Which Rules Bind a Financial Institution Using AI?
Türkiye has no separate AI statute. That does not make it a free space — the rules binding your model are already in force, they just do not sit under a heading that says "artificial intelligence".
The first question a bank, insurer or payment institution asks before putting a model into production is usually: "Is there a regulation covering this?" In the form it is asked, the answer is no. There is no single, comprehensive statute addressing artificial intelligence.
But that is the wrong question. The rules binding your model were written before AI arrived, and they apply by outcome, not by technology. Process personal data and KVKK applies. Run inside a bank's information systems and BDDK applies. Sit in customer onboarding or monitoring and MASAK applies.
KVKK: an automated decision is a decision that can be challenged
The clearest provision touching a model's output in Türkiye is Article 11 of Law No. 6698 on the Protection of Personal Data. Paragraph 1, subparagraph (g) gives a person the right to object to a result reached against them through analysis of their data exclusively by automated systems.
Subparagraph (ğ) of the same paragraph covers the right to claim compensation for damage caused by unlawful processing. The procedure sits in Article 13: the controller must conclude the request as soon as possible given its nature and within thirty days at the latest.
In practice: if a credit refusal, a limit reduction or a risk score comes only from an automated system, you may receive an application demanding that the decision be reviewed and a human be brought into it — and a thirty-day clock starts. The model being correct does not remove the duty; what is required is being able to show how the decision was reached.
BDDK: a model is an information system, not an exception to one
The Regulation on Banks' Information Systems and Electronic Banking Services was published in the Resmî Gazete of 15 March 2020, issue 31069, entered into force on 1 July 2020, and replaced the 2007 circular on information systems management.
It sets the minimum procedures and principles for managing the information systems a bank uses, managing the risks arising from them, and the controls that must be established. A model cannot sit outside that frame because it is called AI: if it runs in bank processes it is an information system, and it carries the same governance, the same controls and the same expectation of auditability. More: BDDK information systems compliance guide.
What does it cost?
Administrative fines under KVKK sit in Article 18 and are revalued at the start of each calendar year under Article 17 of the Misdemeanours Law No. 5326 and repeated Article 298 of the Tax Procedure Law; the rate applied for 2026 was 49%.
As one example, failure to meet the duty to inform carries a 2026 band of TRY 85,437 to TRY 1,709,200. That is a single line item; data security duties and failure to comply with Board decisions sit in their own bands, and the current table is published by the Authority itself.
The link is direct: if a model processes personal data, whether your privacy notice covers that processing is not a compliance detail — it is an obligation with a fine attached.
Where are you allowed to run the model?
In banking, the real obstacle in front of AI is usually not the model but where it runs. The regulation is explicit: the requirement for banks to keep their primary and secondary systems inside Türkiye is preserved.
- Where outsourcing or cloud services are used for primary or secondary systems, the information systems the provider uses in that scope and their backups must also be held inside Türkiye.
- Cloud may be taken as a private cloud model, over hardware and software resources allocated to a single bank.
- Outsourcing under a community cloud model is subject to the Board's permission.
So "let's run the model on a cloud provider" is not an infrastructure preference, it is a regulatory decision — and the answer has to be known before procurement, not after.
MASAK: automation does not take over the duty
Models are widely used in customer identification, monitoring and suspicious transaction reporting. The critical point is that automation does not assume the obligation: the duty to report belongs to the institution, not to the system. An alert that was never raised has to be as explainable as an alert that was raised and closed. More: MASAK obligations checklist.
What has to be watched
| Source | Where it binds your model |
|---|---|
| KVKK and Board decisions | Objection to automated decisions, notice, lawful basis, retention periods |
| BDDK regulations | Information systems governance, controls, outsourcing and auditability |
| MASAK regulations | Customer identification, monitoring and suspicious transaction reporting |
| SPK regulations | Suitability and appropriateness in investment services, and disclosure duties |
These four come from four authorities on four timetables, and none of them is published under an "artificial intelligence" label. That is the real difficulty for a team shipping a model: the regulation you are looking for does not arrive under the name you are looking for.
Frequently Asked Questions
Sources
- Mevzuat Bilgi Sistemi — Law No. 6698, Article 11
- Resmî Gazete, 15.3.2020 / 31069 — Regulation on Banks' Information Systems and Electronic Banking Services
- Personal Data Protection Authority — current administrative fine amounts
- BDDK · MASAK · SPK