July 23, 2026

The European Union’s Artificial Intelligence Regulation And Turkey’s Position

What Is the European Union Artificial Intelligence Regulation and What Is Its Purpose?

Today, artificial intelligence technologies have evolved beyond mere technical progress to become a paradigm shift that is transforming social, economic, and normative systems. While this rapid digital transformation process provides innovative solutions and increased efficiency for organizational operations, it also brings with it serious risks in the context of fundamental rights and freedoms, data privacy, and legal liabilities. To mitigate these risks and establish a human-centered, trustworthy AI ecosystem, the European Union adopted Regulation (EU) 2024/1689 on Artificial Intelligence (“AI Act,” “Artificial Intelligence Regulation,” or “Regulation”) on June 13, 2024. Although the Regulation entered into force in 2024, a phased transition period is provided for, with the general rules and core obligations regarding high-risk systems set to take effect on August 2, 2026. 

The Regulation aims to improve the functioning of the internal market by establishing uniform rules regarding the placing on the market, putting into service, and use of artificial intelligence systems; at the same time, it seeks to provide a high level of protection for health, safety, and fundamental rights against the potential harmful effects of artificial intelligence. Rather than being a general-purpose law covering every aspect of artificial intelligence, the Regulation incorporates a framework based on the philosophy of product safety and adopts a risk-based approach. In line with this approach, systems are categorized into different classes—unacceptable risk, high risk, and minimal/limited risk—and legal obligations are structured according to this classification. 

Implications for Legal Disputes, Administrative Procedures, and Contract Law

Artificial intelligence tools, which are now being used across a wide range of applications—from the drafting of corporate contracts to the management of administrative compliance processes—are giving rise to complex legal disputes that go beyond the principles of traditional contract and obligations law. In particular, the use of artificial intelligence in litigation creates serious liability risks that could profoundly impact the professional careers of attorneys and legal professionals. For example, courts’ requests for the disclosure of AI prompts used by experts or the parties in the resolution of disputes are opening up entirely new areas of debate in the context of due process, the protection of trade secrets, and the law of evidence. 

Indeed, the sanctions order issued on May 21, 2026, by a judge of the U.S. District Court for the Northern District of Alabama is the most concrete manifestation of this danger. In the case at issue, the submission of fabricated case law prepared using ChatGPT to the court, coupled with the attorney’s attempt to conceal this by deleting the chat history to destroy evidence, resulted in severe sanctions. In the 34-page ruling in which the judge disbarred the attorney, the judge cited the courts’ approach to AI abuse with the following words:

“Any attorney who believes this court will hesitate to investigate such misuse with all its might and impose [career-altering] sanctions is seriously mistaken.”

However, in another landmark ruling issued on May 18, 2026, by a U.S. District Court judge in Connecticut in the case of Conservation Law Foundation v. Shell Oil Co., the court ordered that the AI prompts used by expert witnesses in preparing their reports be disclosed to the opposing party. These court rulings open up entirely new areas of debate in the context of due process, the protection of trade secrets, and the law of evidence. Therefore, the integration of technological advancements into litigation processes and contracts is not merely a technical adaptation process but a necessity that must be carefully managed through legal strategy.

In this article, we will first address the general framework established by the AI Act, the primary obligations imposed on actors in the supply chain, and the corporate risks arising from the use of “Shadow AI” in the workplace; subsequently, we will detail the implications of this global regulation in Turkey, its intersections with the Personal Data Protection Law (“KVKK”), and Turkey’s current strategic position.

The Risk-Based Approach of the Artificial Intelligence Regulation and the Obligations It Imposes

Rather than imposing blanket restrictions on technological innovation, the AI Act has established a risk-based legal framework that classifies AI systems according to their potential risks, in accordance with the principle of proportionality. Under this framework, systems are categorized as posing unacceptable risk, high risk, or minimal/transparency risk, with penalties increasing in severity based on this classification. 

a. Unacceptable Risks and Prohibited AI Applications

The Regulation has unequivocally prohibited certain AI practices that clearly contravene the European Union’s fundamental values, human dignity, and the principles of a democratic state governed by the rule of law, under Article 5 of the AI Act. The primary unlawful acts falling under this absolute prohibition are as follows: 

1. Manipulative and Deceptive Systems: The placing on the market and use of systems that exploit vulnerabilities arising from individuals’ age, disability, or socioeconomic status, or that materially distort behavior by using subliminal techniques that bypass human consciousness, are prohibited. 

2. Social Scoring: Systems that assess and score the reliability of natural persons based on their social behavior or personal characteristics, and that lead to unfair or disproportionate discriminatory treatment, are prohibited. 

3. Unlawful Use of Biometric Data: Biometric classification systems used to identify and analyze individuals’ sensitive data—such as political views, union membership, religious beliefs, or sexual orientation—as well as applications that create facial recognition databases through indiscriminate data mining from the internet or CCTV recordings are prohibited. 

4. Emotion Recognition in the Workplace and Education: Subject to exceptions such as medical or security reasons, the use of artificial intelligence systems designed to infer the emotions of individuals in workplaces and educational institutions is prohibited. 

5. Real-Time Biometric Recognition in Public Spaces: Real-time remote biometric identification by law enforcement in public spaces is prohibited, except in very narrow and strictly judicially authorized exceptional cases, such as preventing the threat of a terrorist attack or identifying perpetrators of certain serious crimes. 

b. High-Risk Systems and a Strict Oversight Regime

High-risk systems form the regulatory focus of the AI Act. For an AI system to be considered high-risk, it must either be a safety component of a product covered by EU harmonization legislation (such as machinery, elevators, medical devices, etc.) as specified in Annex 1 of the AI Act, or operate in the specific application areas listed in Annex 3. 

In particular, systems used in areas such as biometric identification, the management of infrastructure such as water, electricity, and gas, access to essential private and public services such as education, employment, credit scoring, and healthcare, as well as in law enforcement and the judiciary, are generally considered high-risk. 

Legal Responsibilities of Actors: Providers and Deployers

Similar to traditional supply chain liability, the Regulation imposes asymmetric obligations on different actors in the AI value chain.

a. Obligations of Providers: Providers that place a high-risk AI system on the market under their own name or trademark are required, pursuant to Article 16 of the AI Act, to cumulatively meet a series of strict administrative and technical requirements. In this context, providers must: 

  • must establish a Quality Management System and a Risk Management System covering the entire lifecycle of the system. 
  • They must establish a logging infrastructure to ensure the system’s traceability and prepare comprehensive technical documentation. 
  • The system must undergo a conformity assessment and be registered in the EU database before being placed on the market. 

b. Obligations of Implementers: Institutions and companies that use the system within the scope of their professional activities are obligated to ensure that the system is operated in accordance with the user instructions and to assign human oversight to natural persons with the necessary qualifications. In addition, legal entities providing public services, as well as certain implementers operating in sectors such as banking and insurance, are required to conduct a “Fundamental Rights Impact Assessment” before putting the system into operation. This obligation does not replace the Data Protection Impact Assessment already conducted under the General Data Protection Regulation (“GDPR”); rather, it serves to complement it. 

Transparency Obligations and General-Purpose Artificial Intelligence Models

To make the “black box” nature of artificial intelligence more transparent, the Regulation has established specific transparency obligations under Article 50 for systems that interact directly with natural persons or generate synthetic content, regardless of their risk category. Individuals have the right to know when they are interacting with an AI, unless it is reasonably clear otherwise. It is a legal requirement that text, audio, or images generated by AI be labeled as such in a machine-readable format. 

Additionally, the Regulation establishes a two-tiered framework for “General-Purpose AI Models,” such as large language models. While all general-purpose models are required to prepare technical documentation and develop a copyright compliance policy, models trained with high computational power and deemed to pose systemic risks are subject to stricter security, testing, and incident reporting obligations. 

Turkey’s Position and Regulatory Intersection: The KVKK Perspective

While the European Union is setting a global standard with the Regulation, Turkey is also taking significant strategic steps to integrate into this technological transformation. The National Artificial Intelligence Strategy 2024–2025 Action Plan, which reflects Turkey’s technological vision, has identified the following as strategic priorities: training AI experts, supporting R&D and entrepreneurship, enacting regulations to accelerate socioeconomic integration, and establishing a Central Public Data Hub. 

Although there is not yet a standalone artificial intelligence law in Turkish law, the Personal Data Protection Law (KVKK) provides the fundamental legal framework applicable to data processing activities conducted within the scope of artificial intelligence systems. Compliance with the general principles set forth in Article 4 of the KVKK is mandatory at every stage of artificial intelligence processes. In any scenario where processing is based on the data subject’s explicit consent or other processing conditions set forth in the KVKK, the obligation to provide information under Article 10 must be fully fulfilled. Additionally, data controllers are required to take all necessary technical and administrative measures to ensure data security in accordance with Article 12. 

Generative AI and the “Shadow AI” Risk in the Workplace

Today, routine workflows such as drafting emails, analyzing contracts, summarizing meeting notes, and generating software code are largely carried out using Generative Artificial Intelligence (“GAI”) tools provided by third parties. However, the use of these tools by employees on their own initiative, without the organization’s approval or IT oversight, gives rise to a dangerous corporate risk known as “Shadow AI.” 

The primary legal and operational risks posed by the use of Shadow AI for organizations and companies are as follows:

1.Violation of Intellectual Property and Trade Secrets: Providing source code, contract drafts, business strategies, or confidential documents constituting trade secrets as input (prompts) to external AI tools may result in this information being used in third-party model training and being disclosed. 

2. Data Protection Risk: Sharing customer files or human resources data with unauthorized AI tools could lead to unlawful data processing and data breaches, potentially exposing companies to heavy administrative fines. 

3. Decision Quality and Automation Bias: When employees integrate content—which may contain “hallucinations,” defined as misleading outputs generated by AI that do not correspond to reality but appear logical—into business processes without questioning it, this can lead to flawed corporate decisions. 

4. Lack of Auditability and Accountability: Because these uses are not subject to corporate record-keeping mechanisms, it becomes difficult to determine what data is being used and for what purpose, and compliance processes are disrupted. 

Conclusion: What Steps Should Organizations Take?

Given the efficiency gains offered by artificial intelligence, companies’ radical decisions to completely ban the use of these tools may not yield practical results; on the contrary, they may inadvertently encourage the covert use of “Shadow AI.” Instead, companies can take the following steps: 

A clear internal “AI Usage Policy” must be established; restrictions must be placed on which AI tools can be used with which data. Employees must be trained to use anonymized and abstract terms—rather than personal names, financial data, or trade secrets—when entering commands into AI tools. When creating transactions or drafts, AI outputs must not be accepted as final decisions; it must be mandatory for all content to undergo human review. Finally, the corporate technology infrastructure must be equipped with role-based access controls to maximize data security. 

Frequently Asked Questions (FAQ)

Does the European Union Artificial Intelligence Act (AI Act) apply to companies in Turkey?

Yes. The Act applies to operators in Turkey regardless of the provider’s or deployer’s location, provided that the AI system is placed on the market within the EU, or even if the system is located outside the EU but its output is used within the EU. 

What is Shadow AI?

It refers to the use of generative AI tools within an organization or institution in business processes based entirely on employees’ individual preferences, without the organization’s knowledge, approval, or corporate IT oversight. 

Should companies completely ban the use of generative AI to prevent data breaches?

No. Prohibitive approaches are not recommended because they would push employees toward uncontrolled use. Instead, guidance- and awareness-based approaches should be adopted, clear internal guidelines should be established, and shared data should be ensured to contain anonymous or general terms. 

Under what circumstances is an AI system considered “High-Risk”?

For a system to be classified as high-risk, it must be a safety component of a product covered by EU compliance legislation and require a third-party conformity assessment, or it must be used in specific application areas listed in Annex 3 of the AI Act, such as biometric identification, hiring, education, and critical infrastructure management. 

Authors

Eren Can Ersoy

Eren Can Ersoy

Senior Lawyer

Bilal Faruk Erbay

Bilal Faruk Erbay

Lawyer