The Limits of Employer's Right to Manage in the Age of Artificial Intelligence
The Limits of Employer's Right to Manage in the Age of Artificial Intelligence
Entrance
Artificial intelligence systems have evolved from being mere technical tools that facilitate employees' work in the workplace to becoming management tools that directly influence processes such as recruitment, task assignment, shift scheduling, performance measurement, compensation, promotion, discipline, and dismissal. Software that measures employee computer usage time, systems that analyze email traffic, applications that track attendance through facial recognition, and algorithms that rank employees based on performance scores are concrete examples of this transformation.
The International Labour Organization defines the use of employee data in organizing, assigning, monitoring, supervising, and evaluating tasks as "algorithmic management." While these systems accelerate the employer's management authority, they also create significant legal risks in terms of employees' privacy, personal rights, the principle of equality, and job security.
In Turkish law, employers have the right to determine the manner in which work is performed, to maintain order in the workplace, and to give instructions to employees. However, the right to manage is not unlimited and absolute. Even if the employer uses artificial intelligence, they are still bound by the Constitution, the Labor Law, the Turkish Code of Obligations, Law No. 6698 on the Protection of Personal Data, occupational health and safety legislation, employment contracts, and collective bargaining agreements.
Therefore, artificial intelligence should not be considered an independent legal authority that expands the employer's right to manage, but rather a technical tool employed in the exercise of existing management rights.
The Legal Nature of the Employer's Right to Manage
An employment contract is an agreement that stipulates that an employee performs work under the employer's supervision. This relationship of dependence grants the employer the authority to give instructions regarding the performance of the work. Within this scope, the employer;
- Where, when and how the work will be done,
- The division of labor in the workplace,
- Working methods,
- Tools and technologies to be used in the workplace,
- Occupational health and safety measures,
- General order of the workplace
can determine.
However, the right to manage is a supplementary authority that can be exercised in areas not regulated by law or contract. The right to manage cannot be given precedence over mandatory legal provisions, employment contracts, collective bargaining agreements, workplace practices, and the fundamental rights of the worker.
The employer's instructions must comply with the principle of honesty, the duty of equal treatment, and the principle of proportionality. An instruction that infringes upon the employee's personality, human dignity, privacy, or health and safety cannot be considered within the scope of the employer's right to manage.
The fact that it was generated by artificial intelligence does not make an unlawful instruction lawful. The fact that the algorithm's decision is efficient or economical for the business does not, in itself, mean that the decision is legally valid.
Legal Framework Regarding Artificial Intelligence in Türkiye
As of July 31, 2026, a comprehensive artificial intelligence law directly and directly regulating the use of AI systems in all sectors has not yet come into effect in Türkiye. Various draft laws concerning the safe, ethical, and fair use of AI systems and the protection of personal data are currently before the Turkish Grand National Assembly committees.
This does not mean that employers are operating within a legal loophole in the use of artificial intelligence. Artificial intelligence applications in the workplace primarily include:
- The Constitution of the Republic of Türkiye,
- Labor Law No. 4857,
- Turkish Code of Obligations No. 6098,
- Law No. 6698 on the Protection of Personal Data,
- Occupational Health and Safety Law No. 6331,
- Law No. 6701 on the Turkish Human Rights and Equality Institution
This should be evaluated within the framework of existing legislation.
Article 17 of the Constitution guarantees the right to protect one's physical and moral integrity, Article 20 guarantees the privacy of private life and the protection of personal data, and Article 10 guarantees the principle of equality. The right to protection of personal data also includes the right of an individual to be informed about data concerning them, to access that data, to have inaccurate data corrected, and to learn whether the data is being used for its intended purposes.
Fundamental Limitations on the Use of Artificial Intelligence from the Perspective of Governing Rights
1. Compliance with the Law and Employment Contract
Employers cannot use artificial intelligence systems to impose unlimited new obligations on employees that do not arise from the law or the employment contract.
For example, using artificial intelligence to schedule shifts can, as a rule, be considered within the employer's management rights. However, if the system consistently assigns night shifts, exceeds working hour limits, eliminates weekly rest days, or leads to a reduction in employee wages, then the limits of management rights are exceeded.
If an employee's duties, workplace, working hours, wage system, or responsibilities change substantially as a result of using an artificial intelligence system, Article 22 of the Labor Law comes into play. Substantial changes in working conditions are not binding on the employee unless they are notified in writing and accepted in writing within the legally prescribed period.
Therefore, an employer cannot unilaterally and fundamentally change an employee's working conditions on the grounds that "that's how the system is designed.".
2. Equal Treatment and Prohibition of Discrimination
Artificial intelligence systems learn from past data. If discrimination or imbalance was found in past human resources decisions, the system can reproduce that discrimination.
For example, the fact that employees in certain age groups, genders, or regions have been promoted more frequently in past years may lead AI to rate candidates with similar characteristics higher. Even if the system doesn't directly use gender or age information, it can produce discriminatory results through indirect indicators such as postal code, graduation date, military service information, interruptions in work history, or language spoken.
The employer's duty to treat all equally requires not only that the decision be seemingly impartial, but also that the consequences of its implementation do not create discrimination. Therefore, the employer;
- You should review the datasets used
- We should test the possibility of producing discriminatory results
- They should be able to explain the reasons for applying different procedures to employees in similar situations
- Promotion, salary, and dismissal decisions should not be based solely on algorithmic scores.
The fact that the algorithm generated the discriminatory result spontaneously does not absolve the employer of responsibility. Since the artificial intelligence system was used on behalf of the employer, the system's result is legally considered an action taken by the employer.
3. Protection of the Employee's Personal Rights
According to Article 417 of the Turkish Code of Obligations, the employer is obligated to protect and respect the employee's personality in the employment relationship. This obligation encompasses not only the employee's physical safety but also their psychological integrity, human dignity, professional reputation, and reasonable expectation of privacy.
Continuous camera surveillance of an employee, recording of their screen activity, measurement of keyboard movements, analysis of emotional state from facial expressions, or detailed scoring of bathroom and break times can create intense pressure on the employee.
While the employer has the right to supervise the conduct of work, the employee is not considered to have completely relinquished their right to privacy the moment they enter the workplace. The scope, duration, intensity, and intrusiveness of the supervision methods used must be considered together.
Using stringent surveillance methods would be contrary to the principle of proportionality if the same objective can be achieved with a less intrusive approach.
4. Protection of Personal Data
AI-based human resources systems often rely heavily on the processing of employees' personal data. Performance scores, location information, screen activity, email traffic, voice and video recordings, health information, biometric data, and behavioral analyses are all considered personal data.
According to the KVKK (Turkish Personal Data Protection Law), personal data;
- In accordance with the law and principles of honesty,
- Accurate and up-to-date when necessary,
- For specific, explicit and legitimate purposes,
- Limited and proportionate to the purpose for which they were committed,
- By keeping it for the necessary period of time
It should be processed.
The fact that an employer has purchased an artificial intelligence system or outsourced the service does not relieve them of the obligation to comply with these principles. Contracts with the system provider must clearly regulate data security, data storage location, access permissions, subcontractors, data transfer abroad, and data deletion.
It is not sufficient to simply inform employees that "your data may be processed." It must be clearly explained which data is collected by which system, for what purposes it is analyzed, in what decisions the results are used, and how long the data will be stored. The Personal Data Protection Law (KVKK) considers insufficient information provided to employees regarding the purposes of data processing and storage processes as a violation of the law.
5. The Explicit Consent Must Be Truly Free
The economic and hierarchical power imbalance between employee and employer makes the validity of explicit consent debatable. Consent given by an employee out of fear of not being hired, not being promoted, or losing their job cannot always be considered based on free will.
In its Principle Decision No. 2026/921 dated April 29, 2026, the Personal Data Protection Board specifically evaluated the processing of biometric data for the purpose of tracking working hours. The Board stated that biometric methods such as fingerprint, facial recognition, iris, or retina scans are extremely sensitive; and that the power imbalance between employee and employer creates serious doubts about whether explicit consent is based on free will. Furthermore, it was noted that there is no explicit legal regulation mandating the use of biometric methods for tracking working hours.
Therefore, the validity of consent obtained without offering employees genuine and equivalent alternatives to biometric systems, such as cards, passwords, or electronic signatures, will be questionable.
6. The Principle of Commitment to the Purpose
Using data collected for one purpose for another purpose may constitute a violation of the law.
For example, cameras installed for security purposes cannot later be used to measure employee performance, break times, or work commitment.
The Turkish Personal Data Protection Authority (KVKK)'s 2026 announcement regarding the use of security cameras in workplaces clearly states that cameras installed for workplace security purposes should not be used to monitor employee attendance or performance. It further clarifies that abstract purposes such as observing employee productivity, increasing discipline, or maintaining overall control cannot be considered legitimate purposes on their own.
The same principle applies to artificial intelligence systems. Location data collected for occupational safety purposes cannot subsequently be converted into performance scores. Screenshots recorded for technical support purposes cannot be automatically used in employee disciplinary evaluations.
Performance Evaluation with Artificial Intelligence
Employers have the right to evaluate employee performance within the scope of their management responsibilities. However, in AI-powered evaluation systems, performance criteria must be predetermined, objective, measurable, and relevant to the nature of the job.
If the system relies solely on easily measurable numerical data, it can lead to misleading results. For example, evaluating a customer service representative only based on call duration might not reflect the quality of the call; similarly, evaluating a lawyer only based on the number of documents they prepare might not consider the legal complexity of the case.
For the performance system to be considered legally compliant;
- The criteria should be communicated to the employee in advance
- The goals must be achievable
- Applying the same criteria to employees doing the same job,
- Giving the employee the opportunity to appeal the results,
- Correction of erroneous or incomplete data,
- The final decision must be made by an authorized person
is necessary.
Article 11 of the Turkish Personal Data Protection Law (KVKK) grants the right to object to an outcome that is detrimental to an individual, solely as a result of the analysis of personal data through automated systems. This provision constitutes an important legal safeguard against performance scores, risk assessments, and employee rankings generated by artificial intelligence.
AI-Based Disciplinary and Dismissal Decisions
An artificial intelligence system can generate a risk score for an employee, detect behavioral abnormalities, or recommend dismissal. However, the system's recommendation alone should not be considered grounds for disciplinary action or termination.
According to the Labor Law, in cases of termination for a valid reason, the employer must clearly and definitively state the reason for termination. In cases of termination due to the employee's conduct or performance, the employee's defense must be heard. The employer is also obligated to prove that the reason cited for termination actually exists and necessitates the termination.
A simple statement like, "The AI system identified the employee as a low performer," is insufficient. The employer must;
- Which data does the system use?
- What criteria did you use for the evaluation?
- Whether the data is accurate or not,
- Which specific behavior of the employee led to the negative outcome?
- Why a less stringent measure is not enough
They should be able to explain it.
The argument that the algorithm's working principle constitutes a trade secret cannot be used to completely eliminate the employee's right to defend themselves and object. The employer must at least explain the fundamental reasons for the decision and the determining criteria relating to the employee.
The approval of an AI-generated termination proposal by a human resources officer without any review should not be considered true human oversight. Human oversight should not be merely a formality, but should be effective and capable of influencing outcomes.
Digital Surveillance in the Workplace
Employers can implement a certain level of surveillance to ensure workplace safety and the smooth running of operations. However, AI-powered surveillance systems can have far broader implications than traditional camera applications.
These systems;
- Facial recognition,
- Voice analysis,
- Emotion or stress analysis,
- Screen and keyboard tracking,
- Analyzing internet activity,
- GPS and location tracking,
- Classification of email content,
- Mapping the employee's social relationships
These methods can create very detailed employee profiles.
When evaluating the lawfulness of surveillance, the criteria of legitimate aim, necessity, suitability, and proportionality must be considered. Prior notification of the employee is also mandatory.
In the Constitutional Court's approach to the monitoring of employees' communication tools by employers, the following are important: whether the employee was informed in advance about the monitoring, whether the monitoring is based on a legitimate aim, whether less intrusive methods are available, and whether the interference is proportionate.
Forcing employees, especially those working from home or remotely, to constantly turn on their cameras, subjecting them to surveillance of their private spaces, and monitoring their online status outside of working hours can lead to serious privacy violations.
Artificial Intelligence in Occupational Health and Safety
Artificial intelligence systems can offer significant benefits in preventing workplace accidents, detecting dangerous activities, and monitoring risky areas. However, systems that set unrealistic goals for employees, reduce break times, or create constant performance pressure can increase psychosocial risks.
The Occupational Health and Safety Law No. 6331 obligates employers to ensure the health and safety of employees, conduct risk assessments, and provide necessary training.
Before implementing an AI system, employers should assess not only physical hazards but also psychosocial risks such as stress, burnout, overmonitoring, pressure to be constantly available, and increased workload.
Production or delivery targets set by artificial intelligence should not be so high as to force an employee to violate workplace safety regulations.
The Impact of the European Union Artificial Intelligence Regulation
The European Union's Artificial Intelligence Regulation 2024/1689 classifies certain AI systems used in recruitment, employee selection, task assignment, performance evaluation, promotion, and termination of employment contracts as high-risk systems.
For companies operating in Türkiye and having commercial relations with the European Union, these regulations constitute an important compliance standard. In high-risk systems;
- Risk management,
- Data quality,
- Record keeping,
- Transparency,
- Human surveillance,
- Accuracy and cybersecurity
Their responsibilities stand out.
Even if the EU regulation does not directly apply to Turkish employers, it would be appropriate to consider internationally accepted standards of transparency, accountability, and human oversight when assessing the legality of the use of artificial intelligence in the workplace.
Legally Compliant AI Policy for Employers
Employers need to develop a written workplace AI policy before they begin using artificial intelligence systems. This policy should include at least:
- The names of the artificial intelligence systems used and their purpose,
- The scope of employee data being processed,
- The legal condition for processing personal data,
- Data retention periods,
- The people who can access the system,
- The responsibilities of system providers,
- How algorithmic decisions can be reviewed by humans,
- The employee's avenues for objection and correction,
- Discrimination and error detection methods,
- How artificial intelligence outputs can be used in disciplinary and termination processes
It should be clearly regulated.
It is not enough to simply inform employees about the policy. Regular training should be provided on how the system works, its risks, and employees' rights.
Conclusion
Artificial intelligence neither eliminates nor makes unlimited the employer's right to manage. Employers can use AI systems for work organization, performance evaluation, and workplace safety. However, this use must be based on the principles of legality, proportionality, transparency, equal treatment, data minimization, human supervision, and accountability.
Employers cannot implement decisions made by artificial intelligence without questioning them. Lack of knowledge of how the algorithm works, the purchase of the system from an external provider, or the automated generation of decisions does not absolve the employer of legal responsibility.
Especially in areas with significant consequences for employees, such as recruitment, performance evaluation, discipline, promotion, and dismissal, the final decision should be made by an authorized and knowledgeable person. The employee should be informed of the reasoning behind the decision and given the opportunity to object to inaccurate data and request a review.
In the age of artificial intelligence, the legitimacy of the right to manage depends not on how advanced the technology is, but on the extent to which the fundamental rights of employees are respected. The employer's primary obligation is not to replace management with algorithms, but to manage the use of algorithms within the framework of legal rules.