Turkey has no AI law, and the bill that would create one has sat in committee since June 2024. What binds an operator is data protection law, and the Turkish provision on automated decisions is narrower than the guide it is usually compared to. The more useful signal is elsewhere: the Turkish data protection authority has published two substantial AI documents in the last year, including a forty six page study of agentic AI, and the Grand National Assembly has a standing research commission on AI whose remit is expressly to establish the legal infrastructure. This guide sets out what actually applies, what does not, and where the real Turkish material is.
Key takeaways
- Turkey has no enacted AI statute. A private member's bill, the Yapay Zeka Kanun Teklifi, Esas No 2/2234, was submitted to the Grand National Assembly on 24 June 2024 and referred to committee the following day. Its status is still KOMISYONDA, in committee. It has never left committee and has not passed.
- KVKK, Law No. 6698 on the Protection of Personal Data, is the binding instrument. The relevant provision is Article 11(g), which gives a data subject the right to object to a result arising against them from analysis of their data exclusively by automated systems. It is not a prohibition, it has no legal or similarly significant effects threshold, and it does not grant a right to human review.
- The 2024 reform, not a 2021 one, is what changed KVKK. Law No. 7499 of 2 March 2024, published in the Resmi Gazete on 12 March 2024, amended Articles 6, 9 and 18 and added Provisional Article 3, all in force from 1 June 2024. It rebuilt the regime for transfers abroad around adequacy decisions, standard contracts and binding corporate rules.
- KVKK administrative fines are revalued annually. The 2026 figures, published by the Board on 31 December 2025 applying a revaluation rate of 25.49 per cent, run to TRY 17,092,242 at the top of three of the five limbs. Any guide quoting TRY 1,000,000 as the ceiling is quoting the 2016 base for one limb.
- Turkiye has not signed the Council of Europe Framework Convention on Artificial Intelligence, CETS No. 225. As at 17 August 2026 the treaty office records twenty signatures not followed by ratification and one ratification, the European Union, and Turkiye is in neither column.
- The most on-point Turkish material for anyone deploying AI agents is the Board's own: a generative AI and personal data protection guide of November 2025, and a forty six page study on agentic AI published in February 2026 with chapters on AI agents and the personal data risks in agentic systems.
The regulatory landscape
Turkey's AI environment in 2026 has three layers that are binding or nearly so, and one that is frequently described as binding and is not.
The binding layer is data protection law under KVKK, Kisisel Verilerin Korunmasi Kanunu, Law No. 6698, published in the Resmi Gazete on 7 April 2016. Note that its commencement was staged: Articles 8, 9, 11, and 13 to 18 entered into force six months later, on 7 October 2016. Article 11 is the data subject rights provision that matters most for AI.
The legislative layer is a bill and a commission. The bill is described below. The commission is the more consequential of the two: the Grand National Assembly established a parliamentary research commission on artificial intelligence by Decision No. 1426 of 5 October 2024, published in the Resmi Gazete No. 32683, selected its members by Decision No. 1438 of 16 January 2025, and extended its mandate by Decision No. 1445 of 11 April 2025. Its remit is expressly to establish the legal infrastructure in this field and to determine measures to prevent the risks of AI use. That is where Turkish AI legislation will come from, and it is a better thing to watch than the private member's bill.
The strategy layer is the Ulusal Yapay Zeka Stratejisi 2021 to 2025, promulgated by Presidential Circular 2021/18 of 19 August 2021 and published in the Resmi Gazete of 20 August 2021, No. 31574. It is policy, not law. A full-title search of the Resmi Gazete archive for Yapay Zeka returns thirty four records, and the 2021 circular is the only national AI strategy instrument among them. An earlier version of this guide said Turkish authorities have published a 2026 to 2030 successor strategy while its own footnote said the successor was not yet formally published; no successor appears in the Gazette and the claim has been removed. The Digital Transformation Office's own site could not be read in this verification pass, so the strategy's publishing bodies and its seven strategic axes could not be confirmed at source.
The layer that is not binding is the Council of Europe Framework Convention, dealt with below.
The AI bill, and what it would do if it ever passed
The Yapay Zeka Kanun Teklifi, Esas No 2/2234, was submitted by Kocaeli deputy Omer Faruk Gergerlioglu and reached the Presidency of the Assembly on 24 June 2024. On 25 June 2024 it was referred to the Industry, Trade, Energy, Natural Resources, Information and Technology Committee as the principal committee and the Justice Committee as a subsidiary committee. Its recorded status is KOMISYONDA. There is no exit date, no decision date and no recorded outcome.
Its content is worth knowing precisely because it is not in force, and because a reader who encounters its figures elsewhere should be able to place them. Article 6 of the bill would set fines of TRY 35 million or up to 7 per cent of annual turnover for prohibited AI practices, TRY 15 million or up to 3 per cent for breach of obligations, and TRY 7.5 million or up to 1.5 per cent for false information. Article 4 would require high-risk systems to be registered with supervisory authorities. None of this binds anyone. A private member's bill that has not left committee in over two years is not a compliance signal.
KVKK: the binding obligation for AI operators
Territorial scope, stated accurately
An earlier version of this guide said KVKK applies regardless of where the controller is established, provided the controller offers goods or services to data subjects in Turkey or monitors their behaviour in Turkey. That is the wording of Article 3(2) of the GDPR, and it is not in KVKK. Article 2 of Law 6698 contains no targeting test, no monitoring test and no express extraterritoriality clause. The one narrow extraterritorial hook found at an official source sits in Board Decision 2019/10 on breach notification, which reaches a controller established abroad where the affected persons benefit from the products or services in Turkey.
The practical consequence for a foreign operator is that the analysis is harder, not easier: scope has to be worked out from the facts of establishment and processing rather than read off a targeting clause.
Article 11(g): what it actually grants
The provision is Article 11(g), not 11(f). Article 11(f) is the right to have correction or erasure notified to third parties. Article 11(g) gives the data subject the right to object to the occurrence of a result against the person themselves by analysis of the processed data exclusively through automated systems.
That is a bare objection right. It contains no prohibition on solely automated decision-making. It has no legal or similarly significant effects threshold. And it does not grant a right to request human review, which an earlier version of this guide asserted three times, going on to advise that the review must be substantive and capable of overriding the automated decision. That advice had no statutory basis and has been removed.
Comparing Article 11(g) to Article 22 of the GDPR overstates it. Article 22 GDPR is a prohibition with mandated safeguards. Article 11(g) KVKK is an objection right. An operator should still build a route for a data subject to raise an objection and have it considered, because that is what the provision requires, but it should not represent to itself or to anyone else that Turkish law mandates human review of automated decisions.
Lawful bases under Article 5
Article 5 permits processing on explicit consent, or on one of six exceptions in Article 5(2): where expressly provided by law; actual impossibility or protection of vital interests; where directly related to a contract; a legal obligation of the controller; where the data has been made public by the data subject; where necessary for the establishment, exercise or protection of a right; and the legitimate interests of the controller where these do not override the data subject's fundamental rights.
An earlier version of this guide listed a basis of necessity for a task carried out in the public interest or in the exercise of official authority. That is GDPR Article 6(1)(e) and it is not in KVKK. It also omitted the two bases that are distinctively Turkish and often the most useful in practice: data made public by the data subject, and necessity for the establishment, exercise or protection of a right.
Transfers abroad after Law 7499
This is the change that matters most to an AI operator moving training or inference data offshore, and it is not what an earlier version of this guide described. Law No. 7499 of 2 March 2024, published in the Resmi Gazete on 12 March 2024, amended Articles 6, 9 and 18 of Law 6698 and added Provisional Article 3, all with effect from 1 June 2024. The official amendment table for Law 6698 lists exactly three amending instruments ever: Law 7061 of 2017, Decree Law 703 of 2018, and Law 7499 of 2024. There was no 2021 amendment.
Article 9 as amended rebuilds transfers abroad around adequacy decisions, standard contracts and binding corporate rules. The Board has published a transfers guide, model standard contracts and binding corporate rules material at kvkk.gov.tr, and any operator with cross-border AI processing should start there.
Breach notification
Article 12 requires technical and administrative measures preventing unlawful access. The Article itself says only that a breach must be notified as soon as possible, en kisa surede. The seventy two hour figure comes from Board Decision of 24 January 2019, No. 2019/10, which interprets that phrase as seventy two hours for notification to the Board. Affected data subjects must be notified within the shortest reasonable time, not within seventy two hours. An earlier version of this guide described Decision 2019/10 as a guideline on technical security measures and attributed the seventy two hour rule to a 2021 announcement; both descriptions were wrong.
For AI systems, the breach events worth building into the procedure are model inversion attacks allowing reconstruction of training data, prompt injection causing an agent to expose personal data, and unauthorised access to inference logs containing personal data.
Fines, at 2026 values
KVKK administrative fines are revalued annually under the general revaluation mechanism, which is why any hardcoded figure in a guide like this one goes stale every January. The Board published the 2026 amounts on 31 December 2025, applying a revaluation rate of 25.49 per cent. By limb of Article 18: failure to inform under Article 10, TRY 85,437 to 1,709,200; failure of data security under Article 12, TRY 256,357 to 17,092,242; failure to comply with Board decisions under Article 15, TRY 427,263 to 17,092,242; failure to register with VERBIS under Article 16, TRY 341,809 to 17,092,242; and failure to notify a transfer under Article 9(5), TRY 90,308 to 1,806,177.
An earlier version of this guide gave a range of TRY 15,000 to TRY 1,000,000, described as approximately EUR 400 to EUR 27,000. That was the 2016 statutory base for one limb only, and it understated the current top of the range by roughly seventeen times. Articles 135 to 140 of the Turkish Penal Code provide separate criminal penalties for unlawful data processing.
VERBIS
VERBIS, the Veri Sorumlulari Sicili, is the data controllers registry operated by the Board under Article 16, with registration mandatory above Board-defined thresholds. An earlier version of this guide asserted that controllers established outside Turkey processing Turkish data subjects' personal data are subject to registration obligations. Article 16 contains no such extraterritorial rule, and the claim has been withdrawn.
What the Board has actually published on AI
This is the section an operator should read first, and it did not exist in the earlier version of this guide.
The Board published "Uretken Yapay Zeka ve Kisisel Verilerin Korunmasi Rehberi (15 Soruda)", a generative AI and personal data protection guide in fifteen questions, as publication number 113 in November 2025.
In February 2026 it published "Etken Yapay Zeka (Agentic AI)", a forty six page study with dedicated chapters on AI agents and on the personal data risks arising in agentic systems. For a publication about AI agent liability, this is the single most on-point Turkish document in existence.
Alongside these it has published material on the use of generative AI tools in workplaces, recommendations for parents on children using AI tools, and a public announcement concerning the Grok AI assistant. An earlier version of this guide cited none of these.
The Council of Europe Framework Convention: Turkiye has not signed
The Council of Europe Treaty Office chart for CETS No. 225, status as at 17 August 2026, shows the Turkiye row with no signature date and no ratification. Twenty states have signed without ratifying; one party has ratified, the European Union, on 15 May 2026.
An earlier version of this guide stated that Turkiye signed the Convention at its opening ceremony in September 2024, in the lede, a key takeaway, twice in the body, in an FAQ, in the FAQPage structured data and in a footnote. It went on to assert that Turkiye had indicated an intent to extend the Convention's obligations to private-sector AI on ratification, that it was under an obligation not to defeat the Convention's object and purpose, and that ratification was expected in 2026 or 2027, and it advised operators to align their governance documentation with a Convention that Turkiye has signed. None of that survives. All of it has been removed rather than softened.
Note also that the Convention is not in force anywhere: it requires five ratifications including at least three Council of Europe member states, and has one.
Financial sector AI governance
The correct reference for banks is the Bankalarin Bilgi Sistemleri ve Elektronik Bankacilik Hizmetleri Hakkinda Yonetmelik, the BDDK regulation on banks' information systems and electronic banking services, published in the Resmi Gazete on 15 March 2020, No. 31069. An earlier version of this guide gave the title without Bankalarin, misspelled Bankacilik, dated it 15 March 2021 and gave gazette number 31086. The regulation addresses information systems governance and model risk in ways that reach algorithmic and machine learning systems used by banks, and third-party AI suppliers to Turkish banks should expect contractual governance requirements to flow down from it.
An earlier version of this guide also cited SPK Communique No. III-43.5 on algorithmic trading and automated advisory systems, dated 2023, and built a set of obligations on it: that investment firms must document the AI's role, maintain override capability, and keep the final investment decision with a human professional. The official SPK list of communiques contains no III-43 series at all, running from III-42.1 to III-45.1, and no communique on algorithmic trading or automated advisory systems. The citation and everything resting on it have been removed.
The same applies to a claim that BDDK issued remediation orders to three Turkish banks in 2024 for inadequate model risk governance affecting credit AI systems, which the earlier version of this guide accompanied with the words "though these orders were not made public in detail". A claim that concedes it cannot be checked is not a claim this desk should publish, and it has been deleted. Claims about the Board's 2024 Annual Activity Report naming automated decision-making a priority, and about competition authority examinations of algorithmic pricing in 2023 and 2024, could not be confirmed at source and have gone with it.
The EU accession dynamic
Turkey applied for EEC membership in 1987 and formal accession negotiations opened in 2005. Turkish law in technology, data protection, consumer protection and financial services has been progressively aligned with EU standards across that period. KVKK is modelled on European data protection law, and the 2024 reform of transfers abroad moved it closer still.
For AI regulation the reasonable inference is that any dedicated Turkish AI law will draw on the EU AI Act's architecture. That is an inference, not a commitment, and an earlier version of this guide attributed a public statement of alignment intent to the Digital Transformation Office that could not be confirmed at source. Operators building AI compliance for Turkey should design programmes that are extensible to EU AI Act requirements without restructuring, which is prudent regardless of what Ankara eventually legislates.
Comparison with the EU AI Act and NIST AI RMF
An operator already compliant with the EU AI Act will find that its documentation and governance address the substance of Turkish obligations, with three specific things to add. First, an Article 11(g) objection route for Turkish data subjects, which is a narrower requirement than EU Article 14 human oversight but a distinct procedural one. Second, the Article 9 transfers analysis as reconstructed by Law 7499, which is the real cross-border constraint. Third, VERBIS registration where the threshold is met.
The NIST AI Risk Management Framework 1.0 of 26 January 2023 and the Generative AI Profile NIST AI 600-1 of 26 July 2024 remain useful as a governance scaffold, and Turkey is an OECD member whose National AI Strategy references the OECD AI Principles. Neither is binding in Turkey.
What operators should do
Five things. First, conduct a KVKK scope assessment on the facts of establishment and processing rather than by analogy to GDPR targeting, map each processing activity to a basis under Article 5, and register with VERBIS if you meet the threshold. Second, build an Article 11(g) objection route: a way for a Turkish data subject to object to an adverse result from exclusively automated analysis, and a record of how the objection was handled. Do not promise a statutory right to human review that Turkish law does not give. Third, work through the Article 9 transfers regime as amended by Law 7499, using the Board's published transfers guide, standard contracts and binding corporate rules. Fourth, read the Board's agentic AI study of February 2026 and its generative AI guide of November 2025; they are the clearest statement of what the Turkish regulator thinks about the systems this publication covers. Fifth, watch the parliamentary research commission rather than the private member's bill.
For comparison with other jurisdictions in the region, see the UAE and Gulf AI governance guide and the Israel AI regulation guide. For the EU AI Act obligations Turkish law is most likely to draw on, see the Article 26 deployer obligations analysis on agentliability.eu.
Frequently asked questions
Does Turkey have a dedicated AI law in 2026?
No. A private member's bill, the Yapay Zeka Kanun Teklifi, Esas No 2/2234, was submitted to the Grand National Assembly on 24 June 2024 and referred to committee the next day. Its status remains KOMISYONDA, in committee, with no exit date and no recorded outcome. The binding framework is KVKK, Law No. 6698 on the Protection of Personal Data, enforced by the Personal Data Protection Board. The Ulusal Yapay Zeka Stratejisi 2021 to 2025, promulgated by Presidential Circular 2021/18 of 19 August 2021, is policy rather than law, and no successor strategy appears in the Resmi Gazete. The Grand National Assembly established a parliamentary research commission on artificial intelligence by Decision No. 1426 of 5 October 2024, whose remit includes establishing the legal infrastructure in this field.
What does KVKK Article 11 actually grant for automated decisions?
Article 11(g), not 11(f), gives a data subject the right to object to the occurrence of a result against them arising from analysis of their processed data exclusively through automated systems. That is a bare objection right. It is not a prohibition on solely automated decision-making, it has no legal or similarly significant effects threshold, and it does not grant a right to request human review. Comparing it to Article 22 of the GDPR overstates it: Article 22 is a prohibition with mandated safeguards. Operators should build a route for a Turkish data subject to raise an objection and a record of how it was handled, without representing that Turkish law mandates human review.
What are the KVKK administrative fines in 2026?
KVKK fines are revalued annually. The Board published the 2026 amounts on 31 December 2025 applying a revaluation rate of 25.49 per cent. By limb of Article 18: failure to inform under Article 10, TRY 85,437 to 1,709,200; failure of data security under Article 12, TRY 256,357 to 17,092,242; failure to comply with Board decisions under Article 15, TRY 427,263 to 17,092,242; failure to register with VERBIS under Article 16, TRY 341,809 to 17,092,242; and failure to notify a transfer under Article 9(5), TRY 90,308 to 1,806,177. Articles 135 to 140 of the Turkish Penal Code provide separate criminal penalties for unlawful data processing.
What changed in Turkish data protection law for cross-border AI processing?
Law No. 7499 of 2 March 2024, published in the Resmi Gazete on 12 March 2024, amended Articles 6, 9 and 18 of Law 6698 and added Provisional Article 3, all in force from 1 June 2024. Article 9 as amended rebuilds transfers abroad around adequacy decisions, standard contracts and binding corporate rules. The official amendment table for Law 6698 lists three amending instruments ever: Law 7061 of 2017, Decree Law 703 of 2018, and Law 7499 of 2024. There was no 2021 amendment, contrary to what an earlier version of this guide stated.
Has Turkiye signed the Council of Europe Framework Convention on AI?
No. The Council of Europe Treaty Office chart for CETS No. 225, status as at 17 August 2026, shows no signature and no ratification for Turkiye. Twenty states have signed without ratifying and one party has ratified, the European Union, on 15 May 2026, so the Convention is not in force anywhere. An earlier version of this guide asserted a Turkish signature at the September 2024 opening in six places, including its structured data, and built compliance advice on it. That has been removed.
What has the Turkish data protection authority published on AI?
Two substantial documents. Uretken Yapay Zeka ve Kisisel Verilerin Korunmasi Rehberi (15 Soruda), a generative AI and personal data protection guide in fifteen questions, publication number 113, November 2025. And Etken Yapay Zeka (Agentic AI), a forty six page study published in February 2026 with dedicated chapters on AI agents and the personal data risks arising in agentic systems. It has also published material on generative AI tools in workplaces, recommendations for parents on children using AI tools, and a public announcement concerning the Grok AI assistant. For an operator deploying AI agents in Turkey, the agentic AI study is the most directly relevant Turkish source in existence.
References
- Law No. 6698 on the Protection of Personal Data (Kisisel Verilerin Korunmasi Kanunu, KVKK), published Resmi Gazete No. 29677, 7 April 2016. Articles 8, 9, 11 and 13 to 18 entered into force 7 October 2016. Article 5 (processing conditions), Article 9 (transfers abroad, as amended), Article 11(g) (objection to a result from exclusively automated analysis), Article 12 (data security), Article 16 (VERBIS), Article 18 (administrative fines). mevzuat.gov.tr and kvkk.gov.tr.
- Law No. 7499 of 2 March 2024, published Resmi Gazete 12 March 2024, amending Articles 6, 9 and 18 of Law 6698 and adding Provisional Article 3, in force 1 June 2024. resmigazete.gov.tr.
- Personal Data Protection Board, 2026 administrative fine amounts, published 31 December 2025 applying a revaluation rate of 25.49 per cent. kvkk.gov.tr.
- Personal Data Protection Board Decision of 24 January 2019, No. 2019/10, on data breach notification, interpreting "en kisa surede" as 72 hours for notification to the Board. kvkk.gov.tr.
- Personal Data Protection Board, "Uretken Yapay Zeka ve Kisisel Verilerin Korunmasi Rehberi (15 Soruda)", publication number 113, November 2025; "Etken Yapay Zeka (Agentic AI)", February 2026, 46 pages. kvkk.gov.tr.
- Grand National Assembly of Turkiye, Yapay Zeka Kanun Teklifi, Esas No 2/2234, submitted 24 June 2024, referred to committee 25 June 2024, status KOMISYONDA. tbmm.gov.tr.
- Grand National Assembly of Turkiye, parliamentary research commission on artificial intelligence: Decision No. 1426 of 5 October 2024 (Resmi Gazete 32683), member selection by Decision No. 1438 of 16 January 2025 (Resmi Gazete 32784), mandate extension by Decision No. 1445 of 11 April 2025 (Resmi Gazete 32867).
- Ulusal Yapay Zeka Stratejisi 2021 to 2025, promulgated by Presidential Circular 2021/18 of 19 August 2021, published Resmi Gazete 20 August 2021, No. 31574. resmigazete.gov.tr. The Digital Transformation Office site could not be read in this verification pass, so the strategy's publishing bodies and axis count are not asserted here.
- Bankalarin Bilgi Sistemleri ve Elektronik Bankacilik Hizmetleri Hakkinda Yonetmelik (BDDK), published Resmi Gazete 15 March 2020, No. 31069. resmigazete.gov.tr.
- Council of Europe Treaty Office, chart of signatures and ratifications of CETS No. 225, status as at 17 August 2026. Turkiye has neither signed nor ratified. coe.int.
- NIST AI Risk Management Framework (AI RMF 1.0), NIST AI 100-1, 26 January 2023, and NIST AI 600-1 Generative AI Profile, 26 July 2024. nist.gov. Voluntary.
- Regulation (EU) 2024/1689 (EU AI Act), Article 14 (human oversight) and Article 26 (deployer obligations), for comparison.