← Back to Insights

Turkey's National AI Strategy and Enterprise AI Adoption

What Turkey's National AI Strategy actually regulates, what the end of the 2025 period means, and which rules genuinely bind Turkish companies.

Turkey’s National AI Strategy is one of the most frequently cited and least frequently read documents in enterprise AI discussions. Companies that mistake it for an incentive catalogue put it aside once they fail to find a concrete entitlement in it. The strategy does not promise any single company a budget or an exemption; it signals the direction in which the ecosystem will be shaped. This article covers what the document actually says, what the closing of the 2025 period means, and why the rules that genuinely constrain a Turkish company’s AI plans are written somewhere else entirely.

What the strategy document actually governs

The National AI Strategy was published in 2021 by the Presidency’s Digital Transformation Office together with the Ministry of Industry and Technology, covering the 2021 to 2025 period. The document is built around six strategic priorities:

  • Increasing employment of AI specialists and the pool of qualified talent in the field
  • Supporting the research, entrepreneurship and innovation ecosystem
  • Expanding access to quality data and technical infrastructure
  • Introducing regulations that accelerate socioeconomic alignment
  • Strengthening international collaboration
  • Managing structural and workforce transformation

These priorities share a revealing characteristic: none of them impose an obligation on an individual company. The strategy is an ecosystem document, not a compliance regime. Your AI project is not required to comply with it. Establishing this distinction early matters, because the most common enterprise mistake we see is treating the strategy as a compliance checklist and handing it to the legal department.

The document’s real value for companies lies elsewhere. It tells you where the state intends to direct resources, which capabilities it will support, and where the regulatory appetite is pointing. When making an investment decision, that directional signal is often more decisive than the size of any single incentive.

What the end of the 2025 period means

The period covered by the strategy closed at the end of 2025. This does not make the document void, but its planning implications are more subtle.

First, the strategy was executed through periodic action plans. The end of period assessment and the framework for the following period reveal which priorities were met and which were carried forward. A company planning AI investment should track the current action plan in the areas that touch its own sector.

Second, and more importantly, a document drafted in 2021 does not share today’s technological assumptions. When it was written, generative AI did not carry its current weight on the enterprise agenda, and autonomous agent architectures were not yet a practical discussion at all. Using the strategy as a roadmap for today’s technology decisions is therefore misleading.

The practical conclusion: read the strategy to understand the direction of the ecosystem, but do not derive your own roadmap from it. We cover the framework you actually need for that in our AI transformation framework article.

Where the binding rules are actually written

The provisions that genuinely constrain your enterprise AI plans are not in the national strategy. They sit in two other places, and this is the most commonly skipped part of the adoption discussion.

KVKK and the 2024 amendment

Turkish Data Protection Law No. 6698 is the most concrete boundary around AI projects. Every piece of personal data used in model training is subject to processing conditions. The 2024 amendment introduced by Law No. 7499 restructured the cross border transfer regime in particular, bringing instruments such as standard contractual clauses into the system.

The AI implication is direct: when you send corporate data to a model hosted abroad, that is a cross border transfer of personal data. Which legal basis the transfer relies on, whether the contractual infrastructure is in place, and whether required notifications were made are all auditable questions. Many companies skip this step without noticing, because the transfer happens through the interface of an intermediary tool.

The EU AI Act and exporters

The European Union’s AI Act can bind companies established in Turkey. What matters is not where the company is incorporated, but whether the output of the system is used within the Union. If you sell products or services into Europe, have European customers, or operate an AI system that enters a European customer’s process, you fall within scope.

The Act entered into force in 2024, and obligations are phased in on a staged timetable. Provisions on prohibited practices applied first, obligations for general purpose AI models from August 2025, and the main block of obligations for high risk systems from August 2026.

The high risk classification covers far more enterprise territory than most companies assume. Recruitment and candidate evaluation, monitoring of employee performance, assessment of creditworthiness and management of critical infrastructure all fall within it. A company saying “we only use an HR tool” may be sitting in the heaviest obligation category without knowing it.

The real bottleneck in enterprise adoption

The obstacle is rarely technology. Three bottlenecks recur in the field.

Undefined data ownership. Most companies launching an AI project have not documented who inside the organisation owns the data it will use, who may change it, and what quality assurance it passes through. This must be resolved before any model is built, because no system built on unowned data can be audited.

Undefined decision rights. When the system produces a recommendation, who approves it, who may reject it, and where is the rejection rationale recorded? Systems deployed without answering these three questions either die because nobody uses them or become dangerous because nobody questions them.

Pilots chosen so they cannot scale. Pilots that demonstrate well but do not survive production create early enthusiasm and then stall. The right pilot is narrow in scope but embedded in a real operational process. We walk through how to make that choice in our enterprise AI adoption article.

What your company should do in this period

Given the picture above, the sequence a company should prioritise is as follows.

Start with an inventory. How many AI tools are already in use across your organisation, and which departments are connecting which data to which tools? Most companies that run this exercise discover usage at dozens of points despite never having formally launched an AI project.

Next, sort that inventory by risk class. If any tool feeds recruitment, performance evaluation or credit decisions, it is a candidate for the high risk category and it becomes your priority.

Third, map the data transfer path. Which tool sends data where, and on what legal basis does the transfer rest?

Finally, build the capability layer. You need at least one internal resource who can read these regulations and translate them into your organisation’s own language. External consulting accelerates the work, but it needs an internal counterpart to become durable.

The ATAOL AI Institute approach

At ATAOL AI Institute we design enterprise adoption programmes without separating regulatory literacy from technical capability. The reason is straightforward: most AI projects stall not for technical reasons but because the organisation cannot defend the system. A team that cannot explain a model’s output to a regulator, a customer or a board will eventually withdraw it from use.

Our programmes therefore address three things together: what the system does, how the decision is justified, and where responsibility sits. To assess where your organisation currently stands, complete our free assessment or contact us directly.

Frequently Asked Questions

Does Turkey’s National AI Strategy impose obligations on companies?

No. The strategy is an ecosystem document, not a compliance regime. The regulations that impose direct obligations are KVKK and, if you export, the EU AI Act. The strategy’s value lies in showing where state resources and regulatory intent are heading.

The strategy period ended in 2025, so is the document obsolete?

The document is not void, but the period it covers has closed. The right approach for corporate planning is to track current action plans as they relate to your sector, and to avoid applying technology assumptions written in 2021 directly to today’s decisions.

Why would a company based in Turkey be subject to the EU AI Act?

The Act’s scope is determined by where the output of the AI system is used, not by where the company is incorporated. If you operate a system that touches a customer or a process inside the European Union, being established in Turkey does not place you outside its scope.

What is most often overlooked on KVKK grounds in AI projects?

Cross border data transfer. Sending corporate data to a model hosted abroad counts as a transfer. This step usually goes unnoticed because it passes through an intermediary tool’s interface, yet the legal basis for the transfer and the contractual infrastructure behind it are auditable.

Which enterprise AI uses count as high risk?

Under the EU AI Act, recruitment and candidate evaluation, employee performance monitoring, creditworthiness assessment, education and examination processes, and critical infrastructure management fall into the high risk category. Tools in these areas carry the heaviest obligations even when the company regards them as ordinary software.

Where should adoption start?

With an inventory of the AI tools already in use inside the organisation. Even companies that have never launched a formal project typically find usage at dozens of points. A risk assessment carried out before that inventory exists will be incomplete.

Related Articles

aiinstitute 9 min read aiinstitute 8 min read aiinstitute 9 min read