Gains:
- Understand the risk-based logic of the EU AI Law (unacceptable, high, limited, minimum) and the obligations of high-risk systems
- Ability to detect personal data processing, purpose limitation, disclosure and international transfer risks in terms of KVKK in the use of artificial intelligence
- Ability to pre-evaluate the artificial intelligence output without considering it as definitive legal advice and include personal data and legal support in high-risk initiatives.
Ethics describes "what is right"; Compliance, on the other hand, describes what is “required by law” and violation of which leads to penalties, lawsuits, and loss of reputation. For a senior executive, compliance is a matter of personal legal responsibility; "I didn't know" is not a defence. In this unit, we will discuss the two most critical regulations for artificial intelligence: the EU Artificial Intelligence Act (EU AI Act; the European Union's comprehensive law regulating artificial intelligence according to its risk level) and KVKK (Personal Data Protection Law; Türkiye's personal data protection law is similar to the GDPR in Europe). The goal is not to become a lawyer; Knowing when to stop and get legal support and avoiding blind risks.
Rationale of the EU AI Law: risk-based
The EU AI Law divides artificial intelligence systems into four categories according to the level of risk and imposes different obligations on each category. Although it is not directly implemented in Türkiye; It binds institutions that sell products/services to the EU, have EU customers or process the data of EU users, and is becoming a worldwide standard.
Risk level
example
liability
unacceptable
Social scoring, manipulative systems
forbidden
high risk
Recruitment, credit, healthcare, critical infrastructure
Strict: risk management, data quality, human oversight, recording, transparency
limited risk
Chatbot, productive content
Transparency: notifying the user that it is AI
minimal risk
Spam filter, game
Free, voluntary good practice
Important term: high-risk system is an application of artificial intelligence that can directly affect people's fundamental rights, safety or life opportunities (jobs, credit, education, health). The law for these systems is; It mandates risk assessment, quality and unbiased data, human oversight, technical documentation, record keeping and transparency.
Tip: When evaluating an AI initiative, ask yourself: “Is this system involved in a decision that affects a person's job, money, health, or freedom?” If the answer is yes, it is likely high risk and requires special diligence with legal support.
Basic obligations of KVKK
KVKK regulates the processing of personal data (any information that makes a person specific or identifiable: name, TR ID, e-mail, location, even behavioral data). Critical points in terms of artificial intelligence:
- Legal basis: A valid reason (explicit consent, contract, legitimate interest, etc.) is required to process personal data.
- Purpose limitation: Data cannot be used for purposes other than the purpose for which it was collected. Introducing data collected for a purpose into artificial intelligence training may require additional support.
- Data minimization: Only as much data as necessary is processed.
- Disclosure: The person concerned must be informed about how his data is processed.
- Transfer: Transfer of data abroad (for example, to an overseas artificial intelligence provider) is subject to special rules.
- Automatic decision: The right to object to completely automatic decisions affecting the person should be respected.
Pasting customer data into an AI tool often amounts to “data transfer abroad” and “unintended processing”; This is the most common and most dangerous compliance violation.
Step by step: fit check
1. Determine the risk level. What is the system at unacceptable/high/limited/minimum risk?
2. Check if there is personal data. Which personal data goes where, on what basis?
3. Match obligations. List legal requirements based on risk level and data status.
4. Get legal support. Involve the law in every initiative that is high risk or involves personal data.
5. Document and monitor. Record compliance decisions, disclosures and inspections.
three mini cases
Case 1 — Silent transfer abroad. A retailer sent data to an overseas-based AI tool to analyze customer complaints. The clarification text did not cover this, there was no basis for transfer. A violation has occurred in terms of KVKK; There was a risk of administrative fines during the audit. The institution switched to a solution that processes data domestically and updated the lighting.
Case 2 — Rigor of the high-risk system. A human resources technology company was selling recruiting software to AB. This was deemed "high risk" in the EU AI Law. The company entered the market smoothly because it prepared risk management, data quality evidence, human oversight and documentation in advance. An unprepared competitor's access was delayed because he could not meet the same obligations. Harmony turned into a competitive advantage.
Case 3 — The power of lighting. An insurance company clearly enlightened customers when pricing with artificial intelligence and opened the way for objections to completely automated decisions. A customer objected, human reviewed, and a data error was corrected. Transparency and appeal not only met the legal requirement but also caught a genuine error.
Four copyable templates
1) Risk classification preliminary control:
Your role: AI compliance advisor (preliminary assessment, not legal advice).Classify the following system according to EU AI Act risk levels: unacceptable, high, limited, minimal. Write your rationale and what main obligations will arise; State that legal support is required for a final decision. System: [text]
2) Personal data flow map:
In this use of artificial intelligence, map which personal data is processed, for what purpose it is collected, and where it is transferred (especially abroad). Mark the risky points in terms of KVKK and indicate which issues require legal support. Usage: [text]
3) Lighting and objection control:
Check the KVKK clarification and automatic decision objection requirements for customer-facing artificial intelligence: what should the user be informed about, how should the objection be processed? List the shortcomings. Usage: [text]
4) Compliance readiness checklist:
Produce an EU AI Act compliance readiness checklist for the following high-risk AI initiative: risk management, data quality, human oversight, documentation, registration, transparency. Write a question for each item that I can evaluate as "ready/incomplete". Initiative: [text]
Weak prompt / Strong prompt
Weak: “Is this AI legal?”
Result: A superficial, unreliable response; AI cannot and should not provide definitive legal advice.
Güçlü: "I am evaluating a recruitment pre-screening tool sold to customers in the EU. Pre-classify it according to the EU AI Law risk levels and list what obligations (risk management, data quality, human oversight, documentation) will arise if it is deemed likely high risk. Also, in terms of KVKK, raise the questions I need to ask which data of the candidates is processed and how. State that this is a preliminary evaluation, the law is required for a final decision."
Result: A structured preliminary assessment and preparation for legal support; not a blind "legal/not" clause.
Common mistakes
- Expecting definitive legal advice from AI. Artificial intelligence makes a preliminary assessment; The final legal decision belongs to the lawyer.
- Ignoring data transfer abroad. Entering customer data into an external AI tool is often a compliance violation.
- Underestimating the high-risk system. Systems involved in business, credit and health decisions require special care.
- Bypassing the right to information and objection. Transparency and appeal are legal requirements for automated decisions affecting individuals.
- Thinking that harmony is a one-time thing. Legislation and systems change; Compliance must be constantly monitored.
Caution: The information in this unit is for general awareness and is not legal advice. Artificial intelligence output is also not legal advice. In any initiative that processes personal data or is high risk, it is mandatory to consult a qualified legal expert before making a decision. The cost of compliance violations grows exponentially in the form of fines, lawsuits and loss of reputation.
In summary
Compliance is the minimum required by law, and its violation imposes legal liability on the manager. The EU AI Law regulates AI according to the level of risk (unacceptable, high, limited, minimal); Risk management, data quality, human oversight and transparency are essential for high-risk systems. KVKK, on the other hand, requires personal data to comply with the legal basis, purpose limit, minimization, disclosure and international transfer rules; Entering customer data into an external AI tool is the most common breach. AI can only make preliminary assessments; Expert support must be obtained for a definitive legal decision. In the next unit, we will discuss the team and competency structure that will implement this entire strategy.
Application task
Choose an AI use case. 1. Pre-classify the EU AI Act risk level with template. 2. Map the flow of personal data with the template and determine if there is an international transfer. Write down the two most critical compliance questions that arise and note which legal source/expert you would direct them to. Make no definitive legal rulings; just clarify the questions.
checklist
- [ ] I have pre-classified the EU AI Act risk level of the system.
- [ ] If it is high risk, I have listed the relevant liabilities.
- [ ] I mapped the personal data processed and its basis.
- [ ] I checked whether there is data transfer abroad.
- [ ] I have reviewed the requirement for information and right to object.
- [ ] I prepared critical compliance questions for legal support.
- [ ] I did not consider the AI output as definitive legal advice.