Legal Liability of Companies Using Artificial Intelligence

Artificial intelligence tools have become an integral part of companies’ day-to-day operations, ranging from customer service to the generation of marketing content, from software development to the drafting of contracts and other documents, and even to decision-support processes such as recruitment and credit assessment. However, this rapid adoption also entails significant legal risks. Since there is currently no specific law in force in Türkiye that comprehensively regulates artificial intelligence, the liability of companies using artificial intelligence is largely assessed within the framework of the existing general legislation.
The Current Legal Framework and Regulatory Trend in Türkiye
Under Turkish law, there is as yet no standalone statute that comprehensively governs a liability regime specific to artificial intelligence. In 2024 and 2025, several legislative proposals were submitted to the Grand National Assembly of Türkiye in this field; these proposals generally focus on matters such as establishing a legal definition of artificial intelligence, the labelling of generated content (in particular deepfake content), content liability, the transparency of training data, and administrative sanctions. Nevertheless, these proposals remain at the committee stage and have not yet attained a statutory framework. Accordingly, liability arising from the use of artificial intelligence is, as of today, determined through the interpretation of existing legislation such as the Personal Data Protection Law No. 6698, the Law on Intellectual and Artistic Works No. 5846, the Industrial Property Law No. 6769, the Turkish Code of Obligations No. 6098, the Turkish Commercial Code No. 6102, and the Law on the Protection of Consumers No. 6502.
A significant development that partially fills this gap is the “Guidelines on Generative Artificial Intelligence and the Protection of Personal Data (in 15 Questions)” published by the Personal Data Protection Authority on 24.11.2025. While it does not constitute binding regulation, the Guidelines assess the personal data processing activities carried out throughout the lifecycle of generative artificial intelligence systems within the framework of Law No. 6698 and provide concrete guidance to data controllers.
- Liability with Respect to Data Security
Among the most common legal risks that companies encounter in their use of artificial intelligence is the protection of personal data. An employee’s entry of customer information, employee personnel data, or data belonging to business partners into any generative artificial intelligence tool constitutes a personal data processing activity within the meaning of Law No. 6698. Moreover, since the servers of the vast majority of these tools are located abroad, such sharing may at the same time qualify as a cross-border transfer of data. In that case, compliance with the transfer regime set out in Article 9 of Law No. 6698 — which was fundamentally amended by Law No. 7499 dated 12.03.2024 — (the conditions relating to an adequacy decision, appropriate safeguards, or incidental situations) is mandatory.
Pursuant to Article 12 of Law No. 6698, data controllers are obliged to take appropriate technical and administrative measures to prevent the unlawful processing of personal data and unlawful access to such data. In this context, the Authority’s generative artificial intelligence guidelines recommend, among other things, carrying out a data protection impact assessment, employing privacy-enhancing technologies, implementing technical controls against vulnerabilities specific to artificial intelligence such as prompt injection, and adopting the principles of privacy by design and privacy by default. A breach of these obligations may give rise to administrative fines under Article 18 of the Law; furthermore, in the event of a data breach, the data controller is under an obligation to notify the Board as soon as possible and in any event within 72 hours, and to notify the relevant data subjects within the shortest reasonable time.
The data security dimension is not confined to personal data alone. Entering information constituting a trade secret, customer portfolios, or strategic documents that have not yet been disclosed into publicly available artificial intelligence tools may create the risk that such information is used in the training of the model or is disclosed, thereby exposing the company to liability both for breach of contractual confidentiality obligations and with respect to unfair competition.
- Liability with Respect to Intellectual Property Infringement
The intellectual property dimension of the use of artificial intelligence gives rise to a two-fold risk: one concerning the protection of the output, and the other concerning the infringement of the rights of third parties. Pursuant to Article 1/B of Law No. 5846, for a product to be protected as a “work,” it must bear the individual character (hususiyet) of its author and must have been created by a natural person. For this reason, outputs generated entirely autonomously by means of a mere general instruction, without human intervention, are as a rule not regarded as works and do not benefit from copyright protection. The practical consequence of this is that a company may be unable to assert an exclusive right over content it has had artificial intelligence generate, and may be unable to protect that content against use by third parties. By contrast, where the user makes a meaningful contribution to the process through detailed, original, and creative direction, it is possible for the element of individual character to be satisfied and for copyright protection to arise.
The second dimension, and the one that is riskier for companies, is that the output infringes rights belonging to third parties. Where an image, text, or code generated by means of artificial intelligence reproduces or adapts an existing work, this may lead to an infringement of the rights of reproduction, distribution, and adaptation under Law No. 5846; where it contains a trademark belonging to another, to an infringement of trademark rights under Law No. 6769; and where it uses a person’s image or identity without consent, to an infringement of personality rights under the Turkish Civil Code. Even in cases where copyright protection is unavailable, the provisions of Law No. 6102 on unfair competition may come into play. It must be emphasised that the fact that an artificial intelligence provider’s terms of use permit the commercial use of the output does not mean that the output in question does not infringe the rights of third parties; liability arising from the infringement remains, in most cases, with the company using the tool.
- Liability Arising from Incorrect or Erroneous Output
A structural feature of generative artificial intelligence systems is their ability to produce content that is contrary to the truth yet appears convincing. A company’s establishing a transaction in reliance on an erroneous, incomplete, misleading, or discriminatory output obtained from artificial intelligence may give rise to various forms of liability. With respect to damage caused to third parties, Articles 49 et seq. of Law No. 6098 on tort apply; in contractual relationships, Article 112 on breach of obligation finds application. The critical point here is the following: since artificial intelligence is not a subject of rights in law, the company cannot transfer its liability to the “tool.” On the contrary, since the artificial intelligence system is in the position of an auxiliary instrument used in the course of performance, the outcomes are attributed directly to the company within the framework of Article 116 of Law No. 6098, which governs liability for the acts of auxiliary persons.
For commercial enterprises, the prudent-merchant standard set out in the second paragraph of Article 18 of Law No. 6102 stands out as a factor that aggravates liability. A merchant’s blind reliance on artificial intelligence without verifying its output may be regarded as a breach of the duty of care expected of a prudent business person and does not relieve the merchant of liability. In services provided to consumers, the provisions on defective services under Law No. 6502 may arise; and in professional advisory services in fields such as law, health, or finance, professional liability may come into question. In all of these cases, the most effective means of limiting liability is to subject the output to a final, qualified human review and to retain decision-making responsibility with a human.
Comparative Perspective: The European Union Artificial Intelligence Act
In contrast to the regulatory gap in Türkiye, the European Union has implemented the world’s first comprehensive and horizontal artificial intelligence regulation through the Artificial Intelligence Act No. 2024/1689 (the “Regulation”). Having entered into force on 1 August 2024, the Regulation adopts a risk-based approach, dividing artificial intelligence systems into the categories of unacceptable, high, limited, and minimal risk, and prescribing differentiated obligations for each category. The provisions of the Regulation enter into force in a phased manner.
The Regulation is notable for providing for administrative fines of up to EUR 35 million or 7% of global annual turnover in the event of an infringement. The true significance of the Regulation, however, lies in its extraterritorial effect: Turkish companies that offer artificial intelligence-based products or services to the European Union market, or whose outputs are used in that market, may likewise be subject to the obligations of the Regulation in their capacity as providers or deployers — in particular the transparency rules concerning the labelling of content generated by artificial intelligence.
Conclusion
The absence of a specific law in force does not mean that companies using artificial intelligence are exempt from liability. On the contrary, the existing legal framework applies with full force, and the use of artificial intelligence as a tool in no way mitigates a company’s legal liability. Within this framework, we recommend that companies take the following measures:
- Establishing a written artificial intelligence usage policy that determines which tools may be used within the organisation, with which data, and for which purposes.
- Clearly allocating liability, in the contracts concluded with artificial intelligence providers, by means of provisions on data processing, confidentiality, intellectual property warranties, and indemnification.
- Carrying out a data protection impact assessment and complying with the transfer regime in uses involving personal data.
- Subjecting all outputs to a qualified human review before they are published or processed, and keeping records of these processes.
- Performing checks to ensure that outputs do not infringe the copyright, trademark, or personality rights of third parties.
- Reviewing compliance with the obligations of the Artificial Intelligence Act in respect of companies operating toward the European Union market.
Benefiting safely from the opportunities offered by artificial intelligence technologies is possible only through a proactive approach to legal compliance.


