Focus Area

Actionable compliance in artificial intelligence that starts with the AI Act.

The AI Act's phased timeline is under way: role determination, risk classification, GPAI transparency, data-set copyright clearance and AI contracts — we make artificial intelligence legally usable.

Overview

An integrated legal framework for Artificial Intelligence

Artificial intelligence projects give rise, all at once, to risks around data sourcing, model output, human oversight, intellectual property, liability and regulation. With the EU Artificial Intelligence Regulation (AI Act), this field has now acquired a binding framework that enters into force on a phased timeline and provides for substantial administrative fines in the event of breach.

From system inventory and risk classification to provider/deployer obligations, and from the transparency rules for generative models to AI contracts and internal governance, we make compliance part of product design and bridge the language of technology and the language of law.

Artificial Intelligence strategy / operations
Why Köksal?

A team that both uses and regulates artificial intelligence

Artificial intelligence law is learned through practice, not theory. As a team that uses AI in its own workflows and knows the sector from the inside through its Legal Tech desk, we read the AI Act, KVKK and GDPR within a single framework and set up the rules in a way that fits technical reality and is ready for audit.

  • Analysis that reads the AI Act, KVKK and GDPR within a single framework
  • A compliance plan prioritised according to the phased AI Act timeline
  • Realistic rules drawn from our own artificial intelligence practice
  • Lawyers who speak the same language as technical teams
  • A roadmap for companies oriented towards the Germany/EU market
Artificial Intelligence multi-disciplinary team
03

Related Services

Our services most often engaged in this focus area — together with their scope.

AI Compliance & Governance

The EU Artificial Intelligence Regulation (AI Act), KVKK and GDPR impose concrete obligations on every company that uses artificial intelligence. From risk classification to governance policies, from impact assessments to procurement contracts, we build AI compliance end to end.

Explore

AI-Assisted Legal Services

Thousand-page contract sets, large data rooms and extensive case-law reviews are processed within days through our AI-assisted workflows. Every output passes through attorney review: the speed comes from AI, the responsibility and quality from us.

Explore

Compliance

Compliance advisory: we build programmes that bring your company into line with KVKK/GDPR, anti-corruption rules, and sectoral regulations. Through internal audit, policy, and training, we turn compliance into a lasting corporate culture.

Explore

Process Automation

Process automation reduces lost time and errors by digitalising routine document production, approval and signature workflows, and compliance checks. We design auditable workflows tailored to your processes while preserving legal accuracy.

Explore

Contract Digitalisation

Contract digitalisation brings your CLM process into a single order with a template library, electronic signatures, and renewal tracking. We turn scattered documents into traceable, analysable contract management.

Explore

Data & Document Management

Data and document management brings secure storage, KVKK/GDPR compliance, and the access and authorisation framework together under one roof. We manage your information without losing any of it, while protecting confidentiality and keeping it audit-ready.

Explore
View all
08

Related Publications

Artificial Intelligence — latest insights and guides.

09

Related Legislation

Artificial Intelligence — the legislation that directly affects this focus area, tracked in plain language on our Legislation Radar.

ABAvrupa B.EU Directive & RegulationRecently amendedEU Artificial Intelligence Act (AI Act)Source · ABl. L, 12.7.2024In force · 01.08.2024 (phased)Last amended · Jul 2026 (Digital Omnibus — high-risk timeline deferred; OJ publication pending)

The world’s first comprehensive artificial intelligence regulation: risk-based classification, provider/deployer obligations, and a phased implementation timeline. It may also cover Turkish companies whose output is used in the EU.

RelatedPersonal Data ProtectionIntellectual Property LawLaw of Obligations & Contracts
ABAvrupa B.EU Directive & RegulationRecently amendedEU Data ActSource · ABl. L, 22.12.2023In force · 12.09.2025 (application)Last amended · Sep 2025 (application) · next 12.09.2026 (design obligation); Digital Omnibus proposal under negotiation

Rules on access to, sharing of, and cloud switching for connected-product and related-service data: the regulation that re-establishes the contractual order of the data economy has been in application since September 2025.

RelatedPersonal Data ProtectionLaw of Obligations & ContractsCommercial Law
ABAvrupa B.EU Directive & RegulationIn progressNew EU Product Liability Directive (PLD)Source · OJ L 2024/2853, 18.11.2024In force · 08.12.2024 (new regime from 09.12.2026)Last amended · -

The new regime treats software, updates and AI systems as products, eases the claimant’s burden of proof and makes the EU importer strictly liable; it applies to products placed on the market after 09.12.2026.

RelatedCommercial LawLaw of Obligations & ContractsIntellectual Property Law
ABAvrupa B.EU Directive & RegulationIn progressEU Cyber Resilience Act (CRA)Source · OJ L 2024/2847, 20.11.2024In force · 10.12.2024 (phased; full application 11.12.2027)Last amended · Dec 2025 (Implementing Regulation (EU) 2025/2392)

The Regulation imposing EU-wide cybersecurity requirements and CE marking on products with digital elements; a Turkish company placing such a product on the EU market is itself the manufacturer and cannot delegate these duties.

RelatedCommercial LawIntellectual Property LawPersonal Data Protection
Open the Legislation Radar

The determining factor is the area of use: Annex III areas such as employment, credit, education, critical infrastructure, and product-safety components give rise to high risk. We determine your system's class through its use scenario and derive the set of obligations.

CV screening and performance-evaluation systems are high-risk candidates under the AI Act; from the KVKK/GDPR side, the limits on automated decision-making and profiling also come into play. We establish lawful use through human-approval thresholds and a disclosure framework.

A comprehensive AI law is not yet in force; studies and drafts are on the agenda, and at present the KVKK, the TKHK (Turkish Consumer Protection Law), and sector-specific rules apply. We track developments on our Legislation Radar and are already positioning companies in line with the EU framework.

Only if there is a legal basis, purpose limitation, and contractual safeguards. Whether the tool uses the data for training and where it processes it are critical. We run the data flow through the KVKK/GDPR filter and define a framework for safe use.

Yes, you can be; an automated system’s statements can be attributed to the business. Through terms of use, warning notices, thresholds requiring human approval and proper record-keeping, we bring this liability down to a manageable level.

Yes; the regulation applies in stages: the rules on prohibited practices and AI literacy obligations apply from early 2025, the general-purpose (GPAI) model rules from August 2025, while the main obligations for high-risk systems take effect from August 2026. We build a scheduled compliance plan that starts with an inventory and risk classification.

Copyright protection for purely machine-generated content is contested; the nature of the human contribution is decisive. In addition, tool agreements may regulate output rights differently. We structure your production workflow to secure ownership of the rights.

It may be: the AI Act also covers third-country companies that place a system on the EU market or whose output is used in the EU. If the product or service you offer from Türkiye has an EU touchpoint, we determine your role (provider/deployer) and clarify the scope of your obligations.

Focus Area

Let us build a legal strategy in the Artificial Intelligence focus area.

Let us assess your need together with the relevant practice areas, sectors and regional desks.