In the first two parts of this comprehensive report series designed to understand and manage the Artificial Intelligence (AI) revolution, we focused primarily on its socio-economic dimensions. In the first part, we examined the extent to which automation could create unemployment across various sectors and the quota measures necessary to protect human employment. In the second part, moving away from doomsday scenarios, we explored how AI will create millions of fresh employment opportunities based on brand new skills, in what it calls the "New Collar" era.

However, it is not enough for a state to approach technology merely within an economic context. Behind the scenes lies the "legal infrastructure" that will manage all these socio-economic tremors and keep the system standing. AI systems are not just fragments of code; they are autonomous actors that make decisions, produce content, diagnose illnesses, create artworks, and sometimes "make mistakes." If a medical AI makes a misdiagnosis, who does the patient sue? If a generative AI writes a new book by copying the stylistic essence of a world-renowned author, who owns the copyright? Can the health, financial, and educational data of citizens of the Republic of Turkey be used to train US-based AI servers?

This third and most comprehensive section you are reading sheds light on the legal, ethical, and national security dimensions of a prospective AI Act that Turkey should draft. This section is designed as an in-depth reference source for policymakers, legal professionals, data scientists, and anyone interested in the social impacts of technology.

1. The Black Box Problem and Algorithmic Transparency

One of the most fundamental principles of law is the obligation of justification. Whether it is a court ruling, a bank's loan rejection, or a job application denial; in civil life, the citizen has the right to know "why" a decision was made. However, modern AI systems operating with deep learning and neural networks function with a "Black Box" logic, which even their creators—the engineers—cannot fully decode.

1.1 Explainability of Decisions (Explainable AI - XAI)

Millions of data points enter an AI system (input), and the system produces a result (output). Yet, we cannot know exactly which weights were used among billions of parameters internally, or which data point was preferred over another while reaching that result. The first major crisis a prospective Turkish AI Act must solve lies here.

Imagine a citizen applying for a loan, and the bank's AI algorithm rejects this application in seconds. When the citizen asks the customer representative, "Why was I rejected?", they cannot receive the answer: "The system deemed it appropriate; we don't know how the algorithm works either." The law must offer citizens the "Right to Request an Explanation." The European Union's AI Act has strictly regulated this issue under the "High-Risk Systems" category.

Legislative Proposal: The "Algorithmic Justification" Mandate AI systems used in sectors that directly impact people's lives, freedom, economic status, or reputation (e.g., recruitment, credit allocation, judicial proceedings, insurance premium calculation) must absolutely be built on an "Explainable AI" (XAI) architecture. The system must be legally obligated to report the primary 3 variables its decision is based upon in plain language that an average citizen can understand. The use of systems with a "black box" architecture in these critical sectors must be banned.

1.2 Algorithmic Bias and Systematic Discrimination

AI is not an autonomous entity originating from a vacuum; it is created by humans and trained on historical data produced by humans. If an AI is trained on a dataset where the majority of engineers hired in the past were male, the system develops a fatal bias that "a good engineer is male" and automatically begins filtering out the resumes of female candidates. Amazon's defunct AI recruiting bot did exactly this.

In the context of Turkey, this situation could touch upon even more critical sociological fault lines. If algorithms filter out candidates based on birthplace, the high school they graduated from, or their district of residence (postal code), this constitutes a violation of the Constitution's principle of equality via technology. The Act must mandate the establishment of independent Algorithm Audit Firms to conduct Equality Audits and require these algorithms to pass a "Discrimination Test" annually.

2. Legal Liability and Tort Law: "If the Robot Makes a Mistake, Who Pays?"

The classical Turkish Code of Obligations (TBK) and Criminal Law system are based on the principle of fault (negligence). When damage occurs, a "human" will at fault is sought. However, the AI revolution shakes this concept of human will to its core. If a fully autonomous vehicle hits a pedestrian, or if an AI-assisted surgical robot severs the wrong nerve, who is liable?

  • The Software Developer? The developer might argue, "I just wrote the code; the system learned on its own (machine learning) and made this decision."
  • The Manufacturing Company? The company might claim, "Our hardware was flawless; the user fed incorrect data into the system."
  • The User (Doctor/Driver)? The user might state, "The system was autonomous; I had no chance to intervene."

This "liability gap" is one of the biggest obstacles to the widespread adoption of technology. Because where there is no legal certainty, insurance companies cannot produce policies, and where there is no insurance, investors do not take risks.

2.1 Strict Liability and "Mandatory AI Insurance"

The Turkish AI Act should adopt the principle of "Strict Liability" (Liability for Danger) for damages caused by autonomous systems. Just as with the liability of vehicle operators in the Highway Traffic Act or hazardous facility operators in the Environmental Law, a company (operator) that releases an AI system into the market for commercial purposes and profits from it must be held liable (even if they are not at fault) for damages arising from the decisions the system makes through self-learning.

Legislative Proposal: Mandatory AI Financial Liability Insurance Developers releasing, or institutions using, systems with the potential to cause physical or massive financial harm—such as autonomous driving systems, medical AIs, and financial decision algorithms—should not be allowed to operate in the Turkish market without securing "Mandatory AI Financial Liability Insurance" (similar to compulsory traffic insurance). In the event of damage, the victim should not have to deal with lengthy court battles; the compensation should be paid directly from this insurance fund. The insurance company should later determine whether the fault originated from the hardware, software, or the user, and seek recourse from the relevant party.

2.2 Legal Personality and "Electronic Personhood" Debates

The European Parliament previously debated granting a special "Electronic Personhood" status to highly advanced autonomous robots but has currently shelved the idea. In a prospective Turkish law, granting AI legal personality (the capacity to have rights and obligations) is premature and dangerous for now. AI should not be established as a "person," but rather as an advanced "tool/product" under the legal responsibility of its owner or operator.

3. Generative AI and the Copyright Crisis

Generative AI models like ChatGPT, Midjourney, DALL-E, and Claude do not materialize out of thin air. The only reason these models are "smart" is that they use billions of articles, tables, codes, books, photos, and videos found on the internet by "web scraping" them as training data. And a vast majority of this data consists of human-made products protected by copyright.

The massive copyright lawsuit filed by The New York Times against OpenAI, or the lawsuits by Getty Images against Stability AI, are the first global reflections of this crisis. Turkey's Law on Intellectual and Artistic Works (FSEK) was written in 1951, an era when AI couldn't even be fully imagined in sci-fi movies. Adapting this law to today's realities is imperative.

3.1 Violation Regarding Training Data (Input) and "Fair Use"

Can an AI company (whether a global giant or a local Turkish startup) scrape the novels of Yaşar Kemal, the lyrics of Sezen Aksu, or the poems of Sabahattin Ali without permission to train its model? Tech companies argue that this is akin to "reading and learning," just like a human reading thousands of books to write their own, and should be considered under "Fair Use." Creators, however, claim this is blatant "unauthorized reproduction and commercial exploitation" (theft).

3.2 Who Owns the Copyright of the Generated Output?

According to Turkish Copyright Law (FSEK), the copyright of a work belongs to the "human" who created it. But if a citizen writes a highly detailed, multi-page prompt into Midjourney (e.g., "Hot air balloons flying over Cappadocia at sunrise, in the style of Van Gogh's Starry Night, in 4K resolution, with cinematic lighting") and generates an image, who owns the copyright of this image?

  • Is it the citizen's? (Because they wrote the prompt and conceptualized the idea).
  • Is it the AI company's? (Because the algorithm applied the brushstrokes).
  • Is it the original painters' who trained the AI?
  • Or is this work a copyright-free product that has entered the "public domain"?
FSEK Adaptation: Proposed Matrix for AI Copyrights Under the New Act
Copyright Issue (Scenario) Current Status / Uncertainty AI Act Proposed Solution
Data Scraping for Training Pulling data without permission can be considered a violation under FSEK. However, banning it would kill domestic AI development. "Opt-out" Mechanism: AI training should be considered legal, but content creators must be granted the right to add a machine-readable code to their sites declaring "do not use my work for AI training" (Opt-out).
AI Generated Output According to FSEK Article 1, a work is a product "bearing the characteristics of its owner." A machine cannot be an author. Public Domain Principle: Works generated solely by AI should not be copyrighted. However, if a human expends significant manipulation and effort on the AI output, it should be considered an "adapted work," and copyright should be granted to the human.
Deepfake Audio/Video Violation of personal rights, but tracking and penalizing mechanisms are slow when done via anonymous accounts. Mandatory Digital Watermark: AI tools must be obligated to embed indelible cryptographic watermarks into the images/audio/video they generate. Platforms hosting non-watermarked AI content must face heavy sanctions.

4. Data Sovereignty, Privacy, and National Security

The "oil" of AI models is data. Today in Turkey, millions of citizens, private companies, and public institutions are uploading massive amounts of data to US-based models like ChatGPT, Claude, and Google Gemini to facilitate their work. This data can range from correspondence, trade secrets, and draft patents to financial statements, personal health records, and even critical code snippets of the state's infrastructure.

4.1 Cloud Computing and Cross-Border Data Transfer

Turkey's Personal Data Protection Law (KVKK) subjects the transfer of data abroad to rather strict conditions (or explicit consent). However, the speed of daily AI assistant usage has surpassed the speed of the law. This data sent to overseas servers (the cloud) is used to further train those models. In other words, Turkey's intellectual accumulation and critical data are flowing abroad for free to enrich the "closed algorithms" owned by foreign corporations.

"In the world of the future, sovereignty will not be measured by possessing a piece of land, but by owning your citizens' data and ruling over the algorithms that process that data."

4.2 Mandatory Use of Domestic Models in Critical Infrastructure

The concept of "Data Sovereignty" must lie at the heart of the national security concept of a prospective Turkish AI Act. Defense industries, energy grid management, telecommunications, core financial systems, and health databases must be defined as "Critical Infrastructure."

Legislative Proposal: The "Domestic LLM" Mandate for Strategic Sectors AI assistants to be used in the databases of the Republic of Turkey's Ministry of Health, the Ministry of Justice's UYAP system, or e-Government integrations must be "Domestic or Localized" AI models (e.g., models trained for Turkish, running "On-Premise") whose servers are physically located within Turkey's borders and whose source codes can be audited by the state. APIs of foreign companies (cloud-based foreign AIs) cannot be integrated into these critical systems.

5. Global Competition, Risk Classification, and the Brussels Effect

Turkey is a country that conducts half of its foreign trade with the European Union (EU). The European Union has adopted the world's first comprehensive Artificial Intelligence Act (EU AI Act) and is in the process of implementing it. The phenomenon known as the "Brussels Effect" is the EU using the massive size of its internal market to impose its regulations on the rest of the world as a "de facto" global standard (just as it did with GDPR).

If Turkey wants to continue exporting software, autonomous vehicle parts, e-commerce services, or AI-supported industrial products to Europe, it must make its own law "harmonized" with EU norms. Otherwise, an AI product manufactured in Turkey that has not passed safety tests by EU standards will not be allowed through customs or digital borders.

5.1 The Heart of the EU Model: The Risk-Based Approach

Turkey's law should not evaluate AI systems in a "single basket" but should categorize them according to risk levels, just as the EU has done. The rules governing a spam email filter cannot be the same as the rules governing a driverless car or a judicial decision support system.

Global Comparison (EU, US, China, TR Projection) of AI Regulatory Strictness
European Union (EU AI Act)
90% - Strict, Human-Centric, Risk-Based
People's Republic of China
75% - State Control, Political Security Focus
United States of America
40% - Loose, Innovation & Corporate Focus
Turkey (Proposed Balance)
65% - EU Harmonized but Innovation-Friendly Balance

Chart: A visionary comparison of the strictness (audit and penalty) ratios countries adopt in their AI regulations. Turkey must not be as strict as the EU to avoid scaring away entrepreneurs, yet it must not abandon everything to wild capitalism like the US.

5.2 The Proposed Four-Tier Risk Pyramid

In the Act, AI systems should be divided into the following four categories:

  1. Unacceptable Risk (Banned Systems): Systems that manipulate people's subconscious to cause them harm, or systems like "Social Scoring" applied in China that constantly monitor, score, and profile citizens, as well as real-time biometric facial recognition systems in public spaces, must be unconditionally banned in Turkey.
  2. High Risk (Strict Audit): AI used in transport, education, critical infrastructure, law enforcement, recruitment algorithms, and medicine. These systems must be registered with the state before hitting the market and must pass rigorous safety, accuracy, transparency, and human oversight tests.
  3. Limited Risk (Transparency Obligation): Chatbots, customer service bots, or deepfake/generative AI software. The only obligation for this category is "Transparency." Meaning, the system must clearly warn the interacting human: "You are currently speaking with an AI, not a human," or "This image was generated by AI."
  4. Minimal/Zero Risk (Free Market): AIs in video games, spam filters, simple inventory management bots. They should be freely developed and used without being subject to any extra regulation.

6. Conclusion: While Turkey's Window of Opportunity is Open

Drafting AI laws does not merely mean finding solutions to current problems (unemployment, copyright, liability); it also means determining where the country will stand in the global digital economy for the next 50 years. If you enact an overly strict and prohibitive law, you will lose your start-ups, brilliant engineers, and international investments to Silicon Valley or other innovation hubs. If you set no rules and say "let the market handle it," you leave your citizens' data, personal rights, and your country's national security to the mercy of a handful of global tech giants.

Turkey has the opportunity to adopt the concept of "Human Rights and Ethics-Centric Innovation." A draft law is essential—one that strengthens the KVKK infrastructure, balances copyright laws at an optimal point (with an "Opt-Out" logic) that neither crushes the content creator nor halts technological progress, mandates an "Explainable AI" (XAI) architecture, and secures legal liability on the axis of strict liability and "mandatory insurance."

When combined with the sectoral quotas and new employment fields mentioned in the previous sections of our report, a properly structured Turkish AI Act will transform the country from merely being a technology consumer into a shining star in the global arena as a fair, transparent, secure, and productive technology ecosystem. We cannot stop technology, but we can train, audit, and steer it to serve human dignity and our national interests. The issue is not how smart the machine is, but how visionary the lawmaker is.