Service · Cybersecurity

Safe use of AI

Generative AI did not wait for a purchasing decision. Across Turkish SMEs, employees already paste quotations, customer correspondence and even contract drafts into free chatbots under private accounts. Picture an architecture practice where one designer condenses a tender specification with a free assistant, a colleague uploads the client list to a different service to have it grouped, and the managing partner knows about neither. With consumer tiers, it is often unclear whether prompts help train the model, in which country they are stored and how long they are kept. Prohibition is no answer, because it only pushes the habit out of sight. Turkey currently has no dedicated AI statute, yet KVKK still governs any personal data involved, and the Authority has issued recommendations on generative AI. Businesses that sell into the EU should also keep the EU AI Act in view. What we want is productive AI use in which client files and internal figures stay under your control. That takes an approved tool, a single page of rules and around half an hour of training per person.

Company licence
prompts stay out of model training
One page
of plain-language guidance
Shadow AI
measured, not wished away
Training log
names, dates and topics recorded

What the work covers in practice

Nobody wants to stand in the way of useful AI. The task is to keep client and company information inside boundaries you have chosen.

Agree the scope with the engineer who will do the work

Usage discovery

We establish which AI services people really rely on, using sign-in records, browser and firewall data and a brief anonymous questionnaire, so you see the facts without anyone being blamed.

Tool selection

Candidates typically include Microsoft 365 Copilot, the free Copilot Chat signed in with a work identity and the business tiers of ChatGPT or Gemini. We weigh contract terms, where data is held, whether prompts feed training and the cost, then recommend one.

Tidy permissions first

Copilot surfaces anything the signed-in person is allowed to open. Payroll spreadsheets or board minutes shared with the whole organisation must be locked down before it goes live.

Usage policy

One short document listing the sanctioned tools, the information that stays out of prompts (personal data, confidential client material, credentials), how answers are double-checked and who to contact with questions.

Guard rails

Unsanctioned AI sites are blocked or display a caution banner, and DLP rules stop confidential text from being pasted into chat windows.

Training and evidence

A compact video course covering good practice, common pitfalls and data protection; attendance is logged. If you sell into the EU, that log also helps demonstrate the AI literacy the EU AI Act expects.

How we approach the job, from first call to handover

A matter of weeks takes you from improvised, individual use to an organised set-up the team genuinely likes.

01

Snapshot

An overview of the services people use and the jobs where AI really saves time: drafting quotes, answering emails, condensing documents, translating.

02

Choice

Selection of a primary tool, two at most, a review of its contract and data processing terms, and a briefing pack for your lawyer's KVKK assessment.

03

Launch

Licences assigned, the tool configured, guard rails and rules in place, then every employee completes the training.

04

Refinement

Once people have worked with it for a while, we review real usage, refine the rules and add further use cases.

Forbidding AI does not stop it; it only hides it. People seldom abandon something that saves them an hour a day, so a ban simply moves the work onto personal phones. A good sanctioned tool plus clear rules lowers the risk and lets the team get genuine value from AI.

Frequently asked questions

Not at the moment. KVKK applies wherever personal data is processed, and the Authority has published recommendations on generative AI and personal data. Selling goods or services into the EU may bring the EU AI Act into play as well. Please ask your legal adviser for a formal legal view.

Under the provider's business terms your inputs are excluded from model training, and you gain an admin console, user management and usually retention controls. Free and personal accounts either lack those protections or leave them to each individual's settings, which matters most when client data is involved.

Permission hygiene comes first. Copilot will find and summarise anything a user can already open, so a salary file accidentally shared with the whole company could appear in reply to a single question. Review SharePoint and OneDrive sharing, introduce sensitivity labels and roll out to a small group first.

No, reading individual prompts is not the aim. Guard rails block specific content, such as ID numbers or documents labelled confidential, from reaching unsanctioned services. Who can view which events is agreed in advance, and we recommend telling staff how it works.

Put AI to work without the worry

Describe the AI tools in use today and whether you are on Microsoft 365 or Google Workspace. We will recommend where to begin.

Availability
Weekdays 09:00-18:00 Turkey time (GMT+3); an answer follows by the next working day
Calls
By video, over Microsoft Teams or Google Meet

The only cookies here are the essential ones: they keep the site running and remember the city you picked. Nothing is used for advertising or tracking. See our privacy notice for more.