Turkey Artificial Intelligence Act Draft: A 100-Article Founding Vision

This draft bill is the direct translation of the massive socio-economic analyses from the first 4 parts of our report series into a legal text. It is conceptualized not merely as a list of bans, but as a global pioneering text that protects employment, secures copyrights, paves the way for innovation, and most importantly, places "Human Dignity" at the center.
PART ONE: Purpose, Scope, and Basic Principles (Articles 1-10)

Article 1: Purpose of the Act

The purpose of this act is to ensure that AI systems are developed, deployed, and used in a manner worthy of human dignity, fundamental rights, and democratic values; and to protect employment and public safety while supporting technological innovation.
  • Rationale: Placing the supremacy of law and humanity over technological determinism at the heart of the legislation.
  • Global Context: Similar to the EU AI Act (Article 1) but distinguished by its strong emphasis on employment.
  • Turkish Law: Directly integrated with Article 5 of the Constitution (Fundamental Aims and Duties of the State).

Article 2: Scope

This act applies to all public institutions, natural, and legal persons developing, deploying, importing, or using AI systems within the borders of the Republic of Turkey. AI systems intended solely for national security and military purposes fall outside the scope of this act.
  • Rationale: To regulate civil and commercial life without tying the hands of the defense industry (e.g., UAV/UCAVs).
  • Global Context: All global AI acts exclude military applications.
  • Turkish Law: Leaves room for Defense Industry Agency legislation.

Article 3: Extraterritorial Effect

All AI systems whose outputs affect users in Turkey or process the data of Turkish citizens are subject to this Act, even if their developers or servers are located abroad.
  • Rationale: To prevent US tech giants (like OpenAI, Google) from claiming exemption by stating "Our headquarters are in the US."
  • Global Context: The "Brussels Effect" logic applied by GDPR and the EU AI Act.
  • Turkish Law: Compatible with the extraterritorial doctrine in KVKK (Data Protection Law) and Internet Law No. 5651.

Article 4: Definition of Artificial Intelligence

AI System: A machine-based system that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.
  • Rationale: To distinguish between a simple calculator and a learning algorithm.
  • Global Context: Based on the updated 2023 OECD definition, globally recognized as the standard.
  • Turkish Law: Provides the clear definition required by the principle of legal certainty for penalization.

Article 5: Human-Centricity and the Human Decision Principle

AI is positioned not as an ultimate decision-maker replacing humans, but as an assistant/advisor augmenting human capacity. The final decision in critical matters always belongs to a human.
  • Rationale: Creating a society that manages the machine, rather than submitting to it.
  • Global Context: UNESCO Recommendation on the Ethics of AI.
  • Turkish Law: Ensuring that administrative actions (e.g., tax penalties) are instituted by human authorities, not machines.

Article 6: Principle of Transparency

It is essential that individuals interacting with AI systems can clearly and easily understand that they are engaging with a machine, not a human being.
  • Rationale: To prevent emotional manipulation and deception (e.g., in customer service).
  • Global Context: Transparency obligations under the EU AI Act.
  • Turkish Law: Consumer Protection Law - The right to accurate information.

Article 7: Ban on Algorithmic Discrimination

AI systems cannot be trained or used to discriminate based on race, language, religion, gender, political opinion, philosophical belief, or regional affiliation (zip code).
  • Rationale: To prevent algorithms from exhibiting latent racism or bias in hiring or credit scoring.
  • Global Context: US Algorithmic Accountability Act (Draft).
  • Turkish Law: Constitution Article 10 (Equality before the law).

Article 8: Explainability (XAI) Principle

The parameters on which AI decisions negatively affecting individuals (e.g., loan denial, job rejection) are based must be explained in language understandable to citizens. The "Black Box" excuse is unacceptable.
  • Rationale: Citizens must know the rationale of a decision to exercise their right of appeal.
  • Global Context: "Right to Explanation" (GDPR and EU AI Act).
  • Turkish Law: Constitution Art. 40 and Administrative Procedures Act (Right to reasoned decisions).

Article 9: Principle of Environmental Sustainability

Companies training Large Language Models (LLMs) are obliged to report annually on the energy consumed by their servers, their carbon footprint, and water usage.
  • Rationale: Systems like ChatGPT consume roughly 10 times more electricity than a traditional search engine.
  • Global Context: The Green AI doctrine.
  • Turkish Law: Integrated monitoring obligations under the Environmental Law.

Article 10: Pro-Innovation Principle

In applying this act, utmost care is taken to ensure that administrative measures do not create disproportionate bureaucratic burdens that would hinder the development of local startups and academic research.
  • Rationale: To avoid creating a "Regulatory Capture" wall where only Big Tech can survive.
  • Global Context: The UK's Pro-Innovation approach to AI.
  • Turkish Law: Freedom of enterprise and R&D incentives.
PART TWO: Risk Classification and Banned Systems (Articles 11-20)

Article 11: Four-Tiered Risk Approach

AI systems are categorized into four tiers based on their potential to harm society: Unacceptable Risk, High Risk, Limited Risk, and Minimal Risk. Audits and obligations are enforced proportionally according to this risk weight.
  • Rationale: To avoid judging a spam email filter and an autonomous vehicle with the same legal severity.
  • Global Context: The global standard risk pyramid adopted by the EU.
  • Turkish Law: Adaptation of the "Proportionality" principle in administrative law to technology.

Article 12: Banned AI - Social Scoring

Systems by the state or private companies that score the general behavior or social media activities of citizens and deprive them of credit, travel, or public services based on these scores are banned in Turkey.
  • Rationale: To prevent a "Digital Dictatorship" dystopia similar to China's model.
  • Global Context: EU AI Act Prohibited Practices (Article 5).
  • Turkish Law: An absolute violation of human rights and the principle of equality.

Article 13: Banned AI - Subliminal Manipulation

AI techniques aiming to target the subconscious, impair conscious will, and alter behavior in a way that causes physical or psychological harm (impulsive consumption or self-harm) are banned.
  • Rationale: To prevent Dark Patterns that hack the human mind.
  • Global Context: Neuro-rights and Cognitive Liberty movements.
  • Turkish Law: Penal Code (vitiation of will) and Consumer Law (unfair commercial practices).

Article 14: Banned AI - Real-Time Biometric Identification in Public Spaces

Except for law enforcement agencies under strict conditions, real-time, non-consensual biometric facial recognition and profiling in public squares, streets, or malls by private companies or institutions are banned.
  • Rationale: The feeling of constant surveillance (Panopticon) deteriorates societal psychology.
  • Global Context: San Francisco facial recognition ban and EU AI Act exceptions.
  • Turkish Law: Violation of KVKK Article 6 (Special category personal data).

Article 15: Banned AI - Emotion Recognition in Workplace and Education

"Emotion Recognition" systems that analyze micro-expressions or voice tones of employees in workplaces or students in schools to constantly measure and profile fatigue, sadness, or productivity levels are banned.
  • Rationale: To prevent employees from feeling constantly on edge in front of a machine.
  • Global Context: Specific ban introduced by the EU AI Act for workplaces and educational institutions.
  • Turkish Law: Labor Law (limits of employee surveillance and privacy).

Article 16: Banned AI - Biometric Categorization

The use and sale of AI systems that attempt to infer individuals' sexual orientation, political views, or religious beliefs from their facial features or biometric data are banned.
  • Rationale: To prevent the pseudoscience of "Phrenology" from returning via AI.
  • Global Context: Ban on profiling contrary to human dignity.
  • Turkish Law: KVKK (Non-consensual inference of sensitive data).

Article 17: Banned AI - Exploitation of Vulnerabilities

AI systems that exploit the vulnerabilities of children, the elderly, or the mentally/physically disabled arising from their age, health, or social situation, causing them material or moral harm, are banned.
  • Rationale: Protecting disadvantaged groups from AI bots that approach them as "friends."
  • Global Context: UNICEF AI Ethics guidelines.
  • Turkish Law: Civil Code (Incapacity) and Penal Code (Fraud).

Article 18: Banned AI - Predictive Policing (Minority Report)

Judicial AI systems that calculate the percentage of "future probability of committing a crime" based on an individual's past data and recommend preventive arrest/detention based on this prediction are banned.
  • Rationale: To protect the presumption of innocence (innocent until proven guilty).
  • Global Context: A safeguard against scandals like the US COMPAS system unjustly targeting minorities.
  • Turkish Law: Principle of the presumption of innocence under the Criminal Procedure Code (CMK).

Article 19: Scope Exceptions for Bans

The bans listed from Articles 12 to 18 may be exceptionally relaxed in state emergencies concerning counter-terrorism, severe organized crime, or national security, strictly subject to an independent court order (judicial authorization).
  • Rationale: Not to leave the state helpless in a severe national security crisis (e.g., tracking a suicide bomber).
  • Global Context: Law Enforcement Exception clause in the EU AI Act.
  • Turkish Law: Constitution Article 13 (Restriction of fundamental rights by law for public safety).

Article 20: Penalties for Violating Bans

Companies that develop, sell, or deploy the banned (Unacceptable Risk) AI systems specified in this Part in the Turkish market shall be punished with administrative fines of up to 7% of their global turnover or 500 Million TL (whichever is higher).
  • Rationale: To maximize deterrence and prevent bans from merely being a "cost of doing business" for Big Tech.
  • Global Context: Asymmetric proportional penalty architecture similar to GDPR and EU AI Act.
  • Turkish Law: Turnover-based penalty model similar to Competition Authority fines.
PART THREE: High-Risk Systems and Transparency (Articles 21-30)

Article 21: Definition of High-Risk AI Systems

AI systems used in critical infrastructure management, transport (autonomous vehicles), education (grading), employment (CV screening algorithms), law enforcement, and judicial systems are considered "High-Risk" and are subject to strict audits before entering the market.
  • Rationale: Identifying sectors that can permanently alter human lives.
  • Global Context: The "Annex III" list forming the core of AI laws.
  • Turkish Law: An umbrella definition for sectoral regulations (Ministry of Health, BRSA).

Article 22: Algorithmic Impact Assessment

Providers deploying a high-risk AI system must prepare and submit to the Authority an "AI Impact Assessment Report" analyzing the system's effects on fundamental rights, employment, and the environment.
  • Rationale: Eliminating risks proactively rather than selling the product and denying responsibility.
  • Global Context: Canada's Algorithmic Impact Assessment (AIA) model.
  • Turkish Law: EIA (Environmental Impact Assessment) logic from the Environmental Law.

Article 23: Data Quality and Bias Testing

Datasets used to train high-risk systems must be appropriate to Turkey's demographic realities and cultural structure, and must be free of erroneous/missing data to prevent discrimination. Data quality must be documented.
  • Rationale: "Garbage in, garbage out" rule. AI trained on corrupt data makes corrupt decisions.
  • Global Context: Data governance and model training transparency standards.
  • Turkish Law: Compliance with Human Rights and Equality Institution of Turkey (TİHEK) standards.

Article 24: Human Oversight and the Kill-Switch

High-risk AI systems must be designed with a hardware or software "Manual Kill-Switch" mechanism that allows them to be understood by a human at any moment and instantly intervened upon or disabled.
  • Rationale: The hardware capability to stop an autonomous system from spiraling out of control (emergent behavior) and causing a disaster.
  • Global Context: Asimov's Laws of Robotics and modern "Stop-Button" regulations.
  • Turkish Law: The emergency stop button logic found in Occupational Health and Safety machinery regulations.

Article 25: Logging and Record-Keeping Obligation

High-risk systems must maintain a cryptographically immutable "event log" of critical decisions made, errors occurred, and human interventions made throughout their lifecycle.
  • Rationale: Preventing the "Black Box" excuse from being presented to the court when a lawsuit is filed over an AI error; creating digital evidence.
  • Global Context: EU AI Act Article 12 (Record-keeping).
  • Turkish Law: Logging (digital footprint) obligation under Law No. 5651.

Article 26: Limited Risk: Transparency in Generative AI

Systems that generate text, audio, images, or video (ChatGPT, Midjourney, etc.) are obligated to clearly inform the user: "This content was generated by artificial intelligence."

Article 27: Deepfake and Watermark Mandate

All Generative AI platforms operating in Turkey must embed an indelible digital watermark into the pixel or frequency depths (metadata) of the visual and audio media they produce.
  • Rationale: Ensuring immediate detection of fake evidence or perception operations during elections or criminal cases. This is a direct national security issue.
  • Global Context: US White House Executive Order on AI watermarking recommendations.
  • Turkish Law: Infrastructure to detect crimes of Forgery and Disinformation under the Penal Code.

Article 28: Identity Disclosure in Chatbots

Companion AIs used for customer service, therapy, psychological support, or friendship must periodically state, "I am not a human, I am an artificial software" at the beginning and during the communication.
  • Rationale: Preventing dangerous "emotional bonds" (parasocial interaction) and perceptual illusions, especially in children and lonely adults.

Article 29: TR-AI Conformity Mark (CE Equivalent)

High-risk AI systems must obtain a "TR-AI Safety Mark" before being placed on the market, proving they meet the safety, transparency, and ethical requirements of this act. Systems without this mark cannot be sold or used.

Article 30: Post-Market Surveillance

Because AI systems continuously change via machine learning, they are periodically audited by the Authority while in use in the field even after receiving approval. Systems exhibiting model drift are recalled from the market.
PART FOUR: Governance - Turkey Artificial Intelligence Authority (Articles 31-40)

Article 31: Establishment of Turkey Artificial Intelligence Authority (TAIA)

To ensure the implementation of this act, conduct audits, and execute the national AI strategy, the Turkey Artificial Intelligence Authority (TAIA) is established with administrative and financial autonomy.
  • Rationale: AI violations in health, finance, or agriculture cannot be handled by a single existing institution. A horizontal and independent supreme authority is essential for a horizontal technology.
  • Global Context: UK AI Safety Institute and EU AI Office.

Article 32: TAIA Staff Structure and Merit

Authority personnel cannot consist solely of jurists and bureaucrats. At least fifty percent of the staff must be data scientists, algorithm engineers, sociologists, and ethical philosophers.
  • Rationale: It is physically impossible for a bureaucracy that does not understand technology to audit codes and algorithmic weights. The authority's speed and intelligence must match Big Tech.

Article 33: Digital Forensics Authority (Black Box Review)

TAIA is authorized to examine the source codes and training datasets of tech companies' secret algorithms in a laboratory environment via a court order in case of a complaint or severe violation suspicion.

Article 34: Open Source Incentive

The Authority allocates special funds to support academic institutions and startups in Turkey to develop "Open Source" AI models. Open-source systems are exempted from certain administrative audits as they inherently provide transparency.

Article 35: Coordination with Sectoral Regulators

The audit of a medical AI system is conducted by joint commissions of TAIA and the Ministry of Health; financial AI audits with the BRSA. TAIA sets umbrella rules, while sectoral institutions conduct vertical audits.

Article 36: Independent Algorithm Audit Firms Sector

TAIA licenses "Authorized Private Algorithm Audit Firms" to test AI systems on the market. Similar to Certified Public Accountants, these firms conduct independent ethical and security audits on AI systems.
  • Rationale: The state cannot examine every software alone. A brand new "Algorithm Auditing" employment sector must be created in the private sector.

Article 37-40: Global Collaboration, Literacy, Whistleblowers, and Annual Reports

TAIA is authorized to sign intelligence-sharing agreements with international AI authorities. It conducts "Algorithm Literacy" campaigns for the public. Whistleblowing engineers reporting dangerous AI models are legally protected from termination. TAIA submits an annual "State of AI Report" to the Parliament with mathematical data on employment and economic impact.
PART FIVE: Employment, Quotas, and Working Life (Articles 41-50)

Article 41: Sectoral "Human-in-the-Loop" Quota

In labor-intensive service sectors such as call centers, banking, and retail, delegating 100% of customer transactions end-to-end to AI bots is banned. Enterprises must employ human support staff to manage at least 25% of the transaction volume.
  • Rationale: Preventing companies from plunging the country into a massive unemployment crisis out of cost-cutting greed; offering consumers the right to "connect to a real human."

Article 42: Decision-Maker Assistant Doctrine

In decisions directly affecting human health, liberty, or careers (Medical diagnosis, judicial rulings, recruitment), AI can never be the ultimate "Decision Maker"; it can only be used as an "Assistant." The signature and final approval must absolutely belong to a human.

Article 43: AI Automation Tax

If an enterprise replaces human labor (e.g., 10 people) with licensed AI software on a single computer, resulting in a net employment contraction, it is liable to pay an "Automation Tax" at a rate of 15% of the savings derived from labor costs (social security/salary).
  • Rationale: Preventing companies from transferring the burden of unemployed masses onto the state's (society's) shoulders while profiting. Regulating this wealth transfer.

Article 44: Universal Reskilling Fund

Revenues from the Automation Tax (Article 43) are transferred directly to a "Reskilling Fund" rather than the Treasury. This fund is used SOLELY to finance next-generation tech education (data analysts, drone pilots, etc.) for individuals who lose their jobs to AI.

Article 45: Employment Impact Assessment Report (EIAR)

Large enterprises with over 250 employees must submit an EIAR to the state and the company union at least 6 months before transitioning to massive AI automation. The report must explain how many people will be displaced and the plan for shifting these personnel to other internal departments (rotation).

Article 46: Human-AI Synergy Corporate Tax Deduction

If an enterprise integrates AI but does not reduce total employment—instead maintaining or increasing it by creating new departments with AI productivity—it receives a "Synergy Corporate Tax Deduction" (5%).

Article 47: Ban on Algorithmic Performance Profiling (Workplace Tyranny)

Systems that measure employees' bathroom breaks, screen viewing times, and keystroke speeds second by second to generate a "Productivity Score" via AI, forcing the employee to compete at superhuman machine speed, are banned in workplaces.

Article 48: Algorithmic Management and Union Transparency

The core logic of AI algorithms determining wages, shifts, and penalties for couriers and drivers on Gig economy platforms must be transparent and disclosed to their labor unions.

Article 49: Algorithmic Interview Limits in HR

It is strictly forbidden to eliminate candidates in video interviews using AI by analyzing biometric data such as voice tone, pupil movement, or sweating to label them "lying" or "incompatible." CV screening bots may only consider objective criteria (years of experience, education).

Article 50: AI and the Right to Disconnect

The 24/7 operation of AI assistants does not mean 24/7 responses can be expected from human employees. The "Right to Disconnect"—allowing human employees to turn off AI notifications and emails outside of working hours—is guaranteed by law.
PART SIX: Data Sovereignty, Privacy, and Security (Articles 51-60)

Article 51: Local LLM Mandate for Critical Infrastructure

AI assistants integrated into the state's critical infrastructures like defense, health, justice (UYAP), and energy grids must be "Local" AI models whose servers are physically located within Turkish borders and whose source codes are open to the state. Foreign cloud APIs cannot be integrated here.

Article 52-55: Synthetic Data, Data Localization, Cloud Audit, and Machine Unlearning

Public health/finance data used for training AI must be converted to "Synthetic Data." Bulk transfer of Turkish users' behavioral data abroad by global tech giants requires TAIA permission and a data tax. Citizens have the right to demand "Machine Unlearning" under KVKK if their data was scraped without consent, forcing companies to retrain models if necessary.

Article 56-60: Cybersecurity and Data Poisoning

External "Data Poisoning" attacks on AI models are classified as "Hacking and Disrupting Information Systems" under the Penal Code. AI providers must secure their APIs at military standards.
PART SEVEN: Copyrights, Intellectual Property, and Media (Articles 61-70)

Article 61: Training Data Copyrights and "Opt-Out" Mechanism

Unauthorized training of AI on copyrighted works is considered temporary copying under "Machine reading." However, creators have the absolute right to forbid this by adding a simple "Opt-Out" code to their sites. Scraping data bypassing opt-outs constitutes copyright infringement.

Article 62-70: Dataset Transparency, Public Domain Output, Adapted Work, and Link Tax

Generative AI companies must publish Training Data Transparency Reports. Pure AI-generated outputs (prompt-only) are immediate "Public Domain" and cannot be copyrighted. However, substantial human editorial manipulation of AI drafts earns "Adapted Work" copyright. Scraping breaking news via LLMs triggers a mandatory "Link Tax" payable to publishers. Voice cloning without consent is aggravated fraud.
PART EIGHT: Legal Liability, Compensation, and Consumers (Articles 71-80)

Article 71: "Strict Liability" for High-Risk AI

If a high-risk AI (e.g., surgical robot) harms a human, the deploying company cannot escape liability by claiming the AI learned independently (black box). The company is strictly liable to pay damages regardless of direct fault.

Article 72-80: Burden of Proof, Mandatory Insurance, Algorithmic Pricing, and Joint Liability

The "Burden of Proof" shifts from the victim to the AI company. Commercial deployers of high-risk AI must hold "Mandatory AI Liability Insurance." AI-driven discriminatory "Dynamic Pricing" based on consumer vulnerability is banned. Start-ups fine-tuning open-source models hold Joint and Several Liability with the original developer for major errors.
PART NINE: Education, Neuro-Rights, and Protection of Democracy (Articles 81-90)

Article 81: Neuro-Rights (Cognitive Liberty and Mental Privacy)

All AI systems tracking, reading, and manipulating citizens' brainwaves, thoughts, and neurological reactions via wearables or Brain-Computer Interfaces (BCI) for commercial purposes are banned. "Mental Privacy" is a Constitutional immunity zone.

Article 82-90: Child Protection, Educational Limits, Election Security, and Bot Transparency

Companion AI for under-18s requires parental consent and Age Verification. Screen time with AI tutors in schools is capped to preserve socialization. Spreading political "Deepfakes" 90 days before elections is punished as "Usurpation of Democratic Will." Social media bots must be labeled with a "🤖 BOT" icon.
PART TEN: Sandbox, Sanctions, and Enforcement (Articles 91-100)

Article 91: Establishing a Regulatory Sandbox

TAIA provides a closed "Sandbox" where local start-ups and universities can safely test new AI models before market release. Entrepreneurs conducting R&D here are exempt from heavy legal liabilities, bureaucracy, and fines during the testing period.
  • Rationale: Preventing the suffocation of innovation and bright minds through fear of penalties.

Article 92: Proportional Administrative Fines (Asymmetric Sanctions)

Fines up to 2% (or 100M TL) of global annual turnover for transparency violations; up to 4% (or 500M TL) for High-Risk rule violations; and up to 7% (or 1 Billion TL) for Banned System violations.
  • Rationale: Fixed fines are pocket change for Big Tech. Sanctions must be percentage-based to bite.

Article 93: Asymmetric Discounts for SMEs and Start-Ups

The severe fines in Art. 92 are applied with a 90% discount to local SMEs, newly established start-ups, and academic centers; or only a "Warning/Correction" is issued for the first violation.

Article 94: Personal Criminal Liability of Executives (Imprisonment)

Alongside corporate liability, CEOs, board members, and Chief Data Officers (CDO) who directly approve the development of AI models that knowingly endanger human health, deliberately discriminate, or manipulate elections (deepfake) face direct personal imprisonment under the Penal Code.

Article 95-100: Recall, Blocking, Grace Period, and Enforcement

Dangerous AI is subject to immediate market Recall and Cloud API blocking under Law No. 5651. A 24-month Grace Period is granted for High-Risk AI currently on the market. Technical regulations will be issued by TAIA within 6 months. The Act enters into force 1 year after its publication in the Official Gazette.