and the Medicines and Medical Devices Agency (TITCK) regulate AI applications in healthcare, including diagnostic tools, clinical decision support systems, and AI-powered medical devices. These systems are subject to conformity assessment procedures before they can be placed on the Turkish market.

The Competition Authority (Rekabet Kurumu) has signalled interest in AI-driven pricing and market behaviour, particularly in digital markets. Businesses using AI for dynamic pricing or market analysis should be aware that competition law scrutiny in this area is increasing.

Sector-specific AI compliance obligations

The practical compliance burden for any given business depends on the sector in which it operates. Turkey';s approach to AI regulation is, at present, predominantly sector-driven rather than horizontal.

In financial services, AI systems used for credit decisions, anti-money laundering screening, or customer risk profiling must meet explainability standards set by BDDK. A common mistake among foreign fintech companies entering Turkey is assuming that compliance with EU AI Act requirements automatically satisfies Turkish rules. The two frameworks differ in important respects, particularly around documentation and local audit requirements.

In healthcare, AI-powered diagnostic or monitoring tools are treated as medical devices and must undergo a conformity assessment process administered by TITCK. This process can take several months and requires technical documentation, clinical evidence, and in some cases local clinical validation. Many underestimate the time required for this process and plan product launches without adequate lead time.

In the media and platform sector, BTK';s oversight of algorithmic content systems has intensified. Platforms using AI to moderate content or curate feeds for Turkish users must be able to demonstrate that their systems do not systematically suppress or amplify content in ways that violate Turkish law. The practical challenge is that BTK';s expectations in this area are still evolving, and guidance is issued through administrative decisions rather than formal legislation.

In the public procurement and government services context, Turkey has been piloting AI tools in tax administration, customs, and social services. Vendors supplying AI systems to public bodies must comply with procurement rules and, increasingly, with cybersecurity and data localisation requirements that affect how AI systems are designed and hosted.

For businesses operating across multiple sectors, a practical scenario worth considering is a multinational technology company that provides an AI-powered HR platform to Turkish employers. Such a platform would simultaneously engage KVKK rules on automated employment decisions, BTK rules on data processing infrastructure, and potentially the Ministry of Labour';s evolving guidance on algorithmic management. Mapping these overlapping obligations early is essential.

If your business operates AI systems in Turkey and you are uncertain which regulators apply to your specific use case, contact info@vlolawfirm.com. We can help structure the compliance analysis correctly the first time.

Recent legislative developments and upcoming changes

Turkey';s legislative activity on AI has accelerated noticeably in recent periods. Several developments are shaping the near-term compliance environment.

The most significant development is the preparation of a draft AI Law that would introduce a horizontal, risk-based framework broadly inspired by the EU AI Act but adapted to Turkey';s legal and administrative context. The draft has been circulated for stakeholder consultation and is expected to introduce tiered obligations based on the risk level of AI applications - from minimal-risk systems subject only to transparency requirements, to high-risk systems requiring conformity assessments, to prohibited applications. The timeline for formal adoption has not been finalised, but businesses should treat the draft as a reliable indicator of where binding obligations are heading.

The KVKK Kurumu has issued updated guidance on automated decision-making and profiling, clarifying that AI systems making consequential decisions about individuals - such as credit approvals, insurance pricing, or employment screening - must provide meaningful human oversight and the ability for individuals to contest automated outcomes. This guidance builds on existing KVKK provisions but applies them explicitly to AI contexts.

BTK has introduced new requirements for large online platforms, including obligations to publish transparency reports on algorithmic systems. These reports must describe how recommendation and content moderation algorithms function at a general level, what safeguards are in place, and how user complaints about algorithmic decisions are handled.

Turkey';s alignment with the Council of Europe';s Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law - the first binding international AI treaty - is also relevant. Turkey participated in the negotiations and has signalled its intention to ratify. Once ratified, the Convention will impose obligations on Turkey to ensure that AI systems used by public authorities and, in certain respects, private actors respect human rights standards. This will likely accelerate domestic legislative action.

A non-obvious requirement that surfaces in practice is the interaction between AI regulation and Turkey';s data localisation rules. Certain categories of data - including financial data and health data - must be stored on servers located in Turkey. AI systems that process such data must therefore be designed with localisation in mind from the outset, not retrofitted after deployment.

Practical compliance steps for international businesses

For international companies already operating or planning to operate AI systems in Turkey, the following practical framework is useful.

The first step is to map all AI systems against the sectors and regulators described above. A system that seems straightforward in one jurisdiction may trigger multiple regulatory touchpoints in Turkey. This mapping exercise should identify which authority has primary jurisdiction, what documentation is required, and whether any pre-market approval or registration is needed.

The second step is to assess data flows. Any AI system processing personal data of Turkish residents is subject to KVKK. This means conducting a data protection impact assessment for high-risk processing activities, establishing a valid legal basis for each processing purpose, and implementing data subject rights mechanisms - including the right to contest automated decisions.

The third step is to build explainability into AI systems from the design stage. Turkish financial and health regulators, in particular, expect to be able to audit how an AI system reaches its outputs. Black-box systems that cannot provide any account of their reasoning are increasingly difficult to defend before Turkish regulators, even where they are technically lawful.

The fourth step is to monitor the progress of the draft AI Law and the Council of Europe Convention ratification. Both instruments will introduce new obligations, and businesses that begin adapting their systems and documentation now will be better positioned than those that wait for formal adoption.

A practical scenario that illustrates the compliance challenge: a European insurance company deploying an AI-driven underwriting tool in Turkey must simultaneously satisfy KVKK requirements on automated decision-making, BDDK guidance on explainability in financial services, and the emerging expectations of the draft AI Law on high-risk AI systems. Each layer adds documentation, governance, and audit requirements. Companies that treat these as separate compliance exercises rather than an integrated programme typically face duplication of effort and gaps in coverage.

FAQ

What is the most significant legal risk for a foreign company deploying AI in Turkey right now?

The most immediate risk is non-compliance with the Personal Data Protection Law (KVKK) in the context of automated decision-making. Turkish law gives individuals the right not to be subjected to decisions based solely on automated processing that produce legal or similarly significant effects. AI systems that make such decisions without adequate human oversight, without a valid legal basis, or without a mechanism for individuals to contest outcomes are exposed to administrative fines and potential suspension orders from the KVKK Kurumu. Foreign companies often underestimate this risk because they assume GDPR compliance is sufficient - but KVKK enforcement is conducted independently, and Turkish regulators may reach different conclusions on specific issues.

How long does it take to obtain regulatory clearance for an AI system in Turkey, and what does it cost?

The timeline and cost depend entirely on the sector and the risk level of the system. For a healthcare AI product classified as a medical device, the conformity assessment process administered by TITCK typically takes several months and requires substantial technical documentation and clinical evidence. For a financial services AI tool, there is no formal pre-approval process, but building the documentation required to satisfy BDDK audit expectations can take weeks to months depending on the complexity of the system. Professional and legal fees for a comprehensive AI compliance programme in Turkey typically start from the low thousands of EUR for straightforward cases and rise significantly for multi-sector or high-risk deployments. State registration or filing fees, where applicable, are modest by comparison.

Should a business wait for Turkey';s draft AI Law to be adopted before investing in compliance?

Waiting is not advisable. Existing obligations under KVKK, BDDK guidance, and BTK requirements are already in force and are being actively enforced. The draft AI Law will add to these obligations rather than replace them, and businesses that have not addressed the existing framework will face a larger compliance gap when the new law is adopted. Moreover, the draft law';s risk-based approach means that high-risk AI systems will face the most demanding requirements - and the time needed to redesign systems, build documentation, and train staff means that early preparation delivers a material advantage. Companies that begin compliance work now, based on the draft law';s direction, will be better positioned to meet formal obligations quickly once the law enters into force.

Conclusion

Turkey';s AI regulatory environment is complex, multi-layered, and changing quickly. Existing rules under KVKK, sector-specific guidance from BDDK, BTK, and TITCK, and the approaching draft AI Law together create a demanding compliance landscape for any business deploying AI systems in the country. The cost of non-compliance - in fines, reputational damage, and operational disruption - is rising as enforcement activity increases. Acting early, mapping obligations carefully, and building explainability and human oversight into AI systems from the outset are the practical steps that distinguish well-prepared businesses from those that face avoidable problems.

Contact info@vlolawfirm.com to discuss your specific situation. We can assist with documents and filings, and with structuring your compliance programme to address both current and upcoming requirements.

VLO Law Firms advises international clients on AI regulation in Turkey. We can assist with regulatory mapping, KVKK compliance, sector-specific filings, and preparation for the upcoming AI Law. To request a consultation, contact: info@vlolawfirm.com