Employee Use of Generative AI Tools — a Different Problem Than Deploying One
Generative AI Guide (15 Soruda) — What KVKK Actually Said and Etken Yapay Zekâ (Agentic AI) Guidance — KVKK's March 2026 Framework both assume an organization that deliberately built or deployed an AI system. Most KOBİs have a more immediate exposure: employees already pasting customer data, contracts, and internal documents into consumer AI tools on their own initiative, with no processing agreement, no role assignment, and no one who decided this was a processing activity at all. KVKK's guidance on workplace generative-AI use targets exactly this gap.
Why this is a distinct problem, architecturally
Everything in Deployment Patterns — KVKK-Aware Agent Architecture assumes you control the system — what enters its context, where transcripts live, who the processor is. None of that applies when the "system" is an employee's personal ChatGPT account. The controls are organizational and behavioral before they are technical:
- A written policy on which tools are approved for which data categories — silence is not a policy; it is a gap that becomes a breach when discovered during an audit or (worse) after a leak.
- Classify before you prohibit or permit. Public customer information, internal-only business data, and personal/special-category data need different rules, not one blanket "no AI tools" memo that gets ignored.
- Enterprise/business-tier tools typically carry different data-handling terms (no training on inputs, defined retention) than free consumer tiers — the tier matters as much as the tool.
- This is where VERBİS and role questions start, not end. If the company adopts an approved tool company-wide, it likely becomes veri sorumlusu for that processing the moment the policy exists — see KVKK in Brief — for AI Builders.
The practical order of operations for a KOBİ
1. Find out what's already happening — ask, don't assume. Shadow use is the default state, not an edge case. 2. Classify the data categories that matter (customer PII, employee data, special categories, trade secrets — KVKK only governs the personal-data slice, but the business risk is broader). 3. Write the policy, scoped to what you found in step 1, not a generic template. 4. Pick (or formally bless) a small number of business-tier tools, assign controller/processor roles in writing, and route this into the same decision trail as any deliberately deployed agent (Pattern 5).
Where this fits in the reading order
If you are advising a KOBİ that has not yet built or bought an AI agent, this page is where the conversation actually starts — before Deployment Patterns — KVKK-Aware Agent Architecture, not after.
---
Educational reference maintained by Avalanche AI — not legal advice.