The EU Artificial Intelligence Act: A New Compliance Landscape for Companies

Artificial intelligence systems are increasingly being used across a broad range of corporate activities, including recruitment, customer services, credit assessments, content generation and operational decision-making. While this transformation offers significant opportunities for efficiency and scalability, it also gives rise to new legal risks relating to discrimination, transparency, data protection, product safety and fundamental rights. In response, the European Union (the “EU”) adopted Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (the “AI Act” or the “Regulation”) with a view to addressing these risks within a uniform regulatory framework.

Under the AI Act, artificial intelligence systems are classified not solely by reference to their technical features, but also by considering their intended purpose, the context in which they are used and the consequences they may produce. Accordingly, the scope and intensity of the applicable obligations increase in line with the level of risk generated by the relevant system.

I. Scope of Application and Implications for Companies in Türkiye

The territorial scope of the AI Act is not limited to companies established in the EU. Providers established outside the EU may fall within the scope of the Regulation where they place an AI system or a general-purpose AI model on the EU market. The Regulation may also apply to providers and deployers located outside the EU where the output produced by an AI system is used within the EU. Importers, distributors, product manufacturers and organisations deploying AI systems in their own operations are also subject to differentiated obligations depending on their respective roles in the AI value chain.

The extraterritorial reach of the Regulation is therefore particularly relevant for companies operating in Türkiye. Companies with customers or group companies in the EU, companies supplying software or AI-enabled products to the EU market, and companies using AI systems in relation to employees or consumers located in the EU should not assume that they fall outside the scope of the AI Act solely because they are not established in the EU. The assessment should be conducted by reference to the company’s role in the AI value chain, the intended purpose of the system, the location in which its output is used and the market in which the relevant product or service is offered.

II. The Risk-Based Regulatory Framework

The AI Act establishes a four-tier risk-based framework. In determining the applicable legal regime, the decisive factors are not merely the technical sophistication of an AI system, but its intended purpose, the sector in which it is deployed and its potential impact on individuals.

A. Prohibited AI Practices

The principal prohibited practices include manipulative applications that materially impair an individual’s ability to make an informed decision, the harmful exploitation of vulnerabilities, certain forms of social scoring, individual criminal risk assessments based solely on profiling or personality traits, and the untargeted scraping of images from the internet or CCTV footage for the purpose of creating or expanding facial recognition databases. The use of emotion-recognition systems in workplaces and educational institutions, as well as certain biometric categorisation practices designed to infer sensitive characteristics, is also prohibited as a general rule. The use of real-time remote biometric identification systems for law-enforcement purposes is permitted only within narrowly defined exceptions and subject to strict conditions.

The provisions governing prohibited AI practices have applied since 2 February 2025. These rules should therefore not be treated as a future compliance requirement; rather, they constitute a current area of compliance that should be reviewed without delay against companies’ existing AI inventories.

B. High-Risk AI Systems

An AI system may qualify as high-risk in two principal circumstances. First, the system may constitute a safety component of a product governed by specified EU product-safety legislation, or may itself constitute such a product. Second, the system may be intended for use in one of the sensitive areas listed in Annex III to the AI Act.

Certain AI systems used in the safety of critical infrastructure, education and vocational training, recruitment and workforce management, access to essential public or private services, creditworthiness assessments of natural persons, risk assessment and pricing in life and health insurance, biometric applications, law enforcement, migration and border management, and the administration of justice may fall within this category. Accordingly, a system used to filter job applicants or assess employee performance does not become low-risk merely because it is described as human-resources software.

Providers of high-risk AI systems are subject to requirements relating to risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness and cybersecurity. Before being placed on the market, the system may need to undergo a conformity assessment, bear the CE marking where required and be registered in the relevant EU database. Organisations deploying such systems are also required to follow the instructions for use, ensure effective human oversight, monitor the system’s operation and comply with applicable information and reporting obligations.

C. AI Systems Subject to Transparency Obligations

Even where an AI system is neither prohibited nor classified as high-risk, individuals may need to be provided with clear and intelligible information that an AI system is being used. Key examples include disclosing that a person is interacting with an AI-powered chatbot, marking artificially generated or manipulated content in a machine-readable and detectable format, and visibly labelling images, audio or video constituting a deepfake. Subject to the exceptions set out in the Regulation, disclosure obligations may also arise in relation to AI-generated or manipulated text published for the purpose of informing the public on matters of public interest. These transparency requirements will apply from 2 August 2026.

D. Minimal or No-Risk AI Systems

A substantial proportion of AI systems, including spam filters and certain AI-enabled games, fall within the minimal or no-risk category, for which the AI Act does not impose additional mandatory requirements. Nevertheless, classification as low-risk under the AI Act does not exclude the application of other legal regimes, including the GDPR, consumer-protection rules, intellectual-property law, employment law and product-safety legislation.

III. Obligations Applicable to General-Purpose AI Models

General-purpose AI models capable of performing a broad range of tasks are subject to a separate set of obligations that complements the risk-classification framework. Providers may be required to prepare and maintain technical documentation, provide relevant information to downstream actors integrating the model into their own systems, adopt a policy to comply with EU copyright law and make publicly available a sufficiently detailed summary of the content used to train the model. Although certain exemptions are available for open-source models, these exemptions are not absolute.

Providers of general-purpose AI models presenting systemic risk are subject to additional obligations, including model evaluations, adversarial testing, the identification and mitigation of systemic risks, the reporting of serious incidents and the implementation of adequate cybersecurity measures. The rules applicable to general-purpose AI models have applied since 2 August 2025. Providers of models placed on the market before that date benefit from a transitional period until 2 August 2027.

IV. Phased Implementation Timeline

The AI Act applies on a phased basis, and its original implementation timeline has been amended in certain respects by the 2026 AI Omnibus. The provisions concerning prohibited practices and the definition of an AI system became applicable on 2 February 2025, while the governance rules and obligations relating to general-purpose AI models became applicable on 2 August 2025. A substantial part of the Regulation’s general provisions, together with the transparency obligations, will apply from 2 August 2026.

Following the AI Omnibus, the rules applicable to high-risk use cases listed in Annex III will apply from 2 December 2027, while the rules governing high-risk systems embedded in regulated physical products will apply from 2 August 2028. These extensions should not be regarded as a standstill period for businesses. The classification of AI systems, allocation of contractual responsibilities, and establishment of appropriate data, governance and documentation structures require a substantial preparatory process.

V. Sanctions for Non-Compliance

The AI Act provides for significant administrative fines depending on the nature and severity of the infringement. Infringements involving prohibited AI practices or certain data-related requirements may result in fines of up to EUR 35 million or 7% of the undertaking’s total worldwide annual turnover for the preceding financial year. Non-compliance with other obligations may result in fines of up to EUR 15 million or 3% of worldwide annual turnover, while the provision of incorrect, incomplete or misleading information to competent authorities may result in fines of up to EUR 7.5 million or 1% of worldwide annual turnover. The size of the undertaking, the nature of the infringement and the proportionality rules applicable to small and medium-sized enterprises are taken into account when determining the applicable fine.

The consequences of non-compliance are not limited to administrative fines. Depending on the nature of the infringement, additional legal and commercial consequences may include the withdrawal of the system from the market, suspension of its use, contractual liability, personal-data breaches and loss of confidence among customers, investors and business partners.

VI. Recommended Compliance Steps for Companies

As an initial step, companies should prepare a comprehensive inventory of the AI systems developed or used within their organisation, including tools procured from third-party providers. For each system, the intended purpose, categories of data processed, impact on decision-making processes, geographical scope and the company’s role as provider, deployer, importer or distributor should be identified.

Following the inventory exercise, companies should screen for prohibited use cases and conduct a preliminary risk classification for each system. Priority should be given to applications connected with human resources, credit, insurance, education, biometrics, critical infrastructure and public services. Agreements with AI-system suppliers should be reviewed in relation to access to technical documentation, audit and information rights, use of data, intellectual property, cybersecurity, incident notification, compliance with regulatory changes and allocation of liability between the parties.

AI governance should not be assigned exclusively to either technology or legal teams. Companies should establish a governance and approval framework that clearly allocates responsibilities among legal, compliance, information-security, data-protection, human-resources and relevant business functions. Meaningful human oversight should be maintained for high-impact decisions, and personnel should receive training proportionate to the nature of the systems used and their respective responsibilities.

Assessment

The AI Act is not intended to prohibit or broadly restrict the use of artificial intelligence. Rather, it establishes standards of trust, traceability and accountability for applications capable of producing significant effects. For companies in Türkiye, the relevant assessment should not be limited to whether the Regulation applies directly. Compliance expectations of EU-based customers, investors and business partners are also expected to extend to Turkish companies through contractual arrangements, supply-chain requirements and group policies.

Against this background, companies should structure their use of artificial intelligence around system inventories, risk classification, contractual governance and internal oversight before regulatory scrutiny or enforcement action arises. A proactive approach will be important to ensure that the associated legal and commercial risks are managed effectively.

Best Regards,

DT Law