KVKK Among Four — How Agentic AI Guidance Compares Internationally
Between November 2025 and March 2026, four data protection authorities published guidance addressing agentic AI specifically — not AI in general. In order: the EDPS (EU, Nov 2025), the UK ICO (8 Jan 2026), Spain's AEPD (18 Feb 2026), and KVKK (12 Mar 2026, see Etken Yapay Zekâ (Agentic AI) Guidance — KVKK's March 2026 Framework). That is a genuinely tight window for four separate authorities, in four separate legal systems, to independently land on the same emerging topic.
Be precise about what this is and isn't. These are four separate national/EU publications, not one joint framework — nothing here claims KVKK formally co-authored anything with the other three. What the timing and content overlap do show is convergence: similar risk read, similar vocabulary, arriving close together. For a KOBİ owner asking "does Turkey lag the EU/UK on AI regulation" — on this specific question, the honest answer is no.
What each authority emphasized
- EDPS (EU) — framed agentic AI as one of six key emerging-technology trends, with a memorable framing of the human role shifting toward "shepherds of AI agents" — oversight of a system that acts, rather than operation of a tool that responds.
- ICO (UK) — positioned its output as forward-looking research (Tech Futures) rather than binding guidance, and explicitly works the topic through multilateral channels: the Digital Regulation Cooperation Forum (DRCF) domestically, and the G7 Data Protection Authorities' Emerging Technologies Working Group internationally. Of the four, the ICO's materials lean hardest into "we are watching and coordinating," not yet "here are the rules."
- AEPD (Spain) — went further into the mechanics: determining controller/processor roles becomes harder as autonomy increases, especially once an agent calls third-party services on its own initiative — an agent making its own tool calls blurs who "decided" the processing took place. This is the closest international echo of the role-assignment question Generative AI Guide (15 Soruda) — What KVKK Actually Said already answers for KVKK's context.
- KVKK (Türkiye) — the most operationally concrete of the four: four named pillars (human oversight, traceability, accountability structure, privacy by design), plus explicit DPIA update requirements for autonomy level, multi-agent architecture, and special-category-data inference. See Etken Yapay Zekâ (Agentic AI) Guidance — KVKK's March 2026 Framework for the full breakdown.
Reading across all four: the DPIA question is universal
Every authority above lands, in its own vocabulary, on the same structural worry: the assessment you did for a single-turn assistant does not cover an agent that now acts, multi-step, with other agents, with less human involvement per action. None of the four call this optional. If your DPIA process hasn't been revisited since before your agent could take actions — not just generate text — treat that as the gap to close first, regardless of jurisdiction.
Why a Turkish KOBİ should read the other three, not just KVKK
Two practical reasons: (1) if you use a foreign-hosted model or platform, that vendor is very likely reading the EDPS/ICO/AEPD material as their own compliance driver, so understanding it tells you what your vendor is actually building toward; (2) KVKK's guidance and these three overlap enough in substance that a gap identified against any one of them is worth checking against the others too — this is exactly the kind of cross-referencing a compiled, linked knowledge base makes cheap and a folder of PDFs does not.
---
Educational reference maintained by Avalanche AI — not legal advice. This page is a comparative synthesis prepared by Avalanche AI from public sources; verify each authority's current position directly before relying on it.