Reading the timeline correctly
The AI Act enters into force not on a single date but in waves. Since February 2025, applications posing unacceptable risk have been prohibited, and companies have an obligation to build competence (AI literacy) among staff who work with AI. In August 2025, transparency and copyright rules for general-purpose AI models (GPAI) began to apply. The main wave has moved to 2 December 2027: under the Digital Omnibus, the quality management, technical documentation, record-keeping and human oversight obligations for standalone Annex III high-risk systems apply from 2 December 2027. The dates for prohibited practices (2 February 2025) and general-purpose AI (2 August 2025) are unchanged.
Practical guidance
The first step is an inventory: which AI systems are used in the company, for what purpose, and in whose role? The classification and obligation map is built on this inventory.
Let us put your AI Act preparation on a timeline
We set up the inventory, risk classification, and policy suite within a single framework aligned with KVKK/GDPR.
Role first, then risk
Your set of obligations is determined by two questions: what is your role in the system (provider, deployer or importer) and what is the system’s risk class? The same company may hold different roles across different systems: a provider for a product it develops itself, a deployer for an HR tool it purchases. Compliance work carried out without mapping out this matrix hangs in the air.
Scope seen from Türkiye
The Regulation is broad in territorial terms: providers/deployers of systems placed on the EU market and of systems whose output is used in the EU may fall within scope even if they are established in a third country. Turkish companies that sell SaaS to the EU, produce analytical output for EU clients, or ship products with embedded software to the EU market are affected through this gateway; in certain cases an authorised representative in the EU is required.
What to do before 2026
1) System inventory and role/class determination; 2) a prohibition screen (particularly uses touching on biometrics, scoring and emotion recognition); 3) a usage policy, human-approval thresholds and a record-keeping regime; 4) adding AI compliance commitments to procurement contracts; 5) planning technical-documentation preparation for high-risk candidates; 6) documenting the training programme. This sequence spreads the cost across the waves and leaves an audit-ready trail.
Intersection with KVKK/GDPR
AI systems often process personal data: the rules on automated decision-making, profiling, and data minimisation apply independently of the AI Act. The most efficient approach is to combine the two compliance streams within a single governance framework.
Sanctions: a tiered penalty architecture
The Regulation’s penalty framework has three tiers: for prohibited practices, administrative fines of up to EUR 35 million or 7% of total worldwide annual turnover; for other breaches of obligations, up to EUR 15 million / 3%; and for supplying misleading information to the authorities, up to EUR 7.5 million / 1%. For SMEs, the rates are adapted more favourably. As in the GDPR experience, this architecture creates the expectation of tiered but deterrent enforcement — particularly for uses that have skipped the prohibition screen. We track current enforcement developments in our AI Act radar entry.
A quick assessment by use case
Customer-service chatbot: limited risk; a transparency notice and management of liability for incorrect information are sufficient — for the liability structure, apply the human-approval thresholds model from our Artificial Intelligence focus area. CV-screening and promotion tools: a high-risk candidate; deployer obligations plus employment law and KVKK’s limits on automated decision-making come into play together. Credit scoring: high risk; a double framework with financial regulation. Generative content tools: GPAI transparency plus copyright and data-leakage policies. AI embedded in a product: a combined assessment with product safety legislation from 2 August 2028. In every scenario the first question is the same: what is your role, and where is the output used?
The Köksal approach
Our AI compliance & governance service sets up the inventory, classification, and policy set within a single framework together with KVKK/GDPR compliance. As a team that uses AI in our own workflows, we write the rules to fit technical reality; for legal departments, our legal tech roadmap is the twin of this guide.
Conclusion
The cost of falling behind on the AI Act is commercial before it is a penalty risk: EU clients have begun to ask their suppliers for a declaration of compliance. Starting today with an inventory turns the 2026 wave into routine — and turns artificial intelligence from a risk into a competitive advantage.


