A model produces a wrong number, a wrong summary or a wrong recommendation, and somebody acts on it. A customer is quoted a price the company did not intend. A filing goes out with a figure that was never checked. An applicant is rejected on a basis that does not hold. The question then is not whose fault it feels like. It is which contract, and which provision of the Commercial Code, moves the loss.
This closes a series on what the move to artificial intelligence does to a company’s legal position, following the board decision, the vendor contract, the data going in, the workplace and automated decisions about people.
The counterparty does not care about your model
Start where the money starts. The person who suffered the loss has a relationship with the company, not with the company’s supplier and certainly not with the provider of the underlying model. Their claim runs on the contract they signed or the duty they were owed, and the internal cause is, to them, an implementation detail.
This is the structural point that gets missed in procurement. The company is the first line in every direction — customer, counterparty, regulator, employee — regardless of where the error originated. Everything the supplier chain offers is recovery, and recovery is a second, slower, less certain conversation. A liability cap of twelve months’ fees is not a risk transfer for an exposure that is not measured in fees.
What the supplier chain actually gives you
Three things, and it is worth being clear about which is which.
A service level commitment addresses availability, not correctness. It is the wrong instrument for this risk and companies routinely treat it as the right one.
An indemnity is the useful instrument, and its scope is narrow in most standard terms: third-party intellectual property claims arising from output, sometimes data protection breaches caused by the supplier. Extending it to consequential loss from erroneous output is a real negotiation and on a large platform it is usually not winnable. Knowing that before deployment is the point; it tells you what has to be handled another way.
A cap defines the ceiling on everything not carved out. Read it against a realistic bad day for the specific process, not against the subscription value.
Where the Commercial Code sits
Internally, the allocation runs through Article 553. Directors and managers are liable to the company, to shareholders and to company creditors for damage caused by culpably breaching duties arising from the law and the articles. Its second paragraph protects those who delegate, unless failure to exercise reasonable care in selection is proven — which is why the selection file discussed in the second part is a liability instrument and not an administrative one.
Its third paragraph matters just as much in the other direction. Nobody may be held liable for breaches outside their control, and that position cannot be defeated by invoking the duty of supervision. A director who established a standard, delegated within a documented framework, and could not have known of a specific failure is arguing from a different place than one who never set a standard at all. The Code does not ask directors to guarantee outcomes. It asks whether the organisation was put in place.
Insurance is a separate question and it is not automatic
Companies assume existing cover responds. Often it does not, because the loss is neither a physical event nor a classical cyber incident, and professional indemnity wordings differ considerably on whether an erroneous automated output is a covered act. We examined how errors and omissions, cyber and product liability wordings respond to a model being wrong in a separate analysis. The short version is that this is a question to put to the broker before deployment, with the specific use described, rather than after an incident.
What a workable allocation looks like
The realistic position for most companies is not a clean transfer of risk. It is a layered one. Contract terms take what they can from the supplier and are read honestly for what they leave behind. Process controls — human review proportionate to consequence, logging that makes a past decision reconstructible, a defined threshold above which output is verified independently — reduce the frequency and the size of the exposure that remains. Insurance is checked against the actual deployment rather than assumed. And the board records that this is the position it has chosen, which returns the series to where it began.
None of this makes the technology risky in a way that argues against using it. It makes it ordinary: a capability the company depends on, carrying a loss profile that somebody has to own deliberately rather than discover afterwards.
This entry is for general information only and is not legal advice. How any of it applies depends on the company, the deployment and the agreements actually in place.
Author
-
View all postsMümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement. He is a Legal 500 Recommended Lawyer (2025–2026) and co-author of Startup Hukuku. Canonical profile: https://mumtazhacipasaoglu.com · Open-access legal guides: https://github.com/mumtazhpo
More from Vircon Insights
When the Model Decides About a Person: Hiring, Performance and KVKK Article 11
October 7, 2026Feeding Company Data to a Model: KVKK Basis, Transfer Abroad and the Trade Secret You Just Uploaded
October 5, 2026Director Liability in a Turkish Joint-Stock Company: Founders, Investor Nominees and Articles 553–560
September 28, 2026When a Family Company Invests in Startups: Structure, Conflicts and the Rights That Break the Next Round
August 28, 2026Privileged Shares in a Turkish Joint-Stock Company: How Liquidation Preference and Investor Vetoes Are Actually Built
October 5, 2026Buying an AI Tool, Not Building One: What the Vendor Contract Has to Say
October 4, 2026Related Practice Areas
Corporate Law
Share transfers, capital increases, board structuring, governance.
View service →ICOs, Crypto & Blockchain
Crypto-asset regulation, token offerings, exchange and custody licensing.
View service →US Company Formations & Flip-Ups
Delaware C-Corp, flip-up structures, SAFE/convertible notes, 83(b).
View service →