Skip to content
Contact

ARCH Teknoloji · Article

THE AI-REGULATION RELATIONSHIP: HOLDING ON IN THE AGE OF AI

The global landscape, the cost of compliance, and the de facto framework shaped by KVKK in Türkiye

Abstract

The real question is not which model, but who is responsible when something goes wrong: case law, the cost of compliance, and the de facto framework shaped by KVKK in Türkiye.

When a company decides to build an AI-assisted feature or a business automation, the technical question usually comes first: "Which model will we use, where will we pull the data from, how will the automation be set up?" The legal question is often asked too late or not at all: "Who is responsible when this system makes a mistake?"

This question exposes a starker reality than it first appears. AI is now part of everyday business practice, yet there is no clear consensus, at either the global or the local level, on who will be held responsible for the outcomes these systems produce and under what framework, who will sign off, and what happens if a mistake is made. The European Union withdrew the AI Liability Directive it had worked on for years entirely in 2025. In the United States, regulation is advancing in a fragmented way, state by state. In Türkiye, there is not yet a dedicated "Artificial Intelligence Law."

It is easy to read that last sentence and conclude that "there is a gap in Türkiye," but that would be wrong. Turkish law is not standing still waiting for AI; existing frameworks such as the Personal Data Protection Law (KVKK), the Turkish Code of Obligations, and the Consumer Protection Law, shaped by Board decisions and court precedents, are in effect filling this space. The real risk is not the absence of a law; it is that companies using AI without knowing how this indirect framework works are left with blind spots.

In this article, we will first briefly sketch the global landscape and then address the real cost of regulation. But we will cover most of the ground on Türkiye specifically: data processing risks, the absence of legal personhood for AI and its effect on the chain of liability, and where Turkish law is evolving in light of European precedents. Alongside sourced findings, we will also share how we see this picture from within, managing projects and corporate reporting at a technology company, because the place where this gap is really felt is not the courtroom but the management meeting.

The Global Landscape: Where Does Regulation Stand?

According to data from the OECD's official AI Policy Observatory, 69 countries and the European Union have reported more than 800 national AI policy initiatives to this shared database (OECD.AI, 2026a). This is a sign of awareness on a global scale; but the gap between awareness and binding regulation is the real issue we will address in the later sections of this article.

The 2026 AI Index Report by Stanford University's Institute for Human-Centered AI is recognized in academia as the most comprehensive and most widely cited independent study in this field. The report's finding is clear: while AI capabilities advance rapidly, the regulatory, evaluation, and transparency mechanisms needed to govern them cannot keep pace; in short, there is a "governance gap" (Stanford Institute for Human-Centered Artificial Intelligence, 2026).

Even the EU's own flagship regulation is part of this picture. Full compliance obligations for high-risk systems under the AI Act were originally set to take effect on August 2, 2026; but according to the European Parliament's official legislative tracking platform, the Council and Parliament moved that date to December 2, 2027 for standalone systems and to August 2, 2028 for systems embedded in products. The rationale was technical: harmonized standards and national supervisory mechanisms were not yet ready (European Parliament, 2026).

This picture is actually nothing to be afraid of. By its nature and structure, law follows events rather than leading them; technology is lived first, the problem emerges first, and law takes shape after seeing it. It is vital but slow; this is not a flaw but the way law works. In periods when the law has not yet caught up, companies and individuals proceed with the existing general frameworks (in Türkiye, such as KVKK, the Turkish Code of Obligations, and the Consumer Protection Law). As the law develops, these general frameworks gradually become more specialized, turning into sharper, field-specific rules; exactly as the EU is doing with the AI Act and the Digital Omnibus, and as Türkiye is doing in effect by interpreting existing legislation.

In the United States, the picture is even more fragmented. There is no comprehensive AI law at the federal level; instead, states are moving on their own. According to the National Conference of State Legislatures, 38 states adopted roughly 100 AI-related measures in 2025, and that number continues to grow in 2026 (NBC News, 2026). On top of this, in March 2026 the White House launched an initiative proposing to constrain state AI regulations under a central framework, so federal-state tension within the US is also part of the picture (Wikipedia contributors, 2026).

Türkiye, for its part, sits in the "no law yet, but no complete gap either" category in this picture. The Grand National Assembly of Türkiye's 28th Term Artificial Intelligence Research Commission published its report No. 260 in March 2026; this is the first institutional parliamentary document to address Türkiye's AI law debate holistically (SETAV, 2026). The report recommends establishing a Turkish Artificial Intelligence Authority and ratifying the Council of Europe Framework Convention on Artificial Intelligence. But this is a roadmap; for it to become law, a separate bill must pass the General Assembly of the Grand National Assembly, and there is no firm date (Sanal Hukuk, 2026).

Why Regulate: Lessons From Case Law

What best explains why regulation exists are concrete cases that show the cost of a regulatory gap. Two of these cases show, from two different angles, where human oversight should stand.

The first example comes from Italy. Deliveroo managed shift access for the independent riders delivering food in Italy through an algorithm called "Frank." The algorithm calculated a reliability score based on how often riders canceled delivery shifts they had booked in advance, and used that score to set riders' priority for access to future shifts. In December 2019, three local federations affiliated with CGIL, Italy's largest trade union confederation, sued Deliveroo Italy before the Court of Bologna, arguing that the system was discriminatory. According to the claim, the algorithm made no distinction as to why a rider canceled a shift, whether for a legally protected reason such as illness, childcare, or exercising the right to strike, or out of ordinary unwillingness, and penalized all of them equally with a lower score (Pietrogiovanni, 2021).

In December 2020, the Court of Bologna ruled in favor of the unions and ordered Deliveroo to pay damages. The court's reasoning mattered: the case was treated not as a classic "employee or independent contractor" classification dispute, but as a matter of discrimination arising directly from algorithmic management. In the court's view, the problem was not that the algorithm was malicious but that it was blind: the system did not distinguish between a rider who canceled a shift for a legally protected reason and one who canceled out of mere unwillingness, penalizing both in the same way. The court also specifically noted that it was technically possible for Deliveroo to train the algorithm to make this distinction, but that choice was not made (Clifford Chance, 2021).

The second example comes from the United States and reaches an almost opposite conclusion about where an algorithm should stop. Eric Loomis, charged in Wisconsin in connection with a drive-by shooting, pleaded guilty to some of the charges and went to court. The presentence report included a recidivism risk score for Loomis calculated by a proprietary software called COMPAS. The judge referred directly to this score when denying Loomis parole and sentencing him to the maximum penalty. Loomis appealed, arguing that keeping the workings of the algorithm secret as a trade secret violated his right to challenge and question the score, that is, his due process guarantees; he also objected to the use of gender as an input in calculating the score.

In 2016, the Wisconsin Supreme Court held that using COMPAS in sentencing decisions was not unconstitutional, but it did so within a specific limit: in the court's view, the algorithm was not making the decision; it merely offered the judge an additional source of information, and the final decision still rested with the judge. The court reached this conclusion on the grounds that Loomis's rights had not been violated, because he was able to challenge the outcome of the score and the judge was in a position to weigh the tool's potential weaknesses (Fine, 2018).

The Deliveroo and Loomis cases show the same principle from opposite sides. In Deliveroo, the mistake was this: the system had taken the human out of the loop and carried automation all the way to the final decision. In Loomis, the structure the court found acceptable was different; the algorithm comes as close as possible to the final point and provides information, but a human (the judge) still makes the final decision. The difference is not a technical detail but a fundamental design decision that determines where responsibility rests.

This principle resembles the concept of a limit in mathematics: a function can approach a point indefinitely without ever touching it. Automation should do exactly this; it should come as close as possible to the final decision point and take over all the work in between, but never touch the final point itself. Because the law does not grant personhood to any system, and something without personhood can be neither held liable nor punished. That is why the final decision, the final check, and the final point of value must always remain with a person: it must be a person who creates the real value, signs, and takes responsibility.

The Reality of Cost: The Compliance Burden in Numbers

The cost of regulation needs to be seen in numbers, not emotions, because what we call the "compliance burden" is often exaggerated or repeated without being properly understood. An analysis by the Brussels-based think tank CEPS of the European Commission's own impact assessment paints a clear picture: the cost of setting up a Quality Management System from scratch for a high-risk AI system is between €193,000 and €330,000, with roughly €71,400 added on top as annual maintenance. CEPS specifically stresses that these figures have been distorted in some press and think-tank reports, and that the real cost is more nuanced than claimed (Centre for European Policy Studies, 2021).

There is an important nuance: this cost arises in full only if the company has no Quality Management System at all. For companies that already have a quality and compliance infrastructure, the cost falls significantly; here, too, a recurring theme emerges: organizational readiness, not the shock of regulation, is the real factor that determines compliance.

The scale of these figures is especially painful for small and medium-sized enterprises. An analysis by the Italian consultancy Intellera, based on the European Commission's official impact assessment, argues that it is unbalanced in terms of economies of scale for small businesses to bear these costs alone, but that early investment in technology through common and shared compliance solutions can reduce this imbalance (Intellera Consulting, 2024). In other words, the cost is real but not unavoidable; it can be absorbed with the right timing and the right choice of infrastructure.

This is exactly where the logic of resource optimization comes in: rather than investing in more hardware and a more complex architecture than necessary, allocating resources according to the real needs of the work. At Arch, we apply this principle ourselves: we host and serve the software's backend and frontend on plain RAM servers without GPUs, while hosting the local models that process personal data, and the personal data that must be retained, on our own physical infrastructure (on-premises hardware), and we ensure these two layers communicate securely with each other. This approach minimizes hardware investment costs while keeping data at maximum security. Regulatory compliance thus stops being a large, one-time investment and becomes a natural result of the right architectural decisions.

The Counter-Model: Regulatory Sandboxes

The tool that best shows regulation is not always a restrictive wall is the regulatory sandbox. This model first emerged in the financial sector and is now being adapted to AI: a regulator allows companies to test a new technology in a controlled, supervised environment, temporarily relaxing or not applying certain rules, while closely monitoring the risks in return. In academic terms, regulatory sandboxes are described as experimental governance regimes in which regulators support participants but also temporarily relax or suspend rules to facilitate the controlled testing of innovations (Papageorgiou, 2026).

In the UK, the pioneer of this model is the Regulatory Sandbox of the Information Commissioner's Office (ICO), which has been operating for more than eight years. Alongside it are the financial regulator FCA's own sandbox and the "AI Lab" initiative launched in 2024. According to an academic review, concrete cooperation mechanisms such as staff exchanges were established between the ICO and the FCA, enabling joint work on overlapping topics such as anti-money laundering and anonymization (Papageorgiou, 2026).

Singapore, meanwhile, follows a different philosophy: rather than setting hard rules, it offers iterative guidance through a "light-touch" approach. The country runs several mechanisms at once, such as the Generative AI Evaluation Sandbox, the AI Verify Sandbox for small businesses, and the Data Protection Trustmark. According to a comparative analysis by the development bank ADB, some of these tools are not "regulatory sandboxes" in the classic sense but can be better described as "technology sandboxes"; they offer room for trial and learning rather than rule exemptions. Singapore's financial regulator MAS, on the other hand, also runs its own sandbox offering supervised testing in the classic sense. This dual structure is referred to in the academic literature as a "quasi-regulatory" approach (Asian Development Bank, 2026).

The Brazilian example is especially striking, because it is one of the few countries that chose to set up a national sandbox while it still had no comprehensive AI law. Brazil's National Data Protection Authority (ANPD) operates a Regulatory Sandbox authorized under Complementary Law No. 182 of 2021; in this environment, ANPD, regulated institutions, and relevant parties test AI and machine learning technologies, with a focus on algorithmic transparency and compliance with Brazil's general data protection law (OECD.AI, 2026b). The Future of Privacy Forum's comparative analysis emphasizes this point in particular: rather than waiting for regulation, Brazil chose to learn first, wanting to see what works in practice before writing the law (Future of Privacy Forum, 2025).

What the three examples have in common is this: none of them says "let's remove the rules"; all three say "let's understand first, then set the right rule." This does not contradict the fact that law follows events; on the contrary, it accepts that fact and builds a mechanism accordingly. Rather than leaving a complete gap in areas the law has not yet caught up with, the sandbox offers a supervised and reversible intermediate step. For Türkiye, too, this model is open to consideration as part of the roadmap proposed by the parliamentary report; indeed, the commission report also refers to regulatory sandboxes.

The Situation in Türkiye

The Data Question

The first and most concrete legal question facing a company using AI in Türkiye is almost always about data. The Personal Data Protection Authority now offers official and direct guidance on this. The Authority's Guide on Generative AI and the Protection of Personal Data states clearly that AI should be approached in a human-centric, safe, and responsible way that serves the public good, and that the use of these systems brings ethical and legal issues with it. The guide also requires that systems interacting directly with users, such as chatbots, clearly disclose that they are based on generative AI, and that data controllers implement technical controls against vulnerabilities specific to generative AI, such as prompt injection (Kişisel Verileri Koruma Kurumu, 2026; Zümbül Avukatlık Bürosu, 2026).

The most critical provision of this guide concerns data localization: where generative AI systems are used through service providers established abroad, the transfer of personal data abroad must be carried out in accordance with Article 9 of KVKK and the relevant regulation. According to the Authority's own official Guide on Cross-Border Transfers, this article operates on a three-tier logic: first, it is checked whether there is an adequacy decision for the country to which the data will be transferred; if not, appropriate safeguards (such as standard contracts or binding corporate rules) are sought; and if these are also absent, data can leave the country only in limited and exceptional cases (Kişisel Verileri Koruma Kurumu, 2024). Türkiye is counted among the countries with a strong tendency toward data localization, which creates a significant point of friction in practice for companies using AI tools that rely on global cloud infrastructure (Genesis Hukuk, 2025).

This framework should not be left as an abstract legal text. The approach that works in practice starts with correctly classifying the type of data and the regime it is subject to. In practice, three tiers can be distinguished. First, if the data is insignificant and anonymized, there is no legal obstacle to storing it abroad; in the Authority's own guidance, anonymization is at the top of the recommended preventive measures. Second, if the data is meaningful but there is an appropriate safeguard, such as an adequacy decision that Türkiye considers safe or standard contractual clauses, the data can be shared with a large and reliable institution abroad; what the company must do here is duly notify this transfer within the framework of KVKK Article 9. Third, if the data is at a sensitivity level that requires it to remain in Türkiye, a server center that is secure both technologically and physically, to industry standards, should be chosen; this center must operate in line with industry rules such as regular backups, snapshots, and logging. Where the data is at the highest confidentiality level and must never leave the organization, core-level security measures come into play, such as a hardware investment tailored to the needs of the work, sound network procedures, and zero-trust policies.

There is a balance to strike here: data should never be valued more than it needs to be. Approaching data emotionally is the wrong reflex; data given more importance than necessary, which is in fact meaningless, can create serious storage and security costs. At Arch, we turned this principle into a concrete architecture: we host and serve the software's backend and frontend layers on plain RAM servers without GPUs, while hosting the local models that process personal data, and the personal data that must be retained, on our own physical infrastructure, and we ensure these two layers communicate securely with each other. This approach minimizes hardware investment costs while keeping data at maximum security: regulatory compliance here is not a large, one-time burden but a natural result of the right architectural decisions.

Legal Personhood and the Chain of Liability

Once the data question is resolved, a more fundamental question arises: who will be responsible when an AI system makes a mistake? The answer depends first on "who" AI is in the eyes of the law, and the answer is clear: no one. The European Parliament's position on this has shifted markedly over the years. In 2017, the Parliament's Committee on Legal Affairs prepared a report proposing the concept of "electronic personhood" for autonomous robots. But in its resolution of October 20, 2020, the Parliament stepped back from this line and made clear that granting legal personality to AI systems was not necessary, and that instead the persons who create, maintain, or control the risk associated with the system could be held liable in line with widely accepted concepts of liability (İstanbul Okan Üniversitesi Hukuk Fakültesi, 2022).

This also aligns fully with the concept of the person in Turkish law. In the Turkish legal system, being a subject of rights and obligations, that is, being considered a "person," is a legally defined and limited category: a natural person or a legal entity. An AI system is neither a human being nor a structure with organs like a company; it therefore does not fully fit into any of the existing categories of personhood.

Something without personhood can be neither held liable nor punished. Simple as this principle seems, the subtlest point in practice is hidden here: if responsibility is always to remain with a person, a system must be designed in which that person can make their decision meaningfully. This is where the question of "choosing the right tool" comes in. Today everyone talks about AI and tries to hand every problem to large language models, but real value does not come from hitting every piece with the same hammer. Rather than telling a large language model to "match" a data point and an input whose relationship should be clear and deterministic, establishing a direct deterministic match, for example with an OCR tool, gives a result that is both less costly and more reliable. The legal counterpart of this is also clear: how a deterministic system reached its result can be explained and audited, which makes human oversight genuinely possible; that is exactly what the Court of Bologna found lacking in its Deliveroo ruling.

AI itself is a very broad term. Saying "AI" without clarifying whether we are talking about a large language model, a classic machine learning model, OCR, or a vision-language model blurs both the technical and the legal debate. In the end, the goal is this: to let automation come as close as possible to the final decision, while guaranteeing that it never touches the final point itself. All the work in between is left to automation; the person who decides and signs focuses on the point where they create real value and makes the decision.

Two precedents in Europe show very clearly what happens when this principle is violated or ignored. In Germany, the CJEU's SCHUFA judgment (C-634/21, December 7, 2023) held that credit scores generated by a credit agency count as "automated decision-making" under GDPR Article 22 when third-party lenders rely heavily on them; this liability falls not only on the bank granting the credit but also on the agency producing the score (Matheson, 2024). In the Netherlands, the Hague District Court's SyRI ruling (February 2020) halted a fraud prediction algorithm targeting low-income populations, because the system was excessively opaque and the purpose of the data collected was not sufficiently specific (International Association of Privacy Professionals, 2026). Both rulings share the same message: a system being open to human oversight and audit is not an ornamental principle but a precondition of legal validity.

Recommendations for Companies

The first step in making this entire legal picture useful for a company is an inventory. No step is reliable if it is taken without knowing in which of an organization's processes AI is used, which types of data those processes touch, and which regime those data fall under (anonymous and transferable, required to remain in Türkiye, or required never to leave the organization). The Authority's own guidance implicitly confirms this: it states that data controllers must take appropriate technical and administrative measures to prevent the unlawful processing of personal data, and that this begins with a data protection impact assessment (Kişisel Verileri Koruma Kurumu, 2026). In practice, this should not be a one-off audit but a checkpoint that becomes routine before any new AI feature is put into service; a step that should work exactly like a project management discipline.

The second step is choosing the right tool for the right job. A company's reflex to hand every problem to a large language model is a wrong assumption in terms of both cost and legal explainability. Preferring classic, deterministic methods where deterministic relationships can be established, and using AI where uncertainty and interpretation are truly required, both lowers cost and makes it possible to explain how the system reached its result. This explainability is not just a technical preference but a direct legal safeguard: a system's inability to explain its decision carries exactly the kind of blindness risk that the Court of Bologna penalized in Deliveroo's algorithm.

The third step is not to leave human oversight as an abstract principle but to turn it into a concrete workflow. The job of automation is to come as close as possible to the final decision: taking on all the intermediate steps, such as collecting and classifying data, carrying out preliminary analysis, and presenting possible options. But the final point itself, that is, the decision to approve, sign, or release, must always remain with a clearly defined person. In organizations where this distinction is blurred, the question of "who made the decision" goes unanswered when an error occurs; this is the most fragile point, both legally and operationally.

The fourth step is corporate reporting and documentation: this is the area truly owned not by lawyers but by those managing the project. When an AI feature is put into service, which type of data is processed, which safeguard is applied, and who holds the final decision point should become a standard part of the project documentation. Positioning this not as a burden but as an indicator of the project's maturity improves both audit processes and the speed of internal decision-making.

The fifth step is to plan for cost early and realistically. CEPS's analysis, based on the European Commission's impact assessment, shows that the cost of a quality management system built from scratch is a significant burden, but that this cost varies largely depending on the compliance infrastructure the company already has (Centre for European Policy Studies, 2021). The right timing, taking on the compliance burden not all at once but spread across architectural decisions, can reduce the cost dramatically. An architecture built on the logic of resource optimization, allocating hardware according to the needs of the work rather than concentrating everything in a single expensive infrastructure, becomes both a technical and a legal advantage here.

The final step is to bring the sandbox logic inside the company. Brazil's ANPD or the UK's ICO and FCA model choose to understand before setting rules; companies can likewise run a new AI feature through a limited, supervised pilot phase before taking it straight to production. This makes both technical and legal risks visible early and at low cost; the company repeats internally, on a small scale, exactly what sandboxes do for public regulators.

Conclusion

Let us return to the question we asked at the start of this article: is regulation an obstacle, or the new rules of the game? The answer does not fit into a single sentence, but it points in a clear direction. Although regulations often seem frightening, exhausting, and restrictive to companies and individuals, they are in fact structures that work in everyone's interest. The right players, making the right choices, can automate their work without breaking the law; the point is not to escape regulation but to read it correctly.

By its nature, law follows events; it is vital but slow. In periods when the law has not yet caught up, companies proceed with the existing general frameworks, and as the law develops, these frameworks gradually become more specialized. This is exactly what is happening in Türkiye today: there is not yet a dedicated Artificial Intelligence Law, but existing frameworks such as KVKK, the Turkish Code of Obligations, and the Consumer Protection Law are in effect filling this gap, guided by the roadmap set out in the Grand National Assembly's March 2026 report.

What really makes the difference for companies is seeing this transition period not as a threat but as a design opportunity. Classifying data correctly, choosing the right tool for the right job, always keeping the final decision point with a person, and embedding all of this in institutional memory and documentation: beyond being a legal necessity, these are also the cornerstones of building a long-lived, trustworthy technology company.

References

  1. Asian Development Bank. (2026, January 28). Let AI Developers Play in the Regulatory Sandbox. Asian Development Blog. https://blogs.adb.org/blog/let-ai-developers-play-regulatory-sandbox
  2. Centre for European Policy Studies. (2021). Clarifying the costs for the EU’s AI Act. CEPS. https://www.ceps.eu/clarifying-the-costs-for-the-eus-ai-act/
  3. Clifford Chance. (2021, June). The Italian courts lead the way on explainable AI. https://www.cliffordchance.com/insights/resources/blogs/talking-tech/en/articles/2021/06/the-italian-courts-lead-the-way-on-explainable-ai.html
  4. European Parliament. (2026). Legislative Train Schedule: Digital Omnibus on AI. https://www.europarl.europa.eu/legislative-train/package-digital-package/file-digital-omnibus-on-ai
  5. Fine, S. (2018). Does the use of risk assessments in sentences respect the right to due process? A critical analysis of the Wisconsin v. Loomis ruling. Law, Probability and Risk, 17(1), 45-53. https://doi.org/10.1093/lpr/mgy001
  6. Future of Privacy Forum. (2025, August 4). Balancing Innovation and Oversight: Regulatory Sandboxes as a Tool for AI Governance. https://fpf.org/blog/balancing-innovation-and-oversight-regulatory-sandboxes-as-a-tool-for-ai-governance/
  7. Genesis Hukuk. (2025, December). Yapay Zeka Hukuku: ZKP ile KVKK İhlalsiz Veri Kullanımı. https://www.genesishukuk.com/tr/yayinlar/yapay-zeka-hukuku-zkp-kvkk-veri-gizliligi
  8. Intellera Consulting. (2024). An analysis of the cost of compliance with the AI Act for SMEs. https://www.intelleraconsulting.com/wp-content/uploads/2024/07/AIactpaper_v16_singola_web.pdf
  9. International Association of Privacy Professionals. (2026). Digital welfare fraud detection and the Dutch SyRI judgment. IAPP. https://iapp.org/news/a/digital-welfare-fraud-detection-and-the-dutch-syri-judgment
  10. İstanbul Okan Üniversitesi Hukuk Fakültesi. (2022). Yapay Zeka Sistemlerinin Hukuki Kişiliği. Hukuk Bülteni. https://www.okan.edu.tr/hukuk/sayfa/8088/yapay-zeka-sistemlerinin-hukuki-kisiligi/
  11. Kişisel Verileri Koruma Kurumu. (2024). Kişisel Verilerin Yurt Dışına Aktarılması Rehberi (KVKK Yayınları No: 48). https://www.kvkk.gov.tr/Icerik/8142
  12. Kişisel Verileri Koruma Kurumu. (2026). Üretken Yapay Zekâ ve Kişisel Verilerin Korunması Rehberi (15 Soruda). https://www.kvkk.gov.tr/Icerik/8547
  13. Matheson. (2024, January 16). CJEU Delivers Important Decision on Automated Decision-making Under the GDPR. https://www.matheson.com/insights/cjeu-delivers-important-decision-on-automated-decision-making-under-the-gdpr
  14. NBC News. (2026, January 6). New laws in 2026 target AI and deepfakes, paid leave and rising Obamacare premiums. NBC News. https://www.nbcnews.com/politics/politics-news/2026-new-laws-states-elections-midterms-ai-obamacare-aca-paid-leave-rcna247602
  15. OECD.AI. (2026a). OECD.AI Policy Observatory: National AI policies & strategies. https://oecd.ai/en/dashboards/national
  16. OECD.AI. (2026b). Regulatory Sandbox (Brazil’s ANPD). https://oecd.ai/en/dashboards/policy-initiatives/regulatory-sandbox
  17. Papageorgiou, A. (2026). Getting Regulatory Sandboxes Right: Design and Governance Under the AI Act. European Journal of Risk Regulation. https://www.cambridge.org/core/journals/european-journal-of-risk-regulation/article/getting-regulatory-sandboxes-right-design-and-governance-under-the-ai-act
  18. Pietrogiovanni, V. (2021). Deliveroo and Riders’ Strikes: Discriminations in the Age of Algorithms. International Labor Rights Case Law, 7(3), 317-322. https://brill.com/view/journals/ilrc/7/3/article-p317_317.xml
  19. Sanal Hukuk. (2026). Yapay Zeka Hukuku 2026: Türkiye’de Güncel Durum ve Kapsamlı Rehber. https://sanalhukuk.org/yapay-zeka-hukuku-rehber
  20. SETAV. (2026). Türk Yapay Zeka Kanununa Doğru: TBMM Raporunun Hukuki Değerlendirmesi. Siyaset, Ekonomi ve Toplum Araştırmaları Vakfı. https://www.setav.org/turk-yapay-zeka-kanununa-dogru-tbmm-raporunun-hukuki-degerlendirmesi
  21. Stanford Institute for Human-Centered Artificial Intelligence. (2026). The 2026 AI Index Report. Stanford University. https://hai.stanford.edu/ai-index/2026-ai-index-report
  22. Zümbül Avukatlık Bürosu. (2026). Üretken Yapay Zeka Rehberi KVKK Yayınlanmıştır. https://www.zumbul.av.tr/tr/duyurular/uretken-yapay-zeka-rehberi-kvkk-yayinlanmistir