Turkey - AI Regulation Bill (2/2234)

Artificial Intelligence Law Bill — TBMM Main No. 2/2234

Yapay Zeka Kanun Teklifi (Artificial Intelligence Law Bill) — TBMM Esas No. 2/2234

Turkey

RAI-TR-NA-YZKTAXX-2024
Under Review(Under Review)
BillGovernance and OversightRisk ManagementConformity Assessment and Registration
Export PDF

The Yapay Zeka Kanun Teklifi (TBMM Esas No. 2/2234) is a comprehensive Turkish parliamentary bill introduced in June 2024 to create a regulatory framework for the safe, ethical and transparent development, distribution and use of artificial intelligence systems. It sets out principles (safety, transparency, fairness, accountability, privacy), introduces risk-management and conformity/registration requirements for high‑risk AI systems, and provides significant administrative penalties tied to fixed amounts and turnover percentages.

Summary

Background and purpose: The Yapay Zeka Kanun Teklifi (TBMM Esas No. 2/2234), submitted to the Grand National Assembly of Turkey (TBMM) in June 2024, proposes a national law to regulate artificial intelligence (AI) across sectors. The bill’s stated objectives are to ensure AI systems are developed and used in a safe, ethical, fair and transparent manner; to protect personal data and privacy; to prevent harms arising from biased or unsafe models; and to promote public trust in AI technology. The bill was filed on 24 June 2024 and referred to the Sanayi, Ticaret, Enerji, Tabii Kaynaklar, Bilgi ve Teknoloji Komisyonu as the primary commission with the Justice Commission as a subordinate commission.

Core structure and principles: The bill establishes foundational principles (safety, transparency, fairness, accountability and privacy) applicable to providers, distributors, importers, users and other “AI operators.” It requires risk assessment and management across AI lifecycles, with special mandatory provisions for systems identified as “high-risk” (examples in the bill include autonomous vehicles, medical diagnostics and AI used in justice/criminal contexts). High‑risk systems must be registered with relevant oversight authorities and undergo conformity and suitability assessments before or during deployment.

Obligations and compliance regime: AI operators must carry out documented risk assessments; implement mitigation measures; ensure data governance and privacy-compliant processing; maintain technical and organizational measures for cybersecurity and model security; keep auditable documentation and logs; and enable oversight and audits by designated authorities. The bill foresees the development of implementing regulations and standards and empowers supervisory bodies with inspection and enforcement tools.

Enforcement and sanctions: The bill defines administrative sanctions with both fixed-amount fines and turnover-based caps: prohibited AI applications carry penalties up to 35 million TL or up to 7% of annual turnover; violations of obligations up to 15 million TL or up to 3% of turnover; and penalties for dissemination of materially false or misleading information up to 7.5 million TL or up to 1.5% of turnover. Denial-of-service, mandatory remedial orders and temporary suspensions are within the enforcement toolkit.

Relationship to existing law and regulators: The bill is drafted to operate alongside Turkey’s personal data protection framework (Law No. 6698) and sectoral statutes; it contemplates coordination with the Kişisel Verileri Koruma Kurumu (KVKK), Bilgi Teknolojileri ve İletişim Kurumu (BTK) and relevant ministries (e.g., Ministry of Industry and Technology, Ministry of Trade). It anticipates transposition/alignment with international standards and best practices.

Policy implications: If adopted, this bill would create one of Turkey’s first consolidated statutory AI regimes, combining preventive risk governance, conformity assessments, registration for high‑risk systems and significant penalties designed to ensure compliance. The bill focuses on balancing innovation and protection: enabling lawful development while imposing obligations aimed at preventing discrimination, privacy violations, safety harms and systemic misinformation. Stakeholders including technology developers, platform operators, importers and regulated sectors such as healthcare and finance will need to prepare compliance documentation, implement risk management systems, and plan for registration/conformity processes.

Full article

Read full text ↗

Overview

The Yapay Zeka Kanun Teklifi (TBMM Esas No. 2/2234) is a parliamentary bill introduced to the Grand National Assembly of Turkey in June 2024 that establishes a general statutory framework for artificial intelligence. The bill was submitted by MP Ömer Faruk Gergerlioğlu and registered with the TBMM on 24 June 2024; its official dossier (text and rationale) is published by the TBMM legislative portal and the bill text is available as the official PDF linked on the parliamentary site. The proposal sets out five core principles—safety, transparency, fairness, accountability and privacy—and requires AI operators (providers, distributors, importers and users) to implement lifecycle risk management, documentation and auditing, with targeted requirements for "high‑risk" AI systems. The TBMM entry for the bill and the submitted text are primary sources for the reform; see the official parliamentary record and the bill PDF at TBMM – Kanun Teklifi: Yapay Zeka Kanun Teklifi (Esas No. 2/2234) and the bill text at TBMM PDF of the proposed law (e50ccc8a).

Definitions

The bill contains a definitions article that scopes covered technologies and actors. Key defined terms include "Artificial Intelligence" (broadly defined to include systems that exhibit cognitive functions such as learning, reasoning, perception and decision-making), "Provider" (entities that develop, produce or market AI systems), "Operator" (collective term for providers, distributors, importers, users and other entities that place AI in service), "High‑risk AI systems" (systems whose malfunction or bias could create significant harm, with examples such as medical diagnostic tools, autonomous vehicles, and systems used in the justice system), "Personal data" (bound to existing data protection law definitions), and "Conformity assessment" (formal verification that an AI system meets statutory and regulatory requirements). The bill’s definitions are designed to capture both software and integrated hardware solutions and to ensure coverage of cross-border supply chains.

Governance and Institutional Framework

The bill assigns oversight responsibilities across multiple bodies and anticipates implementing regulations to allocate detailed tasks. Primary legislative oversight is exercised by TBMM committees while operational supervision is anticipated to be shared among ministries and independent authorities. The bill contemplates coordination with the Kişisel Verileri Koruma Kurumu (KVKK) for privacy matters and the Bilgi Teknolojileri ve İletişim Kurumu (BTK) for areas touching telecommunications, network integrity and emergency interventions. For economic and industry policy coordination, the Ministry of Industry and Technology and the Ministry of Trade are named as key partners for standards, certification and industrial policy alignment. The proposal empowers designated enforcement authorities with inspection, audit, stop‑use and remedial order powers and contemplates a registration and conformity mechanism for high‑risk AI systems; see the official bill text at Official bill PDF.

Key Focus Areas

The legislative text organizes regulatory attention into a set of core focus areas: (1) Principles and duties (safety, transparency, fairness, accountability, privacy); (2) Risk management (mandatory risk assessment and mitigation plans across design, deployment and operation); (3) Conformity and registration (pre‑market or post‑market conformity assessments for high‑risk systems and a national registry); (4) Documentation and auditability (technical documentation, model cards, training data summaries and logs to enable traceability); (5) Data protection and governance (alignment with Law No. 6698 and KVKK guidance for lawful processing and deletion/retention controls); (6) Cybersecurity and model security (measures to protect models from poisoning, adversarial attacks and unauthorized access); (7) Consumer and fundamental rights protection (prohibitions on discriminatory datasets and requirements to avoid systemic bias); (8) Market surveillance and enforcement (administrative investigations and corrective powers); and (9) Sanctions and remedies (administrative fines, turnover-linked penalties and measures to remove or suspend illicit AI services). The bill explicitly contemplates differentiated regulatory requirements for systems that operate in critical domains such as healthcare and transport where errors carry higher human-safety risks.

Implementation Framework

Implementation is organized around primary duties for AI operators plus enabling instruments. Operators are required to: (i) perform and document comprehensive risk assessments; (ii) implement technical and organizational measures to mitigate identified risks; (iii) ensure training data governance (accuracy, fairness and non‑discrimination); (iv) prepare conformity evidence for high‑risk systems and register them with the appropriate supervisory body; (v) enable auditability via logs and documentation; and (vi) notify incidents and cooperate with supervisory inspections. The bill anticipates secondary legislation that will specify forms, technical standards, conformity assessment procedures, certification bodies and fees. It also foresees guidance documents and capacity-building measures to support compliance, with coordination among KVKK, BTK and relevant ministries. The official bill text describes the broad implementation architecture; see the bill at TBMM Kanun Teklifi page and the PDF here.

Monitoring and Evaluation

The bill requires supervisory authorities to establish market surveillance and monitoring systems. Authorities will carry out conformity assessments, audit compliance documentation, request corrective actions and maintain a public register of high‑risk AI systems. The law envisions periodic reporting by authorities and publication of enforcement statistics to allow evaluation of regulatory effectiveness. It also contemplates mechanisms for whistleblower and complaint submissions to trigger investigations. Monitoring includes technical audits, on‑site inspections, and remote checks of logs and model documentation. The bill calls for coordination protocols among enforcement bodies to avoid duplication and to ensure timely remedies.

Penalties, Liability, and Appeals

The bill creates a tiered sanctions architecture combining fixed administrative fines and turnover-based caps to ensure proportionality. Article 6 sets penalties including up to 35 million TL or up to 7% of annual turnover for prohibited AI applications; up to 15 million TL or up to 3% of annual turnover for breaches of statutory obligations; and up to 7.5 million TL or up to 1.5% of turnover for dissemination of materially false information by AI systems. Supervisory bodies may also order remedial measures, temporary suspensions and removals from the market. The bill foresees administrative appeal mechanisms (internal review and judicial review) consistent with Turkish administrative law; affected parties retain rights to challenge enforcement decisions in courts subject to standard procedural rules.

Relationship to Other Instruments

The proposal is drafted to operate alongside Turkey’s existing legal frameworks. It explicitly references coordination with the Kişisel Verileri Koruma Kanunu (Law No. 6698) for data protection matters and anticipates interaction with sectoral statutes (healthcare, financial services, transport). It also envisages alignment with consumer protection rules, competition law and criminal law where misuse of AI triggers criminal conduct. The bill tasks regulators to develop implementing regulations and memoranda of understanding to ensure coherence with existing regimes and to avoid regulatory overlap. Stakeholders will need to map compliance under the AI law against obligations under KVKK, sectoral regulators and the Electronic Communications Law.

International Alignment

The bill explicitly cites the need to align with international best practices and standards while preserving national policy objectives. It references global trends in risk‑based AI governance and anticipates mutual recognition and cooperation with foreign regulators for cross‑border enforcement, certification and information sharing. The law contemplates adopting technical standards and conformity frameworks that facilitate trade and interoperability, while allowing national supervisory authorities to require additional measures for sensitive national security and public order cases. The drafters emphasize that the law should help Turkey keep pace with regulatory developments in the EU and other jurisdictions while tailoring implementation to domestic needs; primary sources include the TBMM text and explanatory memorandum which address international comparators (official bill PDF).

Implementation Timeline

MilestoneTarget / Recorded Date
Bill filed with TBMM (registered)2024-06-24 (TBMM record)
Referral to primary and secondary commissions2024-06-25 (Sanayi/Ticaret/Adalet commissions)
Expected implementing regulation draftingUpon enactment – 3 to 12 months after law (to be set by government)
Registry and conformity body designation6–12 months after enactment

Sources and References

SourceType
TBMM – Kanun Teklifi entry for "Yapay Zeka Kanun Teklifi" (Esas No. 2/2234)Primary Source
Official bill text PDF (TBMM)Primary Source
Kişisel Verileri Koruma Kurumu (KVKK) – official sitePrimary Source (data protection regulator)
Bilgi Teknolojileri ve İletişim Kurumu (BTK) – official sitePrimary Source (telecom/regulator)

Requirements for a company

What an organisation has to do under Turkey - AI Regulation Bill (2/2234), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Under Review). These requirements apply once the instrument takes effect and may change before then.

Must do

11
  • Do not develop or deploy prohibited AI applications.AI operators.
  • Prevent AI systems from disseminating materially false information.AI operators.
  • Perform and document comprehensive risk assessments for AI systems.AI operators.
  • Implement technical and organizational measures to mitigate identified AI risks.AI operators.
  • Perform conformity assessments for high-risk AI systems.Operators of high-risk AI systems.
  • Register high-risk AI systems with the appropriate supervisory body.Operators of high-risk AI systems.
  • +5 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Turkey - AI Regulation Bill (2/2234), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1AI operators.Do not develop or deploy prohibited AI applications.
up to 35 million TL or up to 7% of annual turnover for prohibited AI applications
Critical
2AI operators.Prevent AI systems from disseminating materially false information.
up to 7.5 million TL or up to 1.5% of turnover for dissemination of materially false information by AI systems.
Critical
3AI operators.Perform and document comprehensive risk assessments for AI systems.
mandatory risk assessment and mitigation plans across design, deployment and operation
Critical
4AI operators.Implement technical and organizational measures to mitigate identified AI risks.
implement technical and organizational measures to mitigate identified risks
Critical
5Operators of high-risk AI systems.Perform conformity assessments for high-risk AI systems.
pre‑market or post‑market conformity assessments for high‑risk systems
Critical
6Operators of high-risk AI systems.Register high-risk AI systems with the appropriate supervisory body.
register them with the appropriate supervisory body
Critical
7AI operators.Ensure training data governance aligns with existing data protection law.
alignment with Law No. 6698 and KVKK guidance for lawful processing
Critical
8AI operators.Avoid discriminatory datasets and systemic bias in AI systems.
prohibitions on discriminatory datasets and requirements to avoid systemic bias
Critical
9AI operators.Notify authorities of incidents and cooperate with supervisory inspections.
notify incidents and cooperate with supervisory inspections
Critical
10AI operators.Maintain technical documentation, model cards, and audit logs.
technical documentation, model cards, training data summaries and logs to enable traceability
Important
11AI operators.Implement measures to protect AI models from cybersecurity threats.
measures to protect models from poisoning, adversarial attacks and unauthorized access
Important

© Regulations.AI · updated on 13-Jun-2026