Skip to content

Process setup

Is using AI in hiring legal?

A rejected candidate writes an email and asks one single thing: did a piece of software eliminate me. Answering that takes three things. Who made the decision, which criterion was checked, what was recorded at that moment. This guide does not interpret the law; it shows where those three answers come from in the panel and what stays with you.

A human decides

AI never changes the status of an application on its own; a transition requires a user identity and lands in the audit trail

A 3 valued gate

The mandatory criterion gate returns passed, closed or unknown; unknown is never counted as closed

At least 10 characters

Whoever opens a closed gate by hand has to write a reason; the reason is stored and appears in the audit trail

12 minute readUpdated: 2 August 2026

Quick answer

Using AI in hiring is not banned in Türkiye, it is conditional. KVKK gives the data subject the right to object to an adverse outcome produced solely by automated analysis, which means you have to provide human review and a channel for objections. The equal treatment principle of the Labour Law binds whoever uses the tool, not the tool itself. Responsibility sits with the employer who opened the posting, not with the software.

The question is not whether it is banned, it is under which condition

Turkish legislation carries no provision banning the use of AI in hiring. What binds you is not the tool but how it is used. Two rules apply directly today: the right under KVKK to object to solely automated analysis, and the equal treatment principle of Labour Law no. 4857. The third one, the artificial intelligence regulation of the European Union, is out of scope today for a product established in Türkiye that sells only to Türkiye.

The real risk is not where it is expected. Under the equal treatment principle the burden of proof shifts to the employer: if the employee shows a strong likelihood of a violation, it is the employer who proves that there was none. Saying "I did not discriminate" is not enough, you have to be able to show why that particular candidate was eliminated. If an elimination decision was never written down anywhere, there is nothing left to defend.

The split of responsibility is clear. For candidate data the data controller is the company that opened the posting, and the software provider works as a data processor. You write the criterion, you open the gate, you make the decision. The sections below show what these conditions correspond to in the panel. They do not replace legal advice, which your own lawyer gives you.

  • There is no banning provision to look for. What exists is conditions: a channel for objections, human review and no discrimination.
  • The rule binds the user, not the tool. Whoever writes a discriminatory criterion and whoever opens a closed gate by hand is the employer.
  • Automatic elimination is not banned, elimination that cannot be audited is. The difference lies in whether the reason can be shown after the fact.
Two people at an office desk looking at a single printout together, one of them pointing at a line on the page
The question is never whether you used software; it is why you eliminated this candidate.

Which rule binds what

Three separate texts speak at once and all three say something different. The table puts what each of them says next to what it means at the hiring desk. The legal texts are given in shortened form; what binds you is the text itself.

The rule, what it contains and what it means on the hiring side
RuleWhat it saysWhat it means on the hiring side
KVKK art. 11/(g)The data subject may object to an outcome against them arising from their data being analysed solely by automated systems.Automated evaluation is not banned. Offering an objection mechanism and human review is mandatory.
Labour Law no. 4857 art. 5Discrimination on grounds such as language, race, colour, sex, disability, political opinion, philosophical belief, religion and sect is prohibited. A violation carries compensation of up to four months of wages.The criterion list is written by the employer. The software does not say which criterion is discriminatory; the risk stays with whoever wrote it.
The shift in the burden of proofIf the employee shows a strong likelihood of a violation, it is the employer who proves that there was none.If the reason for an elimination is not on record, there is no material to prove anything with.
EU AI Act Annex III(4)Systems used for recruitment and candidate selection count as high risk; obligations follow on risk assessment, technical documentation, bias testing, human oversight, notifying the candidate and retaining logs.Out of scope today for a product established in Türkiye that sells only to Türkiye. The obligation date has been pushed back to 2 December 2027.

Where the European side stands today

What sets the scope is not where the company sits but where the output is used. Three scenarios open it up: selling to a customer established in the European Union, that customer using the output inside the Union, and placing the product on the Union market directly. As long as none of them happens, no obligation arises. The date being postponed does not narrow the scope, it only moves the calendar.

There is no marketing sentence to draw out of this. No conformity assessment was carried out for the product, so no declaration of conformity or certification can be made either. The only thing that can be said concerns the design side: the explainability and record keeping behaviour that the high risk framework asks for were taken as a reference in the product. If a customer in the Union ever appears, it is clear where the preparation starts.

Where responsibility stays

For candidate data the data controller is the company that opened the posting; the software provider is the party processing the data on that company's instructions. What follows in practice: the privacy notice presented to the candidate is issued under your company name, you answer candidate requests, you decide the retention period. Information, correction, deletion and objection requests are sent by email and concluded within thirty days at the latest.

Nothing is handed over on the equal treatment side either. The product does not block a discriminatory criterion, because the criterion text is free text. The check that runs while you write it asks a single question: can this criterion be verified from a CV. It does not ask whether the criterion is discriminatory, and it does not claim to.

Two paper folders standing apart from each other on an off white background, the left one carrying a cobalt blue strip
The decision sits on one side, the infrastructure on the other; the line between them is drawn not by a contract but by who wrote what.

What meeting the conditions looks like in the panel

The conditions above share one demand and it fits in a single sentence: let a human decide, let the candidate know what is happening, keep the reason on record. The three headings below are what that looks like in the product. All of it applies in companies where AI analysis is switched on; the setting is on by default, and while it is off no pre evaluation, gate or score is produced at all.

A young woman standing at a desk, moving one of the candidate files into the pile beside her
The suggestion stays on the screen; the hand that decides which candidate moves to which list is always the same one.

The suggestion and the decision stay apart

AI never changes the status of an application on its own. The score and the decision band are a suggestion. The operation that changes a status goes through a single service, requires a user identity and completes in one database transaction. The changed field, the old value, the new value and the user who made the change are recorded together.

The mandatory criterion gate does not eliminate anyone either, it puts a mark: passed, closed, unknown. Unknown is never equated with closed, because the cost of a wrong elimination was taken to be higher than that of keeping an unnecessary candidate on the list. The year arithmetic behind the gate is not asked of the model, it is done in code; in the measurement run it returned the correct result in twelve out of twelve hard edge cases and produced no false elimination.

What the candidate is told

Before sending the application, the candidate sees that it goes through an AI assisted pre evaluation, and the text states that the final decision is always made by a human. This is not a checkbox. It was deliberately not made one, because a checkbox would mean that a candidate who does not accept cannot apply; the KVKK privacy notice and explicit consent approvals already stand there as two separate boxes.

After sending it, the candidate can see what was read from the CV: experience titles, date ranges, technologies. The score, the decision band, the gate result and the ranking are not shown. What makes that true is not an interface preference but the service never looking at the score table; the data never reaches that endpoint, so it cannot leak. A candidate reporting that their details are wrong flags the record for human review; it does not delete the analysis, does not change the score, and the fact that the flag came from the candidate is read from a separate field.

Why the decision goes on record

A human can open a closed gate, but not without writing a reason: the reason is mandatory and at least ten characters. The sentence on the screen says the same, that the reason is stored and appears in the audit trail. The decision is permanent and survives every recalculation; a refreshed score does not erase a human decision. The decision is also written as an immutable event independent of the fit record, because had it gone into a single field a second override would have written over it.

Next to every score record sits the version and model trail: the fit version, the scoring and rubric version, the model name, the temperature and the structured basis of the gate (which criterion, which call, how many months required, how many months found). When a score is recalculated the previous state is not lost; the history record keeps the old score, the band, the gate call and its reason. The reason is derived not from a user statement but from a stored summary comparison, so a criterion change cannot be hidden behind the claim that the CV changed.

The position rubric is produced once per posting, stored, and applied identically to everyone who applies to that posting. Versions are immutable: an edit opens a new version and the old one drops into the archive without being deleted. It was built this way so that the question a candidate was measured against can still be shown months later.

The system does not learn from past decisions

Evaluation does not learn from past hiring outcomes. Who was invited or hired never enters scoring; calibration is used only to set the scale of the score distribution. The reasoning is written down: a system that learns from outcome labels reproduces the preferences of the past.

The model does not produce a score in the first place. Item by item it answers whether something is evidenced in this CV, leaves a verbatim quote from the CV next to every answer, and the arithmetic is done in code. An item with no evidence found does not count as half a point, it leaves the denominator.

Two things are deliberately not claimed. First, the pairwise comparison layer inside the pool is not live, and it will not go live before passing the audit that measures how far the ranking shifts when identity signals are changed. Second, the calibration report that shows the band distribution across the company, how many times the gate closed and how many times a human stepped in returns numbers only: no candidate name, no email, no score per row.

Five paper cards laid out in a single row on a paper background with no link between them, the middle one cobalt blue
Every application is read against the same list; the outcome of the previous hire is not carried into the next one.

The part the software does not solve, the part that stays with you

This is usually the most useful section of a compliance page. What follows is what the product does not do, and in places what it looks like it does but does not; every item comes back to the responsibility of a person.

A process set up without knowing these relies on a protection that is not there. Learning about them during an audit is the most expensive route.

  • There is no discriminatory criterion check. The criterion text is free text; the check that runs while you write it only looks at whether the criterion can be verified from a CV, and it writes its reasoning in Turkish.
  • The closed gate warning does not block anything. If a posting is about to be closed while nobody ever looked at the closed gate group, a warning appears, but it does not stop the closing.
  • There is no separate screen that shows the audit trail. Records are kept and can be produced after the fact; do not expect a ready made audit trail page.
  • There is a limit the gate cannot see: if a candidate has left a job but the CV still says "present", no deterministic calculation can catch it. That risk is left to reference checking.
  • The application form collects neither sex nor marital status; those fields exist only on the employee record. Date of birth is an optional field on the candidate record.
  • Masking is role based. For a user without permission to see personal data the gate and override reasons drop; that a decision was made, who made it and when it was made stay visible.
Cards stacked on a paper background, the top one empty and pushed out past the edge, with a thin cobalt blue strip beside it
Knowing the gap the product does not close costs less than believing a protection sits there.

Frequently asked questions

No. There is no provision banning its use, what exists is conditions. Because KVKK gives the data subject the right to object to an adverse outcome produced solely by automated analysis, you have to offer an objection channel and human review. The equal treatment principle binds whoever uses the tool rather than the tool itself, which means the responsibility for your criteria stays with you.

The product does that for you. Before sending the application, the candidate reads that it goes through an AI assisted pre evaluation and that the final decision is always made by a human. That text is deliberately not a checkbox; as a checkbox it would mean that a candidate who does not accept cannot apply. The KVKK privacy notice and explicit consent approvals do stand there as two separate boxes.

Three things. That a human made the decision: a status change requires a user identity and is recorded field by field. The reasoning: the model produces no score, it looks for evidence item by item and leaves verbatim quotes from the CV. The record: because every score keeps the version, the model and the basis of the gate, you can show which item the candidate fell short on.

A product established in Türkiye that sells only to Türkiye is out of scope today. Three situations open the scope: a customer established in the Union, that customer using the output inside the Union, and placing the product on the Union market. Because no conformity assessment was carried out for the product, no declaration of conformity or certification is made either.

No, there is no such check. The criterion text is free text, and the check that runs while you write it asks a single question: can this criterion be verified from a CV. It does not flag a criterion built on sex, age or marital status as discriminatory. The risk under the equal treatment principle stays with whoever wrote the criterion.

On the scoring side, yes. Every record keeps the version, the model and the structured basis of the gate; on recalculation the previous score, band and reason drop into the history; rubric versions stay in the archive. The reason written by whoever opened a closed gate by hand is stored as well. The one limit: there is no ready made audit trail page that gathers all of this on a single screen, the record is produced and presented.

You make the decision, the reason stays on record

The suggestion, the gate and the reason record are already there in the panel. Request a demo to see how it works with your own posting.

Contact Us