The EU AI Act entered into force in August 2024 and applies to organisations based in Turkey. If your system touches the EU market, affects EU citizens, or sits within an EU company's supply chain — the regulation applies to you.
So where do you start?
The first step is always the same: understand which risk category your system falls into.
Four Tiers, One Question
EU AI Act classifies AI systems into four risk tiers. This classification directly determines your compliance obligations.
Where Turkish Companies Most Often Get Stuck
In practice, Turkish organisations tend to encounter difficulties in two areas.
First, they don't know the risk category of the SaaS tools they use. Recruitment platforms, automated CV screening features, and performance management software can fall within the high-risk category. Not having developed the tool yourself does not exempt you from obligations — deployers are liable too.
Second, the "we're not in the EU" assumption. A company based in Turkey that serves EU customers or evaluates EU employees is covered by the regulation. Geographic location is not the deciding factor — scope of impact is.
Three Practical Questions to Classify Any System
Use these three questions to position your system quickly.
-
Does this system make decisions about an individual? If it produces outputs about specific people in hiring, credit, education, healthcare, or justice contexts, you are close to the high-risk category.
-
How binding is the output? Is the system offering a recommendation or directly shaping a decision? How real is human oversight — genuine review or nominal rubber-stamping?
-
What data does it process? If the system handles biometric, behavioural, or sensitive personal data, the risk level increases automatically.
The answers to these three questions will point you to the right category. If the answers are ambiguous — as they usually are at the start — that is itself a signal: your system needs better documentation.
Classification Is Not a One-Time Event
The most important mindset shift EU AI Act introduces is this: risk classification is not a checklist exercise — it is an ongoing evaluation practice. As systems are updated, deployment contexts change, and data flows evolve, the category can shift.
The starting point is straightforward: know where your system stands today.
Note: This article is based on information available as of February 2026. Article references are to Regulation (EU) 2024/1689. For information on proposed amendments, see our article on the Digital Omnibus. This article does not constitute legal advice.