Turkey - AI Legislative Framework (2/2234, 2/3358)
Turkey AI Regulation Overview
Türkiye Yapay Zeka Regülasyonu Genel Görünümü
Turkey
RAI-TR-NA-SUMMARY-2026Turkey's AI landscape is defined by the National AI Strategy (2021-2025) and pending horizontal legislation (Bills 2/2234 and 2/3358) that introduce risk-based classifications, high administrative fines, and criminal liability for AI misuse.
Overview
Turkey’s regulatory philosophy regarding artificial intelligence (AI) is deeply rooted in its broader "National Technology Move" (Milli Teknoloji Hamlesi) and "Digital Turkey" agendas. The country views AI not merely as a technical challenge but as a strategic pillar for economic sovereignty, national security, and global competitiveness. Since the promulgation of the National Artificial Intelligence Strategy (2021–2025) via Presidential Circular 2021/18, Turkey has moved from a purely aspirational policy phase into a more mature, implementation-focused era. This approach is characterized by a centralized governance model where the Presidency Digital Transformation Office (CBDDO) and the Ministry of Industry and Technology orchestrate cross-sectoral efforts to build a sustainable AI ecosystem while ensuring that technological advancement does not compromise fundamental rights, public order, or the democratic fabric of society. The government has integrated AI goals into its 12th Development Plan (2024-2028), emphasizing the need for domestic large language models and specialized AI hardware. As of 2026, Turkey’s AI landscape has reached a critical juncture with the introduction of comprehensive legislative proposals that seek to codify ethical principles into binding law. The regulatory environment is currently navigating a transition from "soft law"—consisting of ethical guidelines from the Personal Data Protection Authority (KVKK) and the Council of Higher Education (YÖK)—to a robust statutory framework. This transition is marked by two significant legislative efforts: the Artificial Intelligence Law Bill (Esas No. 2/2234), which proposes a horizontal, risk-based regulatory structure, and the Bill on Amendments to Certain Laws Regarding Artificial Intelligence (Esas No. 2/3358), which focuses on immediate enforcement, transparency, and criminal liability. Together, these instruments reflect a philosophy that balances the promotion of domestic innovation with the necessity of protecting citizens from the risks of algorithmic bias, deepfakes, and data misuse.
Regulatory Approach
Turkey employs a hybrid regulatory approach that combines horizontal statutory frameworks with targeted sectoral interventions. The primary horizontal instrument is the proposed Artificial Intelligence Law Bill (2/2234), which adopts a risk-based classification system similar to international models. Under this framework, AI systems are categorized based on their potential for harm, with "high-risk" applications—such as those used in healthcare, justice, and critical infrastructure—subject to stringent conformity assessments, registration requirements, and mandatory human-in-the-loop oversight. This prescriptive approach for high-risk systems is balanced by more flexible standards for low-risk applications, aiming to foster a pro-innovation environment for startups and researchers while maintaining a safety net for sensitive deployments. The Turkish approach also emphasizes "Digital Sovereignty," ensuring that critical AI infrastructure and data remain under national jurisdiction. Complementing this horizontal ambition is a series of sectoral and soft-law measures that address specific domains. For instance, the Ministry of National Education (MEB) has implemented a dedicated "Policy Document and Action Plan on Artificial Intelligence in Education (2025–2029)," which provides granular operational guidance for the use of AI in classrooms. Similarly, the KVKK has issued numerous information notes and recommendations that apply existing data protection principles to AI-specific contexts like chatbots and deepfakes. This dual-track approach allows the Turkish government to address immediate technical risks through administrative guidelines while building a long-term, stable legal architecture through parliamentary legislation. The overall strategy emphasizes transparency, accountability, and the preservation of human autonomy as non-negotiable principles across all sectors, ensuring that AI development serves the public interest.
Key AI Legislation
- National Artificial Intelligence Strategy (2021-2025): The foundational policy document establishing Turkey's 5-year roadmap, targeting AI's contribution to GDP and workforce development. It sets six strategic priorities including human capital, R&D, and international cooperation.
- Presidential Circular No. 2021/18: The executive instrument that officially promulgated the National AI Strategy and established the high-level Steering Board chaired by the Vice President.
- Artificial Intelligence Law Bill (TBMM Esas No. 2/2234): A comprehensive draft law proposing a risk-based regulatory regime, mandatory registration for high-risk AI, and significant turnover-based fines. It defines AI systems and establishes the National AI Registry.
- Bill on Amendments to Certain Laws Regarding AI (TBMM Esas No. 2/3358): A 2025 legislative proposal to amend the Penal Code and Internet Law, introducing 6-hour takedown windows for deepfakes and criminal liability for developers who facilitate illegal acts.
- National AI Strategy 2024-2025 Action Plan: An updated implementation framework focusing on 71 concrete actions, including the development of Turkish Large Language Models (LLMs) and the creation of AI-specific technoparks.
- KVKK Recommendations Guide on AI (2021): The primary data protection guideline for AI developers, emphasizing privacy-by-design, data minimization, and the legal basis for processing training data.
- MEB AI Policy Document (2025-2029): A sectoral roadmap for integrating AI into the national education system with a focus on ethics, pedagogical safety, and teacher training.
- YÖK Ethics Guide for Generative AI (2024): Provides standards for the use of AI in academic research, prohibiting AI authorship and requiring disclosure of AI assistance in theses and publications.
Governance & Enforcement Bodies
The governance of AI in Turkey is structured to ensure high-level political coordination alongside technical expertise. At the apex of this structure is the National AI Strategy Steering Board (Yönlendirme Kurulu), chaired by the Vice President of Turkey. This board provides strategic oversight and ensures that AI policies are aligned with national development goals and the 12th Development Plan. The day-to-day operational coordination is shared between the Presidency Digital Transformation Office (CBDDO) and the Ministry of Industry and Technology. The CBDDO focuses on the "Digital Turkey" vision, data sharing frameworks, and public sector adoption, while the Ministry of Industry and Technology manages R&D incentives, the startup ecosystem, and the "National Technology Move" initiatives through its specialized directorates. Enforcement is distributed among existing regulatory authorities that have seen their mandates expanded to cover AI-related issues. The Personal Data Protection Authority (KVKK) is the primary watchdog for AI systems that process personal information, ensuring compliance with Law No. 6698. The Information and Communication Technologies Authority (BTK) plays a critical role in content regulation, particularly regarding the labeling of AI-generated content (deepfakes) and the enforcement of takedown orders under Law No. 5651. Additionally, the Grand National Assembly of Turkey (TBMM) established a dedicated AI Research Commission in late 2024 to identify legal gaps and coordinate the drafting of new regulations. This multi-agency approach ensures that AI is regulated through the lens of data privacy, cybersecurity, and consumer protection simultaneously, though it requires high levels of inter-agency communication to avoid jurisdictional overlaps.
Penalties & Enforcement
The enforcement regime for AI in Turkey is currently in a state of significant escalation, moving from advisory warnings to heavy financial and criminal sanctions. The proposed Artificial Intelligence Law Bill (2/2234) introduces a tiered penalty structure based on the severity of the violation and the entity's global turnover. Prohibited AI applications—those that violate fundamental rights, use manipulative techniques, or exploit vulnerabilities—can attract administrative fines of up to 35 million TL or 7% of the operator's annual global turnover, whichever is higher. Other violations, such as failure to comply with high-risk registration or transparency obligations, carry fines of up to 15 million TL or 3% of turnover. These penalties are designed to be deterrent and are modeled after international best practices in digital market regulation. Beyond financial penalties, the 2025 AI Amendment Bill (2/3358) seeks to integrate AI misuse into the Turkish Penal Code (TCK). This includes treating users who direct AI to commit crimes as principal perpetrators and increasing sentences for developers whose systems are designed or trained in a way that facilitates criminal acts, such as fraud or identity theft. In the realm of digital content, the BTK is empowered to issue emergency blocking orders for non-compliant AI content, with a mandatory 6-hour response window for platforms. Non-compliance with these takedown orders or labeling requirements can result in temporary activity suspensions, bandwidth throttling, or additional administrative fines of up to 10 million TL. Appeals against these sanctions are typically handled through the administrative court system, though criminal penalties remain the jurisdiction of the judicial courts. The KVKK also maintains the power to order the cessation of data processing activities if an AI model is found to be in systemic violation of privacy laws.
Data Protection Framework
The bedrock of AI regulation in Turkey is the Law on the Protection of Personal Data (Law No. 6698, or KVKK), which is largely aligned with the principles of the EU's GDPR. Under this framework, any AI system processing the personal data of Turkish residents must adhere to the principles of lawfulness, fairness, transparency, and purpose limitation. The KVKK has been proactive in issuing AI-specific guidance, such as the 2021 Recommendations Guide and the 2024 Explanatory Note on Chatbots. These documents clarify that data controllers must conduct Data Protection Impact Assessments (DPIAs) for high-risk AI processing and ensure that datasets used for training models are either anonymized or processed under a valid legal basis, such as explicit consent or the performance of a contract. Turkey also maintains specific requirements for data localization and the cross-border transfer of sensitive data, which significantly impacts AI developers using global cloud infrastructures. The KVKK emphasizes that biometric data, often used in AI-driven facial recognition or authentication, is a special category of personal data requiring heightened protection and explicit consent. Recent legislative proposals, such as the 2025 Amendment Bill, further tighten these rules by requiring that datasets used in AI applications conform to strict anti-discrimination and legitimacy principles. Failure to secure datasets against algorithmic bias is increasingly treated as a violation of data security obligations under Article 12 of Law No. 6698, subjecting entities to both administrative audits and fines. The 2024 amendments to the KVKK law have also introduced more flexible mechanisms for international data transfers, provided that adequate safeguards are in place, which is expected to facilitate the training of AI models using global datasets while maintaining Turkish privacy standards.
Sector-Specific Rules
Sector-specific AI regulation in Turkey is most advanced in the fields of education and research. The Ministry of National Education (MEB) has established a comprehensive framework through its 2025-2029 Action Plan, which mandates ethical reviews for any AI tool deployed in public schools. This includes strict vendor evaluation criteria, requirements for model transparency, and pedagogical safeguards to prevent over-reliance on automated systems. The MEB also issued a specific guide for teachers on prompt engineering, emphasizing the need for human oversight in AI-assisted grading and lesson planning. Similarly, the Council of Higher Education (YÖK) has issued an Ethics Guide for Generative AI in Scientific Research, which prohibits the listing of AI as an author and requires researchers to disclose any material assistance provided by GAI tools in their publications. These rules ensure that the academic and primary education sectors maintain high standards of integrity and safety. In the financial and healthcare sectors, AI regulation is primarily governed through the circulars and standards issued by the Banking Regulation and Supervision Agency (BDDK) and the Ministry of Health, respectively. While a standalone "Healthcare AI Act" does not yet exist, AI-driven medical devices must comply with existing medical device regulations and undergo rigorous clinical validation. The proposed Artificial Intelligence Law Bill (2/2234) specifically identifies medical diagnostics and autonomous transport as high-risk sectors, which will eventually require these industries to register their systems in a national AI registry and undergo periodic conformity audits. This sectoral approach ensures that high-stakes applications are subject to specialized oversight that understands the unique risks of the domain, such as patient safety in health or systemic stability in finance.
International Alignment
Turkey’s AI regulatory trajectory shows a strong commitment to international alignment, particularly with European and OECD standards. The draft Artificial Intelligence Law Bill (2/2234) explicitly mirrors the structure of the EU AI Act, utilizing a similar risk-based classification and emphasizing the protection of fundamental rights. This alignment is strategic, aimed at ensuring that Turkish AI companies can easily access the European Digital Single Market and that Turkey remains a compatible partner for cross-border data flows. The National AI Strategy also emphasizes Turkey's goal to be among the top 20 countries in international AI indices, which necessitates adherence to global norms regarding trustworthy and reliable AI. Furthermore, Turkey is an active participant in international forums such as the OECD and the Council of Europe, where it contributes to the development of global AI governance principles. The KVKK’s guidelines frequently reference the OECD AI Principles and the Council of Europe’s Convention 108+ as foundational texts for its domestic recommendations. Turkey has also expressed interest in bilateral and multilateral agreements regarding AI safety and cybersecurity, recognizing that the borderless nature of AI requires a coordinated international response. This commitment to alignment is balanced with a focus on "data sovereignty," ensuring that while Turkey follows international standards, it retains the ability to protect its national security interests and promote its domestic AI industry. The alignment with the EU AI Act is particularly important for the Turkish automotive and manufacturing sectors, which are heavily integrated into European supply chains and must comply with EU safety standards for AI-enabled products.
Future Developments
The next two years are expected to be the most active period for AI lawmaking in Turkey's history. The primary focus is the passage and implementation of the Artificial Intelligence Law Bill (2/2234), which is currently under commission review in the TBMM. Once enacted, this law will trigger a wave of secondary legislation, including the establishment of technical standards for conformity assessments and the creation of the National AI Registry. Stakeholders should also expect the 2025 AI Amendment Bill (2/3358) to pass, which will immediately change the compliance landscape for social media platforms and AI developers regarding content labeling and takedown procedures. Additionally, the 2024-2025 National AI Action Plan identifies the development of a "Turkish Large Language Model" as a high-priority deliverable, intended to reduce reliance on foreign models and ensure linguistic and cultural accuracy. This project will likely be accompanied by new guidelines on the ethical use of generative AI and the intellectual property rights associated with AI-generated content. The TBMM AI Research Commission is also expected to release a comprehensive report in late 2026, which may recommend further sectoral laws for autonomous vehicles and AI in the justice system. As Turkey nears the end of its first 5-year strategy cycle (2021-2025), the government is already preparing the groundwork for the "2026-2030 National AI Strategy," which is expected to focus on scaling industrial AI applications, deepening international regulatory cooperation, and establishing Turkey as a regional hub for AI ethics and safety research. The integration of AI into the "Digital Turkey" portal (e-Devlet) will also be a major focus, with new AI-driven public services expected to launch by 2027.
Key Regulations
| Title | Type | Status | Year |
|---|---|---|---|
| Bill on Amendments to Certain Laws Regarding Artificial Intelligence (Esas No. 2/3358) | Bill | Under Review | 2025 |
| Policy Document and Action Plan on AI in Education (2025-2029) | Policy | In Force | 2025 |
| Teacher Guide: Applied Prompt Engineering and Generative Tools | Guideline | In Force | 2025 |
| Yapay Zeka Kanun Teklifi (Artificial Intelligence Law Bill — Esas No. 2/2234) | Bill | Under Review | 2024 |
| National Artificial Intelligence Strategy 2024-2025 Action Plan | Policy | In Force | 2024 |
| Deepfake Information Note ("Deepfake Bilgi Notu") | Guideline | In Force | 2024 |
| Explanatory Note on Chatbots (ChatGPT Example) | Guideline | In Force | 2024 |
| Ethics Guide for Generative AI in Higher Education Institutions | Guideline | In Force | 2024 |
| TBMM Decision Establishing an AI Research Commission | Act | In Force | 2024 |
| National Artificial Intelligence Strategy 2021-2025 | Policy | In Force | 2021 |
| Presidential Circular No. 2021/18 on the National AI Strategy | Policy | In Force | 2021 |
| Recommendations Guide on Personal Data Protection in AI | Guideline | In Force | 2021 |
Enforcement Bodies
| Agency | Mandate | Key Powers | Website |
|---|---|---|---|
| Presidency Digital Transformation Office (CBDDO) | Coordinates national AI strategy and digital transformation across public agencies. | Policy design, inter-agency coordination, setting data sharing standards. | https://cbddo.gov.tr |
| Ministry of Industry and Technology | Oversees industrial AI policy, R&D incentives, and the National Technology Move. | Grant allocation, startup support, industrial standards setting. | https://www.sanayi.gov.tr |
| Personal Data Protection Authority (KVKK) | Enforces Law No. 6698 regarding personal data processing in AI systems. | Audits, administrative fines, issuing binding decisions and guidelines. | https://www.kvkk.gov.tr |
| Information and Communication Technologies Authority (BTK) | Regulates telecommunications and online content, including AI labeling and takedowns. | Content blocking, administrative fines for ISPs/platforms, technical supervision. | https://www.btk.gov.tr |
Real enforcement actions
2 actions recorded · ~€725K in finesPublic enforcement actions where regulators cited Turkey - AI Legislative Framework (2/2234, 2/3358). Helps you see how the law is actually applied in practice.
- FineAug 4, 2022
KVKK (Turkish Data Protection Authority) vs Employer (data controller, redacted)
500KFineKVKK fined a data controller TRY 500,000 for unlawfully processing employees' biometric data via a facial-recognition system for workplace entry/exit control, lacking a valid legal basis and freely-given consent.
Source ↗ - FineFeb 27, 2020
KVKK (Turkish Data Protection Authority) vs Gym / sports-facility operator (redacted)
225KFineKVKK fined a gym operator TRY 225,000 for processing members' biometric data (palm/fingerprint) for entry-exit control in violation of proportionality, and ordered it to cease processing and destroy the biometric data.
Source ↗
Related Regulations
Yapay Zeka Kanun Teklifi (Artificial Intelligence Law Bill) — TBMM Esas No. 2/2234
Turkey92% similar
Bill on Amendments to Certain Laws Regarding Artificial Intelligence (Kanun Teklifi — Esas No. 2/3358)
Turkey91% similar
National Artificial Intelligence Strategy 2024-2025 Action Plan (Ulusal Yapay Zeka Stratejisi)
Turkey91% similar
Hungary AI Regulation Overview
Hungary90% similar
Tunisia AI Regulation Overview
Tunisia89% similar
© Regulations.AI — created on 06-Jan-2026 using Gemini 3 Flash Preview