Home About Us Services Awards Team Insights Career Contact Us TÜRKÇEENGLISH Devin Law & IP — Istanbul
← All Insights
CategoryData Protection
Published19 March 2026
Authors
Uğurcan TekinPartner
İnci ÖzçilsalAttorney at Law
Beyza ErdemirAttorney at Law

Generative Artificial Intelligence in the Workplace: Risks, Responsibilities and Compliance Strategies

The integration of generative artificial intelligence technologies into business processes has accelerated significantly in recent times, and the tendency of employees to make use of these tools in their daily workflows has increased markedly. Generative AI systems are widely used in business life for the speed and efficiency advantages they provide in areas such as text generation, data analysis, translation, software development and content creation.

Nevertheless, the use of these technologies — particularly through third-party platforms and outside institutional supervision mechanisms — brings with it significant risks in terms of data security, the protection of personal data and the confidentiality of trade secrets.

Indeed, all data entered by employees into generative AI tools constitutes, in most cases, a personal data processing activity; moreover, such data may be transferred to servers located abroad. This gives rise to obligations for data controllers under Law No. 6698 and requires compliance processes to be reassessed. Uncontrolled and unaware use in particular — known as 'Shadow AI' — can lead to a loss of supervision over an organisation's processing activities and increase the risk of legal liability.

The General Scope of Generative AI Tools

As explained in Article 4 of Law No. 6698, all data processing activities carried out through artificial intelligence tools must be lawful and conducted in accordance with the rules of good faith, must be processed for specified, explicit and legitimate purposes, and must be relevant, limited and proportionate to the purposes for which they are processed.

Generative artificial intelligence refers to AI systems trained on large-scale datasets that can produce content in various formats — text, image, video, audio or software code — in response to prompts or commands provided by the user. As examined in detail in the Authority's announcement, unlike traditional approaches which mostly perform classification or prediction on existing data, these systems have the capacity to create new content similar in nature to human-generated material, on the basis of statistical patterns.

Because entering data into generative AI tools constitutes, in most cases, a processing and transfer activity within the meaning of the Law, the processing conditions under Article 5 and the additional protective mechanisms provided under Article 6 for special categories of personal data must be assessed separately.

Categories of Use in the Workplace

Today, the use of generative AI in workplaces largely occurs through services developed by third parties outside the organisation and offered via publicly accessible platforms. The application categories to which employees most frequently resort in order to optimise their work processes and increase their efficiency are as follows.

  • Chat-based interaction applications — systems used for answering complex questions and obtaining information through dialogue
  • Software and coding assistants — tools providing support in code writing, debugging and technical documentation in software development processes
  • Translation and content generation services — platforms for translating texts into different languages, drafting e-mails and restructuring existing content

Moreover, since the great majority of these tools provide services through servers located abroad, entering data into such systems may be assessed as a cross-border data transfer within the meaning of the Law. In that case appropriate transfer mechanisms must be established under Article 9.

Shadow AI use spreads faster than the policies written to govern it.

Shadow AI and Risk Analysis

Shadow AI refers to generative AI tools used by employees in business processes outside the organisation's knowledge, approval or institutional supervision. This generally arises from employees' motivation to save time, reduce routine work and improve output quality. Although Shadow AI resembles traditional 'Shadow IT' — the use of external cloud storage or devices — it carries far deeper risks, since it can intervene directly in data processing, content generation and institutional decision-making mechanisms.

Within this scope, whether generative AI service providers act as data processors or as independent data controllers must be separately assessed according to the technical and legal conditions of the platform used.

  • Auditability and accountability — in tools outside institutional monitoring it may become impossible to determine which data was used for what purpose and why particular results were produced, making compliance difficult to demonstrate
  • Decision quality and accuracy — outputs that have not passed through verification processes may produce erroneous, misleading or biased results, leading to flawed institutional decisions
  • Intellectual property and trade secrets — sharing source code, strategic plans or trade secrets with external tools may result in their use in model training or in access by unauthorised persons
  • Information and cyber security — personal devices or insecure integrations widen the attack surface, increasing the risk of data loss and malware
  • Protection of personal data — risks of unlawful processing of shared personal data, exposure to unauthorised access, or disclosure to third parties through AI outputs

Law No. 6698 applies in every case where personal data is processed, independently of the technology used. Operations carried out through generative AI systems are subject to this legal framework, and compliance with the legislation in these processes is an obligation for data controllers.

“Prohibitive policies may encourage employees toward greater use of Shadow AI; a balanced approach based on direction, calibration and awareness is required rather than strict bans.”

Management Approach and Policy Formulation

The Authority makes clear that prohibitive approaches may encourage employees toward greater Shadow AI use. Rather than strict bans, an approach based on guidance, balance and awareness should therefore be adopted. In practice, wholly prohibitive policies do not eliminate employee behaviour but rather drive that use outside institutional supervision — resulting in a loss of institutional visibility and an inability to manage risk.

In order to create a safe and responsible ecosystem of use, the boundaries of generative AI use must first be clearly defined. Which tools may be used, which types of data may appropriately be shared and which use scenarios fall within the scope of prohibition should be set out in a concrete and comprehensible policy document. The accessibility of that policy to all employees, and its design in a manner that will find application in practice, will place generative AI use on a foreseeable footing and contribute to reducing the risks arising from uncontrolled use.

Data Security and the Protection of Personal Data

To ensure data security and legal compliance, it is of great importance that employees act carefully in their interactions with generative AI tools in respect of institutionally sensitive information and personal data. The data processing policies, privacy notices and data retention processes of such third-party platforms are frequently standard and general in nature, and carry risks that may result in shared data passing outside the organisation's control. Employees must therefore take these risks into account before sharing data and act with a data minimisation approach.

Within this scope, prompts entered into generative AI tools should as far as possible use anonymised, generalised expressions containing no personal data. The use of distinguishing elements such as personal names, dates and locations should be limited; a higher standard of care should be adopted in particular for data relating to sensitive areas such as health, finance and law. Otherwise the risk arises of personal data being transferred unwittingly to third-party systems and processed outside the organisation's control.

Data minimisation begins at the prompt: anonymised and generalised formulations reduce exposure.

Technical and Administrative Measures

Managing the risks associated with generative AI use is not limited to policy formulation; it also requires the implementation of appropriate technical and administrative measures. Limiting access to generative AI tools within a duty- and need-based authorisation model plays an important role in preventing uncontrolled use. Rather than every employee having unlimited access to every tool, an access structure appropriate and proportionate to the nature of the work should be designed.

In addition, measures such as keeping access to external platforms within defined limits, conducting use as far as possible through corporate devices, and applying network-level restrictions where necessary will reduce the organisation's cybersecurity risks. Such controls not only ensure data security but also contribute to keeping generative AI use within a traceable and manageable framework.

Human-in-the-loop review remains the decisive safeguard in workplace AI deployment.

Human Oversight and Evaluation of Outputs

Although the outputs offered by generative AI systems have the capacity to produce rapid and practical solutions, unquestioning reliance on those outputs may give rise to various risks. This tendency — expressed in the literature as 'automation bias' — describes users' inclination to accept results produced by a system as error-free. The human-in-the-loop principle must therefore be preserved at every stage of generative AI use.

It must also be borne in mind that generative AI systems can from time to time produce content that is contrary to fact yet persuasive — a phenomenon known as hallucination. Outputs obtained should be treated not as final decisions but as supporting elements contributing to the assessment process. Particularly in matters capable of producing legal, technical or financial consequences, generative AI outputs must be checked against human judgement and verified where necessary.

Training and Institutional Awareness

The safe and effective use of generative AI technologies in institutional processes is possible not only through technical measures but also through increasing employee awareness. Regular training should therefore be provided to employees regarding the risks associated with generative AI use, correct methods of use and the rules of institutional policy. Through such training, employees will develop not only tool-use skills but also the capacity to anticipate risks and make correct decisions.

It is likewise important to establish feedback mechanisms through which problems encountered in practice, doubts and possible breaches may be shared. Such mechanisms enable the organisation to develop its generative AI policy dynamically and to respond rapidly to needs arising in practice.

Conclusion

Generative AI is now part of ordinary business practice rather than an exceptional technology, and compliance strategy must reflect that reality. The organisations best positioned are not those that prohibit use, but those that define its boundaries clearly, support those boundaries with proportionate technical controls, preserve human judgement over consequential outputs, and maintain the awareness and feedback channels that allow policy to evolve with practice.