Actionable compliance in artificial intelligence that starts with the AI Act.
The AI Act's phased timeline is under way: role determination, risk classification, GPAI transparency, data-set copyright clearance and AI contracts — we make artificial intelligence legally usable.
An integrated legal framework for Artificial Intelligence
Artificial intelligence projects give rise, all at once, to risks around data sourcing, model output, human oversight, intellectual property, liability and regulation. With the EU Artificial Intelligence Regulation (AI Act), this field has now acquired a binding framework that enters into force on a phased timeline and provides for substantial administrative fines in the event of breach.
From system inventory and risk classification to provider/deployer obligations, and from the transparency rules for generative models to AI contracts and internal governance, we make compliance part of product design and bridge the language of technology and the language of law.

Services We Offer in This Focus Area
In the Artificial Intelligence focus area, we bring together the relevant legal disciplines in a single work plan.
AI Act Risk Classification
System inventory; identification of the prohibited-practice, high-risk and transparency categories, together with an obligation map tied to the phased entry-into-force timeline.
Explore →Provider & Deployer Obligations
Establishing technical documentation, record-keeping, human oversight, AI literacy and monitoring arrangements according to the provider and deployer roles.
Explore →Generative AI & GPAI Rules
Obligations relating to transparency, copyright policy and the training-data summary for general-purpose models; the labelling of generative outputs and rules on their use.
Explore →Data Sets, Copyright & KVKK/GDPR
Legal compliance of training and test data in its personal-data, copyright and contractual dimensions; meeting data-governance requirements.
Explore →AI Contracts & Procurement
Balanced structuring of liability, data, intellectual property and compliance commitments in model procurement, development, integration and API agreements.
Explore →Governance, Policy & Liability
In-house use policy, human-approval thresholds and training; defence against claims arising from faulty output and automated decisions.
Explore →A team that both uses and regulates artificial intelligence
Artificial intelligence law is learned through practice, not theory. As a team that uses AI in its own workflows and knows the sector from the inside through its Legal Tech desk, we read the AI Act, KVKK and GDPR within a single framework and set up the rules in a way that fits technical reality and is ready for audit.
- Analysis that reads the AI Act, KVKK and GDPR within a single framework
- A compliance plan prioritised according to the phased AI Act timeline
- Realistic rules drawn from our own artificial intelligence practice
- Lawyers who speak the same language as technical teams
- A roadmap for companies oriented towards the Germany/EU market

Related Practice Areas
The legal disciplines this focus area draws on.
Related Services
Our services most often engaged in this focus area — together with their scope.
AI Compliance & Governance
The EU Artificial Intelligence Regulation (AI Act), KVKK and GDPR impose concrete obligations on every company that uses artificial intelligence. From risk classification to governance policies, from impact assessments to procurement contracts, we build AI compliance end to end.
Explore →AI-Assisted Legal Services
Thousand-page contract sets, large data rooms and extensive case-law reviews are processed within days through our AI-assisted workflows. Every output passes through attorney review: the speed comes from AI, the responsibility and quality from us.
Explore →Compliance
Compliance advisory: we build programmes that bring your company into line with KVKK/GDPR, anti-corruption rules, and sectoral regulations. Through internal audit, policy, and training, we turn compliance into a lasting corporate culture.
Explore →Process Automation
Process automation reduces lost time and errors by digitalising routine document production, approval and signature workflows, and compliance checks. We design auditable workflows tailored to your processes while preserving legal accuracy.
Explore →Contract Digitalisation
Contract digitalisation brings your CLM process into a single order with a template library, electronic signatures, and renewal tracking. We turn scattered documents into traceable, analysable contract management.
Explore →Data & Document Management
Data and document management brings secure storage, KVKK/GDPR compliance, and the access and authorisation framework together under one roof. We manage your information without losing any of it, while protecting confidentiality and keeping it audit-ready.
Explore →Related Sectors
The sectors this focus area touches often.
Technology
Legal advisory on licensing, SaaS, data, intellectual property, investment, scaling, compliance, and product law for technology companies.
Explore →Banking & Finance
Advisory services in banking, fintech, payments, lending, collateral, investment, regulation and financial dispute processes.
Explore →Healthcare
Regulatory, data, contract, investment and dispute advisory for healthcare services, medical products and the pharmaceutical ecosystem.
Explore →Education
Licensing, contract, data, employment law, consumer and investment advisory for educational institutions, courses, and edtech ventures.
Explore →Automotive
Contract, compliance, investment, and dispute advisory across the automotive value chain for OEMs, suppliers, distributors, and investors.
Explore →Related Regional Desks
Our cross-border and specialist desks that run this focus area.
Legal Tech Desk
International advisory on process innovation, compliance and scalable legal architecture for legal-technology ventures and next-generation business models.
Explore →Data & Cybersecurity Desk
Integrated advice spanning multiple jurisdictions in KVKK and GDPR compliance, cross-border data transfer, and cyber incident response.
Explore →Germany Desk
An end-to-end legal bridge in Türkiye for companies from the DACH region and in Germany for Turkish companies.
Explore →Track Record: Selected Matters
Anonymised examples of our work in this focus area, including the approach, process and outcome.
Mapping AI Act roles and risk classification
An inventory of the company's AI products and uses; provider/deployer role determination, risk classification, and a roadmap tied to the phased timeline.
Review the matter →Corporate generative-AI policy and tool contracts
A policy setting data boundaries, confidentiality, and copyright rules for employees' use of generative AI; negotiation of the tool contracts accordingly.
Review the matter →Negotiating an AI procurement contract with its data clauses
Negotiation of performance, data-use, IP and liability clauses in a model-API procurement, together with the KVKK/GDPR layer.
Review the matter →Team in This Focus Area
Artificial Intelligence and meet our experienced multilingual team.
Related Publications
Artificial Intelligence — latest insights and guides.
Related Legislation
Artificial Intelligence — the legislation that directly affects this focus area, tracked in plain language on our Legislation Radar.
The world’s first comprehensive artificial intelligence regulation: risk-based classification, provider/deployer obligations, and a phased implementation timeline. It may also cover Turkish companies whose output is used in the EU.
ABAvrupa B.EU Directive & RegulationRecently amendedEU Data ActSource · ABl. L, 22.12.2023In force · 12.09.2025 (application)Last amended · Sep 2025 (application) · next 12.09.2026 (design obligation); Digital Omnibus proposal under negotiationRules on access to, sharing of, and cloud switching for connected-product and related-service data: the regulation that re-establishes the contractual order of the data economy has been in application since September 2025.
ABAvrupa B.EU Directive & RegulationIn progressNew EU Product Liability Directive (PLD)Source · OJ L 2024/2853, 18.11.2024In force · 08.12.2024 (new regime from 09.12.2026)Last amended · -The new regime treats software, updates and AI systems as products, eases the claimant’s burden of proof and makes the EU importer strictly liable; it applies to products placed on the market after 09.12.2026.
ABAvrupa B.EU Directive & RegulationIn progressEU Cyber Resilience Act (CRA)Source · OJ L 2024/2847, 20.11.2024In force · 10.12.2024 (phased; full application 11.12.2027)Last amended · Dec 2025 (Implementing Regulation (EU) 2025/2392)The Regulation imposing EU-wide cybersecurity requirements and CE marking on products with digital elements; a Turkish company placing such a product on the EU market is itself the manufacturer and cannot delegate these duties.
The determining factor is the area of use: Annex III areas such as employment, credit, education, critical infrastructure, and product-safety components give rise to high risk. We determine your system's class through its use scenario and derive the set of obligations.
CV screening and performance-evaluation systems are high-risk candidates under the AI Act; from the KVKK/GDPR side, the limits on automated decision-making and profiling also come into play. We establish lawful use through human-approval thresholds and a disclosure framework.
A comprehensive AI law is not yet in force; studies and drafts are on the agenda, and at present the KVKK, the TKHK (Turkish Consumer Protection Law), and sector-specific rules apply. We track developments on our Legislation Radar and are already positioning companies in line with the EU framework.
Only if there is a legal basis, purpose limitation, and contractual safeguards. Whether the tool uses the data for training and where it processes it are critical. We run the data flow through the KVKK/GDPR filter and define a framework for safe use.
Yes, you can be; an automated system’s statements can be attributed to the business. Through terms of use, warning notices, thresholds requiring human approval and proper record-keeping, we bring this liability down to a manageable level.
Yes; the regulation applies in stages: the rules on prohibited practices and AI literacy obligations apply from early 2025, the general-purpose (GPAI) model rules from August 2025, while the main obligations for high-risk systems take effect from August 2026. We build a scheduled compliance plan that starts with an inventory and risk classification.
Copyright protection for purely machine-generated content is contested; the nature of the human contribution is decisive. In addition, tool agreements may regulate output rights differently. We structure your production workflow to secure ownership of the rights.
It may be: the AI Act also covers third-country companies that place a system on the EU market or whose output is used in the EU. If the product or service you offer from Türkiye has an EU touchpoint, we determine your role (provider/deployer) and clarify the scope of your obligations.
Let us build a legal strategy in the Artificial Intelligence focus area.
Let us assess your need together with the relevant practice areas, sectors and regional desks.



