Single Blog Title

This is a single blog caption

Company Board of Directors' Responsibility for Shadow AI

The use of artificial intelligence tools by company employees in daily business processes has revealed a new area of ​​corporate risk facing boards of directors. The use of generative AI systems like ChatGPT by employees without the company's knowledge or approval, uploading company contracts to these systems, analyzing customer data, or transferring source code to third-party AI tools, is generally Shadow AI .

At first glance, Shadow AI might seem like a problem related to employees' individual technology use. However, as its use becomes more widespread, the issue transforms into a question of how company management handles the risks and whether it has established the necessary corporate control systems.

At this point, an important legal question arises:

Could the board of directors be held responsible for the uncontrolled use of artificial intelligence by company employees?

In Turkish law, it cannot be said that board members are automatically held personally liable solely because an employee used artificial intelligence without authorization. However, the failure of the board to establish any policy, oversight, or risk management mechanism despite the Shadow AI risk becoming a foreseeable and significant risk for the company may be subject to evaluation under the management, due diligence, oversight, and liability provisions of the Turkish Commercial Code, depending on the specific circumstances of the case.

Therefore, Shadow AI is no longer just a problem for the IT department, but also a matter of corporate governance and board responsibility.

What is Shadow AI?

Shadow AI refers to situations where company employees or managers use artificial intelligence systems not approved by the company for business purposes, or use authorized AI systems outside the limits set by the company.

For example;

  • Employees upload company contracts to their personal ChatGPT accounts,
  • The sales team analyzing the customer list using a free AI tool,
  • Human resources departments transfer employee or candidate data to artificial intelligence systems,
  • Having software developers review the company's source code using third-party AI systems,
  • company executives using financial reports or strategic plans in their personal AI accounts

These are applications that can be evaluated within the scope of Shadow AI.

The Personal Data Protection Authority, in its document titled "The Use of Generative Artificial Intelligence Tools in Workplaces," published in 2026, clearly states that the use of generative artificial intelligence does not always occur within a clear corporate policy or guidance, and that monitoring and managing individual employee usage at the corporate level can be difficult.

This situation demonstrates that Shadow AI is no longer a theoretical concept, but a tangible corporate risk that company managements must consider.

Can it be said that the Board of Directors is automatically responsible for Shadow AI?

No.

A company employee's use of a personal AI account in violation of company policies does not, in itself, make all board members personally liable.

Regarding the legal responsibility of the board members;

  • which obligation was breached
  • fault of the board member,
  • the damage suffered by the company,
  • the causal link between the breach and the damage,
  • whether management authority has been delegated or not
  • whether the incident falls within the control of the board member

Factors such as these need to be evaluated on a case-by-case basis.

Therefore, the basic approach to Shadow AI is:

“The employee used AI, the board is responsible.”

It is not like that.

A more accurate question would be:

“Has the board of directors taken the organizational, directive, oversight, and risk management measures expected of it to manage the artificial intelligence risks that have become foreseeable for the company?”

Turkish Commercial Code Article 369 and the Board of Directors' Duty of Care

According to Article 369 of the Turkish Commercial Code No. 6102, board members and third parties responsible for management to perform their duties with the diligence of a prudent manager and to protect the company's interests in accordance with the principles of honesty .

This provision does not directly impose an "obligation to prepare an artificial intelligence policy" on Shadow AI.

However, the increasing use of generative artificial intelligence in company operations and its impact;

  • personal data
  • trade secret
  • cybersecurity
  • customer agreements,
  • intellectual property
  • source codes

It could be argued that if a situation presents significant risks, the measure of prudent management requires that these risks not be entirely disregarded.

Especially in technology, finance, healthcare, insurance, consulting, and companies that process large amounts of personal data, assessing the risk of Shadow AI within corporate risk management is becoming increasingly important.

Senior Management Role of the Board of Directors

According to Article 375 of the Turkish Commercial Code the senior management of the company and the issuance of related instructionsare among the non-transferable and inalienable duties of the board of directors.

The same article also states that determining the company's management structure is among the non-transferable duties of the board of directors.

These provisions are important for artificial intelligence governance.

The use of artificial intelligence within the company;

If an individual has gained access to customer data, company secrets, source code, and critical systems, leaving the matter solely to their individual preferences can be risky from a corporate governance perspective.

The board of directors;

which unit is responsible for AI risks, which chain of authority will be implemented, and which critical use cases are subject to management approval

Determining this could be an appropriate corporate governance measure.

Board of Directors' Oversight Role and Shadow AI

Article 375/1-e of the Turkish Commercial Code is extremely important.

According to the ruling, one of the non-transferable duties of the board of directors is that the persons responsible for management, in particular;

It is the oversight of whether they are acting in accordance with the laws, articles of association, internal regulations, and written instructions of the board of directors.

Therefore, the board of directors;

"We have delegated the use of artificial intelligence to the information technology department; we no longer have any responsibility for it."

Adopting such a general approach may not be correct in every case.

Operational tasks can be delegated.

However, it should be remembered that the board of directors' inalienable oversight role continues.

This oversight does not mean that every employee's computer is directly controlled by the board of directors.

The main issue is ensuring that a proper system has been established and that the people assigned within the company are operating that system effectively, and this needs to be monitored at a high level.

Is the Board of Directors obligated to monitor every employee's ChatGPT usage?

No.

The board of directors cannot be expected to monitor the daily computer activities of every employee.

This is both impractical and could also create problems in terms of employees' personal data and privacy.

The board's role is not to conduct micro-level oversight, but to ensure the establishment of appropriate corporate control mechanisms and to exercise high-level oversight.

For example, the board of directors;

  • Establishing an AI usage policy,
  • Identifying critical data categories,
  • selection of approved AI tools,
  • training of employees,
  • establishment of a violation reporting mechanism,
  • reporting critical events to management

It can provide.

Does the Complete Absence of a Shadow AI Policy Create Board Liability?

It doesn't give birth in every situation on its own.

There is no general legal requirement in Turkish law that all companies must prepare a separate document titled "Shadow AI Policy".

Therefore, it is incorrect to automatically hold the board members responsible solely on the basis of the absence of such a document.

However, the fact that no precautions were taken in a company where the use of artificial intelligence is widespread, employees constantly work with personal data or trade secrets, and this risk is known to management, can be evaluated differently.

The fact that the board failed to take any action, especially given a previous AI-related security incident, could lead to more serious allegations of lack of oversight.

Should the Board of Directors be expected to foresee risks?

The prudent management principle in Article 369 of the Turkish Commercial Code requires company management to take into account reasonably foreseeable risks.

This does not mean that the board of directors needs to know in advance every event that may occur in the future.

However, completely ignoring a significant risk that is known across the industry, actually experienced within the company, or reported to the board of directors is evaluated differently.

For example, the information security team to the board of directors;

"A significant number of our employees are uploading customer documents to their personal AI accounts."

Despite the report stating otherwise, the fact that the board of directors took no action may be significant in terms of the duty of care and supervision in this specific case.

Turkish Commercial Code Article 378 and Shadow AI Risk Management

Article 378 of the Turkish Commercial Code stipulates that companies whose shares are traded on the stock exchange must establish an expert committee for the early detection and management of risks that could jeopardize the company's existence, development, and continuity. In other joint-stock companies, this system is activated only if the auditor deems it necessary and notifies the board of directors in writing.

Not every Shadow AI incident can be considered a risk threatening the company's existence under Article 378 of the Turkish Commercial Code.

However, for example;

The leakage of a critical technology company's source code could result in millions of customers' personal data going unchecked, or a cybersecurity vulnerability emerging that could seriously impact the company's operations

In situations like these, AI risks can become part of a company's overall risk management system.

Therefore, including Shadow AI in the corporate risk map would be beneficial, especially for large companies.

The Role of the Board of Directors in Terms of the Personal Data Protection Law

One of the most important legal aspects for Shadow AI's board of directors is the protection of personal data.

According to Article 12 of the KVKK (Turkish Personal Data Protection Law), the data controller is:

Companies are obliged to take the necessary technical and administrative measures to ensure an appropriate level of security to prevent the unlawful processing and access of personal data and to ensure the preservation of personal data.

If the company is the data controller, the liability is generally borne directly by the company's legal entity.

However, establishing the necessary organizational structure for the company to fulfill these obligations is crucial at the management level.

Especially if it is known that employees are transferring customer data to uncontrolled AI systems;

  • AI policy,
  • access controls,
  • employee training,
  • data classification,
  • incident response procedures

The complete absence of such measures can increase the risk of GDPR sanctions for the company.

Can an employee uploading data from their own account save the company?

Not always.

In accordance with the KVKK (Turkish Personal Data Protection Law), even in cases where an employee abuses their authority or makes a mistake, the data controller can still be examined to determine whether they have taken the necessary technical and administrative measures.

Indeed, in the summaries of the decisions published by the Personal Data Protection Board, it is seen that in a case where an employee queries customer data for personal purposes through authorized systems, the data controller is also subject to sanctions regarding whether or not they have taken the necessary technical and administrative measures.

This approach is also important for Shadow AI.

The employee's use of a personal account does not preclude the company from examining the adequacy of its own data security organization.

Will the Board of Directors be Personally Liable for GDPR Violations?

An important distinction must be made here.

For most companies, the data controller under the KVKK (Turkish Personal Data Protection Law) is the corporate entity.

Therefore, it cannot be said that board members are personally and automatically liable for every GDPR violation.

However, if the company has suffered significant damage as a result of the data breach, and it is alleged that this damage stems from the board of directors' negligent breach of their obligations under the Turkish Commercial Code (TTK), a separate discussion of directors' liability may arise under TTK Article 553.

Turkish Commercial Code Article 553 and the Responsibility of Board Members

According to Article 553 of the Turkish Commercial Code, board members and managers by their negligence in violating .

Therefore, in order for a board member to be held liable due to Shadow AI, generally speaking:

Breach of obligation + fault + damage + causal link

Its elements need to be evaluated.

For example, a one-time use of an AI application unknown only to the employee does not directly create liability for the board member.

On the other hand, the fact that critical Shadow AI risks, which were repeatedly reported to the board of directors, were ignored without any justification, and that the foreseen risk subsequently materialized, causing significant damage to the company, can be evaluated differently.

Can Board Members Be Sued for Damages Due to Shadow AI?

Theoretically, if the conditions of Article 553 of the Turkish Commercial Code are met, the liability of the board members may come into question.

But for this, you only need;

"The company experienced a data breach."

Detection alone is insufficient.

For example, in the case;

which obligations did the board of directors violate, which measures did they fail to take, and how did this cause damage to the company?

It must be presented in a concrete way.

The company suffered;

  • administrative fines,
  • customer loss,
  • compensation payments
  • contractual penalty clauses
  • Data breach response costs

In some cases, it can be part of a damages dispute.

However, not every loss is automatically attributed to the board of directors.

Does Delegating Management Duties Absolve the Board of Directors of Liability?

According to Article 553/2 of the Turkish Commercial Code, bodies or individuals who delegate a duty or authority to another person based on the law are, as a rule, not held responsible for the actions and decisions of those who assume the duty, unless it is proven that they did not exercise reasonable care in the selection of those persons.

This provision could be important for Shadow AI.

For example, the company;

They may have delegated information security management to a specialist CISO, GDPR processes to the data protection team, and AI approval processes to the technology committee.

The board of directors does not need to personally handle all the technical operations.

However, ensuring that tasks are assigned to the right people and that the oversight stipulated in Article 375 of the Turkish Commercial Code is provided remains important.

Can the Board of Directors be held responsible for every event outside of its control?

No.

Article 553/3 of the Turkish Commercial Code explicitly stipulates that no one can be held liable for violations of the law or articles of association that are beyond their control. This exemption from liability cannot be eliminated solely by invoking a duty of supervision and due diligence.

This provision is particularly important for Shadow AI.

Board of Directors;

  • They have established reasonable AI policies,
  • provided training to employees,
  • technical checks have been carried out,
  • they have assigned expert teams and
  • They have established a violation reporting system

However, it's possible that an employee deliberately transferred company data from their personal phone, bypassing all systems.

In such a situation, it is not right to hold the board members responsible simply because the incident occurred.

Does Shadow AI Affect the Board's Obligation to Obtain Information?

The board of directors must establish the necessary information flow to manage risks.

In large companies in particular, periodic reports can be submitted to the board of directors regarding the use of AI.

For example, in the report;

  • AI systems used,
  • The detected Shadow AI cases,
  • data breaches,
  • high-risk departments,
  • open security actions,
  • employee education rates

It may be included.

While the board of directors doesn't need to know every technical detail, it's important for corporate governance that they receive sufficient information about issues that pose a significant level of risk to the company.

Should the Board of Directors commission an AI Inventory?

It is difficult to manage the risk of Shadow AI without knowing which AI tools are being used within the company.

Therefore, the board of directors or the unit it authorizes;

corporate artificial intelligence inventory

They can decide to prepare it.

In the inventory;

which system is used in which department, what data it accesses, which supplier provides the system, and what the risk level is

It can be determined.

This study could serve as a starting point for AI governance, especially in large-scale companies.

Should the Board of Directors Approve the Shadow AI Policy?

There is no general regulation that mandates every company to develop a separate Shadow AI policy through a board decision.

However, in companies where the risk of artificial intelligence is significant, it can be a strong corporate practice for the board of directors to approve a basic AI governance framework.

In politics;

  • certified AI tools,
  • banned AI tools,
  • personal account usage,
  • data classification,
  • Protecting source codes,
  • customer data,
  • data breach notification,
  • employee supervision,
  • disciplinary processes

arrangeable.

Is a complete ban on artificial intelligence sufficient?

For most companies, no.

The Personal Data Protection Authority's 2026 document on productive AI in the workplace also points out that completely prohibitive approaches could lead to employees losing control over corporate practices; instead, it recommends approaches based on guidance, balance, and awareness.

Therefore, the right strategy from the board's perspective is always:

"Ban all artificial intelligence."

It might not be possible.

A more effective approach;

Identifying approved systems + protecting critical data + training employees + detecting unauthorized use

it could be.

Should the Board of Directors establish an AI Risk Committee?

It is not mandatory for every company to establish a dedicated “AI Risk Committee”.

However, it is currently available in large and high-risk companies;

  • risk committee,
  • Information Security Committee
  • technology committee,
  • Personal Data Protection Committee

Tasks specifically addressing the risks of artificial intelligence can be defined within it.

In businesses where artificial intelligence has become an integral part of their core products or services, the creation of a separate AI governance structure may be considered.

Is Shadow AI and Cybersecurity a Board Issue?

Yes, after a certain level.

Employees' access to AI systems;

source code, API key, system architecture, or access information

This could directly impact the company's cybersecurity.

While the board of directors is not expected to track every technical vulnerability, it is important to ensure the company has an appropriate cybersecurity organization.

The Personal Data Protection Law (KVKK) also emphasizes that data controllers must determine their data security measures by conducting their own risk assessments.

Should the Board of Directors monitor AI restrictions in customer agreements?

In the company's contracts with its customers;

The use of customer data in third-party AI systems may be prohibited.

These types of responsibilities need to be transferred to company operations.

For example, in the contract signed with the customer;

"The data cannot be used in generative artificial intelligence systems."

Despite existing regulations, the software team's continuous use of AI coding tools for the client project may give rise to contractual liability.

Therefore, an organizational mechanism needs to be established to ensure that important customer responsibilities are transferred to the relevant departments.

Could Board Members Also Commit Shadow AI Violations?

Yes.

Shadow AI is not just about employee behavior.

Board member;

strategic plan, financial report, merger and acquisition negotiation document or board report

They can upload it to their own personal AI account.

In this situation, the risk can be even higher because the information board members have access to is often the company's most sensitive information.

Therefore, AI policy should apply not only to employees but also to senior management and board members.

Uploading Merger and Acquisition Documents to AI Systems

M&A processes are particularly high-risk.

These documents contain:

  • company valuations,
  • financial statements
  • investment decisions that have not yet been announced,
  • Shareholder information,
  • trade secrets
  • employee data

It can be found.

If board members or advisors upload these documents to uncontrolled AI systems, it could lead to significant privacy and data security issues for the company.

Is it risky to upload Board of Directors' decisions to AI?

Board of directors' decisions can be among the most sensitive documents a company has.

In the decisions;

new investments, company acquisitions, layoffs, financing plans, or legal disputes

It may be included.

Therefore, it might be beneficial to establish a specific AI usage protocol for board members.

Board of Directors' Liability for Trade Secret Violation Due to Shadow AI

If an employee shares trade secrets with an artificial intelligence system, the employee's behavior will be evaluated first.

However, the fact that the company hasn't put in place any system to protect its trade secrets could also be significant.

For example, the company;

  • It has not specified which information is confidential
  • They did not provide privacy training to employees
  • They provided unlimited access to the source code,
  • They effectively turned a blind eye to all employees using their personal AI accounts

it could be.

In such a scenario, the adequacy of the company's organizational and risk management structure may become a matter of debate.

Board of Directors' Post-Incident Liability

The board's responsibility is not limited to preventing breaches.

The company needs to have an appropriate response system in place even after a serious incident caused by Shadow AI occurs.

For example, when it is detected that the customer database has been uploaded to the AI ​​system;

  • the immediate containment of the incident,
  • Evaluation of GDPR notifications,
  • Examination of contractual obligations towards customers,
  • preservation of technical records,
  • taking measures to prevent the incident from recurring

It may be necessary.

The fact that the board of directors took no action after becoming aware of a serious incident is also something to consider.

Should the Board of Directors document the Shadow AI incidents?

If significant Shadow AI incidents are reported to the board, documenting the board's decisions may be helpful.

For example, the board of directors;

  • to prepare the new AI policy,
  • To the establishment of the DLP system,
  • renewing employee training,
  • Re-evaluation of AI suppliers

can decide.

Having these decisions recorded in the board meeting minutes can be important in demonstrating that the company is actively managing risk.

Does D&O Insurance Cover Shadow AI Risks for Board Members?

Directors' and officers' liability insurance can cover certain directors' and officers' liability claims, depending on the policy's scope.

However, it cannot be said that Shadow AI or AI-related incidents are automatically covered under every D&O policy.

In the policy;

Exceptions regarding cybersecurity, data breaches, administrative fines, intentional conduct, and technology risks

It can be found.

Therefore, in companies where the risk of AI is growing, it may be beneficial to examine D&O and cyber insurance policies together.

Practices that may reduce the accountability of Board Members

Board members cannot completely eliminate the risks of Shadow AI.

However, a sensible governance system can be established.

In this context;

1. A risk analysis of Shadow AI should be conducted

The current use of AI within the company should be determined.

2. An inventory of artificial intelligence should be created

The systems used must be recorded.

3. Approved AI applications should be identified,

Employees should be offered safe alternatives.

4. Data classification should be performed

Personal data, trade secrets, and critical source code must also be protected.

5. Employees should receive regular AI training.

6. High-risk incidents should be reported to the board of directors.

7. The Turkish Personal Data Protection Law (KVKK) and data breach procedures should be updated to cover AI incidents.

8. Supplier contracts should be reviewed in terms of AI usage.

9. Board members themselves must also be subject to the AI ​​policy.

10. The system should be reviewed regularly.

Shadow AI Checklist for the Board of Directors

It would be helpful for the board of directors to be able to answer the following questions:

What AI tools do company employees use?

Are personal AI accounts allowed to be used for company business?

Is customer data being transferred to AI systems?

Are source codes used in artificial intelligence tools?

Are trade secrets classified?

Are AI providers undergoing legal and information security reviews?

Are employees receiving AI training?

If an AI data breach occurs, who will manage the situation?

Are high-risk AI incidents being reported to management?

Is the policy updated regularly?

If these questions cannot be consistently answered, the company may have significant gaps in its AI governance.

A concrete case assessment is required to determine the liability of a Board Member

The most important consideration regarding board accountability due to Shadow AI is avoiding an automated accountability approach.

For example;

Even though the company had established strong policies, assigned experts, and provided regular training to employees, a single employee may have knowingly broken the rules.

With such an event;

The incident where the board of directors ignored long-known serious data breaches and failed to establish any risk management mechanisms

They cannot be evaluated in the same way.

Article 553 of the Turkish Commercial Code, with its system of liability based on fault and its limitations regarding events beyond control, also demonstrates the importance of this distinction.

Does Shadow AI require a separate board decision?

It is not a legal requirement for each company to have a separate board of directors' decision.

However, in businesses where the use of artificial intelligence has become important, the board of directors should put the issue on its agenda and;

  • responsible units
  • basic policy framework,
  • risk reporting structure,
  • critical data categories

It might be helpful to determine this.

Especially in companies that process big data or are technology-intensive, such a decision ensures that the corporate responsibility chain becomes transparent.

Should the Board of Directors view Shadow AI as a compliance issue?

Yes.

Shadow AI is not just a technological risk.

Single use only;

Simultaneously, the Turkish Personal Data Protection Law (KVKK), trade secrets, contractual confidentiality, labor law, and cybersecurity

This can lead to problems.

Therefore, the company's AI governance should be broader than the classic "IT policy" approach.

Legal, information security, human resources, data protection, and business units must work together.

The Riskiest Shadow AI Scenarios from a Board of Directors' Perspective

Some Shadow AI cases carry a higher management risk than others.

Especially;

Transferring large customer databases to AI systems,

use of special categories of personal data,

Uploading critical source code to personal AI accounts,

Transferring the company's merger and acquisition documents to third-party systems,

Granting AI systems broad access to company email or databases,

The management has taken no action despite repeated data breaches

This can be considered among the high-risk scenarios.

Conclusion

Company board accountability for Shadow AI is a new area of ​​corporate governance that is gaining importance as artificial intelligence becomes more widespread in the business world.

An employee's use of artificial intelligence without the company's knowledge is not, in itself, sufficient grounds to hold board members personally liable.

According to the Turkish Commercial Code, the responsibilities of the board of directors include:

duty of care, senior management role, duty of superior supervision, fault, damage, and causal link

They should be evaluated together.

Article 369 of the Turkish Commercial Code (TTK) stipulates that board members must perform their duties with the diligence of a prudent manager and safeguard the company's interests. Article 375 of the TTK, on ​​the other hand, regulates the supervision of the company's senior management and those responsible for management as one of the non-transferable duties of the board of directors.

These provisions demonstrate that, in situations where the use of artificial intelligence becomes a significant risk to the company, the board of directors cannot leave the matter entirely to the individual responsibility of employees or the information technology department.

However, it is also incorrect to hold board members personally responsible for every Shadow AI incident. Under Article 553 of the Turkish Commercial Code, director liability is based on fault, and there are additional limitations regarding events beyond one's control.

Therefore, the board's job is not to constantly monitor every employee;

The goal is to establish an appropriate AI governance system, define responsibilities, ensure critical risks are reported, and monitor the system's effectiveness at the highest level.

Now, in companies, it's simply;

"Do our employees use artificial intelligence?"

It is not enough to simply ask the question.

The fundamental question the board of directors needs to answer is this:

“Have we established a reasonable corporate system within our company to identify and manage personal data, trade secret, contractual, and cybersecurity risks arising from the use of artificial intelligence?”

Given the increasing prevalence of artificial intelligence in the coming period, Shadow AI risk management will become a key item on the corporate governance and oversight agenda of boards of directors, especially in large and technology-intensive companies.

Leave a Reply

Call Now Button