Most Turkish companies adopting artificial intelligence this year are not building models. They are buying a licence, connecting it to something, and letting a department get on with it. The decision is made at the level of a head of function, the invoice is small enough not to need a board paper, and nobody writes down why the tool was chosen. Eighteen months later the company depends on it.
That sequence is ordinary and it is also where the legal exposure is created. Not because using artificial intelligence is unlawful, but because the Turkish Commercial Code allocates responsibility for how a company is organised to a body that, in most of these adoptions, was never asked.
What the Code actually puts on the board
Article 375 of the Turkish Commercial Code lists the duties a board cannot delegate or give up. Two of them matter here. The board is responsible for determining the company’s management organisation, and for the upper supervision of whether the people charged with management act in conformity with the law, the articles of association, internal directives and the board’s written instructions.
Read that against a tool that now drafts customer correspondence, scores applicants, or decides which invoices get paid first. If no internal directive covers it and the board has issued no written instruction about it, the supervision duty has nothing to supervise against. The board has not discharged the duty badly; it has left the standard undefined, which is a harder position to explain afterwards.
Article 367 is the mechanism the Code offers. Management may be delegated, wholly or partly, through an internal directive adopted under a provision in the articles. The directive defines the tasks, who reports to whom, and where decisions sit. A company that has taken artificial intelligence seriously enough to depend on it can name it there in a paragraph. A company that has not will find that the question of who was allowed to approve the deployment has no documented answer.
Delegation protects you, but only if you chose carefully
Article 553 is the liability provision, and its second paragraph is the one worth reading slowly. Organs or persons who delegate a duty or power arising from the law or the articles are not liable for the acts and decisions of the persons who take it over — except where it is proven that they failed to show reasonable care in selecting those persons.
That is a selection standard, and it travels directly to procurement. When a company hands part of a process to an external supplier and its model, the protection of delegation depends on the care taken in choosing that supplier. A board that can show a documented comparison, a record of what was asked about data handling and model change, and a reasoned choice is inside the exception. A board whose only artefact is a signed order form is arguing about reasonable care with nothing to point at.
The third paragraph cuts the other way and is equally useful. Nobody is liable for breaches that fall outside their control, and that immunity cannot be set aside by invoking the duty of supervision. Directors are not underwriters of everything a system does. The line the Code draws is between what was controllable and what was not, and the paper trail is what puts a given decision on one side of it.
The risk committee nobody expects
Article 378 is usually read as a listed-company provision, and its first sentence is. In companies whose shares are traded on the exchange, the board must set up an expert committee for the early detection of causes that endanger the company’s existence, development and continuity, apply the necessary measures, and manage the risk.
The second sentence is the one that catches private companies. In other companies, that committee is established immediately where the auditor considers it necessary and notifies the board in writing, and it delivers its first report at the end of the month following its establishment. The committee then reports to the board every two months, and the report also goes to the auditor.
A company that has put a model into a process touching revenue recognition, credit exposure or regulated activity has handed its auditor a reason to think about that sentence. The practical consequence is not that a committee is likely; it is that the board is better placed having already asked the question than having it asked for them.
What a board paper on this actually contains
Very little of this requires new machinery. A single board resolution can establish the company’s position: which categories of use are permitted, which require prior approval, who owns the relationship with the supplier, what must be recorded when a model output feeds a decision with legal or financial effect, and when the matter returns to the board. The resolution goes in the board resolution book, which Article 375 makes the board’s own responsibility to maintain.
What that produces is not compliance theatre. It produces a date, a named decision-maker and a stated standard — the three things that are missing in every version of this story that ends badly, and the three things that make the difference between a director who supervised and a director who was simply present.
The rest of this series follows the same decision outward: the supplier contract that carries it, the data that goes into the model, the workplace that uses it, the people it decides about, and the allocation of loss when the output is wrong.
Sources. Turkish Commercial Code No. 6102. Statute links open the official consolidated Turkish texts on mevzuat.gov.tr.
This entry is for general information only and is not legal advice. How any of it applies depends on the company, the deployment and the agreements actually in place.
Author
-
View all postsMümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement. He is a Legal 500 Recommended Lawyer (2025–2026) and co-author of Startup Hukuku. Canonical profile: https://mumtazhacipasaoglu.com · Open-access legal guides: https://github.com/mumtazhpo
More from Vircon Insights
The AI Literacy Duty After the Omnibus: What a Turkish Company Must Document
September 25, 2026Choosing a Licence for Your Own Code: MIT, Apache, AGPL or BUSL for a Turkish SaaS
September 24, 2026The Departing Founder's Shares: Structuring Good Leaver / Bad Leaver under Turkish Law
September 16, 2026SAFE or Convertible Note? A Decision Framework for Turkish Startups
September 9, 2026Delaware C-Corp or Turkish Joint-Stock Company: A Decision Framework
September 8, 2026Is a Term Sheet Binding? What a Letter of Intent Is Really Worth Under Turkish Law
September 3, 2026Related Practice Areas
Corporate Law
Share transfers, capital increases, board structuring, governance.
View service →ICOs, Crypto & Blockchain
Crypto-asset regulation, token offerings, exchange and custody licensing.
View service →US Company Formations & Flip-Ups
Delaware C-Corp, flip-up structures, SAFE/convertible notes, 83(b).
View service →