An Omnibus Bill Reshapes Who Controls the Internet Kill Switch
On July 31, 2026, Turkey's Official Gazette (Issue No. 33326) published Law No. 7590, a 32-article omnibus bill that touches everything from pension formulas to driver's licensing. Buried inside it is a provision that matters far more than its packaging suggests: a new Article 60/A of the Electronic Communications Law (No. 5809) that strips the Information and Communication Technologies Authority (BTK) — Turkey's sector regulator — of its power to order internet access blocking, and hands it to the Cybersecurity Presidency, a body embedded in the presidency's national-security apparatus since it was placed on statutory footing by Law No. 7545 in March 2025 (TBMM, Law No. 7545 full text; TBMM legislative record).
The mechanics are straightforward and aggressive. When the Presidency determines "urgent" grounds exist — acting on its own initiative or at the request of security and intelligence agencies — it can order operators, access providers, data centers, and content or hosting companies to implement unspecified "measures." Recipients must comply within two hours of notification. Only afterward does a judge enter the picture: the order must be submitted to a criminal judgeship of peace within 24 hours, and the judge has 48 hours to rule, after which an unconfirmed measure automatically lapses. Non-compliant providers face administrative fines of ₺20,000 to ₺100,000 per violation (Pekin Bayar Mizrahi legal briefing). BTK's related infrastructure — wiretapping systems, monitoring capacity, and blocking tools reportedly worth close to ₺30 billion — transfers to the Presidency within three months (Middle East Forum / Nordic Monitor).
The Case for Speed Is Real
Before dismissing this as pure censorship infrastructure, it's worth taking the government's stated rationale seriously. Cybersecurity incidents — an active distributed-denial-of-service attack against critical infrastructure, a coordinated disinformation surge during a security crisis, or content facilitating an unfolding terrorist act — can do damage in minutes, not the days a normal judicial authorization process takes. Nearly every democracy has some expedited mechanism for emergency network intervention, and centralizing technical response in a dedicated cybersecurity body rather than leaving it fragmented across a sector regulator has a coherent institutional logic. A telecoms authority built to referee spectrum auctions and consumer complaints is a plausible mismatch for fast-moving cyber incidents.
Where the Design Breaks Down
The problem is not that Turkey created an emergency-response power — it's how loosely that power is bounded. Law No. 7590 doesn't just speed up enforcement; it deletes precision. The prior framework specifically defined bandwidth throttling as a distinct, regulated practice. The new Article 60/A replaces that defined term with the open-ended word "measures," covering everything from throttling to full blocking to infrastructure-level interference, without saying which. İFÖD (the Freedom of Expression Association), Turkey's leading digital-rights monitor, flagged exactly this substitution, warning it could make it "harder to determine what action authorities have taken and under what legal authority" (Stockholm Center for Freedom). Vague statutory language paired with a two-hour compliance clock is a recipe for providers erring toward over-compliance — quietly throttling or blocking first and litigating never, since there's no defined harm threshold to challenge.
The institutional shift compounds the drafting problem. BTK, whatever its flaws, is a sectoral regulator subject to administrative-law review and public-facing rulemaking. The Cybersecurity Presidency sits inside the security apparatus, oriented around threat response rather than public accountability. Moving blocking authority from the former to the latter — while simultaneously making judicial sign-off retrospective rather than a precondition — inverts the normal presumption that speech and communications restrictions require prior authorization, not post-hoc ratification. A social-media platform blocked for 48 hours pending a judge's decision has already lost the news cycle it needed to reach; automatic lapse of an unconfirmed order is a weak remedy against a fait accompli.
Notably, this isn't only an outside critique. According to reporting on the bill's own parliamentary committee record, lawmakers' staff recorded concerns internally about the undefined "measures" language and inadequate safeguards before the bill passed — objections that got no textual fix in the final version, which was pushed through as one line item in a sprawling, unrelated omnibus package covering tourism subsidies and driver's licenses (Alomaliye summary of Law No. 7590).
What a Proportionate Fix Looks Like
An evidence-based cybersecurity posture doesn't require choosing between "no emergency powers" and "undefined emergency powers executed by a security body with same-day teeth." Turkey could keep a genuine emergency-response mechanism while (1) defining "measures" with the same specificity the repealed throttling provision had, (2) requiring the security agencies requesting action to document a specific, reviewable threat rather than invoking generalized urgency, and (3) keeping the executing authority a technically independent body answerable to sector law, not folded into the presidency's security architecture. None of that blunts a real-time response to an actual cyberattack. What it prevents is the far more predictable use case critics are pointing to: a two-hour window used to throttle a platform during a politically inconvenient news cycle, with a judge weighing in only once the story has already moved on.