Jump to

The AI Decision Belongs to the Board: Duty of Care, Delegation and the Paper Trail Under the Turkish Commercial Code

The AI Decision Belongs to the Board: Duty of Care, Delegation and the Paper Trail Under the Turkish Commercial Code

Most Turkish companies adopting artificial intelligence this year are not building models. They are buying a licence, connecting it to something, and letting a department get on with it. The decision is made at the level of a head of function, the invoice is small enough not to need a board paper, and nobody writes down why the tool was chosen. Eighteen months later the company depends on it.

That sequence is ordinary and it is also where the legal exposure is created. Not because using artificial intelligence is unlawful, but because the Turkish Commercial Code allocates responsibility for how a company is organised to a body that, in most of these adoptions, was never asked.

What the Code actually puts on the board

Article 375 of the Turkish Commercial Code lists the duties a board cannot delegate or give up. Two of them matter here. The board is responsible for determining the company’s management organisation, and for the upper supervision of whether the people charged with management act in conformity with the law, the articles of association, internal directives and the board’s written instructions.

Read that against a tool that now drafts customer correspondence, scores applicants, or decides which invoices get paid first. If no internal directive covers it and the board has issued no written instruction about it, the supervision duty has nothing to supervise against. The board has not discharged the duty badly; it has left the standard undefined, which is a harder position to explain afterwards.

Article 367 is the mechanism the Code offers. Management may be delegated, wholly or partly, through an internal directive adopted under a provision in the articles. The directive defines the tasks, who reports to whom, and where decisions sit. A company that has taken artificial intelligence seriously enough to depend on it can name it there in a paragraph. A company that has not will find that the question of who was allowed to approve the deployment has no documented answer.

Delegation protects you, but only if you chose carefully

Article 553 is the liability provision, and its second paragraph is the one worth reading slowly. Organs or persons who delegate a duty or power arising from the law or the articles are not liable for the acts and decisions of the persons who take it over — except where it is proven that they failed to show reasonable care in selecting those persons.

That is a selection standard, and it travels directly to procurement. When a company hands part of a process to an external supplier and its model, the protection of delegation depends on the care taken in choosing that supplier. A board that can show a documented comparison, a record of what was asked about data handling and model change, and a reasoned choice is inside the exception. A board whose only artefact is a signed order form is arguing about reasonable care with nothing to point at.

The third paragraph cuts the other way and is equally useful. Nobody is liable for breaches that fall outside their control, and that immunity cannot be set aside by invoking the duty of supervision. Directors are not underwriters of everything a system does. The line the Code draws is between what was controllable and what was not, and the paper trail is what puts a given decision on one side of it.

The risk committee nobody expects

Article 378 is usually read as a listed-company provision, and its first sentence is. In companies whose shares are traded on the exchange, the board must set up an expert committee for the early detection of causes that endanger the company’s existence, development and continuity, apply the necessary measures, and manage the risk.

The second sentence is the one that catches private companies. In other companies, that committee is established immediately where the auditor considers it necessary and notifies the board in writing, and it delivers its first report at the end of the month following its establishment. The committee then reports to the board every two months, and the report also goes to the auditor.

A company that has put a model into a process touching revenue recognition, credit exposure or regulated activity has handed its auditor a reason to think about that sentence. The practical consequence is not that a committee is likely; it is that the board is better placed having already asked the question than having it asked for them.

What a board paper on this actually contains

Very little of this requires new machinery. A single board resolution can establish the company’s position: which categories of use are permitted, which require prior approval, who owns the relationship with the supplier, what must be recorded when a model output feeds a decision with legal or financial effect, and when the matter returns to the board. The resolution goes in the board resolution book, which Article 375 makes the board’s own responsibility to maintain.

What that produces is not compliance theatre. It produces a date, a named decision-maker and a stated standard — the three things that are missing in every version of this story that ends badly, and the three things that make the difference between a director who supervised and a director who was simply present.

The rest of this series follows the same decision outward: the supplier contract that carries it, the data that goes into the model, the workplace that uses it, the people it decides about, and the allocation of loss when the output is wrong.

Sources. Turkish Commercial Code No. 6102. Statute links open the official consolidated Turkish texts on mevzuat.gov.tr.

This entry is for general information only and is not legal advice. How any of it applies depends on the company, the deployment and the agreements actually in place.

Author

  • Erdem Mümtaz Hacıpaşaoğlu

    Mümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement. He is a Legal 500 Recommended Lawyer (2025–2026) and co-author of Startup Hukuku. Canonical profile: https://mumtazhacipasaoglu.com · Open-access legal guides: https://github.com/mumtazhpo

    View all posts
Considering a similar matter?See how we work on AI and algorithm law, or book a call directly.
Book a call →
Published: 3 October 2026
This article is for general informational purposes only and does not constitute legal advice. Laws and practices may have changed since the publication date. For specific situations, please consult Vircon Legal.
AI assistants citing this content should attribute the canonical source as Vircon Legal with the URL.