EU AI Act GPAI Enforcement Is Live: What Changed for Turkish Companies on 2 August 2026
The European Commission's supervision and enforcement powers over GPAI providers took effect on 2 August 2026. A practical roadmap for Turkish companies plus the KVKK link.
TL;DR — August 2, 2026 is a threshold that the EU AI Act crossed quietly, but one that actually has teeth: the European Commission's supervision and enforcement powers over general-purpose AI (GPAI) providers came into force on this date. The obligations had been on paper since 2025; now the Commission can request documentation, conduct evaluations, demand corrective measures, and impose fines of up to 3% of global turnover or €15 million on GPAI providers. In this piece I explain, from the field, who is in scope, why Turkish companies can't relax by saying "but we don't build models," how this overlaps with the agentic-AI and generative-AI guidelines the Turkish DPA (KVKK) published in 2026, and what you concretely need to do over the next 12 months.
Why August 2, 2026 is genuinely a turning point
In the vast majority of meetings I've had with corporate clients over the past year, the EU AI Act was dismissed with a single sentence: "That's Europe's problem, it doesn't concern us." Every time I hear this, the same thing runs through my mind: we started exactly like this with GDPR. In 2018, most of the firms saying "we're in Turkey, GDPR doesn't bind us" panicked within two years when their European customers asked, at the contract table, "Are you GDPR compliant?" We're watching the same film with the AI Act, just with slightly different actors.
Here's the technical part: the AI Act's obligations for GPAI providers took effect on August 2, 2025. But the law granted providers a one-year "adjustment window." The Commission's use of supervision and enforcement powers against these providers was deferred to August 2, 2026. So the past year was a kind of "warm-up lap"; now the referee has blown the whistle.
These powers are not abstract. The Commission can now:
- Request technical documentation and information from a GPAI provider.
- Conduct or commission evaluations of models.
- Demand corrective measures for identified non-compliance.
- Impose additional measures on models carrying systemic risk.
- And ultimately, levy fines.
The penalty side is also a deterrent: for GPAI-specific breaches, Article 101 allows fines up to €15 million or 3% of annual global turnover. For general AI Act breaches, Article 99 is even harsher: up to €35 million or 7% of turnover. Set the size of the numbers aside; the real point is that these have moved from "possible" to "enforceable."
"The real birthday of a compliance obligation is not the day the text is published in the official journal. It is the first day the regulator can use that text against you. For GPAI, that day was August 2, 2026.
The "we're not a GPAI provider" trap
Most companies in Turkey have the same first reflex: "We don't train our own foundation model, so we're not a GPAI provider, this doesn't bind us." Technically you may not fit the definition of a GPAI provider — true. But that doesn't mean the AI Act has nothing to do with you. Here are the three misconceptions I most often see in the field:
First, the supply-chain effect. If you build a corporate application on top of GPT-5.6, Claude Opus 5, or Gemini 3.6, you're a "downstream deployer." The provider's obligations aren't identical to yours, but the AI Act's transparency, documentation, and — especially in high-risk use areas — conformity-assessment obligations flow down into your system too. The technical documentation the provider gives you becomes the cornerstone of your own compliance.
Second, the market-access effect. If you offer your product or service to the EU market — selling a SaaS, publishing a mobile app, consulting for a European organization — being geographically in Turkey does not put you out of scope. Like GDPR, the AI Act works on "placing on the market," not "place of establishment."
Third, contractual pressure. This is the effect you'll feel fastest. When your European customer has to secure its own AI Act compliance, it will pass that on to you as a contract clause. You'll see the sentence "You shall provide technical documentation, risk classification, and human-oversight mechanisms for the AI component you supply" in far more RFPs in the coming months.
I once summarized it to a client like this: the AI Act may not punish you directly, but your European customer can disqualify you from the tender. For most SMEs, the second is a far more immediate and real threat than the first.
GPAI, systemic risk, and that famous threshold
The AI Act splits GPAI models in two: ordinary GPAI models and GPAI models carrying "systemic risk." The technical indicator of the distinction is the total compute used in training the model. When cumulative training compute exceeds the 10^25 FLOP threshold, the model enters the systemic-risk class and is subject to additional obligations: model evaluation, adversarial testing (red-teaming), monitoring of systemic risks, and reporting of serious incidents.
Why am I explaining this threshold? Because in Turkey, the number of teams fine-tuning domestic and open-source-based models — even training relatively small models from scratch — is growing. If you significantly retrain and distribute an open-weight model, under certain conditions you may find yourself in the "provider" position. The scale of the fine-tuning and the way the model is distributed are decisive here. Saying "we only fine-tuned it" does not automatically put you out of scope; the nature of your change matters.
| Category | Who's in scope | Key obligations |
|---|---|---|
| GPAI provider | Trains/places a foundation model | Technical docs, copyright summary, transparency |
| Systemic-risk GPAI | Training above ~10^25 FLOP | Plus: model evaluation, red-teaming, incident reporting |
| Downstream deployer | Embeds the model in its product | Use transparency, human oversight, risk management |
| Turkish firm selling to EU | Product/service on the EU market | Scope based on placing on the market |
The KVKK front: Turkey is drawing its own path
Here we arrive at a critical point. Turkey does not yet have a horizontal, EU-style AI law, but this does not mean a vacuum. KVKK published two important guidelines in 2026, and they clearly show where its supervisory approach is evolving.
In March 2026, KVKK published a guideline on "Agentic AI Systems." It addresses what agentic systems are, the functions of AI agents within these systems, possible use scenarios, and their risks in terms of personal data protection. A month earlier, in early March 2026, another guideline appeared on the "Use of Generative Artificial Intelligence Tools in the Workplace."
These guidelines are not binding — they aren't regulations. But to every executive who takes them lightly, I say: KVKK guidelines are a preview of what the Board will look at in an inspection. KVKK's growing interest in automated decision-making, combined with the right under KVKK Article 11 for the individual to object to decisions made by automated systems, produces a very clear expectation: every decision made by AI must be auditable by a human.
So in the EU, "human oversight" is a principle the AI Act makes mandatory for high-risk systems; in Turkey, a similar result arises via KVKK Article 11. The two regimes enter through different doors but meet in the same room.
An additional note: there is also a regulatory change on targeted advertising and AI, under Commercial Advertising and Unfair Commercial Practices, that took effect on August 1, 2026. So the sentence "there's no regulation in Turkey" has, as of 2026, largely lost its validity.
Dual compliance: managing the EU and KVKK under one roof
Among the exporter firms I advise, the approach that works best is not treating the two regimes as two separate projects. Because the overlapping area is very wide. Both regimes want you to:
- Build an inventory of the AI systems you use.
- Perform risk classification for each system.
- Establish human-oversight and objection mechanisms.
- Ensure data governance and transparency.
- Make decisions explainable and auditable.
I call this shared core "one inventory, two outputs." You keep a single AI-system inventory; from that inventory you can feed both your AI Act risk classification and, for KVKK, your personal-data processing inventory / VERBİS registration. ISO/IEC 42001 (the AI management system standard) is very useful precisely here as an umbrella: it gathers the governance disciplines both regimes expect under a single management system.
"Set up two separate compliance teams and you get double the cost and double the contradiction. Build the shared core once, then add the regime-specific edges later.
A concrete 90-day roadmap
Let's set theory aside and give a concrete plan you can fit into the next three months. I've applied this step by step with many organizations; it works.
First 30 days — Visibility. The goal is to give an honest answer to "what do we have?" List all AI components you use: third-party APIs (OpenAI, Anthropic, Google), embedded SaaS features (the AI assistant in your CRM, the call-center bot), models you've built yourself, and — the most overlooked — tools employees use without official permission. For each item, seek answers to three questions: Which data does it process? On whose behalf does it decide? Does it touch the EU market?
30–60 days — Classification. Label each system by AI Act risk tier: unacceptable risk (prohibited), high risk, limited risk (transparency obligation), and minimal risk. At the same time, mark for KVKK whether each system processes personal data and whether it produces automated decisions. This dual labeling clarifies where to concentrate your resources. Usually 70% of systems land in minimal/limited risk; save your energy for the remaining 30%.
60–90 days — Gap closure. For high-risk or automated-decision systems, gather human-oversight mechanisms, technical documentation, and — if you source from a vendor — provider documentation. Add AI Act and KVKK clauses to your contracts. Define an incident-response procedure: when a model produces an unexpected output, who intervenes, when, and how?
At the end of these three months you won't have perfect compliance — no one does. But when an inspection or customer query arrives, you'll be in a position to say, "we take this seriously; here are the steps we took." The worst position before a regulator is having done nothing; a well-intentioned, documented effort changes the tone entirely.
The GPAI Code of Practice and voluntary compliance
There's a tool that emerged in the AI Act ecosystem in 2025 and matured in 2026: the GPAI Code of Practice. It's a voluntary framework showing how providers will meet their obligations. Most major providers signed on; those who didn't must prove compliance by their own means.
As a Turkish firm on the downstream side, why should you care? Because whether your provider adheres to this code directly affects the quality of the documentation flowing to you. A provider that signed the Code of Practice gives you more standardized, more complete technical documents, which in turn eases your own compliance. When choosing a vendor, you should now look not only at price and performance but also at "does this provider supply me with AI Act documentation?"
Why ISO/IEC 42001 makes your job easier
Managing compliance by chasing each requirement one by one is exhausting and scattered. That's why I recommend a management-system standard as an umbrella to many organizations: ISO/IEC 42001, the AI management system standard. It lets you move from a structure that "starts from scratch for each new regulation" to a governance discipline that is "built once and continuously improved."
Its logic: ISO 42001 requires risk assessment, role and responsibility definition, documentation, monitoring, and continuous improvement across the lifecycle of your AI systems. These requirements largely overlap with the governance behaviors both the AI Act and the KVKK guidelines expect. So while setting up the standard, you're actually building the shared core of both regulatory regimes too.
There's also a commercial face to certification. When a European customer asks, "do you have AI governance?", showing your ISO 42001 certificate is far more powerful than a long explanation. Certification standardizes trust. For small teams, full certification may feel heavy at first; in that case, using the standard's framework as a roadmap and deferring the certificate is entirely reasonable.
Let me say it plainly: the certificate is not an end, it's a means. The goal is to bring your AI use into an auditable, explainable, repeatable order. The certificate is an easy way to prove that — but if you don't have an order to prove, the certificate is meaningless too.
Urgency varies by sector
The urgency of compliance is not the same in every sector. Let me share the picture I see in the field, because this distinction is critical for directing your resources correctly.
Finance and insurance are the front-line sectors. Credit scoring, insurance pricing, fraud detection — all of these are both close to the AI Act's high-risk use areas and at the very center of KVKK's automated-decision provisions. If you're in these sectors, compliance is not a "when" question, it's a "now" question. On top of this, the banking regulator's own expectations also stack onto the picture.
Healthcare is the second most sensitive area. Applications like diagnostic support, patient triage, and image analysis fall into the high-risk category. Because a hospital's or health-tech firm's AI use touches human life directly, both the ethical and regulatory bar is at its highest.
Retail and e-commerce are in the mid-band. Recommendation systems and personalized pricing mostly stay in the limited-risk category, but attention is required when personalization approaches manipulation of consumer behavior. The targeted-advertising regulation that took effect on August 1, 2026 points exactly here.
Manufacturing and logistics are mostly more relaxed. Applications like predictive maintenance, quality control, and route optimization are generally minimal risk. But once you move to human resources, hiring, and employee monitoring, every sector enters the same high-risk zone — because it directly affects people's rights.
The practical lesson from this picture: whatever your sector, the HR- and customer-facing automated-decision systems are the area you must address first. An optimization model on the production line can wait; a model screening CVs in hiring cannot.
What happens if an information request arrives
Suppose you're not in the ideal scenario and one day a European business partner or a customer sends a formal information request about the AI component you use. Panic is the worst reaction. The good news: a measured, honest, documented response to an information request often turns the situation in your favor.
First clarify the scope of the request: exactly which system, which use, which data is being asked about? Then find the relevant system in your inventory and compile the documentation you have. If something is missing, saying "we have an improvement effort underway in that area, estimated completion is X" is far healthier than trying to hide it. Regulators and corporate auditors reward a mature, good-faith process, not perfection.
This is why inventory and documentation matter so much. A firm that tries to produce material from scratch when a request arrives struggles for weeks; a prepared firm compiles its existing documents in a few days and sends them. The difference is the difference between a crisis and a routine task. The real return on compliance work is exactly this: turning a bad day into an ordinary one.
A quick self-audit list
Here's the short list I use for a quick check before a meeting:
- Do we have a current inventory of all AI systems we use?
- Is each system labeled by AI Act risk tier?
- Are systems processing personal data reflected in our KVKK inventory / VERBİS?
- Is human oversight and an objection path defined for every automated-decision system?
- Have we requested AI Act documentation from our vendors?
- Do our contracts contain AI compliance clauses?
- Do we have a policy on employees' shadow-AI use?
- Do we have an AI incident-response procedure?
If you answer "no" to most of these eight questions, don't worry — most firms start there today. What matters is having a plan that will turn this list into "yeses" within six months.
Frequently asked questions
"We only use AI internally, we don't sell anything to the EU. Even so?" In terms of the AI Act, if there's no direct placing on the market, the high-risk-system obligations may not press on you. But the KVKK side is active: every internal AI tool that processes employee or customer data is within KVKK's scope. Also, if internal systems produce automated decisions (e.g., CV screening in HR), KVKK Article 11 and discrimination risks come into play.
"We fine-tune an open-source model. Did we become a provider?" It depends. The scale of your change, whether you re-place the model on the market, and your distribution method are decisive. A light fine-tune for internal use only versus distributing the model to the community as a new GPAI are very different things. If in doubt, assess the nature of your change together with a lawyer.
"If the KVKK guidelines aren't binding, why should I care?" Because a guideline is a map of what the Board will look at in an inspection. Its being non-binding doesn't mean "you can ignore it"; it means "not yet a penalty provision, but this is the direction of expectation." A firm that acts in line with the guideline is deemed to have shown good faith and due care in an inspection.
"Our budget is limited, where should we start?" With the inventory. Without spending any money, just answer the question "which AI systems do we have, which data do they process, which decisions do they make?" Visibility is the cheapest and highest-return first step of compliance.
What to do now
What changed on August 2, 2026 was not the text of the regulation; it was the tools in the regulator's hands. Supervision and enforcement powers over GPAI providers are now active, and this will reflect onto your table too, along the supply chain. The right reading for Turkish companies: even if you are not a direct GPAI provider, this framework will confront you at every point where you touch the EU market and in every European customer contract. On top of this, KVKK is drawing an increasingly clear framework around automated-decision processes and generative-AI use through its own guidelines.
The most practical move is to unite the two regimes under a shared governance core and complete the visibility-classification-gap-closure cycle over the next 90 days. The firm that starts this today won't be caught unprepared by a European customer's compliance question six months from now; the one that doesn't will either lose the tender or try to compensate at the last minute at a far higher cost. The regulation's teeth are real now; but the good news is that what you need to do is also, finally, genuinely clear.
Consulting Pathways
Consulting pages closest to this article
For the most logical next step after this article, you can review the most relevant solution, role, and industry landing pages here.
AI Agents and Workflow Automation
Move beyond single-step chatbots to AI workflows orchestrated with tools, rules and human approval.
AI Governance, Risk and Security Consulting
A governance framework that makes enterprise AI usage more sustainable across data, access, model behavior and operational risk.
Enterprise AI Architecture Consulting for CTOs
Technical leadership consulting to move AI initiatives from isolated PoCs into secure, scalable and production-ready architecture.