Single Blog Title

This is a single blog caption

Employer Training Obligations in the Use of Artificial Intelligence: Legal Liability in Case of Providing or Failing to Provide Training

Employer Training Obligations in the Use of Artificial Intelligence: Legal Liability in Case of Providing or Failing to Provide Training

Entrance

The use of artificial intelligence tools in the workplace does not simply mean that employees learn new software. Employees must also know what information they can input into the AI ​​system, how to control the output produced by the system, how to protect personal data and trade secrets, and how to act when faced with erroneous results.

If an employee uploads customer information to a publicly accessible AI system, sends an inaccurate report generated by the AI ​​to the customer without checking it, or directly applies the algorithmic output as a staff decision, this can create legal liability for both the employer and the employee.

The fundamental question at this point is:

Does an employer have an obligation to provide artificial intelligence training to an employee, and does providing the training absolve the employer of this responsibility?

Turkish law does not contain a specific and independent provision requiring all employers to provide training on AI for every AI tool they use. However, when considering provisions related to occupational health and safety, the employer's duty of care, the protection of personal data, and the proper organization of work, providing training may become a legal obligation depending on the nature of AI use.

Legal Basis for Artificial Intelligence Education

New Technology Education in Light of Law No. 6331

According to Article 4 of the Occupational Health and Safety Law No. 6331, the employer is obligated to ensure the occupational health and safety of employees. This includes preventing occupational risks, providing training and information to employees, establishing the necessary organization, providing tools and equipment, and adapting measures to changing conditions. The same provision explicitly states that obtaining services from external experts or organizations, and the employees' own responsibilities, do not absolve the employer of their obligations.

Article 17 of the law regulates the training obligation in a more concrete way. Accordingly, occupational health and safety training specifically includes:

  • Before starting work,
  • When changing workplace or job,
  • If the work equipment is changed,
  • If new technology is implemented

Training should be updated to reflect changing and emerging risks, and repeated at regular intervals when necessary.

This regulation does not mean that the introduction of artificial intelligence in the workplace will always require traditional occupational health and safety training. However, if the artificial intelligence system changes the working method, work equipment, workload, safety risks, or the physical and psychosocial conditions of the employees, Article 17 of the Law becomes directly relevant.

For example, if an AI system, autonomous machine, algorithmic shift system, or employee-dependent automation application is used to manage the production line, the employee must be trained on the safe use of the system. Similarly, intense algorithmic monitoring, constant performance pressure, or AI-induced workload changes should be included in the risk assessment in terms of psychosocial risks.

Gathering Employee Feedback

According to Article 18 of Law No. 6331, employers are obligated to obtain the opinions of employees or employee representatives regarding the impact of the implementation of new technologies, the selection of work equipment, and working conditions on the health and safety of employees. The opinions of employee representatives must also be sought when planning employee training.

Therefore, an artificial intelligence system shouldn't simply be purchased by managers and deployed by assigning a username to employees. The tasks in which the system will be used, the risks employees may face, the training required, and how human oversight will be ensured should all be evaluated beforehand.

Employer's Duty of Care

Article 417 of the Turkish Code of Obligations imposes on the employer the obligation to protect the employee's personality, to show respect for them, and to establish an order in the workplace that conforms to the principles of honesty. The employer is also obliged to take all necessary measures for occupational health and safety and to provide all necessary tools without any deficiencies. If the employee's personal rights or physical integrity are harmed due to a breach of these obligations, liability for damages arising from the breach of contract may arise.

In this context, an employer's decision to implement an artificial intelligence system for an employee without providing any explanation or training may constitute a breach of their duty of care. This is especially true if the system;

  • If it is rating the employee's performance,
  • If he/she is distributing the work,
  • If he/she is directing the production machines,
  • If it processes personal data,
  • If it is having a decisive influence on the employee's decisions,
  • If misuse results in serious financial or legal consequences,

The employer's obligation to provide training and information should be considered more stringent.

Training Obligations under the Personal Data Protection Law (KVKK)

One of the most significant risks in the use of artificial intelligence is the uncontrolled entry of employees' personal data into the system. When customer files, employee personal information, health data, legal documents, bank information, and communication records are uploaded to an AI system, personal data processing and, in some cases, transfer of data abroad may occur.

According to Article 12 of the Law No. 6698 on the Protection of Personal Data, the data controller is obliged to take the necessary technical and administrative measures to prevent the unlawful processing and access of personal data and to ensure the preservation of the data. The data controller is also required to conduct or have conducted the necessary audits.

The Personal Data Protection Authority's Personal Data Security Guide explicitly lists employee training and awareness campaigns as administrative measures. The Authority deems it necessary to train employees on not disclosing or sharing personal data unlawfully, to define their duties and responsibilities, and to create an environment where they can report data security risks.

The Personal Data Protection Board's decisions indicate that providing only general information or defining online training for employees is not always sufficient. For example, the Board deemed the measures insufficient in a case where, despite the training system being opened to the employee, participation in the training was not ensured and the information provided consisted only of general statements regarding the protection of personal data.

Therefore, it is not enough for the employer to simply say, "KVKK (Personal Data Protection Law) training has been provided to employees." The training must;

  • It must be compatible with the artificial intelligence tool that the employee is actually using
  • Explaining the risks of uploading data to artificial intelligence
  • Showing examples of prohibited and permitted uses
  • Monitoring participation and whether the training was understood,
  • Regular updates

is necessary.

European Union Artificial Intelligence Regulation and AI Literacy

In comparative law, Article 4 of the European Union Artificial Intelligence Regulation stipulates that organizations providing and using artificial intelligence systems must take measures to improve the AI ​​literacy of their employees. When preparing training and information materials, the technical knowledge, experience, and education of the employees, the purpose of the system used, and the individuals affected by the system should be taken into account. This obligation came into effect on February 2, 2025.

The European Commission states that even if a system like ChatGPT is used solely for copywriting or translation, employees should be informed about the risk of the system generating misinformation. Simply sending employees usage instructions is not considered sufficient in every case; appropriate training and guidance tailored to the system and risk level are recommended.

This regulation does not directly apply to every employer in Türkiye. However, the scope of the Regulation should be assessed separately for companies operating in the European Union, offering an artificial intelligence system used in the EU, or whose system outputs affect individuals in the EU. Furthermore, the regulation constitutes an important comparative legal standard in Turkish law regarding the due diligence that employers must exercise.

What training should employers provide?

AI training should not be limited to a technical instruction on how to press buttons on the system. The training should be tailored to the worker's job and the risks of the system they are using.

The Basic Working Principles of Artificial Intelligence

Employees should be informed that AI outputs are not accurate and error-free information. Generative AI systems can produce information that seems convincing but is inaccurate, outdated, or does not actually exist.

The employee should view the system output not as an independent expert opinion, but as a helpful blueprint to be checked.

Approved and Prohibited Vehicles

It should be determined which AI tools employees can use. Information should be provided regarding the difference between corporate and personal accounts, as well as issues related to connecting third-party applications to the system and using unauthorized plugins.

Employees should be aware that conducting transactions from their personal phone or account does not circumvent corporate data security regulations.

Protection of Personal Data

In education, examples should be used to explain which information constitutes personal data and sensitive personal data.

It should be explicitly stated that the following data, in particular, cannot be entered into publicly accessible artificial intelligence systems:

  • Identity and contact information,
  • Health data,
  • Banking and financial information,
  • Employee personnel files,
  • Client and case files,
  • Audio and video recordings,
  • Biometric data,
  • Criminal conviction and security measure information.

Providing regular data security training to employees who process sensitive personal data is explicitly listed among the adequate measures determined by the Personal Data Protection Board.

Trade Secret and Confidentiality

Employees should be informed that customer lists, contracts, pricing information, source code, technical projects, unpublished financial information, and company strategies cannot be uploaded to artificial intelligence systems.

According to Article 396 of the Turkish Code of Obligations, the employee is obligated to protect the legitimate interests of the employer and not to disclose production and business secrets learned during the course of work.

However, the employer cannot shift all responsibility to the employee without specifying which information is confidential. Classifications of confidential information and the unit to contact in case of doubt must be clearly indicated.

Human Monitoring and Verification

Reports generated using artificial intelligence must be reviewed by an authorized person before being used as legal opinions, financial analyses, customer responses, or technical instructions.

At a minimum, the following affirmations should be taught in education:

  • Source control,
  • Update check,
  • Calculation and data accuracy,
  • Privacy control,
  • Discrimination and prejudice control,
  • Copyright and intellectual property control,
  • Authorized manager or expert approval.

Cybersecurity and Fake Content

Employees should be made aware of fake emails, voice impersonations, images, and phishing attacks created using artificial intelligence.

It should be specifically noted that payment instructions, account number changes, urgent money transfers sent in the administrator's name, or password sharing requests must be verified through an independent communication channel.

Bug and Breach Reporting

When an employee accidentally uploads personal data or trade secrets, they must report the incident immediately instead of concealing it.

In education;

  • To whom the notification will be sent,
  • What information will be provided?
  • How to secure your account or connection,
  • What procedures should be followed to delete the data?
  • How to protect screenshots or recordings

It should be explained.

When should training be given?

AI training should not be given after the system has been put into use and errors have been discovered.

Education;

  • Before we begin using the operational artificial intelligence system,
  • When a new vehicle is put into service,
  • When an employee's duties or access rights change,
  • When the system is significantly updated,
  • When a new personal data processing process begins,
  • When a security breach or misuse occurs,
  • During regular information update periods

It would be appropriate to give it.

The costs of training under Law No. 6331 cannot be passed on to employees, and the time spent in training is considered working time. If the training period exceeds the weekly working hours, overtime or overtime regulations apply.

Does providing training eliminate the employer's responsibility?

No. Providing training does not automatically absolve the employer of responsibility.

Training is just one of the measures that employers should take. Employers should also:

  • We should choose a secure artificial intelligence system
  • You should determine the intended use
  • Access rights should be restricted
  • We must technically prevent the uploading of personal data and trade secrets
  • Human control must be established
  • They should monitor the system and its usage by employees
  • We need to conduct a risk assessment
  • A breach response procedure should be established.

Law No. 6331 clearly stipulates that obtaining expert services from outside and the existence of employees' own responsibilities does not absolve the employer of their duties.

Similarly, under the KVKK (Turkish Personal Data Protection Law), the data controller is obligated to take the necessary technical and administrative measures to protect personal data and to supervise their implementation. It is not considered sufficient for the employer to merely provide training to the employee while neglecting technical access controls, authorization restrictions, and supervisory responsibilities.

The Importance of Training from the Employer's Perspective

Proper training is important in assessing whether an employer has exercised due diligence in a dispute.

Employer;

  • He clearly informed the employee,
  • They provided job-appropriate training,
  • They provided a safe vehicle,
  • It listed the prohibited uses,
  • They have established technical controls,
  • They had conducted regular inspections,
  • If he/she checked whether the employee understood the training,

The employer's assessment of fault may differ if the employee knowingly and clearly deviated from instructions.

However, simply having participants sign a form or describing general online training is not enough. There must be a real link between the training and the associated risk.

If an employee violates the rules despite receiving training

Employees are obligated to act in accordance with occupational health and safety training and employer instructions, ensuring that they do not endanger their own safety or the safety of other employees. They must also report any serious hazards and deficiencies in safety measures they identify to their employer or employee representative.

According to Article 399 of the Turkish Code of Obligations, an employee must comply with the employer's lawful regulations and instructions to the extent required by the principles of good faith. According to Article 400 of the same Code, an employee is liable for damages caused to the employer through their fault. When determining the employee's liability, factors such as the hazardous nature of the work, whether it requires expertise and training, and the employee's known abilities and qualifications are taken into account.

This provision is important in the context of the use of artificial intelligence, because the employee's lack of training or sufficient technical knowledge will be taken into account when assessing their fault and responsibility.

In contrast, the employee;

  • If someone uploads customer data to the system knowing it is explicitly prohibited,
  • If an employee knowingly shares their employer's trade secrets on an external platform,
  • If mandatory human control is not carried out intentionally,
  • If someone uses the AI ​​output even though they know it is flawed,
  • If he/she deliberately conceals the security breach,

Depending on the nature of the damage, liability for compensation and disciplinary action may arise against the employer.

In serious cases such as the disclosure of trade secrets or abuse of trust, the possibility of termination for just cause under Article 25/II-e of the Labor Law may arise. However, the severity of the violation, the employee's intent, the training provided, the nature of the damage, and the possibility of a lesser penalty should be evaluated on a case-by-case basis.

What is the employer's responsibility if they don't provide training?

Occupational Health and Safety Responsibility

Failure to provide necessary occupational health and safety training despite the implementation of new technology may constitute a violation of Article 17 of Law No. 6331.

Article 26 of the Law stipulates an administrative fine per employee for each violation in case of failure to fulfill the training obligation set forth in Article 17. Since the basic amounts in the Law may change due to revaluation and depending on the number of employees and the hazard class of the workplace, the current penalty should be calculated separately as of the date of the violation.

If a workplace accident, occupational disease, or violation of personal rights occurs due to a lack of training, the employer may also be liable for material and moral damages.

Personal Data Protection Law Responsibility

If employees are not provided with the necessary training on artificial intelligence and personal data security, and a data breach occurs as a result, the employer may be deemed to have violated its obligation to take technical and administrative measures under Article 12 of the Personal Data Protection Law (KVKK).

In its decisions, the Personal Data Protection Board considers the lack of employee training, incomplete training, inadequate training content, and failure to raise employee awareness regarding their duties as deficiencies in data security measures.

In this case, the employer may face administrative fines, the data breach will be reported to the relevant parties and the Board, and necessary corrective measures will be taken. Administrative fines under the Personal Data Protection Law are increased annually in line with the revaluation rate.

Making it More Difficult to Impose Sanctions on Workers

Imposing severe disciplinary action on an employee can become controversial if the employer hasn't established a clear policy, provided training, or specified which uses of artificial intelligence are prohibited.

An employee cannot be expected to comply with a rule they do not know or cannot foresee. Especially in a workplace where the employer actively encourages the use of artificial intelligence but fails to explain the safety limits, placing all the responsibility on the employee may be incompatible with the principles of fairness and proportionality.

Liability to Third Parties

If an employee uses artificial intelligence to provide incorrect information to a customer, leak personal data, or infringe on the intellectual property rights of a third party, the employer may also be held liable to those third parties.

The fact that an employee acts without training and within the employer's organization is significant in terms of the employer's system choice, supervision, and control deficiencies. The employer cannot absolve themselves of organizational responsibility by claiming that the fault lies solely with the employee.

Examples of Cases Where Training Is Provided and Not Provided

Example 1: Uploading Customer Data Without Providing Training

The employer requested employees to respond to customer complaints via ChatGPT, but did not specify which information could not be entered into the system. The employee uploaded the customer's name, address, and health information to the system.

Although the employee had a duty of care in this incident, the employer;

  • Not providing training,
  • Failure to provide secure enterprise tools,
  • The fact that it does not establish an anonymization rule,
  • Failure to install technical access controls

Therefore, it can be argued that there is a significant organizational and supervisory deficiency in terms of the Personal Data Protection Law (KVKK).

Example 2: Deliberate Violation Despite Receiving Training

The employer clearly stated in training and written policy that personal data could not be uploaded to publicly accessible AI systems. The employee was provided with a secure corporate system and their access rights were defined. Despite this, the employee uploaded thousands of customer records to their personal account for convenience.

In this situation, the employee's fault and liability to the employer may increase. However, the employer is still obliged to explain why the incident could not be technically prevented, whether the control mechanisms were adequate, and what measures were taken after the violation.

Example 3: Training was provided, but the wrong system was selected

The employees received comprehensive training; however, the employer purchased a system that did not securely store the data and used the inputs for its own model training.

In this case, the fact that training has been provided does not eliminate the employer's obligation to select a safe service provider and manage relationships with the data processor.

Example 4: Failure to Control Artificial Intelligence Output

The employee was clearly informed that the AI ​​outputs needed to be reviewed by humans. However, the employee sent the report to the client without checking it, as it contained regulatory provisions that did not actually exist.

The employee's professional duties and educational level may be taken into consideration when determining their misconduct. However, it should also be assessed whether the employer has established a second control mechanism within their reporting and approval system.

How Should Training Be Documented?

It may not be sufficient for the employer to simply claim that they provided training. The scope of the training and its actual delivery must be demonstrable.

To this end;

  • Training dates and duration,
  • Participant list,
  • Educational content,
  • The presentations and materials used,
  • The instructor's identity and qualifications,
  • Practical examples,
  • A brief assessment or proficiency test,
  • The policy communicated to the employee,
  • Update and refresher trainings,
  • Questions and answers

It can be recorded.

However, simply providing documentation does not replace the effectiveness of the training. Sending an unreadable text to an employee, having them sign a general confidentiality agreement, or granting access to the training only through the system should not be considered sufficient on its own.

Training should vary depending on the job

Providing the same training to every employee is not the right approach.

For example;

  • Discrimination, automated decision-making, and candidate data for human resources professionals
  • The legal department is responsible for client confidentiality, source verification, and professional responsibility
  • Payment fraud and financial data security for finance professionals
  • Software developers are provided with source code, open source licenses, and system security
  • Monitoring algorithmic decision-making by management teams,
  • Information technology unit: access control, record keeping, and breach response

More detailed training should be provided on these topics.

The European Commission's approach to AI literacy also envisages differentiating training content according to employees' technical knowledge, experience, and responsibilities.

Conclusion

While Turkish law doesn't have a specific, independent training obligation under the heading "artificial intelligence training" that applies uniformly to all employers, existing legislation imposes significant responsibilities on employers.

If artificial intelligence, as a new technology, alters occupational health and safety risks, work equipment, or working methods, training must be provided under Article 17 of Law No. 6331. When personal data is processed through artificial intelligence systems, employee training becomes one of the administrative measures required under Article 12 of the Personal Data Protection Law (KVKK). The employer's duty of care and obligation to protect the employee also necessitates that the technology requested of the employee be taught in a safe and understandable manner.

Providing training does not automatically relieve the employer of responsibility. The employer continues to fulfill obligations regarding system selection, risk assessment, technical security, access rights, human supervision, and regular inspections.

Conversely, even with comprehensive training, clear policy, safe tools, and effective supervision, an employee's deliberate deviation from instructions can aggravate their culpability and liability.

If training is not provided, the employer;

  • Administrative sanctions regarding occupational health and safety
  • Personal Data Protection Law (KVKK) administrative fines,
  • Material and moral compensation,
  • Liability for data breaches,
  • Liability for work-related accidents or occupational diseases
  • Unlawful disciplinary or termination action

They may face risks.

In conclusion, AI training should not be a mere formality that employers get employees to sign to absolve themselves of responsibility. The training should be tailored to the system being used, the employee's role, and the concrete risks that may arise; it should be regularly updated and supported by technical measures.

The safest legal approach is to teach employees not only how to use artificial intelligence, but also when not to use it, how to monitor the output, and how to act in case of errors.

Leave a Reply

Call Now Button