top of page

When AI Enters the Office: The Legal Questions Turkish Companies Should Answer Before Employees Start Using It

Writer: Özgür Kurucuk
Özgür Kurucuk
1 hour ago
14 min read

Artificial intelligence rarely arrives in a company through the legal department.


It usually arrives through an employee.


Someone discovers an AI tool that can summarise a long contract in seconds. Another employee uses an AI assistant to rewrite an email. A developer asks it to review source code. A sales team uses it to prepare customer responses. Someone uploads a spreadsheet and asks for an analysis.


Nothing may appear unusual.


Then comes the more difficult question:


What exactly has the company allowed its employees to do with AI?


That question is becoming increasingly important for businesses in Turkey. Generative AI can make everyday work faster, but it can also create unexpected issues involving personal data, confidentiality, intellectual property, cybersecurity, employment practices and contractual obligations.


The interesting part is that many of these risks do not begin with a sophisticated AI product.


They begin with an ordinary employee copying and pasting something into a chatbot.


For Turkish businesses, this makes employee AI use and internal AI governance an important legal topic in its own right.


The Turkish Personal Data Protection Authority (KVKK) has already published dedicated material concerning generative AI and personal-data protection. Its guidance considers the processing of personal data throughout the lifecycle of generative AI systems.


This article looks at a practical question that sits beside the broader field of artificial intelligence law:


How should a Turkish company manage the everyday use of AI by its employees?

The AI Problem Most Companies Did Not Plan For

Many organisations have traditionally controlled software through procurement.


The IT department chooses the system. The company signs a contract. User accounts are created. Access permissions are established. Employees receive training.

Generative AI has disrupted that model.


An employee can discover a new AI service in the morning and begin using it before the organisation has evaluated the provider, reviewed its terms or considered what happens to the information entered into the system.


This creates a different kind of technology risk.


The company may have an official software inventory, yet employees may be using several AI services that are not included in it.


The organisation may have a data-protection policy, yet employees may not know whether customer information can be entered into an AI tool.


The company may have strict confidentiality procedures, yet an employee may unknowingly submit a confidential document to an external AI service simply to obtain a summary.


This is sometimes described as shadow AI: AI use taking place outside formal procurement and governance processes.


The legal challenge is not necessarily to eliminate that behaviour.


It is to bring it into a framework that employees can actually understand and follow.


Why a Generic “Do Not Use AI” Rule Usually Misses the Point

A company can simply tell employees:


“Do not use artificial intelligence.”


But that may not solve the underlying problem.


Employees may already be using AI because it is useful. They may also continue using it without telling management.


A more practical approach is to distinguish between different types of use.

For example:

AI use

Possible legal concern

Rewriting a generic email

Usually lower-risk, depending on content and tool

Summarising a public document

Generally different from processing confidential material

Analysing customer information

Personal-data and confidentiality concerns

Reviewing employment records

Potentially significant privacy and employment issues

Uploading source code

Confidentiality and intellectual-property concerns

Generating marketing content

Copyright, consumer and accuracy considerations

Using AI for recruitment

Personal data, profiling and employment concerns

Using AI for important decisions

Human oversight and regulatory questions

The point is not that every use in the table is automatically lawful or unlawful.


The point is that context matters.


A sensible AI policy should reflect that.


Start With One Simple Question: What Is the Employee Putting Into the AI?

Companies often begin AI governance by asking:


Which AI tool are we using?


That is useful, but it is not always the first question.


A better starting point may be:


What information are employees putting into it?


Consider an employee who asks an AI system:


“Please improve the grammar of this paragraph.”

If the paragraph contains no confidential or personal information, the legal considerations may be relatively straightforward.


Now change the paragraph.


It contains a customer's full name, identification details, financial information and details of a contractual dispute.


The technical action is almost identical.


The legal situation is not.


This is why AI governance should be connected to the organisation's existing information-classification system.


A Practical Information Classification Model

A business might divide information into four broad categories:


Public Information

Information already intended for public disclosure, such as published marketing material or publicly available company information.


Internal Information

Ordinary business information that is not intended for public distribution.


Confidential Information

Commercial information, contracts, pricing, business plans, negotiations, customer information and other material subject to confidentiality obligations.


Highly Restricted Information

Trade secrets, sensitive personal data, security credentials, strategic transaction information and other information requiring particularly strict controls.


The AI policy can then explain which categories may be used with which tools.


This is much easier for an employee to understand than a policy containing several pages of abstract legal language.


Personal Data Is Where the Situation Can Change Quickly

Personal data deserves particular attention.


The Personal Data Protection Authority (KVKK) has specifically addressed generative

AI and personal data, explaining that AI systems relying on personal-data processing need to be considered within the framework of Law No. 6698 on the Protection of Personal Data and related legislation.


That matters because employees may not always recognise that an ordinary-looking document contains personal data.


A customer complaint may contain a person's name and contact details.


A CV contains personal information.


An employee performance report contains personal information.


An email chain can contain personal data even if nobody thinks of it as a “database.”


An AI tool can transform that information into another format, but changing the format does not necessarily remove the underlying data-protection considerations.


The Hidden Data Trail of an AI Prompt

A prompt can look harmless:


“Summarise this complaint.”

But the prompt may be accompanied by:


  • the original complaint;

  • the customer's name;

  • email address;

  • telephone number;

  • account information;

  • transaction history;

  • employee comments; and

  • attached documents.


The employee may think they have sent “a question.”


Technically, they may have sent a substantial dataset.


That distinction should be reflected in internal AI training.


Employees need to understand that the legal significance lies in the information being processed, not merely in the fact that it was entered into a chat box.


What Happens to the Information After It Is Submitted?

This is where vendor due diligence becomes important.


Before employees use an external AI service for business information, the company should understand, to the extent relevant:


  • who operates the service;

  • where information is processed;

  • what information the provider retains;

  • how long information is retained;

  • whether data is used for service improvement or model training;

  • who can access it;

  • what security measures exist;

  • whether subprocessors are involved;

  • how information can be deleted; and

  • what contractual terms govern the service.


The answers will differ between providers and between different service plans.


That is why an organisation should avoid assuming that all AI services treat data in the same way.


Turkish Data Protection Law and AI Should Be Considered Together

The KVKK has gone beyond general privacy principles by publishing specific AI-related recommendations.


Its official material includes Recommendations on the Protection of Personal Data in the Field of Artificial Intelligence, which states that AI activities involving personal-data processing should comply with Law No. 6698 and the relevant secondary legislation.


The KVKK's collection of official guidelines also includes AI-related data-protection material.


For businesses, this means AI governance should not sit in a separate corner from privacy compliance.


The two should be connected.


The Employee May Not Own the Confidentiality Risk

Suppose an employee uploads a confidential contract into an AI system.


The employee may have acted with entirely innocent intentions.


Perhaps they wanted to:


  • identify unusual clauses;

  • produce a summary;

  • prepare negotiation points; or

  • compare two versions.


But the company's legal obligations may not disappear because the employee had a legitimate business purpose.


This is particularly important where the company has contractual confidentiality obligations toward:


  • customers;

  • suppliers;

  • investors;

  • business partners;

  • employees;

  • professional advisers; or

  • transaction counterparties.


An AI policy should therefore explain not only what employees cannot do but also why.


That tends to produce better compliance than a list of prohibitions without context.


AI and Trade Secrets

The risk becomes even more serious where information qualifies as commercially sensitive or constitutes a trade secret.


Examples could include:


  • unreleased product designs;

  • source code;

  • algorithms;

  • pricing strategy;

  • acquisition plans;

  • customer lists;

  • manufacturing methods;

  • research results;

  • technical specifications; or

  • confidential business strategies.


Employees may not realise that an AI prompt can expose information outside the company's normal information environment.


For businesses whose competitive advantage depends on confidential information, AI governance should therefore be linked to existing trade-secret and confidentiality procedures.


The Source-Code Question

Technology companies face a particularly practical problem.


Developers can ask AI systems to:


  • review source code;

  • identify vulnerabilities;

  • generate functions;

  • rewrite code;

  • explain an error;

  • produce tests; or

  • suggest architecture.


The productivity benefits can be substantial.


But the company should know what is being submitted.


A developer working on a proprietary application may unknowingly paste a portion of source code into an external AI service.


That can create questions concerning:


  • confidentiality;

  • intellectual-property rights;

  • customer contracts;

  • open-source licensing;

  • cybersecurity; and

  • internal security policies.


The right response is not necessarily to ban AI-assisted programming.


Instead, a technology company can establish rules around which environments, tools and categories of code may be used with AI.


The Turkish Patent and Trademark Office (TÜRKPATENT) is an important official source for Turkish intellectual-property matters, while the Directorate General of Copyright provides official information concerning copyright.


AI-Generated Content Creates Another Layer of Risk

Employees may use AI to produce:


  • blog posts;

  • advertisements;

  • product descriptions;

  • social-media content;

  • presentations;

  • sales proposals;

  • images;

  • videos; or

  • customer communications.


The legal question is not simply whether AI created the material.


The company should also ask:


Where did the material come from?

Could it reproduce protected material?

Does it contain inaccurate claims?

Does it make a promise that the business cannot fulfil?

Could it infringe another person's rights?

Has someone reviewed it before publication?


Human review remains particularly important where AI-generated content is customer-facing or legally significant.


The Employee Should Not Become the Company's Unofficial AI Regulator

Another common mistake is to place all responsibility on individual employees.


A company might say:


“Employees must use AI responsibly.”

But what does “responsibly” mean?


Should an employee know whether a provider stores prompts?

Should they understand international data transfers?

Should they determine whether a dataset contains sensitive personal data?

Should they interpret an AI provider's contractual terms?


In most organisations, those are not reasonable expectations for every employee.


The company should provide a framework.


Employees should then have clear instructions about when they can use AI and when they need to ask for approval.


A Better Internal AI Policy Can Be Surprisingly Short

A useful AI policy does not need to become a 50-page legal document.


For many businesses, a practical policy can begin with a few straightforward rules.


Rule 1: Use Only Approved AI Tools for Company Information

Employees should know which AI services have been reviewed and approved.


Rule 2: Never Enter Restricted Information Without Authorisation

This should cover confidential information, sensitive personal data, credentials, trade secrets and other protected material.


Rule 3: Do Not Treat AI Output as Automatically Correct

AI can produce inaccurate or incomplete information.

Important outputs should be reviewed.


Rule 4: Protect Customer and Employee Information

Employees should understand how personal data is handled before using AI for business tasks.


Rule 5: Keep Human Responsibility

AI can assist with a task without becoming the final decision-maker.


Rule 6: Report Problems

Employees should know whom to contact if confidential information is accidentally submitted or an AI system produces a serious error.


Rule 7: Review the Rules Periodically

AI tools change rapidly.


A policy written once and never reviewed may become outdated.


What About AI in Recruitment?

Recruitment deserves separate attention.


An employer may use AI to:


  • screen CVs;

  • rank applicants;

  • analyse applications;

  • schedule interviews;

  • generate interview questions; or

  • assess candidate information.


The use of AI can make recruitment more efficient, but it can also introduce questions around personal-data processing, profiling, transparency and employment practices.


The KVKK specifically identifies employment among the contexts in which AI and personal-data issues require consideration.


Employers should therefore understand what the AI system actually does before relying on its recommendations.


A useful question is:


Is the AI helping a person make a decision, or is the AI effectively making the decision?


That distinction can matter.


AI in Performance Management

The same issue can arise after recruitment.


Imagine an employer using AI to analyse employee performance.


The system produces a score.


A manager relies on that score when deciding whether an employee should receive a promotion.


The legal analysis cannot stop at:


“The software gave the employee a low score.”


The business may need to understand:


  • what information the system used;

  • how the result was generated;

  • whether the information was accurate;

  • whether the employee was informed;

  • whether human review occurred; and

  • whether the decision complied with applicable employment and data-protection requirements.


Technology can assist management, but it does not necessarily eliminate management responsibility.


The European Dimension for Turkish Employers

A Turkish company may also encounter European AI requirements.


The EU AI Act's Article 50 transparency obligations began applying on 2 August 2026.


The European Commission has published dedicated guidance explaining the obligations for certain AI systems and their providers and deployers.


The European Commission's AI Act resources and the EU AI Act Service Desk provide official information concerning implementation.


For example, Article 50 addresses certain situations where people interact directly with AI and certain AI-generated or manipulated content. The precise obligations depend on the AI system and circumstances.


This can become relevant to Turkish businesses that:


  • provide AI services to European customers;

  • operate AI-enabled platforms in the EU;

  • have European subsidiaries;

  • develop AI systems used in the EU; or

  • participate in cross-border technology supply chains.


A Turkish company should therefore consider its international footprint when designing its AI policy.


Why the EU AI Act Matters Even When the Office Is in Istanbul

Imagine a Turkish software company with 80 employees.


The company is based entirely in Istanbul.


Its developers use AI tools to create software.


Its sales team uses AI to prepare customer material.


Its customer-support system uses an AI chatbot.


Some customers are in Germany, France and the Netherlands.


The company may naturally think of itself as a Turkish business.


Legally, however, some of its AI activities may have a European dimension.


That is why AI governance should consider where the technology is used and who receives its output, not merely where the company's headquarters are located.


AI Transparency Is Becoming a Practical Business Issue

Transparency is one of the areas where AI regulation is becoming increasingly concrete.


The European Commission's July 2026 guidance explains that Article 50 covers specific transparency obligations and that these obligations apply from 2 August 2026.


The official Article 50 text and guidance address, among other matters, informing people when they interact directly with certain AI systems and marking certain AI-generated or manipulated content.


For businesses, this raises a practical product-design question:


Does the user know when AI is involved?


The answer will depend on the particular system and applicable law, but companies should increasingly treat transparency as something to consider during product development rather than after launch.


What Should an AI Vendor Contract Say?

Internal employee use is only half of the problem.


Companies also purchase AI services from vendors.


Before signing, the business may want to understand:


Data Use

Will company information be used to train or improve the provider's systems?


Security

What security measures does the provider maintain?


Confidentiality

What contractual protections apply to business information?


Subprocessors

Can other service providers access or process the information?


Location

Where is the data processed or stored?


International Transfers

Are cross-border transfer arrangements relevant?


Model Changes

Can the provider change the underlying AI model without notice?


Accuracy

What does the provider say about the reliability of outputs?


Liability

What happens if the service causes loss or a third-party claim?


Exit

How can the company retrieve or delete its information when the contract ends?


These questions are particularly important when AI becomes part of a company's core operations.


AI Procurement Should Involve More Than the IT Department

An AI purchase may look like an IT decision.


It may actually involve several departments.


IT may assess technical suitability.


Security may assess vulnerabilities.


Legal may assess contracts and liability.


Privacy may assess personal-data processing.


Compliance may assess regulatory requirements.


Business teams may assess operational usefulness.


Management may determine whether the risk is acceptable for the organisation.


The best AI procurement process therefore tends to be cross-functional.


What Happens When an Employee Makes an AI Mistake?

The company should plan for this before it happens.


For example:


An employee accidentally uploads a confidential customer document to an unapproved AI service.


What should the employee do?


If the answer is:


“I don't know,”

the company has a governance problem.


A simple incident process can make a significant difference.


The policy can tell employees to:


  1. stop using the relevant AI service for the matter;

  2. report the incident promptly;

  3. preserve relevant records;

  4. identify what information was submitted;

  5. identify the service involved;

  6. avoid deleting evidence without instruction; and

  7. allow the responsible legal, privacy or security team to assess the incident.


The appropriate response will depend on the circumstances.


The important point is to make reporting easier than hiding the mistake.


AI Governance Should Not Be About Fear

The purpose of an AI policy is not to frighten employees away from useful technology.


AI can provide genuine business value.


It can help a small company perform work that previously required several hours.

It can help lawyers organize documents.

It can help developers understand unfamiliar code.

It can help businesses communicate across languages.

It can help teams explore ideas quickly.


The legal objective is therefore not necessarily:


“Stop using AI.”


It is closer to:


“Know what you are using, know what information you are giving it, and know who is responsible for the result.”


That is a much more sustainable approach.


A Practical AI Checklist for Turkish Companies

Before allowing employees to use AI for business purposes, management can ask:


Technology

  • Which AI systems are currently being used?

  • Which employees have access?

  • Are personal AI accounts being used for company work?

  • Are AI tools integrated into company software?


Data

  • What information is submitted?

  • Does it contain personal data?

  • Does it contain sensitive information?

  • Does it contain customer information?

  • Does it contain trade secrets?


Vendors

  • Who provides the AI service?

  • What contractual terms apply?

  • Where is information processed?

  • What happens to prompts and uploaded documents?

  • Are subprocessors involved?


Intellectual Property

  • Who owns the relevant input?

  • What rights apply to the output?

  • Are third-party materials involved?

  • Could open-source or copyright issues arise?


Employees

  • Have employees received practical training?

  • Do they know which tools are approved?

  • Do they know what information cannot be entered?

  • Do they know how to report an incident?


International Operations

  • Does the business have EU customers?

  • Is the AI system used in Europe?

  • Could the EU AI Act apply?

  • Are cross-border data issues relevant?


Accountability

  • Who approves new AI tools?

  • Who monitors compliance?

  • Who handles incidents?

  • Who reviews the policy?


If a company cannot answer these questions, it may be using more AI than it actually governs.


The Future AI Policy May Become Part of Ordinary Corporate Governance

AI is increasingly becoming ordinary business infrastructure.


That means AI governance may eventually become as routine as:


  • cybersecurity;

  • data protection;

  • information security;

  • procurement;

  • employment policies; and

  • document retention.


The Turkish regulatory environment is already moving in that direction.


The KVKK has published AI-specific data-protection recommendations and generative-AI guidance. Parliament has also seen AI-related legislative proposals, including a 2026 proposal concerning copyright in the AI era and another proposal concerning AI, automation and social transformation. Those proposals remain matters of parliamentary consideration rather than enacted law.


This makes it particularly important for businesses to distinguish what the law currently requires from what regulators, policymakers or legislators are considering for the future.


A Human-Centered AI Policy Is Often the Most Useful One

Employees do not need to become AI lawyers.


They need clear answers to practical questions:


Can I use this tool?

Can I put this information into it?

Do I need permission?

Do I need to tell the customer?

Should a human check the result?

What should I do if I make a mistake?


A good policy answers those questions without turning everyday work into a legal examination.


For management, that can be the difference between having an AI policy on paper and actually having an AI governance system that people use.


The Most Important AI Policy May Be the One Employees Actually Read

Artificial intelligence is changing the workplace one small task at a time.


An employee asks a chatbot to summarise a document.


A developer asks AI to review code.

A recruiter uses an AI tool to organise applications.

A marketing team generates an image.

A manager asks AI to analyse a report.

Each action may look insignificant.


Collectively, however, they can change how information moves through an organisation.


For Turkish companies, the legal response does not have to be complicated.


It should begin with visibility.


Know which AI tools are being used. Know what information enters them. Know what the providers do with that information. Know where important decisions require human oversight. And give employees rules they can understand and follow.


That is where AI governance becomes practical rather than theoretical.


Kurucuk & Associates advises businesses in Istanbul and Turkey on artificial intelligence, technology contracts, personal-data protection, intellectual property, commercial transactions, cybersecurity and related regulatory matters.



For businesses monitoring the developing regulatory environment, official resources from the KVKK, Turkish Competition Authority, TBMM, TÜRKPATENT, European Commission and EU AI Act Service Desk provide useful primary-source information.


bottom of page