Regulation (EU) 2024/1689 (the "EU AI Act" or the "Act") entered into general application on 2 August 2026. Türkiye is not bound by the Act, yet its extraterritorial scope extends to a wide range of Turkish businesses, from software vendors and outsourcing providers to industrial manufacturers that build AI into products exported to the EU market.
Compliance Timeline: Provisions Applicable as of 2 August 2026
- 2 February 2025: Article 5 prohibitions and the AI literacy obligation (Article 4).
- 27 July 2026: Governance and penalty framework (Articles 102 to 110).
- 2 August 2026: General application of the Act and the Article 50 transparency obligations (disclosure of chatbots, marking of AI-generated content and labelling of deepfakes).
- 2 December 2026: New Article 5 prohibitions on AI-generated intimate imagery and child sexual abuse material (CSAM), together with the transition period for providers whose generative AI systems were already on the market.
- By 1 August 2027: Commission guidance on the interplay with sectoral product safety legislation (Articles 8(2), 9(10) and 17(3)).
- 2 December 2027: Obligations for standalone high-risk systems under Annex III (employment, credit scoring, biometrics, education, law enforcement, migration and justice).
- 2 August 2028: Embedded high-risk systems under Annex I (AI in machinery, medical devices and other goods governed by product safety rules).
- 2 August 2030: High-risk systems already in use by public authorities must comply, regardless of the transitional exemptions listed above.
The Act follows a flexible implementation schedule. Regulation (EU) 2026/1744 of 8 July 2026, which amends the compliance timetable, entered into force on 27 July 2026. For reference, see Article 113 of the EU AI Act, the European Commission's EUR-Lex summary of Regulation (EU) 2024/1689, Rules for trustworthy artificial intelligence in the EU, and the Digital Omnibus Regulation on AI.
The Article 5 prohibitions and the rules on general-purpose AI (GPAI) models are already in effect. The transparency and labelling obligations in Article 50 and the enforcement and supervisory framework of the Act also became applicable on 2 August 2026.
The broader compliance obligations for high-risk AI systems under Annex III, such as conformity assessment, technical documentation and human oversight, have instead been postponed until December 2027 (and until August 2028 for embedded systems).
The revised timeline gives businesses more time to prepare. Companies should not, however, treat this period as a reason to delay implementation. It is better seen as a chance to reinforce governance and compliance frameworks and to move AI readiness projects forward.
Which Turkish Companies Fall Within the Scope of the EU AI Act
Article 2 of the EU AI Act lays down a market-plus-effects test that recalls Article 3 of Regulation (EU) 2016/679 (the "GDPR"). Under this test, the Act applies, among others, to:
- providers that place AI systems or GPAI models on the EU market, wherever they are established,
- authorised representatives of providers established outside the EU,
- affected persons located in the EU, and
- providers and deployers established in third countries whose AI system output is used in the Union.
Many Turkish businesses may therefore be caught by the Act even though they are established in Türkiye and have no physical presence in the EU. Examples include a provider of HR screening software that licenses its product to a German client, a call centre handling interactions with customers in the EU, a manufacturer building AI into machinery intended for the single market, or a fintech company whose creditworthiness assessments feed into the decision-making of an EU credit institution.
Sanctions
The EU AI Act sets fine ceilings higher than those under the GDPR, calculated on the basis of worldwide turnover:
- up to EUR 35 million or 7% of worldwide annual turnover, whichever is higher, for breaches of the Article 5 prohibitions,
- up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher, for failure to meet core operator obligations (applicable to providers, importers, distributors, deployers and notified bodies) and the transparency obligations under Article 50, and
- up to EUR 7.5 million or 1% of worldwide annual turnover, whichever is higher, for supplying incorrect, incomplete or misleading information to competent authorities or notified bodies.
SMEs and start-ups benefit from a proportionality rule under which the lower, rather than the higher, of the two applicable thresholds applies.
GPAI providers are subject to a separate supervisory and enforcement regime run by the European Commission, which may impose fines of up to EUR 15 million or 3% of worldwide annual turnover.
Because the governance and sanctions framework is part of the Act's "general application" wave, the related enforcement risks have been present since 2 August 2026. This holds true even though certain high-risk AI obligations tied to those enforcement mechanisms will only apply at a later date.
Effects on Türkiye's Regulatory Agenda
Much like the GDPR before it, the EU AI Act continues to shape Türkiye's regulatory reform agenda. Three developments deserve particular attention:
- Legislative developments: After the AI Research Commission of the Grand National Assembly of Türkiye completed its work, a draft AI Law was submitted on 24 July 2025. The draft proposes amendments on civil liability for AI, alignment with Law No. 6698 on the Protection of Personal Data (KVKK), deepfake content, cybersecurity and administrative sanctions. The proposal is still in the legislative process, and further alignment with the risk-based approach of the EU AI Act is expected.
- Institutional framework: Through successive legislative reforms, Türkiye's cyber and digital governance framework has generally developed into a more integrated structure. The Cybersecurity Presidency was established by Presidential Decree No. 177, published on 8 January 2025, and its duties, powers and enforcement authority were later set out in statute by Cybersecurity Law No. 7545. In addition, Presidential Decree No. 191 of 25 December 2025 renamed the General Directorate of National Technology within the Ministry of Industry and Technology as the General Directorate of National Technology and Artificial Intelligence, and broadened its mandate to cover the development of AI technologies, national AI policy and data infrastructure. Together, these steps have helped build an increasingly significant institutional framework for the oversight and governance of AI.
- Guidance from the Turkish Data Protection Authority: Through its Guide on Generative AI and the Protection of Personal Data published in 2025 and its 2026 publication on the Use of Generative AI Tools in the Workplace, the Personal Data Protection Authority has indicated that it intends to approach AI as a governance matter and not only as a technological one.
Recommended Steps
For many Turkish businesses, the first question is not whether they develop AI systems themselves. It is where AI is already in use across their products, services, supply chains and customer-facing operations. Where a customer, distributor, affiliate or end user is located in the EU, the EU AI Act should generally be presumed to apply unless a specific assessment shows otherwise.
- Building an inventory and assigning responsibility: Setting up an organisation-wide inventory of AI systems, GPAI models, automated decision-making tools and AI-enabled products, and clearly identifying the persons or functions responsible for each.
- Assessing and classifying exposure under the EU AI Act: Determining whether particular AI use cases fall within the scope of the Act and how they are classified for regulatory purposes. Given the implementation timeline, special attention should be given to recruitment, employee monitoring, credit assessment, customer profiling, insurance risk assessment, biometric systems, critical infrastructure, healthcare and industrial safety applications.
- Ensuring compliance with Article 50: Putting in place measures to meet the requirements on chatbot disclosure, labelling of generative AI output and deepfake disclosure before the transitional cut-off of 2 December 2026 for existing systems.
- Reviewing contracts and supply chains: Examining contractual representations and warranties, rights of access to technical documentation, audit and incident reporting obligations, and provisions on cooperation with EU notified bodies.
- Integrating AI compliance with privacy and cybersecurity processes: AI risks are closely tied to existing obligations on personal data protection and cybersecurity. Handling these areas separately may cause duplicated effort and gaps in compliance programmes.
- Monitoring regulatory developments: Guidance from the European Commission, harmonised standards and implementing measures will play a key role in shaping compliance expectations before the high-risk AI transition date of December 2027. The Turkish legislative proposal is also expected to evolve in light of these developments.
