top of page

How will the EU AI Act Affect Turkish Companies?

  • 1 day ago
  • 5 min read

The increasing use of artificial intelligence technologies in business processes has introduced new legal and compliance obligations for companies. As one of the most comprehensive legislative instruments in this field, the European Union Artificial Intelligence Act (Regulation (EU) 2024/1689) (the “EU AI Act” or the “Act”) establishes a risk-based regulatory framework that applies not only to companies developing AI systems but, under certain circumstances, also to companies deploying and using such systems.

The provisions of the AI Act will enter into application on a phased basis. As of 2 August 2026, the provisions relating primarily to transparency obligations, as well as the governance, implementation and enforcement mechanisms of the Act, will become applicable. The obligations concerning high-risk AI systems will apply as of 2 December 2027. Although the AI Act is an EU regulation, Turkish companies may also become subject to its provisions where the relevant jurisdictional criteria are met.

Scope of Application of the AI Act

Pursuant to Article 2 of the AI Act, the Act does not apply exclusively to natural or legal persons established within the European Union. Under certain circumstances, companies established outside the EU may also fall within its scope.

Accordingly, where an AI system developed or placed on the market by a company established in Turkey is made available on the EU market, or where the output generated by such an AI system is used within the European Union, the provisions of the AI Act may become applicable.

Key Obligations for Companies Under the AI Act

The obligations imposed under the AI Act vary depending on both the company's role within the AI value chain and the risk classification of the AI system concerned. Accordingly, companies should first determine whether they qualify as a provider, deployer, importer, or distributor under the AI Act. A single company may simultaneously assume multiple roles with respect to different AI systems or business activities.

The obligations imposed on providers are the most comprehensive. In particular, with respect to high-risk AI systems, providers are required to establish a risk management system, implement appropriate data governance measures, prepare technical documentation, conduct conformity assessment procedures, provide instructions for use, carry out post-market monitoring activities, and report serious incidents where required. Furthermore, under certain circumstances, a person making a substantial modification to an AI system or placing the system on the market under its own name or trademark may also be deemed a provider under the AI Act.

Deployers, on the other hand, are required to use AI systems in accordance with the provider's instructions for use, ensure that personnel operating the system possess the necessary competence and training, implement appropriate human oversight measures where applicable, and retain the records required for high-risk AI systems. In addition, deployers should take into account the reporting and cooperation obligations prescribed by the AI Act with respect to incidents and risks that may affect the health, safety or fundamental rights of individuals during the operation of high-risk AI systems.

As regards importers and distributors, the AI Act requires them to verify, prior to placing high-risk AI systems on the EU market, that the applicable conformity assessments, technical documentation and other compliance requirements have been fulfilled. Where non-compliance is identified, importers and distributors are required to refrain from making the system available on the market, ensure that appropriate corrective measures are taken, and cooperate with the competent authorities.

How Should Turkish Companies Prepare for Compliance?

The AI Act applies not only to AI systems placed on the market by entities established within the European Union, but also to AI systems and AI-enabled products developed in third countries and made available on the EU market. Furthermore, it may also apply to AI systems established outside the EU where the outputs generated by such systems are used within the European Union.

Accordingly, Turkish providers placing AI systems or AI-enabled products on the EU market, as well as businesses within the EU importing such systems from Turkey, may also become subject to the obligations set out under the AI Act. These obligations require both legal and technical assessments and therefore necessitate close cooperation between different business functions within an organisation. Companies established in Turkey that currently offer, or intend to offer, AI systems and/or AI-enabled products in the EU market should therefore take the necessary steps to ensure compliance with the AI Act.

In order to achieve compliance with the obligations prescribed by the AI Act, companies should first assess their current AI landscape. In this context, establishing an AI inventory by identifying all AI systems used within the organisation, assessing their intended purposes and associated risks, adopting an AI Use Policy, conducting Vendor Due Diligence on third-party AI providers, and implementing AI Literacy training programmes for employees constitute the key building blocks of an effective compliance programme.

In addition, companies should periodically review the use of AI systems, continuously monitor legal and technical risks, and implement human oversight and additional control mechanisms where appropriate in order to ensure the effectiveness of their AI Governance framework.

Compliance with the AI Act should not be viewed solely through the lens of AI systems themselves. Rather, AI compliance should be integrated with broader compliance areas, including data protection, cybersecurity and information security, third-party risk management, and internal corporate governance processes.

Consequences of Non-Compliance with the AI Act

Failure to comply with the obligations set out under the AI Act may result in significant administrative fines, depending on the nature of the infringement. Violations involving prohibited AI practices may result in administrative fines of up to EUR 35 million or 7% of the company's total worldwide annual turnover for the preceding financial year, whichever is higher. Infringements relating to certain obligations applicable to high-risk AI systems may result in fines of up to EUR 15 million or 3% of the company's worldwide annual turnover.

Accordingly, companies should assess their obligations under the AI Act not only from a regulatory compliance perspective but also in light of the substantial financial and reputational risks associated with non-compliance.

Regulatory Developments in Turkey

Regulatory developments concerning artificial intelligence have also accelerated in Turkey. The Personal Data Protection Authority (KVKK) has published guidance regarding the use of generative AI tools, legislative proposals relating to artificial intelligence have been introduced before the Grand National Assembly of Turkey, and new institutional structures focusing on AI governance have been established within public authorities.

These developments demonstrate that the regulation of artificial intelligence in Turkey is increasingly being addressed not merely as a technological issue but also as a matter of regulatory compliance across various sectors.

Considering Turkey's legislative approach of closely aligning with developments in EU legislation, particularly in the fields of data protection and digital regulation, it is expected that future domestic AI legislation will largely adopt the same risk-based approach and core compliance principles reflected in the AI Act.

Conclusion

The AI Act is a regulatory framework capable of applying, under certain circumstances, to companies established outside the European Union and may therefore have significant implications for companies operating in Turkey. In particular, where AI-generated outputs are used within the European Union or companies conduct business activities targeting the EU market, the obligations set out under the AI Act should be carefully assessed.

Against this background, companies should identify their respective roles under the AI Act, assess the AI systems they use together with the risks arising therefrom, establish internal AI-related policies and procedures, enhance employee awareness through appropriate training, and evaluate AI providers from a compliance perspective. Taking these proactive measures will be essential for effectively managing the legal, regulatory and commercial risks associated with the use of artificial intelligence.

bottom of page