Legal Tech · Service

Bring AI into your business without getting caught in regulation.

The EU Artificial Intelligence Act (AI Act), KVKK and GDPR impose concrete obligations on every company that uses AI. From risk classification to governance policies, from impact assessments to procurement contracts, we build AI compliance end to end.

Overview

Artificial intelligence is now a regulated field

Artificial intelligence has moved beyond the experimental stage: it is embedded in business processes from customer service to HR decisions, from production to marketing. Meanwhile, the EU Artificial Intelligence Act (AI Act) is entering into force in stages, while KVKK and GDPR already govern the data dimension. For every Turkish company that touches the German and EU market, these rules have become a direct commercial necessity.

Our AI compliance work spans from an inventory of the systems you use and develop to risk classification, from governance policies and impact assessments to AI procurement contracts. The goal is not to halt innovation, but to place it on a defensible legal footing.

AI & regulation
01

When Does This Apply?

The typical scope of our AI compliance service.

AI Act Compliance

Risk classification of systems, an obligations map, and a roadmap for compliance with the EU market.

Data & Model Compliance

The standing of training data, automated decision-making and profiling processes under KVKK/GDPR.

AI Procurement Contracts

Liability, intellectual property rights and data provisions in the procurement of AI tools and services.

02

How Does the Process Work?

The three-stage method we follow in AI compliance.

01 · Inventory & Classification

We map the AI systems in use and planned, and assess each according to its AI Act risk class and data regime.

02 · Policy & Assessment

We prepare the AI usage policy, human oversight rules and the required impact assessments.

03 · Contracts & Monitoring

We adapt supplier and customer contracts, and keep compliance current by monitoring the legislative calendar.

Why Köksal?

A legal team that knows technology from the inside

AI compliance is built not with policies written without understanding the technology, but with a team that knows how the system works. With our Legal Engineering approach and the hands-on experience that comes from using AI in our own processes, we write rules that can actually be applied.

  • Analysis that reads the AI Act, KVKK and GDPR within a single framework
  • A practical roadmap for companies oriented towards the German/EU market
  • Lawyers who speak the same language as technical teams
  • Realistic rules drawn from our own AI practice
  • Integration with our data protection and legal tech services
04

Other Legal Tech Services

When needed, the same team can seamlessly extend its work to our other solutions in this area.

All Legal Tech services
05

Related Areas & Legislation

The focus areas, practice areas, desks and legislation connected with this service.

07

The Team Delivering This Service

With our multilingual team of lawyers, well-versed in Turkish and German law, we are by your side.

08

Related Publications

Fresh perspectives and guides from the Knowledge Centre.

A few headings decide this contract. The first is data: whether your inputs will be used to train the model, how long they are retained, which sub-processors are involved and in which country the processing happens — written down rather than assumed. Where personal data is processed, a data processor agreement under the Personal Data Protection Law (No. 6698) has to be annexed, with GDPR terms where EU data is invol…

Yes — if the system's output is used in the EU, or if you place AI-containing products/services on the EU market, being established in Türkiye does not take you outside its scope. For companies that export to Germany or have customers there, the AI Act is a direct commercial requirement, similar to the LkSG.

A written acceptable-use policy is strongly advisable for any company whose staff use ChatGPT-like generative AI tools. Without one, employees can paste customer data, trade secrets and personal data into external tools whose terms may permit further processing, creating exposure under Türkiye's Personal Data Protection Law (KVKK, Law 6698) and, for EU-facing data, the GDPR. A concise policy typically defines approv…

You can, but recruitment and performance are among the most exposed uses there are. The AI Act places systems used in hiring, promotion and performance evaluation in the high-risk class, which brings obligations of transparency, record-keeping and human oversight. In Türkiye the same process runs into the Personal Data Protection Law (No. 6698): candidates have to be given an information notice, and the law gives a…

Service

Get the right legal support for AI Compliance & Governance.

Let us define the solution best suited to your needs, together with our experience in Türkiye and the DACH region.