Employees’ Use of Artificial Intelligence and the Employer’s Legal Risks

Generative artificial intelligence tools have become an ordinary part of employees’ day-to-day workflows. In order to summarise a contract, draft an e-mail to be sent to a client, analyse a data table, or review a piece of software code, employees frequently enter corporate data into publicly available artificial intelligence systems, often without the employer’s knowledge and consent. This phenomenon, referred to in the literature as “shadow AI,” gives rise to serious legal risks for the employer along the axes of data protection, trade secrets, and labour law. Since there is as yet no specific law in force in Türkiye comprehensively regulating artificial intelligence, these risks are likewise assessed within the framework of the existing general legislation and of regulatory texts such as the Personal Data Protection Authority’s “Guidelines on Generative Artificial Intelligence and the Protection of Personal Data (in 15 Questions)” dated 24.11.2025.
Data Sharing and “Shadow AI”
By their very nature, generative artificial intelligence tools require that data be supplied to them in order to obtain an output. When an employee wishes to have a contract summarised, they enter the content of that contract; when they wish to have a sales report analysed, they enter customer and pricing information; and when they wish to have an error resolved, they enter the company’s source code into the system. The fact that, in the free or individual versions of a significant portion of these tools, the data entered by the user may be used in model training, and that the servers are located abroad, further amplifies the risk. The employer’s frequent lack of awareness of such use eliminates the controllability of the risk and leaves the legal liability with the employer.
1. The Employer’s Liability under the Personal Data Protection Law (KVKK)
An employee’s entry of personal data belonging to clients, business partners, or other employees into any generative artificial intelligence tool constitutes a personal data processing activity within the meaning of the Personal Data Protection Law No. 6698. The decisive threshold here is whether the data renders a natural person identifiable, directly or indirectly. Since the status of data controller in respect of this activity rests, as a rule, not with the employee but with the employer, the defence that “my employee did it” or “the intermediary system generated it automatically” does not entirely eliminate the obligations that the employer bears as a data controller. Moreover, where the servers of the tools in question are located abroad, such sharing is also subject to the cross-border transfer regime set out in Article 9 of Law No. 6698, as amended by Law No. 7499.
As a data controller, the employer must comply with the general principles set out in Article 4 of the Law (in particular purpose limitation and proportionality), the obligation to inform under Article 10, and the obligation under Article 12 to take appropriate technical and administrative measures to prevent the unlawful processing of personal data and unlawful access to such data. A breach of these obligations may give rise to administrative fines under Article 18 of the Law, as well as to liability for pecuniary and non-pecuniary damages vis-à-vis the data subjects. Indeed, the Personal Data Protection Board has imposed administrative fines on employers acting as data controllers in cases involving the unlawful processing of employees’ personal data and their transfer without explicit consent.
2. Risks with Respect to Trade Secrets and Unfair Competition
The risk of using artificial intelligence is not limited to personal data. Entering as-yet-undisclosed product information, customer portfolios, pricing strategies, R&D outputs, or know-how into a publicly available artificial intelligence tool creates the risk that such information loses its confidentiality and, consequently, its status as a trade secret. Since a trade secret that has once been disclosed can rarely be rendered confidential again, the resulting harm is of a kind that is difficult to remedy.
Such sharing may give rise to various forms of legal liability. As regards the employee, a breach of the duty of loyalty and confidentiality set out in Article 396 of the Turkish Code of Obligations No. 6098 arises. As regards both the employer and the employee, the unlawful disclosure of business secrets may constitute an act of unfair competition under Article 55 of the Turkish Commercial Code No. 6102. Depending on the gravity of the conduct, even the offence of disclosing information constituting a trade secret, regulated in Article 239 of the Turkish Penal Code No. 5237, may come into question. In addition, the disclosure of confidential information belonging to clients or business partners may render the employer liable to those parties for breach of contractual confidentiality obligations.
3. Risks under Labour Law and the Employer’s Right of Management
Employees’ use of artificial intelligence gives rise to mutual obligations between the parties to the employment relationship. Pursuant to Article 396 of Law No. 6098, the employee is obliged to perform their work with due care and to protect the legitimate interests of the employer; the unauthorised transfer of corporate data into artificial intelligence systems may be regarded as a breach of this obligation. The employer, for its part, may, within the scope of its right of management, lay down instructions and policies determining which tools may be used with which data; such rules, once duly announced, are binding upon employees.
An employee’s unauthorised sharing of confidential corporate data may, depending on the gravity of the particular case, be deemed an abuse of the employer’s trust within the scope of the second paragraph of Article 25 of the Labour Law No. 4857, and may give rise to termination for just cause (without compensation). Nevertheless, the validity of such termination is assessed separately in each case within the framework of the gravity of the act and the principle of proportionality. On the other hand, the employer’s authority to monitor employees’ use of artificial intelligence is likewise not unlimited; such monitoring is subject to the safeguard of the privacy of private life under Article 20 of the Constitution and to the criteria established in the case law of the Constitutional Court and the Court of Cassation (a legitimate purpose, prior and explicit notification, proportionality, and minimal interference). Monitoring conducted without observing these criteria may itself give rise to legal liability on the part of the employer.
Comparative Perspective: The EU Artificial Intelligence Act and “AI Literacy”
The European Union’s Artificial Intelligence Act No. 2024/1689 introduces an obligation directly relevant to employee use. Pursuant to the “AI literacy” obligation set out in Article 4 of the Regulation, which has applied since 2 February 2025, providers and deployers using artificial intelligence systems are expected to take the measures necessary to ensure that the personnel using those systems on their behalf possess a sufficient level of AI literacy. This approach demonstrates that the risk must be managed not only through the technology but also through the human element using it. Turkish companies operating toward the European Union market may likewise be subject to this and similar obligations in their capacity as providers or deployers.
Conclusion
As regards the risks arising from employees’ use of artificial intelligence, it is not possible for the employer to escape liability by pointing to the “employee” or the “tool”; liability rests, as a rule, with the employer as the owner of the organisation. Within this framework, we recommend that employers take the following measures:
- Establishing — and duly announcing — a written corporate artificial intelligence usage policy that clearly determines which artificial intelligence tools may be used, with which data, and for which purposes.
- Prohibiting the entry of personal data and trade secrets into publicly available tools, and preferring corporate versions that include a guarantee that the data will not be used in model training.
- Implementing technical measures such as access controls and data leakage prevention, and carrying out a data protection impact assessment in uses involving personal data.
- Adding explicit provisions on confidentiality and the use of artificial intelligence to employment contracts and internal company regulations, and establishing the disciplinary process in advance and in a transparent manner.
- Enhancing AI literacy by providing employees with regular awareness training.
- Conducting employee monitoring in a manner consistent with the safeguard of the privacy of private life and with the principles of proportionality and prior notification.
Benefiting safely from the efficiency that artificial intelligence brings to business processes is possible only through a proactive approach to legal compliance that manages the technology together with the human element.


