How Is the Legal Liability of Startups Using Artificial Intelligence Determined in Turkey?

Artificial intelligence has rapidly become part of the ordinary business infrastructure of startups.

A startup may use artificial intelligence to:

  • answer customer questions;
  • evaluate job applicants;
  • recommend products;
  • determine prices;
  • analyse financial risk;
  • generate marketing materials;
  • write software code;
  • detect fraud;
  • analyse medical information;
  • automate customer support;
  • produce legal or financial reports;
  • personalise user experiences;
  • moderate content;
  • or make decisions affecting users.

Some startups merely use third-party artificial intelligence services. Others integrate an external AI model into their own software. More sophisticated startups develop and commercialise their own artificial intelligence systems.

These different business models create different legal risks.

One of the most important questions for founders is therefore:

Who is legally responsible if an artificial intelligence system makes a mistake and causes damage?

Can the startup argue:

“The AI made the decision, not us”?

Generally, that will not be an adequate legal defence.

Artificial intelligence does not automatically replace the legal responsibility of the company that develops, provides, configures, markets or uses the system.

Under Turkish law, liability may arise through several different legal regimes depending on the nature of the harm.

These may include:

  • contractual liability under the Turkish Code of Obligations;
  • tort liability;
  • consumer protection law;
  • product liability;
  • personal data protection law;
  • intellectual property law;
  • unfair competition law;
  • employment law;
  • sector-specific regulations;
  • administrative sanctions;
  • and, depending on the conduct, criminal law.

As of August 2026, Turkey does not have a comprehensive horizontal artificial intelligence statute in force equivalent to the European Union’s AI Act. Several AI-related legislative proposals remain before parliamentary commissions, including the 2024 Artificial Intelligence Bill and subsequent proposals addressing particular AI-related issues.

This does not mean that artificial intelligence operates in a legal vacuum.

Existing laws continue to apply.

For startups, the correct question is therefore not:

“Is there an AI law in Turkey?”

The better question is:

“Which existing legal obligation applies to this particular AI system, this particular decision and this particular damage?”

This article explains how the legal liability of startups using artificial intelligence in Turkey should be assessed and what founders can do to reduce the risk of AI-related disputes.

Artificial Intelligence Is Not a Separate Legal Person

The first principle is fundamental.

An AI system should not be treated as though it were an independent company, employee or natural person capable of absorbing liability on behalf of the startup.

Suppose a startup provides an AI-powered financial analysis service.

The system incorrectly classifies a customer’s data and generates a materially inaccurate report.

The startup cannot automatically escape responsibility by saying:

“The model produced the result autonomously.”

From a legal perspective, attention will usually turn to the human and corporate actors surrounding the system.

Depending on the facts, these may include:

  • the company that developed the AI;
  • the startup that integrated it;
  • the company that placed the AI-powered product on the market;
  • the professional who relied on its output;
  • the employer using the AI;
  • the data controller;
  • the importer;
  • or another party that controlled the relevant risk.

Therefore, the first stage of any AI liability analysis is to identify who performed which legal role.

The Startup’s Role Determines Its Risk

Not every startup using AI has the same legal exposure.

A useful distinction can be made between several roles.

AI Developer

The startup develops its own model or AI system.

It may control:

  • model architecture;
  • training;
  • datasets;
  • testing;
  • output rules;
  • safety mechanisms;
  • and updates.

Its potential responsibility is therefore relatively extensive.

AI Provider

The startup makes an AI system available to customers under its own product or brand.

Even if a third-party foundation model operates in the background, customers may contract directly with the startup.

AI Integrator

The startup integrates an existing AI API into its own application.

For example:

Customer → Turkish Startup → Third-Party AI API.

The startup may not have created the foundation model, but it determines:

  • how it is used;
  • which prompts are sent;
  • how outputs are presented;
  • whether outputs are verified;
  • and what representations are made to customers.

AI Deployer or Business User

The startup uses AI internally.

For example, it may use AI to:

  • shortlist job applicants;
  • determine creditworthiness;
  • detect fraud;
  • assess employee performance;
  • or prepare customer decisions.

AI Reseller or Distributor

The company may distribute a third-party AI system without materially developing it.

Each role can create a different allocation of contractual, regulatory and operational responsibility.

Contractual Liability Is One of the Most Important Risks

Many AI disputes will begin with an ordinary contract.

Suppose a startup sells an AI-powered SaaS system to a customer and promises that the software will:

  • classify invoices;
  • detect fraud;
  • produce accurate reports;
  • automate recruitment;
  • analyse contracts;
  • or forecast demand.

If the service is not performed in accordance with the agreement, ordinary contractual liability rules may apply.

Article 112 of the Turkish Code of Obligations provides that where an obligation is not performed at all or is not properly performed, the debtor must compensate the resulting damage unless it proves that no fault can be attributed to it.

Therefore, inserting AI into the service does not remove the startup’s contractual obligations.

The relevant questions may include:

  • What exactly did the startup promise?
  • How accurate was the system represented to be?
  • Was the AI described as autonomous or advisory?
  • Were limitations properly disclosed?
  • Did the startup undertake human review?
  • Was the system used for its agreed purpose?
  • Was the model adequately tested?
  • Was the customer warned about known limitations?

The wording of the SaaS agreement can become decisive.

“AI May Make Mistakes” Is Not a Complete Liability Waiver

Many AI applications contain disclaimers such as:

“Artificial intelligence may occasionally provide inaccurate information.”

Such wording may be useful as a transparency measure.

However, it does not automatically eliminate liability.

For example, suppose a company sells an expensive enterprise service specifically marketed as being capable of identifying legally binding compliance violations with 99.9% accuracy.

The company cannot necessarily avoid responsibility for systemic defects by placing a small disclaimer elsewhere stating:

“Outputs may be incorrect.”

Contractual expectations are evaluated as a whole.

Marketing materials, demonstrations, sales correspondence, service descriptions, warranties and technical specifications may all influence what the customer was reasonably entitled to expect.

Liability Clauses Must Be Drafted Within Turkish Law

AI startups should use properly drafted limitation-of-liability clauses, particularly in B2B agreements.

However, Turkish law imposes boundaries.

Article 115 of the Turkish Code of Obligations provides, among other things, that an advance agreement excluding liability for gross fault is absolutely invalid. Article 116 separately regulates liability for persons assisting in performance.

Accordingly, a clause stating:

“The startup shall never be responsible for any loss caused by the AI under any circumstances.”

should not be assumed to be fully enforceable.

The company should instead define risk more carefully, addressing matters such as:

  • indirect damages;
  • loss of profit;
  • liability caps;
  • customer misuse;
  • unsupported use cases;
  • third-party systems;
  • customer-provided data;
  • force majeure;
  • and mandatory liability that cannot legally be excluded.

Using a Third-Party AI Provider Does Not Automatically Eliminate Startup Liability

This is one of the most important practical points.

Suppose a Turkish startup integrates a foreign generative AI API into its application.

A customer pays the Turkish startup.

The customer has no direct commercial relationship with the foreign model provider.

If the AI service produces a defective result, the Turkish startup may still face claims from its customer under the contract between them.

The startup may later have contractual recourse against its model provider, depending on the upstream agreement.

But the customer may not be required to pursue the foreign AI company directly.

This creates two separate contractual layers:

Customer ↔ Startup

and

Startup ↔ AI Provider

The startup should therefore carefully review whether its upstream AI contract provides adequate:

  • warranties;
  • service commitments;
  • intellectual property protections;
  • security obligations;
  • data processing provisions;
  • indemnities;
  • and liability coverage.

Otherwise, the startup may promise far more to customers than it can recover from the underlying AI vendor.

Tort Liability May Apply Even Without a Contract

Not every person harmed by an AI system will have a contract with the startup.

Article 49 of the Turkish Code of Obligations establishes the general principle that a person who causes damage to another through a wrongful and culpable act must compensate that damage.

This can become relevant where an AI system causes harm to third parties.

Consider an AI-based system controlling an autonomous industrial process.

If negligent configuration, inadequate testing or failure to correct a known defect results in damage to another person, contractual rules may not be the only legal basis.

Potential tort questions may include:

  • Was the conduct unlawful?
  • Was there fault?
  • What damage occurred?
  • Is there causation between the conduct and damage?
  • Could the damage reasonably have been prevented?
  • Did the startup comply with applicable professional standards?
  • Were known risks ignored?

Artificial intelligence changes the technology involved, but it does not remove these fundamental liability concepts.

Negligent Design Can Create Liability

An AI startup may create risk long before the final harmful output is generated.

Potential negligence can arise during:

  • data collection;
  • model training;
  • testing;
  • validation;
  • deployment;
  • updates;
  • monitoring;
  • cybersecurity;
  • and incident response.

For example, a startup may discover during testing that its AI incorrectly rejects a significantly higher percentage of applicants from a particular group.

If the company knowingly deploys the system without investigating or mitigating the problem, that conduct may become relevant to later liability.

Likewise, if a model is known to hallucinate factual information but the startup presents its output as verified professional advice, the company’s product design and marketing choices become part of the legal analysis.

Failure to Monitor an AI System Can Also Matter

Artificial intelligence liability is not limited to initial development.

Models can behave differently after deployment because of:

  • changing input data;
  • model updates;
  • external API changes;
  • prompt modifications;
  • user behaviour;
  • new attack techniques;
  • data drift;
  • or modifications to connected systems.

A responsible AI governance system should therefore include post-deployment monitoring.

The company should be able to identify:

  • serious errors;
  • abnormal outputs;
  • bias patterns;
  • security incidents;
  • complaints;
  • and unexpected model behaviour.

Continuing to operate a system after serious defects become known can increase legal exposure.

Employer Liability May Be Relevant

AI systems are ultimately designed, configured and operated by people.

Article 66 of the Turkish Code of Obligations provides a specific liability framework for employers where employees cause damage while carrying out assigned work, subject to the statutory standard concerning selection, instruction, supervision and organisational precautions.

This is relevant where the harmful AI deployment results from actions of:

  • software developers;
  • data scientists;
  • product managers;
  • sales teams;
  • employees entering confidential information into AI tools;
  • or staff relying improperly on automated outputs.

Startups should therefore not view AI governance solely as an engineering responsibility.

Internal policies, employee training and supervision can affect legal risk.

Consumer Protection Law Can Apply to AI Services

An AI startup providing services directly to consumers may also be subject to Law No. 6502 on Consumer Protection.

This is particularly important where the startup sells:

  • AI subscription services;
  • mobile applications;
  • automated consultancy tools;
  • digital content;
  • consumer recommendation systems;
  • or other AI-powered services.

Article 13 defines a defective service to include a service that does not possess the characteristics agreed by the parties or objectively expected from it.

A service may also be defective where it does not possess qualities advertised by the provider or where deficiencies materially reduce the benefit a consumer can reasonably expect.

Article 14 requires the provider to perform the service in accordance with the contract, while Article 15 provides remedies including re-performance, repair where relevant, price reduction, termination and possible compensation under the Turkish Code of Obligations.

For an AI startup, marketing claims are therefore especially important.

Do Not Advertise AI as More Reliable Than It Is

Suppose an AI application is marketed as:

“100% accurate legal advice.”

or:

“Guaranteed medical diagnosis.”

or:

“Our AI never makes investment errors.”

Such statements can materially increase legal risk.

AI startups should avoid absolute claims unless they can genuinely substantiate them.

Marketing should distinguish between:

  • decision support;
  • recommendations;
  • predictions;
  • preliminary analysis;
  • and professional conclusions.

Where human professional review is required, that limitation should be stated clearly.

The product should also be technically designed consistently with the disclaimer.

A disclaimer is of little value if the interface encourages the user to treat the AI output as final and infallible.

High-Risk Sectors Require Greater Care

The potential standard of care is likely to increase where AI is used in areas capable of causing serious consequences.

Examples include:

  • healthcare;
  • finance;
  • insurance;
  • employment;
  • education;
  • legal services;
  • transportation;
  • security;
  • biometric identification;
  • and critical infrastructure.

Consider the difference between:

AI recommending a movie

and

AI deciding whether a person receives a loan.

An incorrect movie recommendation may cause almost no legal harm.

An incorrect lending decision may create:

  • financial loss;
  • discrimination concerns;
  • personal data issues;
  • consumer disputes;
  • and sector-specific regulatory consequences.

AI governance should therefore be risk-based.

Product Liability May Apply When AI Is Part of a Product

Artificial intelligence is increasingly embedded in physical products.

Examples include:

  • autonomous machinery;
  • medical devices;
  • robots;
  • smart home devices;
  • industrial equipment;
  • vehicles;
  • and connected consumer products.

Law No. 7223 on Product Safety and Technical Regulations requires products to be safe.

Article 6 provides that where a product causes damage to a person or property, the manufacturer or importer is required to compensate the damage, subject to the statutory conditions including proof of damage and causation between non-compliance and the damage.

Accordingly, where AI forms part of a physical product, startups should examine not only software contracts but also:

  • product safety rules;
  • applicable technical regulations;
  • conformity assessment;
  • instructions;
  • warnings;
  • traceability;
  • update procedures;
  • cybersecurity;
  • and recall obligations.

A defective AI component can create a product safety problem.

Who Is Responsible When a Startup Uses Someone Else’s Model?

There is no universal answer.

The allocation depends on why the harm occurred.

Consider an AI chatbot provided by Startup A but powered by Model Provider B.

A harmful output might result from:

  • defects in the foundation model;
  • Startup A’s system prompt;
  • Startup A’s fine-tuning;
  • incorrect customer data;
  • inadequate guardrails;
  • external manipulation;
  • failure to implement a provider update;
  • or the user’s deliberate misuse.

Responsibility must therefore be analysed causally.

The existence of several technology providers can also create recourse claims between them.

For this reason, AI supply agreements should define responsibilities clearly.

Personal Data Protection Is a Major Source of AI Liability

Artificial intelligence systems frequently process personal data at several stages.

Personal data may appear in:

  • training datasets;
  • fine-tuning datasets;
  • prompts;
  • uploaded documents;
  • model outputs;
  • logs;
  • user profiles;
  • feedback;
  • and analytics.

In 2025, the Turkish Personal Data Protection Authority published its Generative Artificial Intelligence and Protection of Personal Data Guide, specifically addressing personal data risks throughout the lifecycle of generative AI systems. The Authority emphasises human-centred, safe, transparent and accountable AI development and analyses generative AI processing through Law No. 6698.

This means that an AI startup should conduct a full KVKK analysis rather than assuming the AI provider is solely responsible for privacy compliance.

Training Data Must Have a Lawful Basis

One of the most difficult questions is:

Where did the AI training data come from?

Suppose a startup trains a model using millions of online profiles containing identifiable personal information.

The fact that information can technically be accessed online does not automatically mean it can be processed for any AI purpose.

The startup should examine:

  • whether the information is personal data;
  • whether it was lawfully collected;
  • the processing purpose;
  • applicable Article 5 or Article 6 processing grounds;
  • proportionality;
  • data minimisation;
  • retention;
  • and data-subject rights.

Special-category personal data create an even higher level of risk.

Prompts Can Contain Personal Data

Even a startup that does not train its own AI can create KVKK risk through user prompts.

For example, a business customer may upload:

  • employment contracts;
  • medical files;
  • litigation documents;
  • customer complaints;
  • CVs;
  • bank records;
  • or employee evaluations.

The startup must understand:

  • whether those prompts are stored;
  • who can access them;
  • whether they are used for model training;
  • where they are hosted;
  • how long they are retained;
  • and whether they are transferred abroad.

If a foreign AI provider receives the prompts, Article 9 international data transfer rules may also apply.

Employees Should Not Freely Upload Company Data Into Public AI Tools

Internal AI use creates another major risk.

Employees may paste into public AI systems:

  • source code;
  • customer information;
  • contracts;
  • trade secrets;
  • pricing strategies;
  • financial reports;
  • employee information;
  • or privileged legal correspondence.

This can create:

  • personal data breaches;
  • confidentiality breaches;
  • trade-secret loss;
  • intellectual property problems;
  • and contractual violations.

Every AI-using startup should therefore have an internal AI Usage Policy.

The policy should identify:

  • approved AI tools;
  • prohibited data;
  • confidential information rules;
  • personal data restrictions;
  • security requirements;
  • human review requirements;
  • and procedures for testing new AI products.

Automated Decision-Making Can Trigger Data Subject Rights

The KVKK gives individuals a specific right relevant to AI decision-making.

Article 11 allows a data subject to object where personal data are analysed exclusively through automated systems and this produces a result against that person. The Authority has expressly recognised this right in its guidance and decisions.

This is highly relevant to startups using automated systems for:

  • recruitment;
  • credit scoring;
  • insurance;
  • employee performance;
  • fraud detection;
  • or customer eligibility.

The startup should therefore understand whether:

  • the decision is genuinely automated;
  • meaningful human review exists;
  • the user can challenge the outcome;
  • and the system can explain the basis of the decision sufficiently for legal review.

Human Review Must Be Genuine

Simply adding a person somewhere in the workflow does not necessarily create meaningful human oversight.

For example:

AI rejects an applicant.

An employee automatically clicks “approve” without examining the file.

Calling this “human review” may be misleading.

Meaningful oversight generally requires that the reviewer:

  • understands the AI’s function;
  • has access to relevant information;
  • can challenge the result;
  • can override the system;
  • and has enough time and authority to make an independent decision.

This is good risk management even outside sectors where formal human-oversight rules apply.

Bias and Discrimination Can Create Liability

AI systems can reproduce or amplify biases contained in:

  • training data;
  • historical company practices;
  • proxy variables;
  • scoring rules;
  • or incomplete datasets.

For example, an employment algorithm may unintentionally penalise candidates because of variables correlated with protected characteristics.

A credit model may disproportionately reject applicants from a particular geographical area.

A platform should therefore test AI models for discriminatory effects, especially where the outputs materially affect individuals.

The statement:

“The algorithm treats everyone the same”

is not enough if the model’s real-world effects demonstrate otherwise.

AI and Intellectual Property Liability

Artificial intelligence can also create copyright, trademark and confidential information risks.

A startup may face questions such as:

  • Was copyrighted material used in training?
  • Does the output reproduce protected content?
  • Does AI-generated marketing contain another company’s trademark?
  • Did an employee upload copyrighted source code?
  • Can generated software safely be commercialised?
  • Did the AI reproduce confidential material from the input?

These questions should be analysed separately under applicable intellectual property rules.

For startups offering generative AI, it is particularly important to distinguish between:

  • ownership of the model;
  • ownership of inputs;
  • rights in outputs;
  • third-party materials;
  • and the customer’s contractual usage rights.

A general warranty that “all AI output is completely free of third-party rights” can create significant contractual exposure.

Confidentiality Can Be Lost Through AI Use

Consider a startup negotiating a major acquisition.

An employee uploads the confidential acquisition agreement into a public generative AI tool and asks:

“Summarise this contract.”

Even if no personal data are involved, this may create contractual confidentiality and trade-secret problems.

The company should therefore distinguish between:

  • consumer AI tools;
  • enterprise AI tools;
  • private model deployments;
  • and locally hosted systems.

The cheapest AI service may not be legally suitable for confidential corporate information.

Cybersecurity Is Part of AI Liability

AI systems can introduce new attack surfaces.

Examples include:

  • prompt injection;
  • model extraction;
  • data poisoning;
  • adversarial inputs;
  • malicious file uploads;
  • insecure plugins;
  • excessive agent permissions;
  • and unauthorised tool execution.

Agentic AI creates particular risk because an AI agent may have permission to:

  • send emails;
  • access databases;
  • execute transactions;
  • modify files;
  • purchase goods;
  • or initiate workflows.

The Turkish Personal Data Protection Authority has separately highlighted the privacy implications of agentic AI, noting that increasing autonomy and data-processing capacity create new personal data protection concerns throughout the system lifecycle.

Startups using AI agents should therefore apply a least-privilege approach.

An AI system should not receive unlimited access simply because greater access is technically convenient.

AI Startups Need Logging and Audit Trails

When something goes wrong, one of the first questions will be:

“Why did the AI produce this result?”

A company that keeps no records may struggle to answer.

Depending on the system, useful logs may include:

  • model version;
  • prompt;
  • relevant input;
  • output;
  • user actions;
  • human override;
  • system configuration;
  • safety filter activity;
  • and subsequent updates.

Logs must, of course, be designed consistently with personal data protection and retention obligations.

The objective is not unlimited surveillance.

The objective is sufficient traceability to investigate significant decisions and incidents.

Model Updates Can Change Liability

A third-party model can change without the startup changing its own application.

Suppose the startup has tested Model Version 3 extensively.

The external provider automatically upgrades the API to Version 4.

The new model behaves differently.

The startup should determine:

  • whether automatic updates can be disabled;
  • whether new versions are tested before production;
  • whether customers are informed of material changes;
  • whether risk assessments must be updated;
  • and whether the new model remains appropriate for the intended use.

“Continuous improvement” is not a substitute for change management.

Can the Startup Say the User Is Responsible for Checking Every AI Output?

A User Agreement may require customers to review AI-generated outputs before relying on them.

This can be particularly appropriate for generative AI services.

However, the effectiveness of such a clause depends on the product.

If the entire product is specifically marketed as an autonomous decision-making solution that requires no human review, it would be contradictory to argue after a failure that:

“Every customer was supposed to verify everything manually.”

The technical design, marketing and contract should tell the same story.

Medical AI Requires Particular Caution

A startup providing AI in healthcare should distinguish between:

  • administrative support;
  • wellness recommendations;
  • clinical decision support;
  • and actual diagnosis or treatment functions.

The more the system influences medical decisions, the more likely additional healthcare, medical device, professional liability and product safety rules will become relevant.

A disclaimer stating:

“This is not medical advice”

does not automatically resolve the issue if the product is in reality designed, marketed and used to make medical decisions.

The legal classification should be based on substance rather than branding.

AI Used in Recruitment Creates Employment Risks

Startups increasingly use AI to:

  • screen CVs;
  • rank candidates;
  • analyse interview recordings;
  • score personality;
  • or assess employee performance.

These systems can create risks relating to:

  • personal data;
  • automated decision rights;
  • discrimination;
  • employee privacy;
  • transparency;
  • and evidence.

Recruitment AI should therefore be tested for both technical accuracy and legal fairness.

The employer should also determine whether applicants need to be informed that AI is being used.

AI-Based Pricing Creates Separate Competition Risks

Artificial intelligence can also be used to determine prices dynamically.

This creates potential competition-law issues where algorithms:

  • coordinate prices;
  • incorporate competitor pricing;
  • use common third-party optimisation systems;
  • or facilitate anticompetitive information exchange.

AI does not make prohibited coordination lawful.

Competition authorities will generally examine the economic behaviour and relationship between businesses rather than treating the algorithm as an independent actor.

A pricing startup should therefore carry out separate competition-law review if its technology interacts with competitor information.

Who Bears Liability When the User Misuses the AI?

Users can also cause harm.

For example, a user may deliberately:

  • bypass safety controls;
  • enter false information;
  • generate illegal content;
  • use the system outside its documented purpose;
  • or combine it with another unsafe tool.

The startup may have contractual defences where the loss is caused by prohibited or unforeseeable misuse.

Terms of Use should therefore specify:

  • intended purpose;
  • prohibited uses;
  • technical limitations;
  • user responsibilities;
  • and circumstances permitting suspension.

However, foreseeable misuse should be considered during product design.

If a dangerous misuse is obvious and easy to prevent, simply prohibiting it in the contract may not always represent adequate risk control.

Startup Founders Should Distinguish “AI Error” From “Company Error”

When an AI failure occurs, the company should investigate where the actual failure happened.

Possible causes include:

  • defective training data;
  • incorrect labelling;
  • poor system design;
  • unsuitable model selection;
  • insufficient testing;
  • wrong customer input;
  • missing human oversight;
  • bad prompt engineering;
  • third-party API defect;
  • data breach;
  • unsupported use;
  • model drift;
  • or deliberate user misuse.

Legal responsibility should be assessed after this technical root-cause analysis.

This is why lawyers and engineers should work together in AI incidents.

What Is the Position in the European Union?

Turkish startups should also consider the EU Artificial Intelligence Act, Regulation (EU) 2024/1689.

The AI Act has important extraterritorial scope.

Article 2 provides that the Regulation applies, among other things, to providers established outside the EU that place AI systems or general-purpose AI models on the EU market. It also applies to providers and deployers located in third countries where the output produced by the AI system is used in the European Union.

Therefore, being incorporated in Istanbul does not necessarily place a startup outside the EU AI Act.

The EU AI Act Is Now Partly Applicable in 2026

The AI Act originally provided for general application from 2 August 2026, with certain provisions applying earlier.

Prohibited AI practices and AI literacy rules began applying from February 2025, while governance and general-purpose AI provisions began applying from August 2025.

However, an important 2026 amendment delayed major high-risk AI obligations.

Regulation (EU) 2026/1744 moved the application of the relevant Chapter III high-risk requirements to 2 December 2027 for Annex III high-risk systems and 2 August 2028 for high-risk systems connected to Annex I product legislation.

Accordingly, Turkish startups entering the EU market in 2026 should not rely on outdated summaries of the AI Act.

The exact provision and application date must be checked.

EU AI Act Risk Categories

The EU framework broadly distinguishes between different levels of risk.

Depending on the system, an AI application may fall into categories involving:

  • prohibited practices;
  • high-risk systems;
  • transparency obligations;
  • general-purpose AI requirements;
  • or lower-risk applications.

For Turkish startups, this classification can become relevant where the company:

  • sells AI software to EU customers;
  • provides AI recruitment systems;
  • develops credit-scoring systems;
  • provides biometric technology;
  • supplies AI incorporated into regulated products;
  • or places a general-purpose model on the EU market.

The compliance burden will differ significantly depending on classification.

AI Liability Is Not Determined Only by the AI Act

Even in the EU, complying with the AI Act does not automatically eliminate all civil liability.

A system may comply with AI regulatory requirements yet still create:

  • contractual liability;
  • consumer claims;
  • data protection violations;
  • intellectual property disputes;
  • or product liability.

Likewise, absence of a comprehensive Turkish AI Act does not mean that the startup has no legal responsibility.

Existing laws continue to regulate the surrounding conduct.

A Practical AI Liability Example

Consider the following scenario.

A Turkish startup develops an AI recruitment platform.

The platform automatically ranks applicants.

The startup sells it to employers and markets it as:

“A scientifically objective recruitment system eliminating human bias.”

Later, evidence shows that the algorithm systematically gives lower scores to candidates from a particular demographic group because historical training data reflected previous hiring patterns.

Potential legal questions could involve:

  • contractual representations made to customers;
  • data protection;
  • automated decision-making;
  • discrimination;
  • misleading advertising;
  • testing failures;
  • and potentially EU AI Act obligations if the system is placed on the EU market.

The answer to:

“Who is responsible?”

cannot be determined from the algorithm alone.

The entire product lifecycle must be examined.

Another Example: AI Customer Service Gives Incorrect Information

A consumer asks an AI chatbot:

“Can I cancel my subscription without a fee?”

The chatbot answers:

“Yes.”

The consumer cancels.

The startup later charges a penalty.

Can the company say:

“The chatbot was wrong, so the information does not bind us”?

The answer will depend on the contractual circumstances and consumer law.

If the chatbot is presented as the company’s official customer-service channel, inaccurate information given through that channel can create serious legal and consumer protection problems.

Companies should therefore define which questions AI agents may answer autonomously and which must be escalated to humans.

Another Example: AI Generates Defamatory Content

Suppose an AI platform generates false allegations about a real person.

Possible legal issues may include:

  • personality rights;
  • tort liability;
  • content removal;
  • evidence preservation;
  • and potentially platform-specific legal obligations.

The startup’s response after receiving notice may also matter.

A company that knows its system repeatedly generates harmful false statements but takes no corrective action may face greater risk than a company operating a responsible reporting and correction mechanism.

Another Example: AI Agent Executes a Transaction

An agentic AI system is authorised to:

  • select suppliers;
  • negotiate basic terms;
  • and place orders automatically.

The agent purchases goods worth TRY 1 million due to an incorrect configuration.

The company then argues:

“No employee approved the transaction.”

This raises difficult questions about:

  • contractual authority;
  • electronic declarations;
  • agency configuration;
  • internal approval procedures;
  • and counterparty expectations.

As AI systems become capable of acting rather than merely recommending, authority and approval architecture will become increasingly important.

Can Insurance Cover AI Liability?

Depending on the business, startups may consider insurance products such as:

  • technology errors and omissions insurance;
  • professional liability;
  • cyber insurance;
  • product liability insurance;
  • directors and officers insurance;
  • and sector-specific coverage.

However, policies must be reviewed carefully.

The fact that the company has “cyber insurance” does not mean every AI error is covered.

Exclusions may concern:

  • intentional violations;
  • intellectual property;
  • regulatory fines;
  • professional services;
  • contractual liabilities;
  • or particular AI activities.

Insurance should complement governance rather than replace it.

AI Vendor Due Diligence Is Essential

Before integrating an external AI model, startups should investigate the provider.

Relevant questions include:

  • Where is the provider located?
  • Where are prompts processed?
  • Are prompts retained?
  • Are prompts used for training?
  • Can training be disabled?
  • What subprocessors are used?
  • What security certifications exist?
  • What service-level commitments are provided?
  • What happens if the provider is unavailable?
  • Does the provider indemnify IP claims?
  • What liability cap applies?
  • Are model changes announced?
  • Can the startup export its data?
  • What happens on termination?

The startup should not choose an AI provider solely because the API is technically impressive.

AI Governance Should Begin Before Product Launch

A practical AI governance framework may include:

AI System Inventory

Identify every AI system used by the company.

Role Classification

Determine whether the startup is:

  • developer;
  • provider;
  • deployer;
  • processor;
  • controller;
  • distributor;
  • or another relevant actor.

Risk Classification

Identify whether the system affects:

  • employment;
  • finance;
  • health;
  • education;
  • legal rights;
  • children;
  • biometric data;
  • or other high-impact areas.

Data Assessment

Identify:

  • training data;
  • prompt data;
  • logs;
  • outputs;
  • personal data;
  • special-category data;
  • and cross-border transfers.

Technical Testing

Evaluate:

  • accuracy;
  • robustness;
  • bias;
  • hallucination;
  • cybersecurity;
  • and edge cases.

Human Oversight

Define when human approval is required.

Documentation

Record:

  • intended purpose;
  • limitations;
  • model version;
  • test results;
  • incidents;
  • and changes.

Contract Review

Align customer promises with technical reality.

Incident Response

Create a process for:

  • serious AI errors;
  • data incidents;
  • harmful content;
  • and customer complaints.

AI Liability Checklist for Startups

Before launching an AI-powered product in Turkey, founders should be able to answer:

  1. What exact function does the AI perform?
  2. Did we develop it ourselves or use a third-party model?
  3. What legal role does the startup perform?
  4. Is the AI advisory or autonomous?
  5. Can it make decisions affecting individuals?
  6. What happens if the AI is wrong?
  7. Could an error cause physical harm?
  8. Could it cause financial harm?
  9. Could it affect employment?
  10. Could it affect access to credit or insurance?
  11. Does the system process personal data?
  12. Does it process special-category data?
  13. What lawful processing basis applies?
  14. Are personal data transferred abroad?
  15. Are users properly informed?
  16. Can individuals object to adverse automated results where Article 11 applies?
  17. Is human oversight genuine?
  18. Has the system been tested for bias?
  19. Has the system been tested for hallucinations?
  20. Is the intended purpose clearly defined?
  21. Are prohibited use cases documented?
  22. Are customer contracts consistent with actual capabilities?
  23. Are marketing claims accurate?
  24. Are liability clauses legally valid?
  25. Does the upstream AI provider give adequate warranties?
  26. Can we recover losses from the AI provider if its system fails?
  27. Are intellectual property risks assessed?
  28. Can users upload confidential information?
  29. Are employees prohibited from uploading sensitive company data to unauthorised AI tools?
  30. Are AI agents given excessive permissions?
  31. Are logs maintained for important decisions?
  32. Are model updates tested?
  33. Is there an incident response process?
  34. Does product safety legislation apply?
  35. Does consumer law apply?
  36. Does sector-specific regulation apply?
  37. Is the system offered in the European Union?
  38. Does the EU AI Act apply extraterritorially?
  39. What AI Act provisions are currently applicable?
  40. Can the startup demonstrate all of these controls during investor due diligence?

If these questions cannot be answered, the startup’s AI legal risk has probably not been adequately assessed.

Frequently Asked Questions About AI Startup Liability in Turkey

Is there a specific Artificial Intelligence Act in force in Turkey?

As of August 2026, Turkey does not have a comprehensive horizontal AI statute equivalent to the EU AI Act in force. AI-related legislative proposals remain before parliamentary commissions. Existing laws therefore continue to provide the primary legal framework.

Can a startup say that the AI itself is responsible for a mistake?

Generally no. Legal responsibility will normally be analysed through the conduct and obligations of the human or corporate actors that developed, supplied, configured, marketed or used the system.

Is a startup responsible if a third-party AI API makes the mistake?

Potentially. The customer’s contractual relationship may be with the startup. The startup may then have separate rights against the underlying AI provider depending on the upstream contract.

Can a customer claim damages for inaccurate AI output?

Potentially, depending on the contract, representations, damage, causation and applicable legal regime. Article 112 of the Turkish Code of Obligations provides a general contractual damages framework where an obligation is not properly performed.

Can consumers make claims concerning defective AI services?

Yes. Where consumer law applies, defective service provisions may give consumers statutory remedies and potential compensation rights.

Does KVKK apply to AI?

Yes where personal data are processed. The Turkish Personal Data Protection Authority has issued specific guidance concerning generative AI and personal data protection.

Can AI make decisions about individuals automatically?

The legality depends on the use case and other applicable rules. KVKK Article 11 gives individuals a right to object where personal data are analysed exclusively by automated systems and this produces an adverse result for them.

Does the EU AI Act apply to Turkish startups?

Potentially. Article 2 extends the Act to certain providers located outside the EU, including providers placing AI systems or general-purpose AI models on the EU market and certain third-country providers or deployers where AI output is used in the EU.

Did the EU AI Act become fully applicable on 2 August 2026?

Not entirely. Although 2 August 2026 is the general application date, some provisions applied earlier and major high-risk AI requirements were delayed in 2026 to later dates depending on the category of high-risk system.

Conclusion: How Is the Legal Liability of Startups Using Artificial Intelligence Determined in Turkey?

The legal responsibility of a startup using artificial intelligence cannot be determined by asking only:

“Who created the algorithm?”

AI liability requires a broader analysis.

The first question should be:

What role does the startup perform?

Is it:

  • developing the AI;
  • providing it commercially;
  • integrating another company’s model;
  • using AI internally;
  • controlling the relevant personal data;
  • selling an AI-enabled product;
  • or making decisions about individuals?

The second question is:

What type of harm occurred?

The answer may lead to completely different legal regimes.

Where an AI service does not perform as promised, contractual liability may arise under the Turkish Code of Obligations. Article 112 requires compensation for damage resulting from non-performance or improper performance unless the debtor proves absence of attributable fault.

Where unlawful and culpable conduct causes damage outside a contractual relationship, Article 49 provides the general tort framework.

Where the AI service is provided to consumers, the defective service provisions of Law No. 6502 may create additional rights concerning re-performance, price reduction, termination and damages.

Where AI is incorporated into a physical product, Law No. 7223 and applicable technical product legislation may become important. Products must be safe, and the manufacturer or importer may face compensation liability where statutory conditions are satisfied.

Where AI processes personal data, the KVKK applies. The Turkish Personal Data Protection Authority’s specific guidance on generative AI confirms that AI development and use must be assessed throughout the system lifecycle from a personal data protection perspective.

Where automated processing creates an adverse decision concerning an individual, Article 11 rights should also be considered.

Startups operating internationally must add another layer to this analysis.

The EU Artificial Intelligence Act can apply to Turkish companies even where they have no corporate establishment inside the European Union. Its territorial scope includes certain third-country providers placing AI systems or general-purpose models on the EU market and certain situations where output generated by a third-country AI system is used within the Union.

As of August 2026, startups should also be careful about AI Act implementation dates. The Regulation is now generally applicable, but significant high-risk system obligations were postponed through the 2026 amendment to later dates depending on classification.

The practical lesson is therefore clear:

Artificial intelligence does not eliminate legal responsibility. It changes where legal risk must be identified and controlled.

A startup should not build its defence around the statement:

“We could not control what the AI would say.”

Instead, it should be able to demonstrate:

“We identified the foreseeable risks, tested the system, limited its intended use, provided appropriate information, implemented human oversight where necessary, monitored performance, protected personal data, controlled third-party providers and responded appropriately when problems arose.”

That is a much stronger legal position.

For founders, the most important preventive steps are to:

  • create an inventory of AI systems;
  • classify high-risk use cases;
  • identify applicable laws;
  • review training and input data;
  • document model limitations;
  • implement genuine human oversight;
  • monitor outputs;
  • maintain appropriate logs;
  • regulate employee AI use;
  • review third-party AI contracts;
  • protect confidential information;
  • assess cybersecurity;
  • and ensure marketing statements do not exceed the actual capabilities of the technology.

The legal significance of these measures extends beyond regulatory compliance.

They can affect:

  • customer disputes;
  • insurance coverage;
  • enterprise sales;
  • investment due diligence;
  • startup valuation;
  • acquisition negotiations;
  • and founder liability.

A venture capital investor evaluating an AI startup will increasingly ask not only:

“How powerful is the model?”

but also:

“Can this model legally be deployed at scale?”

An AI system that performs exceptionally well but cannot be lawfully used with customer data, cannot comply with sectoral rules or exposes the company to uncontrolled liability may substantially reduce the startup’s commercial value.

Accordingly, legal compliance should not be added to the AI product after development has finished.

The safer approach is AI compliance by design.

The startup should determine the intended purpose, relevant users, foreseeable misuse, personal data flows, human oversight and liability architecture before the product becomes widely deployed.

For startups using artificial intelligence in Turkey, the decisive principle is therefore not that AI must be risk-free.

No complex technology can guarantee that.

The legal objective is that the company should be able to demonstrate that the risks were foreseeably identified, proportionately managed, transparently communicated and continuously monitored.

That is increasingly becoming the dividing line between responsible artificial intelligence innovation and avoidable legal liability.

Categories:

No Responses

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    Our Client

    We provide a wide range of Turkish legal services to businesses and individuals throughout the world. Our services include comprehensive, updated legal information, professional legal consultation and representation

    Our Team

    .Our team includes business and trial lawyers experienced in a wide range of legal services across a broad spectrum of industries.

    Why Choose Us

    We will hold your hand. We will make every effort to ensure that you understand and are comfortable with each step of the legal process.

    Call Now Button