Turkish banks comply with BDDK rules when using AI primarily by applying the regulator's existing information systems and outsourcing frameworks to AI projects, since BDDK does not yet have an AI-specific regulation as of 2026, so institutions should verify current guidance before finalizing a compliance approach. The Banking Regulation and Supervision Agency's information systems management regulation and its 2021 guideline on cloud informatics services already require board-level risk assessment, data classification, and in many cases explicit notification or approval before critical banking functions, which can include AI-driven decisioning, move to cloud or third-party infrastructure. Where an AI system is developed or hosted by an external vendor, it typically falls under BDDK's destek hizmeti, or support services, outsourcing rules, requiring a documented risk assessment, contractual audit rights, and continuity planning regardless of whether the underlying technology is called AI. Turkey's KVKK data protection law runs in parallel and restricts how customer data used to train or run AI models gets processed and transferred across borders. Given the pace of regulatory attention on AI, Turkish banks should expect BDDK to issue more specific guidance and should build governance practices now that satisfy either an outsourcing review or a future AI-specific rule. Nanobase AI helps Turkish banks structure AI deployments to align with current BDDK outsourcing requirements and KVKK data protection obligations.
Two frameworks apply until BDDK issues AI-specific rules
As of 2026, BDDK has not published an AI-specific regulation, so Turkish banks running AI projects need to route them through two existing frameworks: BDDK's information systems and outsourcing rules, and KVKK's data protection requirements, and confirm current guidance before finalizing any compliance approach. Treating an AI project as automatically outside regulatory scope because no AI-specific rule exists is the mistake to avoid, since BDDK's existing destek hizmeti, or support services, outsourcing rules apply to any external vendor or infrastructure a bank relies on for critical functions, regardless of what the underlying technology is called.
A practical compliance path
| Step | What it covers | Relevant framework |
|---|---|---|
| 1. Classify the AI function | Is it critical, and does it touch customer data or credit decisions | BDDK information systems regulation |
| 2. Assess the deployment model | Cloud, on-premise, or hybrid, and where processing occurs | BDDK 2021 cloud informatics guideline |
| 3. Vendor risk assessment | If external, document risk, audit rights, continuity plan | BDDK destek hizmeti outsourcing rules |
| 4. Data mapping | What personal data the AI system processes and where it flows | KVKK |
| 5. Board-level sign-off | Formal risk assessment and approval before go-live for critical functions | BDDK information systems regulation |
Working through this sequence produces documentation that satisfies either an outsourcing review today or a future AI-specific rule, which is the safest posture given how actively regulators globally are moving on AI oversight.
Cross-border data transfer is the recurring KVKK friction point
Many AI deployment options, particularly hosted LLM APIs from providers outside Turkey, involve customer data crossing borders, and KVKK restricts this kind of transfer unless specific legal bases or safeguards are in place. This is one of the strongest practical arguments Turkish banks have for preferring on-premise or in-country private cloud deployment for any AI system touching customer or transaction data, since it removes the cross-border transfer question rather than requiring the bank to justify it for every new AI feature. Where a hosted foreign API is unavoidable for a specific use case, the data mapping exercise needs to identify exactly what leaves the country and under what legal basis before the project proceeds.
What "critical function" means in practice
BDDK's information systems regulation applies stricter requirements to AI systems supporting critical banking functions, generally meaning anything touching credit decisioning, payment processing, or core customer account operations, than to lower-stakes internal tools like an employee documentation assistant. Scoping a first AI project around a clearly non-critical internal function, similar to how institutions elsewhere start AI pilots on low-risk use cases, gives a Turkish bank a faster path to a working system while the compliance and legal teams build familiarity with how BDDK's existing rules apply to AI specifically.
Frequently asked questions
Does BDDK require prior notification for every AI deployment?
It depends on whether the deployment touches a critical function or involves outsourcing to an external provider; lower-risk internal tools generally require less formal notification than anything affecting customer-facing or credit decisioning functions, but banks should confirm current thresholds with BDDK guidance directly.
Can a Turkish bank use a foreign-hosted LLM API at all under KVKK?
Yes, but it requires a valid legal basis for the cross-border data transfer and documentation of the safeguards in place, which is why many Turkish banks default to on-premise or in-country hosted deployment for anything touching customer data.
Is BDDK expected to issue AI-specific regulation soon?
Given the pace of AI-specific regulatory activity globally, it is reasonable to expect BDDK to issue more specific guidance, though no confirmed timeline exists as of 2026, so institutions should monitor for updates rather than assume the current framework is final.
Does KVKK treat AI training data differently from operational data?
KVKK does not have a separate category for AI training data; data used to train or fine-tune a model is subject to the same processing and transfer rules as any other personal data use, which is why training data sanitization matters as much for KVKK compliance as for the AI system's own security.
How Nanobase AI helps
Nanobase AI helps Turkish banks structure AI deployments to align with current BDDK outsourcing and information systems requirements alongside KVKK data protection obligations, with a strong preference for on-premise deployment where customer data is involved. This connects to on-premise LLM deployment guidance and to how banks deploy LLMs on-premise for data security.
Ready to discuss your project? Contact Nanobase AI or email hello@bumu.tech.