Single Blog Title

This is a single blog caption

Employer Responsibility in the Use of Shadow AI

With the increasing prevalence of artificial intelligence tools in the workplace, one of the new legal risks facing companies shadow AI . Employees using AI tools without the knowledge of company management, legal department, or IT department can lead to personal data, trade secrets, customer information, and company documents becoming uncontrolled.

An employee might upload a company contract to an AI system like ChatGPT to analyze a customer list, categorize employee data, or examine the company's source code using an AI tool, all in an effort to speed up their work. However, the fact that the employee performs these actions from their personal account and without the employer's knowledge raises an important question:

Will the employer be held responsible for the use of Shadow AI?

It is not possible to give the same answer to this question in every case. However, the fact that the employee carried out the transaction without the company's knowledge does not absolve the employer of legal responsibility in every situation.

It is particularly important whether the company has taken the necessary preventive measures with regard to the protection of personal data, the security of trade secrets, the employer's duty of care, information security, and contractual obligations to third parties.

Therefore, Shadow AI should be considered not only as an individual error by the employee, but also a corporate risk management and AI governance issue for the employer .

What is Shadow AI?

Shadow AI refers to employees using artificial intelligence tools not approved by the company for work purposes, or using company-approved AI systems outside of the defined limits.

For example, an employee;

  • You can upload the customer agreement to your personal ChatGPT account
  • The company can have its customer list analyzed by an artificial intelligence system
  • It can classify employee personal information using artificial intelligence
  • The company can have its source code reviewed by a third-party AI tool
  • The company can transfer its pricing table to an artificial intelligence system
  • You can upload case or investigation files to artificial intelligence.

The common feature of these processes is that company information is processed by an artificial intelligence system that is outside the direct control of the company.

Can an employer be held responsible for an employee's use of Shadow AI?

Yes, depending on the specifics of the case.

An employee using artificial intelligence from their own account or without the employer's knowledge does not mean the employer is free from responsibility.

Specifically, the company;

If an employer has not regulated the use of artificial intelligence by its employees, has not specified which systems can be used, has not restricted the uploading of personal data and trade secrets to AI systems, and has not provided its employees with the necessary training, the employer's corporate security obligations may be questioned.

Therefore, in the legal assessment, only;

"What did the employee do?"

not to the question;

"What did the employer do to prevent this risk?"

This question also needs to be answered.

Shadow AI and Employer's Responsibility Under GDPR

One of the most important areas of responsibility for employers is the protection of personal data.

If the company is the data controller with respect to the personal data it processes, it is obliged to fulfill its obligations under the Law No. 6698 on the Protection of Personal Data.

For example, a company employee;

customer name and surname, telephone number, email address, employee information, health data or other personal data

Uploading data to an uncontrolled artificial intelligence system could pose a risk to personal data security.

At this point, the employer;

It is important to know what technical and administrative measures have been taken, whether employees have been trained, whether access rights have been restricted, and whether an internal policy has been established regarding the use of artificial intelligence.

Is the defense "The employee used their own account" sufficient?

It may not always be enough.

Companies are dealing with Shadow AI cases;

"We did not provide this application. The employee used it from their own account."

He can present his defense.

However, since the data controller has an obligation to take the necessary technical and administrative measures in terms of personal data security, the incident cannot be evaluated solely on the basis of the employee's personal conduct.

For example, if hundreds of employees within a company use personal AI accounts and company management fails to create any policies or technical safeguards, the company's risk management could also be examined in the event of a data security breach.

Therefore, it is incorrect for employers to view Shadow AI as solely a personal problem for employees.

Should the employer take data security measures?

Yes.

Companies need to establish reasonable technical and administrative measures to protect the security of personal data and company information.

In terms of Shadow AI, these measures include:

  • Identification of approved artificial intelligence tools,
  • Regulation of personal account usage,
  • data classification,
  • providing training to employees,
  • Restricting the uploading of trade secrets to artificial intelligence systems,
  • controlling critical file movements and
  • Establishing a reporting procedure for AI-related incidents

It may be included.

The employer's failure to take any precautions could become a significant factor in the consideration of a potential dispute.

Employer's Risk Regarding Special Categories of Personal Data

The risk is even higher when sensitive personal data is involved in the use of Shadow AI.

For example, a human resources employee;

employee health reports, disability information, or other sensitive data

By uploading the data to a personal artificial intelligence system, one can have a report generated.

Even if an employee's only intention is to make their job easier, serious data security issues can arise for the employer.

Therefore, it is important to establish stricter rules for the use of artificial intelligence, especially in human resources, health, insurance, and legal departments.

Employer's Responsibility Regarding Data Transfer Abroad

Depending on the infrastructure of the artificial intelligence service used, personal data may be processed or stored abroad.

When an employee transfers personal data to a foreign artificial intelligence system, the provisions of the Turkish Personal Data Protection Law (KVKK) regarding the transfer of personal data abroad should be examined according to the technical and legal nature of the event.

Employer;

"The employee chose the application themselves."

Simply saying that doesn't automatically eliminate this risk.

It is important for the company to determine in advance which systems employees can use and to restrict practices that are risky in terms of international data transfer.

Uploading Trade Secrets to Artificial Intelligence and the Employer's Responsibility

Shadow AI doesn't just pose a risk in terms of personal data.

The employee;

customer lists, source code, cost tables, pricing strategies, investment plans, or other confidential company information

Transferring this information to an artificial intelligence system could have serious consequences for the protection of trade secrets.

To demonstrate that the company genuinely wants to protect its trade secrets, it is important for it to establish reasonable safeguards regarding the confidentiality of this information.

For example, the company's;

its failure to identify which information constitutes trade secrets, its granting of unlimited access to all employees, and its lack of any privacy policy

This could weaken the company's position in any disputes that may arise later.

What should employers do to protect trade secrets?

The company must first classify information that constitutes a trade secret.

For example;

public, internal, confidential, and top confidential

A data classification system can be created in this way.

Next, it can be determined which data categories can be used in artificial intelligence systems.

For example, uploading source code classified as "top secret," board documents, or investment projects to external artificial intelligence systems could be completely prohibited.

Such measures not only provide technical security; they also demonstrate the company's commitment to protecting its trade secrets.

Contractual Liability Towards Third Parties

An employee's use of Shadow AI may also create liabilities for the company towards its customers or business partners.

The company may have committed to keeping certain information confidential in its contract with the customer.

When an employee uploads this information to an artificial intelligence system, it could constitute a breach of contractual confidentiality obligations.

For example, an employee of a consulting firm could upload confidential project documents belonging to a client to an artificial intelligence system.

In this case, the customer;

compensation for damages, payment of any penalty clause if stipulated in the contract, or application of other contractual sanctions

can request.

The company's;

"The document was uploaded by an employee, not management."

This defense does not automatically eliminate the contractual obligation undertaken towards the customer.

Can an employer be liable to pay compensation for an employee's actions?

It is possible depending on the specifics of the case.

If third parties suffer damage as a result of actions taken by an employee while performing their duties, general provisions regarding the employer's liability may apply.

For example, if an employee transfers customer data to an unauthorized AI system, resulting in harm to the customer;

personal data law, contractual liability and general compensation provisions

They can be examined together in terms of these aspects.

The employer's responsibility and the employee's personal responsibility can be considered separately.

Can an employer seek recourse against an employee?

If the company suffers damages due to an employee's negligent conduct, the employer may have the right to seek redress from the employee, depending on the specific circumstances of the case.

However, there is no automatic recourse mechanism here.

The employee;

the degree of fault, job description, training received, instructions given by the employer, company's own safety deficiencies, and other reasons for the incident

They should be evaluated together.

For example, if a company has not presented any AI policies to its employees and has been effectively encouraging the use of AI for years, it may be debatable to place all the resulting harm solely on the employee.

Employer's Duty of Care and Shadow AI

The employer's duty of care towards the employee is a fundamental element of the employment relationship.

As artificial intelligence systems are integrated into business processes, determining the conditions under which employees will use these technologies may become part of the employer's organizational responsibilities.

For example, if a company requires an employee to use an AI tool but provides no training on which data cannot be entered into the system, this may highlight a lack of organization and guidance on the part of the employer.

Therefore, managing Shadow AI is not just about disciplining employees.

Employers also need to create a safe working environment and clear rules of use.

Could an employer face administrative sanctions due to Shadow AI?

In the event of a personal data breach, the company's obligations under the Turkish Personal Data Protection Law (KVKK) and possible administrative sanctions may come into play.

Here's the situation:

whether a personal data breach occurred, whether the data controller took the necessary precautions, and whether the necessary processes were carried out in a timely manner after the breach

It can be examined.

Therefore, the Shadow AI case may not end simply with a disciplinary investigation against the employee.

The company's data protection obligations should also be evaluated.

Are employers required to monitor employees' use of artificial intelligence?

It may not be practically possible for the company to have complete control over its use of artificial intelligence.

However, it is important to take reasonable precautions against known and foreseeable risks.

Especially if the use of artificial intelligence is known to be widespread within the company;

"We didn't know the employees were using it."

Its defenses may become progressively weaker.

Therefore, companies should at least:

It needs to identify which AI tools are being used, pinpoint risky practices, and establish clear rules for employees.

Does the employer have unlimited supervisory authority?

No.

Employers can monitor employees' digital activities to a certain extent in order to prevent the risk of Shadow AI.

However, this control;

protection of personal data, privacy and freedom of communication

It is limited in terms of...

The company's unrestricted access to all private correspondence and personal accounts of employees in an effort to prevent Shadow AI could also create a separate legal problem.

Therefore, an employer should not create another legal breach while trying to prevent one legal risk.

Is it important to inform employees in advance?

Yes.

Companies provide to their employees;

which artificial intelligence systems can be used, which systems are prohibited, which data cannot be uploaded, and to what extent usage can be monitored

It is important to state this clearly.

These rules;

employment contract, employee handbook, information security policy, or a separate artificial intelligence usage policy

It can be edited within.

Rules must be clear and understandable so that it can be determined which rule an employee has violated.

Should employers develop a Shadow AI policy?

For companies where the use of artificial intelligence is widespread, it is extremely important to have a written Shadow AI or enterprise AI usage policy in place.

In politics, especially;

  • artificial intelligence systems that can be used,
  • use of personal accounts,
  • processing of personal data,
  • protection of trade secrets
  • use of source codes,
  • Transfer of classified documents,
  • human control,
  • incident reporting procedure and
  • disciplinary processes

It should be regulated.

The policy should be formulated to align with the company's actual business processes.

Does Simply Drafting Policies Absolve Employers of Responsibility?

No.

It is not enough for a company to simply have a comprehensive artificial intelligence policy on paper.

The policy needs to be implemented.

For example, the company;

"Employees cannot upload personal data."

They may have set such a rule but provided no training, all employees continued to use their personal AI accounts, and management may have known about this but taken no action.

In this situation, simply having a written policy may not be considered an effective measure.

Therefore, politics;

through training, technical measures, supervision and incident response processes

It should be supported.

Why is it important to provide AI training to employees?

A significant portion of Shadow AI cases may stem from a lack of information, not malicious intent.

Worker;

"I only had the contract summarized."

he can say.

However, the contract may contain customer information and trade secrets.

Another employee;

"I only sent the error message to the AI."

he can say.

However, the message may contain an access key or company system information.

Therefore, providing employees with regular training based on real-world business scenarios can significantly reduce a company's risk.

Can Implementing Enterprise AI Accounts Reduce Employer Risk?

To prevent employees from using AI from personal accounts, company-approved enterprise solutions can be provided.

These systems;

Centralized enforcement of account management, access control, security settings, and usage policies

It can provide an advantage in that respect.

However, using an enterprise AI service does not completely eliminate the need for legal oversight.

The service provider's data processing terms, storage policies, and security measures should also be examined.

Why is data classification important in managing employer liability?

If employees don't know which data is sensitive, implementing an AI policy becomes difficult.

Therefore, it is important for companies to classify data.

For example;

Public – Internal – Confidential – Top Secret

A classification can be created in this way.

To the employee;

"You can use publicly available data in an approved AI system, but you cannot upload confidential data."

A clear rule can be given in this way.

This approach both enhances security and helps to more clearly define the boundaries of responsibility in potential disputes.

What should an employer do when a Shadow AI-related incident is detected?

When a Shadow AI incident is detected, the company's first reaction shouldn't be simply to fire the employee.

First, the technical and legal aspects of the incident must be determined.

The company should seek answers to the following questions:

Which artificial intelligence system was used?

Which data was transferred?

Is there any personal data?

Is there any sensitive personal data involved?

Was a trade secret disclosed?

Is there any confidential customer information?

Was the data transferred abroad?

Is it possible to delete the data from the system?

Could third parties have accessed the data?

Were the company's existing security policies adequate?

Following this review, data security, GDPR compliance, contract, and labor law processes should be carried out together.

Can an employee's employment contract be terminated?

Using Shadow AI may result in termination of the employment contract in certain circumstances.

However, not every Shadow AI incident automatically constitutes valid grounds for termination.

For example, a serious breach of trust could occur if an employee knowingly transfers company secrets or large amounts of personal data to an unauthorized artificial intelligence system.

Conversely, in a case where the company has no policy in place and the employee has only prepared a simple text using publicly available information, applying the harshest penalty directly may be debatable.

Because;

the severity of the breach, the employee's fault, company policies, and the resulting damage

They should be evaluated together.

Will the employer's own fault also be taken into consideration?

In Shadow AI disputes, not only employee behavior but also the company's organizational structure can be important factors.

For example, the company;

  • It has not created any artificial intelligence policy,
  • It has not provided training to its employees
  • It has not classified sensitive data,
  • He allowed everyone access to all the files and
  • if he knew that personal AI use was widespread but did not intervene

The company's own risk management shortcomings may also come to light.

Therefore, the safest approach for employers would be to not leave the use of artificial intelligence entirely to the personal responsibility of employees.

Employer Responsibility Regarding Shadow AI and Cybersecurity

Shadow AI is also a cybersecurity issue.

To an unknown AI plugin that is in operation;

permission to access email accounts, cloud storage, or company files

can give.

In this case, the application may not be limited to the information entered by the employee but may access broader company data.

Therefore, employers;

application permissions, third-party integrations, and software that can be used on enterprise devices

It is important to link it to specific safety standards.

Measures Employers Can Take to Mitigate the Risk of Shadow AI

Companies need to establish a holistic system to reduce the liability risk arising from Shadow AI.

In this system;

1. An inventory of artificial intelligence should be compiled

It is necessary to identify which AI tools are being used within the company.

2. Approved artificial intelligence applications should be identified,

Systems that employees can use should be clearly demonstrated.

3. Data classification should be performed

Employees should be informed which information is sensitive.

4. Personal account usage should be regulated

The uploading of company data to personal AI accounts should be restricted.

5. Employees should be provided with training

Personal data protection laws (KVKK) require disclosure of trade secrets and cybersecurity risks.

6. Technical safety measures should be taken

High-risk data transmission channels should be controlled as much as possible.

7. An incident response procedure should be prepared

It should be determined how to proceed if an employee accidentally uploads data.

8. The policy should be updated regularly.

Given the rapid pace of change in artificial intelligence technologies, the regulations should be reviewed periodically.

Which departments are responsible for managing Shadow AI?

Shadow AI isn't just a problem for the IT department.

For an effective risk management system:

law, GDPR, human resources, information technology, cybersecurity, internal audit, and senior management

They must work together.

The legal team;

Personal Data Protection Law (KVKK), labor law, trade secrets, and contractual liability

When evaluating these issues, the technical team must ensure system security.

The human resources department should manage employee training and disciplinary processes.

Conclusion

Employer liability in the use of shadow AI is a corporate law issue that is becoming increasingly important with the widespread adoption of artificial intelligence in organizations.

An employee using a personal AI account without the company's knowledge does not automatically absolve the employer of responsibility.

Especially;

the uncontrolled transfer of personal data, trade secrets, customer information, source code, or confidential company documents to artificial intelligence systems

In this case, it is important to know what preventive measures the company has taken.

The employer;

its failure to establish an AI policy, train its employees, classify data, and take any technical or administrative measures against known Shadow AI risks

This could be a matter of consideration in terms of the company's liability in potential legal disputes.

Conversely, developing a comprehensive AI usage policy, identifying approved systems, training employees, and implementing data security measures can significantly reduce a company's Shadow AI risks.

However, simply drafting policies is not enough. The rules need to be actually implemented and regularly monitored.

With the increasing use of artificial intelligence in the business world, the fundamental question for companies is no longer just:

"Did our employee use artificial intelligence without permission?"

It is not.

The real question is this:

"As a company, have we taken the necessary legal, technical, and administrative measures to anticipate and prevent the risks that may arise from employees' use of artificial intelligence?"

When evaluating the employer's responsibility in the use of Shadow AI, both the employee's individual behavior and the company's corporate risk management should be considered.

Leave a Reply

Call Now Button