EU AI Law and Türkiye: Impact, Adaptation, Risks and Opportunities
Entrance
The European Union's Artificial Intelligence Regulation (EU) 2024/1689 was adopted on June 13, 2024, entered into force on August 1, 2024, and a significant portion of its provisions are to be implemented gradually by August 2, 2026. Considered the world's first comprehensive artificial intelligence regulation, this text is designed to cover not only actors within the EU but also third-country actors offering products and services to the EU market, or whose outputs are used in the EU . In this respect, for Turkey, the AI Act has the potential to become a practically binding market standard , rather than merely "external law" in the classical sense
This study will first briefly outline the basic architecture of the EU Artificial Intelligence Law; then, its scope of application, compliance requirements, risks, and opportunities will be discussed. The analysis will be based on both EU sources and current doctrine and policy texts in this field in Turkey.
I. The Core Architecture of the EU Artificial Intelligence Law: Risk-Based Model
Unlike classic sector-based regulations, the AI Act risk-based approach. Accordingly, artificial intelligence systems are divided into four main categories: unacceptably risky, high risk, subject to certain transparency obligations (limited risk) , and minimal risk .
Unacceptable risky systems – for example, some systems that force individuals to make drastic behavioral changes through manipulative techniques or social scoring systems – are completely prohibited. High-risk systems include AI systems used in healthcare, education, employment, credit scoring, critical infrastructure, justice, and law enforcement, as well as AI applications embedded in products subject to specific security regulations. These high-risk systems are subject to detailed obligations such as risk management, data governance, technical documentation, record keeping, transparency, and human oversight.
The regulation also general-purpose AI (GPAI) models under a separate heading, requiring transparency, technical documentation, and, in certain cases, additional measures specific to "systemic risk." Within this framework, large language models such as ChatGPT also fall under the scope of the AI Act, to the extent that their providers offer them to the EU market.
II. Scope and Extraterritorial Impact: What Does This Mean for Türkiye?
One of the most critical aspects of the AI Act for Turkey is its scope provision . The regulation covers providers and users of artificial intelligence systems or general-purpose AI models that supply these systems to the EU market, deploy them in the EU, or produce outputs used within the EU , regardless of whether they are established within the EU or not. This means that a company based in Turkey, even if it offers its systems from Turkey, could be subject to AI Act obligations if the outputs are used by customers in the EU.
Indeed, law firms and consulting companies operating in Turkey emphasize the extraterritorial impact of the AI Act based on the "market location" or "destination" principle, stating that Turkish actors targeting the EU market cannot ignore the provisions of the Regulation. In this respect, although the AI Act is technically part of EU domestic law, it has become a de facto external regulation that many companies in Turkey must comply with .
III. The Current Legal Framework in Türkiye and its Interaction with the EU AI Act
In Turkey, there is currently no comprehensive framework law specific to artificial intelligence that corresponds to the AI Act . Current doctrine indicates that legal oversight in the field of artificial intelligence is currently carried out primarily through the Personal Data Protection Law (KVKK) , consumer law, competition law, sectoral legislation (banking, insurance, healthcare, etc.), and product safety regulations.
On the other hand, Turkey's National Artificial Intelligence Strategy (2021–2025) and ongoing policy documents clearly state its goal of developing a regulatory framework that is aligned with the EU, based on fundamental rights, and focused on risk. In this context, the EU's AI Act serves not only as "an external regulation" but also as a normative model for Turkish legislators to refer to
Indeed, some policy notes and academic studies published in Türkiye examine the AI Act in detail, both in terms of its risk-based approach and the institutional and technical obligations it imposes on high-risk systems; they point to the possibility that potential AI legislation to be prepared in Türkiye may converge towards the EU line.
Therefore, for Turkey, the situation has a two-tiered impact:
(i) Direct impact, through private sector actors doing business with the EU;
(ii) Indirect impact, through Turkey referencing the AI Act when designing its own domestic regulations.
IV. Adaptation Dimension: Concrete Implications for Turkish Companies
1. Role Identification and Risk Classification
The first question Turkish companies need to answer is what role they play under the AI Act : each role—provider, deployer, importer/distributor, or manufacturer of a product containing embedded AI—is linked to different sets of responsibilities. A Turkish startup offering a SaaS product or API for the EU market is, in most cases, of a provider ; however, a company developing an embedded driver assistance system for the automotive industry may face liability as a “manufacturer/provider” in terms of both product safety and the high-risk systems regime.
Secondly, a risk classification is necessary for each AI system . Applications such as medical devices with autonomous functions, credit scoring systems, and rating and selection systems in employment and education are expected to be categorized as high-risk under the AI Act. In contrast, general-purpose chatbots that only generate marketing content or answer customer questions will remain in the limited or minimal risk category in most cases; however, the context of use (e.g., legal or medical advice) may alter this classification.
2. Institutional and Technical Responsibilities Regarding High-Risk Systems
For projects falling into the high-risk system category, EU sources emphasize a risk management system operating throughout the lifecycle , data governance policies, detailed technical documentation, continuous logging and traceability, human oversight mechanisms, and transparency obligations. This framework represents not only an export requirement to the EU for Turkish companies but also a kind of “trusted AI” standard that reshapes product design philosophy
In practice, this necessitates concrete steps such as establishing an AI governance structure , subjecting AI projects to a specific approval process, documenting datasets and model cards, conducting explainability tests, and adding compliance clauses referring to the AI Act to contracts with EU clients.
V. Risks: Market Access, Fines, and Regulatory Burden
For Turkish actors who fail to comply with the EU Artificial Intelligence Law, three main risk categories stand out: market risk, legal/financial risk , and regulatory burden.
In terms of market risk, distributors and corporate customers in the EU, just as with the GDPR process, are increasingly “AI Act compliant” products and suppliers. Products that have not completed the conformity assessment process or submitted the necessary technical documentation are highly likely to be excluded from key EU market segments.
In terms of legal and financial risks, the AI Act up to 7% of global turnover ; this is even higher than GDPR and is a highly deterrent, especially for large-turnover companies. In addition to these sanctions, product recall, contractual damages, and reputational damage must also be considered.
In terms of regulatory burden, even within the EU, there have been recent the implementation schedule and scope ; some companies and member states have requested postponements and simplifications. However, these discussions are not about completely withdrawing the regulation, but rather about calibration taking into account competitiveness and innovation capacity. Therefore, for Turkish companies, a "let's wait, maybe it will soften" approach carries a significant risk of legal uncertainty and strategic delay.
VI. Opportunities: Transforming Adaptation into a Competitive Advantage
To say that the AI Act only creates risks for Turkey would be an understatement; the regulation also creates significant opportunities for proactive actors
First and foremost, Turkish companies developing products and processes compliant with the AI Act "reliable and regulation-friendly suppliers" . Particularly in highly regulated sectors such as finance, healthcare, automotive, human resources, and public services, compliance with the AI Act a significant commercial differentiator . This will strengthen the hand of Turkish startups in EU partnerships, investment, and acquisition processes.
Secondly, the compliance process is creating a new professional market in Turkey AI law, AI governance, compliance auditing, and RegTech . Law firms, auditing firms, and AI-focused technology startups can find new business opportunities both within Turkey and on a regional scale by offering AI Act compliance projects, model auditing, bias testing, and technical-legal reporting services.
Finally, the corporate practices sought by the AI Act—such as risk management, data governance, accountability, and human oversight—are not merely external compliance requirements, but opportunities for companies to raise their own internal quality and safety standards . These standards will also build trust and brand value among customers outside the EU market.
Conclusion
The EU Artificial Intelligence Act is significant for Turkey on two levels. Firstly, the direct impact: Turkish companies offering AI products or services to the EU market become effectively subject to the Regulation's provisions; non-compliance carries serious market risks, fines, and reputational risks. Secondly, the indirect impact: Turkey's national legislation and policy framework in the field of artificial intelligence will most likely be influenced by and seek a certain degree of convergence with the AI Act's risk-based, fundamental rights-oriented approach.
In this context, the main issue for public authorities and the private sector in Turkey is not to view the AI Act merely as “external regulatory pressure,” but a reference standard that will make their own artificial intelligence ecosystem more reliable, transparent, and competitive . Instead of viewing the compliance process as a passive cost, early and smart compliance as a strategic investment are poised to be the winners in the coming period.