Single Blog Title

This is a single blog caption

Legal Responsibility in Crimes Committed with Artificial Intelligence

Artificial intelligence technologies have become one of the most debated areas in the legal system in recent years. Text-generating systems, image and sound imitation, automated decision-making mechanisms, chatbots, data analysis tools, and autonomous software are no longer merely technical tools; they are systems that can have serious consequences in terms of criminal law, personal data protection law, compensation law, intellectual property law, and commercial law. Therefore, the question of "who is responsible for crimes committed with artificial intelligence?" is gaining increasing importance in practice.

As of today, Turkish law does not recognize artificial intelligence as an independent "person." Therefore, it is not possible to directly punish an artificial intelligence system as the perpetrator. In terms of criminal law, responsibility is directed towards the natural person who used the artificial intelligence in the commission of the crime, those who participated if the conditions are met, and in some cases, security measures that may be applied to legal entities. Article 20 of the Turkish Penal Code stipulates that criminal responsibility is personal, that no one can be held responsible for the actions of another, and that criminal sanctions cannot be applied to legal entities; however, security measures provided for in the law are reserved.

Can Artificial Intelligence Be a Criminal?

In criminal law, the perpetrator is a natural person capable of culpability. Artificial intelligence, however, cannot be categorized in the same way as humans in terms of will, intent, negligence, fault, awareness of unlawfulness, and punishability. Therefore, the issue is not about artificial intelligence "committing a crime on its own," but about it being used as a tool in the commission of a crime. For example, if someone uses artificial intelligence to produce a fake voice recording and defrauds a victim, the perpetrator is not the artificial intelligence itself, but the person using, directing, or knowingly using this system.

The crucial point here is at what stage of the crime artificial intelligence is used. AI can be used in the preparatory stages of the crime, in the execution of the fraudulent act, in deceiving the victim, and in concealing evidence of the crime. For example, generating fake identity images, preparing deepfake videos, sending automated phishing messages, producing malware, or selecting targets by analyzing personal data may bring different provisions of the Turkish Penal Code into play, depending on the nature of the crime.

Major Crimes That Can Be Committed with Artificial Intelligence

Crimes committed using artificial intelligence cannot be grouped under a single crime type. Depending on the specifics of the case, cybercrimes may include fraud, unlawful acquisition of personal data, violation of privacy, defamation, threat, blackmail, forgery, unfair competition, copyright infringement, or attacks on personal rights.

Articles 243, 244, and 245 of the Turkish Penal Code (TCK) are particularly important in attacks targeting information systems. Unlawful entry into or continued presence in an information system falls under Article 243; obstructing or disrupting the system's operation, destroying, altering, rendering inaccessible, or sending data to another location falls under Article 244. Article 244 prescribes imprisonment for those who obstruct or disrupt the system's operation, and additional penalties for those who corrupt, destroy, alter, render inaccessible, insert data into, or send data to another location within the system.

In cases of AI-assisted bank fraud, Articles 245 and 158 of the Turkish Penal Code may come into play. The acquisition of bank or credit card information belonging to another person through AI-assisted methods, the creation of forged card data, the manipulation of payment systems, or the deception of the victim through AI-generated fake conversations, fake emails, or fake images, all bring the provisions regarding aggravated fraud and misuse of bank/credit cards into question. Article 245 of the Turkish Penal Code also criminalizes the unauthorized use of another person's bank or credit card to gain benefit.

Deepfake, the creation of fake audio and video

Deepfake images and fake audio recordings generated using artificial intelligence are among the riskiest areas in practice. The unauthorized use of a person's face, voice, or private image may constitute a violation of privacy, unlawful processing of personal data, defamation, blackmail, threat, slander, or fraud. In particular, if the victim is depicted in a false sexual image, their reputation is damaged, or money is demanded from them, both criminal investigations and lawsuits for moral damages may arise.

At this point, the fact that the AI ​​content is "not real" does not eliminate legal responsibility. On the contrary, presenting fake content as if it were real can increase the severity of the attack on the victim's personal rights and privacy. Separate assessments of responsibility should be made for those who produce, share, facilitate the dissemination of the content, or continue to maintain access to it despite requests for removal.

Responsibility Regarding the Protection of Personal Data

Artificial intelligence systems often work with large datasets. These datasets may include names, phone numbers, email addresses, images, audio, IP addresses, location, biometric data, or behavioral data. According to the Turkish Personal Data Protection Law (KVKK), personal data is any information relating to an identified or identifiable natural person; the processing of personal data encompasses a very broad area including obtaining, recording, storing, modifying, disclosing, transferring, and classifying.

Therefore, if personal data is processed during the training, use, or sharing of outputs of an artificial intelligence system, the provisions of the Personal Data Protection Law (KVKK) come into play. The data controller is the person who determines the purposes and means of processing. This person or company must comply with the obligations of lawfulness, honesty, specific and legitimate purpose, proportionality, limited retention, data security, and disclosure. Articles 4 and 5 of the KVKK stipulate that personal data can only be processed in accordance with the procedures and principles stipulated in the law and, as a rule, cannot be processed without explicit consent.

If personal data is collected, profiled, shared with third parties, or leaked illegally using artificial intelligence, both administrative sanctions and criminal liability under Articles 135, 136, and 138 of the Turkish Penal Code may arise. The official publications of the Personal Data Protection Law (KVKK) also state that Article 135 criminalizes the recording of personal data, Article 136 criminalizes the unlawful disclosure or acquisition of data, and Article 138 criminalizes the failure to destroy data.

Developer, User and Company Responsibility

In crimes committed using artificial intelligence, determining responsibility requires more than just asking "who wrote the program?". The following questions must be considered together: who developed the system, who trained it, who used it, who gave the instructions, who failed to supervise it, who profited commercially, and who could have foreseen the harmful consequences?.

If a user knowingly uses artificial intelligence to commit a crime, they are directly liable as the perpetrator. For example, if someone uses artificial intelligence to create a fake invoice, a fake contract, a fake voice recording, or a fraudulent message, the defense that "AI produced this" does not absolve them of responsibility. This is because in this case, AI is a tool used in the commission of the crime.

Liability on the part of the developer or provider should be examined more carefully. Liability may arise if the developer designed the system directly to commit a crime, encouraged its misuse, knowingly enabled illegal outcomes, or failed to take necessary security measures. However, the misuse of a general-purpose AI tool by a third party does not, in every case, give rise to criminal liability for the developer. Intent, probable intent, negligence, foreseeability, duty of supervision, and causality are evaluated on a case-by-case basis.

While criminal liability for companies is directed at individuals, certain security measures and administrative sanctions may be applied to legal entities. Article 20 of the Turkish Penal Code states that criminal sanctions cannot be applied to legal entities, but reserves the right to implement security measures. Furthermore, under Article 60 of the Turkish Penal Code, security measures such as the revocation of operating licenses and confiscation may be considered for private legal entities under certain conditions.

Liability for Damages

Damages caused by artificial intelligence have consequences not only under criminal law but also under private law. If a person's reputation has been damaged, trade secrets revealed, money taken, personal data disseminated, or harmed due to an unfair algorithmic decision, they can claim material and moral damages.

According to Article 49 of the Turkish Code of Obligations, a person who causes harm to another through a culpable and unlawful act is obligated to compensate for that harm. If the harm occurs due to the unlawful act of a person using artificial intelligence, general tort liability applies.

Furthermore, if company employees use artificial intelligence tools to harm third parties, the employer's liability under Article 66 of the Turkish Code of Obligations may also be discussed. The employer may be held liable if they cannot prove that they fulfilled their obligations to select, instruct, supervise, and monitor their employees.

In some high-risk artificial intelligence applications, the liability under Article 71 of the Turkish Code of Obligations regarding strict liability may be open to debate. Especially in areas such as healthcare, transportation, finance, security, biometric recognition, or automated decision-making systems, where the use of artificial intelligence has the potential to cause serious and grave harm, the liability of the business owner and operator may be interpreted more broadly.

The Problem of Evidence and Proof

In crimes committed using artificial intelligence, one of the most critical issues is evidence gathering. This is because digital content can be easily altered, deleted, or transferred to different platforms. Therefore, victims should not only take screenshots but also collect evidence such as URLs, dates, times, usernames, IP addresses, log records, platform communications, payment records, device examinations, expert reports, and, if necessary, notarized documentation.

In criminal investigations, the prosecutor's office may issue warrants to content providers and platforms, request IP records, investigate account connections, search and seize devices, take images of digital materials, and request expert examination. In deepfake content, image and audio analysis, metadata examination, production traces, sharing chain, and identification of the original disseminating account are of paramount importance.

The European Union AI Act and Developments in Türkiye

One of the most important regulations in the field of artificial intelligence worldwide is the European Union Artificial Intelligence Regulation (AI Regulation). The European Commission describes the AI ​​Act as the first comprehensive legal framework in the field of artificial intelligence and states that the regulation imposes risk-based obligations for developers and users.

In Türkiye, the legal framework regarding artificial intelligence is also developing. The National Artificial Intelligence Strategy 2021-2025 is one of the first fundamental policy documents concerning Türkiye's artificial intelligence ecosystem. Furthermore, draft laws aimed at ensuring the safe, ethical, and fair use of artificial intelligence technologies, protecting personal data, and establishing a regulatory framework are currently at the committee stage in the Turkish Grand National Assembly.

The Personal Data Protection Authority (KVKK) has also published a special guide on generative artificial intelligence and the protection of personal data, emphasizing that generative AI systems should be developed in accordance with human rights, fundamental freedoms, transparency, accountability, and a human-centered approach.

Conclusion

The fundamental rule in crimes committed with artificial intelligence is this: Artificial intelligence itself is not punished; those responsible are the individuals and institutions that use, develop, manage, fail to supervise, or cause harmful consequences from the use of artificial intelligence for unlawful purposes. Responsibility is determined in each case according to the perpetrator's intent, negligence, control over the system, foreseeability, data processing process, the causal link between the harm and the action, and the benefit obtained.

AI-related crimes are not entirely independent of classic crimes; on the contrary, existing provisions of the Turkish Penal Code, the Personal Data Protection Law, the Turkish Code of Obligations, and related special laws are applicable to these crimes. Rapid evidence gathering, expert examination, and accurate legal classification are crucial in the face of deepfakes, AI fraud, data breaches, fake content creation, automated attacks, and algorithmic manipulations. Therefore, when a victim of AI-related crime occurs, the process should be conducted not only from a technical perspective but also by considering criminal law, data protection law, and compensation law together.

Frequently Asked Questions About Crimes Committed with Artificial Intelligence

Can artificial intelligence commit crimes?

In Turkish law, artificial intelligence does not have independent legal personality. Therefore, it is not possible to directly punish artificial intelligence as a perpetrator of a crime. From a criminal law perspective, responsibility lies with the individuals who use, direct, develop, fail to supervise, or cause an unlawful outcome using artificial intelligence for the purpose of committing a crime.

If a crime is committed using artificial intelligence, who would be the perpetrator?

The perpetrator is determined according to the specific circumstances of the case. A person who uses artificial intelligence for fraud, forgery, blackmail, personal data breach, or attacks on information systems may be considered the direct perpetrator. Furthermore, individuals who aid, abet, or knowingly contribute to the commission of a crime may also be held liable under the provisions regarding complicity.

What crime does using artificial intelligence to commit fraud constitute?

If a victim is deceived using artificial intelligence through fake voices, fake images, fake emails, fake identities, or automated messages, the crime of fraud or aggravated fraud may be considered, depending on the nature of the incident. Particularly if unfair advantage has been gained through the use of information systems, banking systems, or payment instruments, the penalties may be more severe.

Is creating deepfake videos or fake audio recordings a crime?

Deepfake videos or AI-generated fake audio recordings may not constitute a crime in all cases. However, criminal liability may arise if this content is used to damage someone's reputation, violate their privacy, blackmail them, commit fraud, defame them, or unlawfully disseminate their personal data. The victim may also seek compensation for emotional distress and the removal of the content.

Are AI-generated fake nude images a crime?

Yes. Using artificial intelligence to place a person's face or image onto an obscene or sexually explicit visual can lead to various crimes, including violation of privacy, unlawful processing of personal data, defamation, blackmail, or obscenity. Sharing, disseminating, or using such content for threatening purposes can increase criminal liability.

Is collecting personal data using artificial intelligence illegal?

The collection, analysis, or processing of personal data by artificial intelligence systems is not always unlawful. However, these processes must comply with the Personal Data Protection Law (KVKK). Data processing activities must be based on specific, clear, and legitimate purposes, be proportionate, inform the data subjects, and obtain explicit consent where necessary. Otherwise, both administrative fines and criminal liability may arise.

Can an AI developer be held responsible for a crime?

The developer is not automatically liable for every instance of AI misuse. However, the developer's legal and criminal liability may be questioned if the system was designed to be directly conducive to committing crimes, if illegal use was knowingly encouraged, if security measures were not taken, or if necessary precautions were neglected despite foreseeable harmful consequences.

Will companies that use artificial intelligence be held accountable?

While companies themselves may not face direct imprisonment, their managers, employees, or officials may be held criminally liable for their specific actions. Furthermore, legal entities may face security measures, administrative fines, GDPR sanctions, and liability for damages. A company's failure to implement necessary oversight and data security measures in its use of artificial intelligence is a significant cause for liability.

Can artificial intelligence be used to commit the crime of defamation?

Yes. If someone uses artificial intelligence to create and share statements, images, videos, or audio recordings that are offensive to another person's honor, dignity, and reputation, the crime of defamation may arise. The fact that the content was produced by artificial intelligence does not absolve one of responsibility; what matters is who created, used, and disseminated the content.

Can artificial intelligence be used to commit the crime of threat or blackmail?

Yes. Using AI-generated fake images, audio recordings, or private content to extort money from someone, force them to perform a certain act, or threaten to damage their reputation can constitute a crime of blackmail or extortion. The use of deepfake content, particularly for the purpose of extorting money, forcing a relationship, or pressuring the victim, carries serious legal consequences.

What crime occurs if a document is forged using artificial intelligence?

If artificial intelligence is used to create fake invoices, fake contracts, fake IDs, fake signatures, fake diplomas, or similar documents, it may constitute crimes of forgery of official or private documents. The type of document, whether it was used in public institutions, and whether an unfair advantage was gained will affect the nature of the crime.

What happens if bank account or card information is stolen using artificial intelligence?

If someone else's bank account, credit card, password, payment information, or digital wallet details are obtained using AI-powered methods, it can lead to cybercrimes, misuse of bank or credit cards, fraud, and unlawful acquisition of personal data. It is important for the victim to promptly contact the bank, the prosecutor's office, and relevant platforms.

What should a victim do in cases of crimes committed using artificial intelligence?

The victim must first preserve all evidence. Screenshots, URL links, usernames, date and time information, payment records, messages, email headers, and any audio or video recordings should be saved. Afterward, a criminal complaint can be filed with the prosecutor's office, a request can be made to remove the content, access can be blocked, and if the conditions are met, a lawsuit for material and moral damages can be filed.

Can screenshots of AI-generated content be used as evidence?

Screenshots can serve as supporting evidence; however, they may not always be sufficient on their own. Therefore, it is important to collect additional evidence such as URLs, dates, times, usernames, platform information, IP addresses, notarized documents, expert examinations, and platform correspondence, in addition to screenshots. Digital evidence must be obtained in accordance with proper procedures.

Is it possible to remove deepfake content?

Yes. Applications can be made to the platform regarding deepfake content that violates personal rights, privacy, or personal data; access can be blocked; and a criminal complaint can be filed with the prosecutor's office. Depending on the nature of the content, it is also possible to obtain a court order to block access.

Is it possible to file a compensation lawsuit for AI-related crimes?

Yes. If a person's reputation has been damaged, their privacy violated, their personal data disseminated, they have suffered economic harm, or they have been wrongfully victimized through the use of artificial intelligence, a lawsuit for material and moral damages can be filed. The amount of compensation is determined according to the severity of the damage, the extent of its dissemination, the fault of the perpetrator, the emotional distress suffered by the victim, and the economic loss.

Will platforms be held responsible for content generated using artificial intelligence?

Platforms' liability is assessed based on whether they are aware of the content, how they respond to removal requests, whether they continue to disseminate illegal content, and their obligations under relevant legislation. The mere fact that a platform has a technical tool does not automatically absolve it of responsibility; inaction, particularly after notification, may give rise to liability.

Is it possible to trace IP addresses in crimes committed using artificial intelligence?

Yes. As part of a prosecutor's investigation, IP addresses, session records, access records, and account logs may be requested from relevant platforms, internet service providers, and digital service providers. However, in some cases, the use of VPNs, fake accounts, foreign platforms, or anonymization tools can make detection more difficult. Therefore, prompt application and the preservation of technical evidence are important.

Why is legal assistance important in crimes committed using artificial intelligence?

AI-related crimes are complex disputes that require a combined technical and legal assessment. Accurate characterization of the crime, timely collection of evidence, timely submission of applications to platforms and the prosecutor's office, and proper establishment of access restrictions and compensation claims are crucial. Therefore, conducting the process from the perspectives of criminal law, cyber law, GDPR, and compensation law is of great importance to the victim.

Leave a Reply

Call Now Button