← Global AI Policy Radar · Methodology
Jurisdiction Baseline · AI × Policy

AI Regulation in Turkey.

At a glance
AI-Specific Law
No comprehensive AI law is currently in force
Data Protection
Privacy law governs AI personal-data processing
Online Platforms
Content, representation, and reporting duties may apply
Cybersecurity
Covered entities face security and incident obligations

No, Türkiye does not have a comprehensive, AI-specific law in force as of August 6, 2026. AI deployments are mainly governed by the Personal Data Protection Law, internet and platform rules, consumer protection law, and cybersecurity requirements for covered entities, while the Turkish Data Protection Authority’s AI and generative-AI guidance is supervisory guidance rather than a standalone law. Enforcement is active under these existing rules, and AI-specific bills remain pending in Parliament.

In force today3 instruments
Personal Data Protection Law No. 6698 in force
This is the central regime for AI systems that collect, train on, infer from, or generate personal data. Companies must establish a lawful processing basis, provide notices, respect data-subject rights including objections to solely automated outcomes, secure data, manage international transfers, and address special-category data such as biometric and health data.
Data processingDisclosureSafety & security
Law No. 5651 on Regulation of Publications on the Internet and Combating Crimes Committed through Such Publications in force
This applies to online services that host, distribute, or facilitate user content, including AI-generated content and social-network functionality. Depending on the service and user scale, obligations can include content-removal and access-blocking processes, cooperation with authorities, representation in Türkiye, response handling, and periodic reporting.
Content moderationDisclosureMinors
Unlock the full baseline

Get the remaining 1 instruments and the founder FAQ. Free: subscribe once and every briefing on this device unlocks.

Already subscribed? Unlock →

Cybersecurity Law No. 7545 in force
The law establishes Türkiye’s national cybersecurity framework and applies broadly to public and private entities operating in cyberspace, with more substantial duties for designated or critical entities. AI companies should assess whether their systems, data, cloud infrastructure, or sectoral activities trigger security controls, incident obligations, audits, or requirements imposed through implementing rules.
Safety & security
Also worth noting
  • The standalone Artificial Intelligence Law proposal submitted to Parliament on June 24, 2024 remains in committee and is not in force.
  • A January 8, 2026 proposal would amend Law No. 6698 to impose major penalties on platforms sharing AI-generated audio, text, or video without consent; it remains in committee.
  • The Turkish Data Protection Authority’s 2026 generative-AI guidance and AI recommendations are worth monitoring, but they are guidance rather than binding AI-specific rules.
Pending and recent legislation1 measures
TR 2/3744 Bill No. 2/3744: Proposal to Establish an Artificial Intelligence, Automation and Social Transformation Adaptation Fund
Advancing · 2026-06-26
The bill proposes creating a fund to support adaptation to artificial intelligence, automation, and related social transformation. It was referred to parliamentary committees covering health, family, labor and social affairs, and industry, trade, energy, natural resources, inform

Live from the Global AI Policy Radar.

Founder FAQAI law, regulators, what applies, what is next, penalties
Is there an AI-specific law in force here?

No. As of August 6, 2026, Türkiye has no comprehensive AI-specific law in force. The Turkish Data Protection Authority has issued AI and generative-AI guidance, but this is supervisory guidance rather than a standalone AI statute.

Who are the key regulators for AI?

The Turkish Data Protection Authority is a key regulator because the Personal Data Protection Law applies to many AI activities involving personal data. Other relevant regulators and authorities enforce internet and platform rules, consumer protection law, and cybersecurity requirements, depending on the system and sector.

Which rules apply to AI systems today?

AI systems may be subject to Personal Data Protection Law No. 6698, including rules on lawful processing, notices, data-subject rights, security, international transfers, and special-category data. Online services may also be subject to Law No. 5651, including content-removal, access-blocking, cooperation, representation, response-handling, and reporting duties. Cybersecurity Law No. 7545 may impose security controls, incident obligations, audits, or other requirements, especially on designated or critical entities.

What is coming next, and when?

AI-specific bills remain pending in Parliament. The source does not provide a date for their adoption or entry into force. Until then, AI deployments continue to be governed mainly by existing data protection, internet and platform, consumer protection, and cybersecurity rules.

What are the enforcement and penalty risks?

Enforcement is active, with regulators using existing powers against data-processing, online content, platform conduct, and cybersecurity failures. The specific risk depends on which rules apply, whether the entity is covered, and the nature of the failure. The source does not specify particular penalty amounts.

Not legal advice. For educational purposes only. AI-researched against official sources (2026-08-06), links verified.

Need a company-specific assessment? Explore Nomos →