AI Act — (AB) 2024/1689 bilgilendirme kartı (AES)
| |

EU Artificial Intelligence Act (AI Act): A Risk-Based Guide for Turkish Exporting Manufacturers

Introduction: Why a New AI Law?

The European Union created the world's first comprehensive legal framework regulating artificial intelligence horizontally with the AI Act (Regulation (EU) 2024/1689), which came into force in 2024. The law focuses on AI systems themselves, rather than a specific sector, classifying them according to the risks they pose. The aim is to enable innovation in reliable AI while protecting fundamental rights, health, and safety.

The most important feature of the law is that it is not limited geographically to the EU borders. If the output of an artificial intelligence system is used within the EU, or if the system is offered to the EU market, the law is applicable regardless of where the supplier or manufacturer is located. This is a point that directly concerns Turkish manufacturers exporting products to the EU.

This article aims to explain the rationale behind the Law, the levels of risk, and especially the obligations regarding AI components embedded in a product, within an unbiased and informative framework. The goal is not to provide commercial guidance, but to offer a solid foundation for exporting manufacturers to assess their own situation.

  • Regulation (EU) 2024/1689 is the first comprehensive horizontal EU regulation on artificial intelligence.
  • It is not the sector but the systemic risk level that is decisive.
  • Non-EU producers may also be included in the coverage when the output or product reaches the EU market.
  • This text is for informational purposes only and does not constitute legal advice.

Risk Categories: Four-Tier Approach

The core of the law is a risk-based approach. Artificial intelligence applications are divided into four main categories according to the risk they pose, and a different level of liability is defined for each category. As the risk increases, the liabilities become heavier; those that pose an unacceptable risk are prohibited altogether.

This categorization means that the same technology can be treated differently depending on the context. For example, an image recognition model might be considered minimally risky when used in a game, but high-risk when used in recruitment decisions or a machine's security function.

  • Unacceptable risk (prohibited): Practices such as social scoring, manipulative techniques, and certain biometric applications are prohibited.
  • High risk: Systems that can have a serious impact on health, safety, or fundamental rights are subject to strict compliance, documentation, and monitoring requirements.
  • Limited risk: For example, chatbots and generative content; these essentially impose transparency obligations (the user must know they are interacting with an AI).
  • Minimal risk: The vast majority of applications can be used freely without additional obligations.
  • A separate transparency and documentation regime is envisioned for general-purpose AI (GPAI) models.

High-Risk Systems and Product-Embedded Artificial Intelligence

For Turkish manufacturers, the most critical issue is the classification of high-risk systems. The law defines high risk in two ways. Firstly, artificial intelligence that is a safety component of a product covered by existing EU product safety legislation, or the product itself (Annex I). Secondly, standalone systems used in specific areas listed in Annex III; for example, employment, education, critical infrastructure, or justice.

Annex I pathway directly concerns product manufacturers. If artificial intelligence acts as a safety component in a machine, toy, medical device, elevator or similar product, and that product is already subject to third-party conformity assessment under EU harmonization legislation (e.g., Machinery Directive, Toy Safety, Medical Device Directive), then this AI component may be considered high-risk. In this case, the obligations of the AI Act are integrated into the product's existing conformity assessment process.

Typical obligations for high-risk systems include risk management systems, data governance, technical documentation, record keeping, transparency, human oversight, appropriate accuracy, robustness, and cybersecurity. Many of these overlap with the CE marking logic that manufacturers are already familiar with in the context of product safety; the AI Act adds additional requirements specific to artificial intelligence on top of this logic.

  • Annex I: AI, which is a safety component of a product or the product itself, within the scope of product safety legislation.
  • Annex III: Independent high-risk systems in areas such as employment, education, critical infrastructure, and justice.
  • AI embedded in products already covered by CE standards, such as machinery, toys, and medical devices, can pose high risks.
  • Responsibilities: risk management, data governance, technical documentation, human oversight, robustness, and cybersecurity.
  • AI Act requirements are integrated into the product's existing conformity assessment; they are not a separate, parallel system.

Important Dates and Gradual Calendar

The law entered into force on 1 August 2024, but the obligations are being rolled out gradually, not all at once. This is a deliberate design to give manufacturers time to prepare. The following dates are based on the canonical text in Article 113 of Regulation (EU) 2024/1689.

The key implementation date in the canonical text for high-risk artificial intelligence embedded in products (Annex I) is August 2, 2027. This is the latest stage tied to product safety legislation and is a direct reference date for manufacturers integrating AI components into products, such as machines.

Important warning: The EU is implementing a process of change, known as the 'Digital Omnibus', which is scheduled to begin at the end of 2025 and postpone some high-risk stages. This change may postpone Annex III standalone systems to 2 December 2027 and Annex I embedded systems to 2 August 2028. The final publication and entry into force of this change in the Official Gazette has not been independently confirmed as of the date of this writing; therefore, manufacturers are advised to review their plans according to both the canonical 2027 date and the possible 2028 postponement, and to base their decisions on the current text in EUR-Lex.

  • August 1, 2024: The law came into effect.
  • February 2, 2025: Prohibitory measures (Part II) and general provisions (Part I) came into effect.
  • August 2, 2025: Obligations, governance, and penalties for general-purpose AI (GPAI) models came into effect.
  • August 2, 2026: General effective date of the law (most obligations including independent high-risk systems in Annex III).
  • August 2, 2027 (canonical): Key implementation date for high-risk AI embedded in Annex I product safety legislation.
  • Caveat: If the 'Digital Omnibus' amendment enters into force, the dates of 2 December 2027 for Annex III and 2 August 2028 for Annex I may apply; the current EUR-Lex text should be used.

What does this mean for Turkish producers and exporters?

For a Turkish manufacturer exporting products to the EU market, the first step is to determine whether their product contains an artificial intelligence component and whether this component serves a safety function. If the product already bears the CE mark under an EU product safety directive/regulation and contains an AI safety component, this component may fall under high-risk categories and create additional liabilities.

The good news is that many of these obligations are not entirely new. The logic behind technical documentation, risk assessment, and conformity assessment is familiar to manufacturers already familiar with product safety processes. The AI Act adds AI-specific layers on top of this process, such as data quality, human oversight, model robustness, and transparency. Manufacturers who prepare early can take advantage of the time offered by the phased timeline.

In practice, it is critical for manufacturers to clarify the division of roles and responsibilities with their customers (importers/distributors) and, if applicable, their authorized representatives in the EU. The law defines different obligations for suppliers, product manufacturers, importers, and distributors, and each actor in the supply chain needs to correctly understand their position. This assessment should be done on a product-by-product basis and using the current official text (EUR-Lex).

  • First step: Does the product have AI, and does it function as a security component?
  • Embedded AI in products already covered by CE marking may pose a high risk; liability is added to the existing process.
  • The logic behind the technical file and conformity assessment is familiar; AI-specific layers (data, human oversight, robustness) are added.
  • The roles within the supply chain (supplier, manufacturer, importer, distributor) must be clarified.
  • The assessment should be done on a product-by-product basis and according to the current EUR-Lex text.
  • The phased calendar offers a valuable window of time for early preparation.

Frequently Asked Questions

Why would the EU AI Law concern a Turkish manufacturer outside the EU?

The law is based on the principle of the system or its output being used in the EU market. If you export your product to the EU and artificial intelligence is included as a component in the product, you may be covered by the law even if your business is based in Türkiye. Therefore, geographical location alone does not provide exemption.

Does the AI embedded in my product automatically categorize it as 'high risk'?

No, it is not automatic. High risk is primarily dependent on two conditions: the AI must be a safety component of a product covered by EU product safety legislation (Annex I) or used in specific areas listed in Annex III. A simple feature that does not serve a safety function is generally assessed at a lower risk level. Classification should be done on a product basis.

When do liabilities begin for high-risk AI embedded in products?

According to the canonical text in Article 113 of Regulation (EU) 2024/1689, the key implementation date for high-risk AI embedded in Annex I product safety legislation is 2 August 2027. However, the EU's 'Digital Omnibus' simplification package may postpone this date to 2 August 2028; the final entry into force of this change must be confirmed and the current EUR-Lex text must be used as a basis.

Which practices are prohibited (considered an unacceptable risk) and since when have they been prohibited?

Social scoring, certain manipulative or exploitative techniques, and some biometric applications are prohibited as unacceptable and risky practices. These prohibitions are effective from February 2, 2025. For a full list of the scope of the prohibitions, see Article 5 of the Law.

Do general-purpose artificial intelligence (GPAI) models fall within this scope?

Yes, but under a separate regime. Transparency, technical documentation, and copyright obligations are stipulated for general-purpose AI models, and these provisions are effective from August 2, 2025. Additional obligations apply to models that pose systemic risks.

This content is for informational purposes only and does not constitute legal opinion or compliance assessment. The current official legislation text (EUR-Lex) should be used for precise requirements.

Other Topics