Abdulaziz Akyol

EU AI Act: a practical compliance guide for Turkish companies

Artificial intelligence · Leadership
25 September 2026 · 10 min read · Abdulaziz Akyol

The EU AI Act (Regulation (EU) 2024/1689) is an EU regulation that governs AI systems according to their level of risk and applies directly in the member states. Turkish companies are within its reach: a company that offers its system on the EU market, or whose system output is used in the EU, takes on obligations wherever it is established.

The Regulation was published in the Official Journal of the EU on 12 July 2024, entered into force on 1 August 2024 and applies in stages. I prepared this guide as of September 2026, taking into account the Digital Omnibus amendments that entered into force on 27 July 2026. I read the text through the eyes of the founder of a company that builds video analytics products, with a practical focus.

Note: This article is for general information only and is not legal advice. Consult a lawyer specialised in EU law to classify your own system.

When does the Act apply to Turkish companies?

Article 2 sets the scope with two tests. The first is the market: providers that place AI systems on the market or put them into service in the EU are covered, whether they are established in the EU or in a third country. The second is output: providers and deployers established in a third country are covered when the output produced by the system is used in the EU.

Getting the roles right matters. The provider develops the system, or has it developed, and places it on the market under its own name; the deployer uses the system in a professional capacity. Importers and distributors have their own obligations too.

ScenarioYour roleStatus
You sell software developed in Turkey to a customer in the EUProviderIn scope
The system runs in Turkey, but a customer in the EU uses the score or report it producesProviderIn scope (output used in the EU)
Your EU subsidiary uses the system for its own employeesSubsidiary is deployer; if you built it, you are providerIn scope
The system is used only in Turkey, for people in Turkey—Generally out of scope; Turkish data protection law applies

Third-country providers of high-risk systems must, before making them available on the EU market, appoint an authorised representative established in the EU by written mandate (Article 22). Systems used exclusively for military, defence or national security purposes, systems developed solely for scientific research, research and testing before placing on the market, and purely personal, non-professional use are out of scope.

What are the risk classes?

ClassExamplesWhat is required?
Unacceptable risk (prohibited)Social scoring, emotion recognition in the workplace and in education, building facial recognition databases through untargeted scraping of facial images from the internet or CCTVCannot be used
High riskAnnex I: safety components of products under product safety legislation. Annex III: biometrics, critical infrastructure, education, employment, essential services (e.g. credit scoring), law enforcement, migration, justiceRisk management, data governance, technical documentation, record-keeping, human oversight, accuracy and cybersecurity, conformity assessment, registration in the EU database
TransparencyChatbots, systems generating synthetic content, deepfakes, deployers of emotion recognition and biometric categorisationInform people; mark generated content in a machine-readable format
Minimal riskSpam filters, demand forecasting, most internal productivity toolsNo legal obligations; voluntary codes of conduct

The list of prohibitions (Article 5) also covers manipulative techniques, exploiting vulnerabilities linked to age, disability or socio-economic situation, predicting criminal risk based solely on profiling, inferring race, political opinions, religion or sexual orientation from biometric data, and real-time remote biometric identification in publicly accessible spaces for law enforcement (with narrow exceptions). The Digital Omnibus added systems that generate non-consensual sexual and intimate content or child sexual abuse material.

An Annex III system may escape the high-risk label if it performs a narrow procedural task, improves the result of a previously completed human activity, detects deviations from decision-making patterns without replacing human assessment, or performs a preparatory task for an assessment (Article 6(3)). However, a system that profiles natural persons is always high-risk, and a provider relying on this exception must document its assessment and register the system.

Obligations for general-purpose AI (GPAI)

The Act separates models from systems. Since 2 August 2025, providers of general-purpose AI models must draw up technical documentation, give providers building systems on the model information about its capabilities and limitations, put in place a policy to comply with EU copyright law and publish a summary of the content used for training (Article 53). Models trained with more than 10^25 floating-point operations are presumed to carry systemic risk and have additional duties: model evaluation, mitigating systemic risks, reporting serious incidents and cybersecurity (Article 55). The Commission’s enforcement powers over these providers started on 2 August 2026; models placed on the market before 2 August 2025 have until 2 August 2027 to comply.

Most Turkish companies use a language model through an API, which does not make them GPAI model providers. According to the Commission’s guidelines, these obligations pass only to those who significantly modify a model. But if you build a product on the model and offer it under your own name, you are the provider of that AI system. Practical advice: ask your model supplier for the documentation it must provide under Article 53 and add it to your own technical file.

Timeline (as of September 2026)

DateWhat applies?
1 August 2024The Regulation entered into force
2 February 2025Definitions, AI literacy and prohibited practices
2 August 2025GPAI model obligations, governance structure
2 August 2026Most rules and enforcement; transparency rules (Article 50)
2 December 2026The new prohibition added by the Omnibus; end of the transition for content marking (Article 50(2)) for systems placed on the market before 2 August 2026
2 August 2027At least one regulatory sandbox per member state; deadline for legacy GPAI models
2 December 2027Rules for Annex III high-risk systems
2 August 2028Rules for high-risk systems embedded in products covered by Annex I

The European Commission proposed the Digital Omnibus on 19 November 2025; political agreement was reached on 7 May 2026, and it was published as Regulation (EU) 2026/1744 on 24 July 2026, entering into force on 27 July 2026. Besides the postponement, according to the Commission’s announcement it simplified the AI literacy requirement for companies, giving the Commission and member states a stronger role; extended some SME measures to small mid-cap companies; streamlined registration of exempted systems in the EU database; enabled processing of special categories of personal data for bias detection; and extended the AI Office’s oversight of certain systems built on general-purpose models.

My reading: the postponement is not a reason to postpone preparation. Quality management, technical documentation and conformity assessment for a high-risk system take months, and corporate buyers in the EU may well examine a supplier’s readiness during procurement.

Where do video analytics and biometrics stand?

This is my own field, so I cover it in detail. The table below is my reading of the text, not a legal opinion:

ApplicationLikely class
People counting, queue length, zone occupancy (no identity)Does not by itself fall under the Annex III biometric categories; minimal risk in most cases
Hard hat and vest detection, forklift–pedestrian proximitySafety event detection; if events are tied to individuals and used to monitor and evaluate employee performance and behaviour, Annex III 4(b) may come into play
Identifying people remotely with face recognitionAnnex III 1(a): high risk; real-time use in publicly accessible spaces for law enforcement is prohibited apart from narrow exceptions
Door access checking “is this person who they claim to be”Excluded from Annex III 1(a); biometric data is still special-category data under KVKK
Inferring employees’ emotions from facial expressionsProhibited (Article 5(1)(f)); medical and safety exceptions exist
Emotion recognition on customersAnnex III 1(c): high risk; people must also be informed (Article 50(3))
Inferring race, religion, political opinion or sexual orientation from imagesProhibited (Article 5(1)(g))

At CX Teknoloji we designed our products without face recognition, with anonymous processing. That choice simplifies classification under both Turkish data protection law and the EU AI Act. For occupational safety, my advice is to keep events as zone-and-time events rather than turning them into a structure that scores individuals. The technical chain is covered in the RTSP-to-event article, the data protection side in the article on video analytics without face recognition.

How does it relate to KVKK?

KVKK is Turkey’s Personal Data Protection Law (Law No. 6698), broadly comparable to the GDPR. The EU AI Act and KVKK answer different questions and apply side by side. The Act treats the safety and fundamental-rights compliance of an AI system in the manner of product regulation; KVKK governs on what legal basis, to what extent and how personal data is processed. Complying with one does not mean complying with the other. If you process data of people in the EU, the GDPR may apply as well.

On the Turkish side, three points stand out. Biometric data is special-category personal data under Article 6 of KVKK, and the processing conditions in that article changed on 1 June 2024 with Law No. 7499. If the model or cloud service is abroad, the cross-border transfer rules of Article 9 apply. On 24 November 2025 the Turkish data protection authority published a guide on generative AI and personal data (in Turkish). My recommendation is to run one AI inventory and one impact assessment process rather than separate projects for the two regimes.

Penalties

InfringementMaximum (whichever is higher)
Prohibited practicesEUR 35 million or 7% of worldwide annual turnover
Other obligationsEUR 15 million or 3%
Incorrect or misleading information to authoritiesEUR 7.5 million or 1%

For SMEs the lower of the two amounts applies (Article 99). Because the Omnibus extended some SME measures to small mid-cap companies, check your own position against the current consolidated text.

Compliance checklist

  1. Build an inventory: List every AI system developed in-house, purchased or used by employees.
  2. Establish the EU link: Which systems are placed on the EU market or have output used in the EU?
  3. Determine your role: Record for each system whether you are provider, deployer or importer.
  4. Classify: Prohibited, high risk, transparency, minimal. If you rely on the Article 6(3) exception, document the reasoning.
  5. Stop prohibited practices now: These provisions have applied since 2 February 2025.
  6. Ensure transparency: Tell chatbot users they are talking to AI; mark generated content.
  7. Prepare for high risk: Start risk management, data governance, technical documentation, record-keeping, human oversight and conformity assessment today, not in December 2027; appoint an authorised representative in the EU.
  8. Manage the supply chain: Request documentation from model and component suppliers; set out responsibilities in contracts with EU customers.
  9. Set up an AI literacy programme: Train staff who use AI and keep records.
  10. Merge with data protection: Run the data protection impact assessment on the same inventory.

I describe how to set up compliance as a governance process in the AI roadmap for CIOs, and permission and audit-log design for agent projects in the AI agents and MCP article.

Frequently asked questions

Does the EU AI Act apply to Turkish companies?

Yes, in certain cases. Providers that place an AI system on the market or put it into service in the EU are covered wherever they are established. Providers and deployers in third countries are also covered when the output produced by the system is used in the EU. An internal system used only in Turkey, for people in Turkey, is generally out of scope.

When did the EU AI Act start to apply?

The Regulation entered into force on 1 August 2024 and applies in stages: prohibited practices and AI literacy from 2 February 2025, rules for general-purpose AI models from 2 August 2025, and most rules including transparency obligations from 2 August 2026. The Digital Omnibus postponed high-risk rules to 2 December 2027 and 2 August 2028.

What did the Digital Omnibus change?

Regulation (EU) 2026/1744 was published on 24 July 2026 and entered into force on 27 July 2026. It postponed the high-risk rules, simplified the AI literacy obligation, extended some SME measures to small mid-cap companies and added systems generating non-consensual intimate content and child sexual abuse material to the list of prohibited practices.

Is a company that uses a language model via an API a GPAI provider?

Usually not. A general-purpose AI (GPAI) model provider is the company that develops the model and places it on the market; according to the Commission's guidelines only those who significantly modify a model take on these obligations. But if you build an AI system on the model and offer it under your own name, you are the provider of that system, and your obligations depend on its risk class.

What are the penalties under the EU AI Act?

Fines of up to EUR 35 million or 7% of worldwide annual turnover for prohibited practices, up to EUR 15 million or 3% for other obligations, and up to EUR 7.5 million or 1% for supplying incorrect information to authorities, whichever is higher. For SMEs the lower amount applies.

Sources

  1. Regulation (EU) 2024/1689 – Artificial Intelligence Act (EUR-Lex) eur-lex.europa.eu
  2. Regulation (EU) 2026/1744 – Digital Omnibus on AI (EUR-Lex) eur-lex.europa.eu
  3. European Commission, AI Act – Regulatory framework for AI digital-strategy.ec.europa.eu
  4. AI Act Service Desk, Timeline for the Implementation of the EU AI Act ai-act-service-desk.ec.europa.eu
  5. European Commission, AI Omnibus enters into force digital-strategy.ec.europa.eu
  6. KVKK (Turkish DPA), Guide on Generative AI and Personal Data Protection (in Turkish) kvkk.gov.tr

EU AI ActDigital Omnibushigh-risk AIbiometricsKVKKcompliance Markdown version

Contact

Let's talk.