Skip to content
September 12, 2026 · English

Microsoft’s AI Governance on Trial: Gray v. Nadella and Directors’ Liability under Turkish Law

By Av. Asutay Duhan Meydan | Attorney at Law

Meydan AI & Tech Law | 12 September 2026

An AI company may incur liability before a model produces an unlawful output. Decisions concerning training material, technology partnerships and investor disclosures can expose the company to claims and subsequently expose its directors to proceedings brought for the company’s benefit. Gray v. Nadella provides an opportunity to examine that second stage of liability. Its practical significance for Turkey lies in the relationship between unlawful business conduct and the obligations of those who approve, supervise and describe it to shareholders.

The distinction is consequential. Corporate exposure does not establish a director’s personal liability. A claimant must connect an identifiable obligation, a particular director’s conduct and legally recoverable loss. In my view, that connection should also determine how AI companies design their internal governance.

The proceedings and the relief sought

Katelyn Gray commenced a shareholder derivative action in the United States District Court for the Western District of Washington on 8 September 2026, Case No. 2:26-cv-03215. Satya Nadella and other Microsoft directors and officers are defendants; Microsoft is the nominal defendant and intended beneficiary of recovery. This article examines the complaint at filing, rather than an adjudication of its allegations. [1]

Gray pleads breach of fiduciary duty, misleading proxy solicitation under section 14(a) of the Securities Exchange Act 1934 and Rule 14a-9, and unjust enrichment of officers. She alleges failures concerning AI copyright compliance and disclosures about Microsoft’s AI business. She seeks compensation payable to Microsoft, restitution of allegedly unjust remuneration, declaratory and injunctive relief, governance reforms, interest and litigation costs. No fixed aggregate damages demand is pleaded. [2]

These remedies have different legal functions. Compensation would restore a proven corporate loss. Restitution would address benefits retained without a sufficient legal basis. Governance relief would seek to change future conduct. A shareholder’s own decline in portfolio value is not interchangeable with damage suffered by the corporation. Likewise, executive remuneration cannot simply be aggregated and treated as recoverable damages: the legal basis for recovering each payment must be established.

The action therefore raises a question extending beyond the legality of model training. Even where a technology company has a defensible position in an underlying copyright dispute, its directors may face a separate allegation that they failed to assess that dispute or described the company’s position inaccurately. Conversely, losing a copyright case would not, without more, establish that every director breached a duty.

Evidence and the limits of the pleaded inference

The complaint relies on public filings, the 2024 and 2025 proxy statements, shareholder proposals, executive statements, remuneration disclosures, press coverage and analyst reports. It invokes Authors Guild, Basbanes, Bird and Richner copyright litigation as warning signs. Additional evidentiary support is anticipated through discovery. [2]

Microsoft’s 2025 proxy provides a concrete example. Its response to the training-data proposal describes exclusions for certain paywalled or restricted sources and domains on the USTR Notorious Markets list, alongside negotiated arrangements with publishers and copyright owners. It also describes board and committee oversight of AI risk. These are specific representations against which operational evidence could be tested. Their precise scope matters: an assurance about Microsoft’s sourcing should not be assumed to describe every dataset used by every third-party model available through its services. [3]

The evidential question is what each category can actually establish. A corporate statement can prove what shareholders were told. It cannot, by itself, prove that the statement was false when made. A shareholder proposal can demonstrate that a concern was raised; rejection of the proposal does not establish that the board ignored the concern. The board may have considered an existing control sufficient, a proposed report unnecessary or the underlying legal position defensible. That response must be tested against the contemporaneous record.

Material identified in the pleadingEvidential significance and necessary qualification
Proxy statements and responses to shareholder proposalsIdentify the representation, its date and the voting context. Compare the wording with the actual scope of the company’s controls and any known exceptions.
Earlier copyright complaintsMay establish notice of an allegation. They do not prove infringement, the use of a particular work or a director’s knowledge of unlawful acquisition.
Earnings statements and analyst commentaryMay assist a chronology of business expectations and later developments. They require independent examination of methodology, attribution and causation.
Executive remuneration disclosuresEstablish reported remuneration. Recoverability depends on the relevant payment terms, alleged misconduct and the connection between them.

The strongest evidence would ordinarily be specific operational material: dataset acquisition records, the rights actually licensed, audit findings delivered to identified decision-makers, minutes recording their response and documents supporting the disputed disclosure. Evidence of model behaviour would require reproducible testing that identifies the model version, prompt, output and relevant protected expression. These are examples of evidence that could resolve the dispute, not a statement that such material has already been produced in Gray.

Chronology matters equally. A later commercial disappointment cannot retrospectively make an earlier statement misleading. Nor does general knowledge that copyright litigation exists establish knowledge that a particular dataset was unlawfully obtained. The claimant’s task is to move from a plausible concern to a properly supported account of responsibility.

The US legal grounds and the authorities cited

Fiduciary duties and the demand requirement

A derivative claimant seeks to exercise a corporate cause of action. Federal Rule of Civil Procedure 23.1 requires a verified complaint and particularised allegations concerning efforts to obtain corporate action, or the reasons for not making those efforts. Kamen v. Kemper Financial Services, Inc., 500 U.S. 90 (1991), explains the distinction between that procedural rule and the substantive law governing demand. For a Washington corporation, Washington corporate law must remain central to the analysis. [4]

Gray expressly invokes United Food & Commercial Workers Union v. Zuckerberg, 262 A.3d 1034 (Del. 2021), on demand futility, and Bartz v. Anthropic PBC on copyright. The section 14(a) count expressly disavows fraud. [2]

Zuckerberg requires an assessment of each director’s material personal benefit, substantial likelihood of liability and independence from an interested person. Demand is excused where at least half of the demand board is disabled under that assessment. The decision also recognises the significance of exculpated claims: conduct for which a director cannot face monetary liability does not necessarily disable that director from considering a demand. [5]

Washington’s demand-futility approach draws on Delaware authority through In re F5 Networks, Inc., Derivative Litigation, 166 Wn.2d 229 (2009). A useful illustration is the Washington Court of Appeals’ unpublished opinion in Trimm v. Kelly, No. 86734-2-I. It applied Zuckerberg and required particularised allegations sufficient to overcome the relevant exculpation provision. It expressly left the adoption of Delaware Caremark claims unresolved. Trimm is an illustration, not binding precedent or a ruling in Gray. [6]

Accordingly, a description of this case as a settled application of Delaware oversight liability would be premature. The court must identify the governing Washington duties, consider any applicable and valid exculpation provision and assess the allegations against individual directors. Assertions that the board supervised AI generally may identify its remit; they still require a connection to the misconduct alleged. The mere fact that directors would be asked to authorise proceedings against colleagues cannot substitute for the applicable demand-futility analysis.

Proxy liability and causation

Section 14(a), 15 U.S.C. § 78n(a), and Rule 14a-9 address materially false or misleading proxy solicitations. The relevant inquiry concerns the information supplied in connection with shareholder voting, evaluated in its contemporary context. A challenge to the wisdom of an AI investment is therefore insufficient unless connected to an actionable representation or omission. [7]

Mills v. Electric Auto-Lite Co., 396 U.S. 375 (1970), supplies an additional analytical authority, rather than a precedent expressly cited in Gray. It addresses the causal relationship between a materially defective solicitation and the corporate transaction, including whether the solicitation was an essential link. That issue should be distinguished from proving the amount and cause of subsequent corporate loss. [8]

This distinction creates a substantial issue for a claim based on directors’ re-election. The claimant must explain the legally sufficient connection between the defective solicitation, the shareholder decision and the injury for which recovery is sought. The proposition that re-election allowed management to remain in office does not, without further analysis, establish responsibility for every later business loss.

The complaint also refers to Regulation S-K Items 105 and 303 and Rule 12b-20. Those references support its disclosure theory; they should not be described as additional, separately pleaded causes of action. The scope of each reporting obligation and the document to which it applies must be examined independently. [2]

What Bartz actually decided

The June 23, 2025 order in Bartz v. Anthropic PBC, No. 3:24-cv-05417-WHA, distinguishes training use from acquiring and retaining pirated copies in a central library. Applying 17 U.S.C. § 107, the court granted Anthropic summary judgment on the training use and on a separate print-to-digital conversion practice. It declined to extend that protection to the pirated library copies. [9]

It would therefore be inaccurate to present Bartz as holding categorically that AI training on copyrighted material is unlawful. Its treatment of acquisition and retention is particularly relevant to governance, but the holding must retain its factual and procedural limits. It is a district-court decision involving another defendant, not an adjudication of Microsoft’s datasets or its directors’ conduct.

For a board, the practical inference is narrower and more useful. A legal opinion supporting one stage of a technical process may not justify the other stages. The company should separately examine acquisition, storage, training and dissemination. Neither an asserted transformative purpose nor a commercial relationship with another developer answers all of those questions.

The same dispute before a Turkish court

Jurisdiction and applicable law come first

Two scenarios must be distinguished. The first is an attempt to bring Gray’s corporate claims against Microsoft’s existing directors before a Turkish court. The second assumes equivalent conduct within a Turkish joint-stock company. Only the latter permits a straightforward application of the Turkish Commercial Code No. 6102, or TCC.

Under Article 40 of the International Private and Procedural Law No. 5718, international jurisdiction generally follows domestic jurisdictional rules. Microsoft’s commercial presence in Turkey would not, by itself, confer jurisdiction over every claim concerning the internal management of its foreign parent. The defendant, the obligation and the relevant connecting factors must be identified. [10]

The corporate statute also requires separate analysis. Article 9(4) connects a legal person’s capacity to the law of its statutory administrative seat, while permitting Turkish law where its actual administrative centre is in Turkey. The treatment of internal corporate obligations requires characterisation within that corporate-law framework. A Turkish subsidiary or Turkish customer base does not relocate the parent’s administrative centre. A Turkish court could consequently be required to apply foreign law to the parent’s internal corporate relationship.

External claims follow their own connecting rules. Article 23 applies the law of the country for which intellectual-property protection is sought. Article 34 contains the general tort rules, including the place of damage where it differs from the place of conduct and the exception for a more closely connected relationship. The law applicable to copyright infringement should not be replaced by the general tort rule without examining the specific intellectual-property provision. [10]

The Turkish corporate liability claim

For an equivalent Turkish joint-stock company, Articles 369, 375 and 553 supply the substantive starting point. They address prudent management and loyalty, retained board responsibilities and liability for culpable breach. Article 555 permits each shareholder to seek compensation for corporate damage, payable to the company. Article 557 requires differentiated assessment of joint liability. Articles 367 and 553(2)–(3) regulate delegation and the limits of responsibility. [11]

Article 555 provides a meaningful functional comparison with a derivative action, although its procedural architecture differs from Washington law. It does not impose Zuckerberg’s director-by-director demand-futility test as a condition of the shareholder’s statutory claim. The shareholder should nevertheless identify the corporate loss and request payment to the company. A demand for personal payment of an exclusively corporate loss would confuse the right being enforced.

A viable pleading could allege that identified managers approved commercial use of a dataset despite a substantiated licensing defect, failed to investigate a specific infringement notice or authorised a materially inaccurate report about those matters. The claim would need to explain how the omission fell within each defendant’s responsibilities and caused recoverable loss. Negligence can matter under Turkish law; the claimant need not automatically reproduce a Delaware bad-faith threshold.

The defence would require equal attention. Technical uncertainty, a product’s weak adoption or a substantial capital commitment does not itself demonstrate culpable management. A contemporaneous, informed assessment of alternatives and legal advice may support the propriety of the decision. Equally, reliance on another developer should be evaluated by reference to the actual allocation of functions and the quality of the information reasonably available.

Delegation is neither a universal defence nor legally irrelevant. A properly structured delegation can affect responsibility for another person’s acts. It cannot simply transfer a duty that the statute retains at board level. Conversely, an allegation of inadequate supervision cannot erase the statutory protection concerning matters outside a person’s control. The court should distinguish a director’s own supervisory omission from automatic liability for an engineer’s or business partner’s conduct.

Turkish legislation creating operational exposure

Copyright and commercial acquisition of data

The Law on Intellectual and Artistic Works No. 5846, or FSEK, is the principal copyright statute. Article 22 protects reproduction, including temporary and indirect copying; Article 25 addresses communication to the public. Articles 35 and 38 contain limited exceptions, rather than an open-ended equivalent of US fair use. Articles 52 and 54 concern the form of rights transactions and acquisition from an unauthorised transferor. Articles 66, 68–70 and 76 govern important remedies and proceedings. [12]

For Microsoft, or any provider whose relevant conduct engages Turkish copyright law, acquisition and processing should be examined operation by operation. A publicly readable book is not necessarily licensed for commercial reproduction. A publisher’s agreement must cover the relevant rights and uses, and the provider must examine whether the licensor possesses those rights. FSEK Article 52 makes a general assurance of “access to content” an inadequate substitute for a properly documented rights transaction.

The personal-use exception presents obvious difficulties for a commercial training operation. A US fair-use conclusion does not supply a Turkish statutory exception. Nevertheless, liability still requires identification of protected subject matter, a relevant restricted act and the absence of sufficient permission or an applicable exception. The proposition that a model’s weights necessarily reproduce every training work should not be assumed without technical and legal examination.

Potential remedies include cessation and prevention of infringement, compensation where the applicable conditions are met and the enhanced licence-fee remedy under Article 68. The latter is commonly expressed as recovery of up to three times the relevant fee; it is not a fixed damages award for every document in a dataset. The rights asserted, appropriate valuation and interaction between remedies require examination. A targeted injunction may also threaten the continued availability of a feature or corpus, making remediation and service continuity relevant to board oversight.

Commercial scraping can additionally raise unfair-competition issues under TCC Articles 54–56 and database protection under FSEK Additional Article 8. These require their own elements. They should not be used as labels that render all automated collection unlawful. Providers should nevertheless assess systematic extraction, objections from the source operator and the commercial use of another undertaking’s investment independently of whether each individual data item qualifies as a copyright work. [11][12]

Contractual liability and personal criminal exposure

The Turkish Code of Obligations No. 6098 supplies further grounds where its conditions are satisfied. Articles 49 and 61 concern tort liability and responsibility for jointly caused harm; Article 112 addresses non-performance or defective contractual performance. Merely supplying computing capacity does not establish that the supplier jointly caused a copyright infringement. For an infrastructure provider, the analysis must identify its own legally relevant conduct and the applicable basis of responsibility. Contractual assurances about data rights may separately expose the entity that gave them. [13]

FSEK Articles 71 and 72 may also become relevant where conduct satisfies the elements of an offence, including the applicable mental element. Under Article 20 of the Turkish Criminal Code No. 5237, criminal responsibility is personal; legal persons are not subject to criminal penalties, without prejudice to statutory security measures. Neither a corporate title nor an investment establishes an individual’s participation in an offence. [12][14]

Personal data and public disclosures

Where datasets or user interactions contain personal data, Law No. 6698 creates a separate compliance inquiry. Its principles, processing conditions, transparency and security duties remain relevant even where copyright permission exists. Article 9’s amended transfer framework must be assessed for transfers from Turkey to foreign infrastructure or group entities. Public availability is not an unrestricted processing licence, and controller responsibility follows the actual determination of processing purposes and means. [15]

For a provider, that means documenting the basis for using personal data for training, examining special-category data separately and selecting a legally available transfer mechanism. Internal approval to upload a corpus cannot replace those requirements. Nor should administrative exposure automatically be attributed personally to every director. Any corporate claim seeking recovery from management must separately establish its own conditions.

For an issuer within the Turkish capital-markets regime, Articles 14, 15 and 32 of Capital Markets Law No. 6362 become relevant to financial reporting, material disclosures and liability for misleading disclosure documents. Article 32 contains particular rules on responsible persons, defences and causation; it also invalidates contractual terms that reduce or remove the liability it regulates. [16]

This regime could create material exposure where an in-scope issuer describes training rights or commercial AI performance in misleading terms. It is not automatically applicable to Microsoft merely because its shares are traded on Nasdaq or its products are sold in Turkey. An investor’s direct disclosure claim must also be distinguished from a shareholder’s claim for corporate damage under TCC Article 555.

The likely Turkish judicial approach

The following assessment is prospective. It does not describe a Turkish judgment deciding Gray’s allegations or an established Turkish precedent on AI directors’ liability.

A Turkish commercial court would first have to resolve jurisdiction, applicable law, standing and the correct relief. For a domestic corporate claim, it would then examine the relevant duty, alleged breach, fault, loss and causation. Article 557 requires attention to the responsibility attributable to each defendant. A financial expert’s assessment of loss would not dispense with that legal analysis. [11]

Access to evidence would probably be decisive. The Code of Civil Procedure No. 6100, or HMK, addresses the burden and particularisation of proof in Articles 190 and 194, electronic documents in Article 199, document production in Articles 219–221, technical expertise in Article 266 and preservation of evidence in Article 400. These mechanisms do not constitute an equivalent of broad US discovery. [17]

The practical consequence is that a claimant should identify relevant documents and the facts each document would establish. A properly directed production request concerning a licensing report or a specified board meeting is more useful than a general allegation that management must possess incriminating information. Shareholder information and special-audit mechanisms under TCC Articles 437–439 may assist, subject to their respective conditions. Evidence-preservation measures may be necessary where logs or model versions are liable to change. [11][17]

The court’s examination should distinguish company loss from market movements. A fall in share price may have numerous causes. A recoverable corporate loss would need a separate basis, such as expenditure attributable to a proven breach or an established liability that competent action would have avoided. Lawful expenditure on innovation cannot be treated as damage merely because a cheaper or more successful strategy becomes apparent afterwards.

In my assessment, the claim would be materially stronger where the record demonstrates a specific legal defect, receipt by an identifiable decision-maker, an available corrective measure and an unjustified failure to act. A claim resting predominantly on adverse press coverage, high remuneration and disappointing business results would face more serious evidential difficulties. This assessment follows ordinary corporate-liability principles; the use of AI does not eliminate them.

Conclusion on internal governance and management liability

AI companies should design their internal rules around the liabilities that particular decisions can create. The articles of association, any internal directive and committee mandates should work together. For a Turkish joint-stock company, Article 367 requires an appropriate legal structure for delegation; Article 375 preserves the board’s non-delegable responsibilities. Article 340 limits departures from mandatory statutory provisions through the articles of association. An AI committee should have a defined mandate, competent members and a route for escalating unresolved issues to the board. [11]

First, approval of training material should require a record of provenance and the legal basis for each intended use. The internal process should distinguish copyright permission from personal-data compliance and should assign authority to quarantine a disputed source. Commercial pressure should not allow an unresolved rights objection to disappear between procurement, engineering and legal review.

Second, the board should receive information that permits a decision. Reporting should identify the affected model or service, the nature of the objection, potential operational consequences and available responses. Minutes should record the assessment actually undertaken, including contrary advice and the reason for accepting residual risk. A policy that exists only as a public statement may create additional disclosure exposure if the company represents that it is operational.

Third, investor communications should be checked against the underlying evidence. Claims about lawful sourcing, adoption or product performance need defined scope and an identifiable factual basis. The team responsible for a disclosure should be able to obtain the relevant information from the operational owner before approval. Unqualified assurances of worldwide compliance are particularly difficult to sustain where the legal treatment of acquisition and training differs between jurisdictions.

Fourth, partnerships should secure access to compliance information, notification of claims, reasonable audit or verification rights and a workable remediation process. Indemnities may allocate economic consequences between contracting parties, but they cannot determine a third party’s statutory rights. Responsibility must follow the particular entity and its role; the parent, local subsidiary, model developer and cloud provider should not be treated as a single legal person.

Finally, remuneration and conflicts require independent scrutiny. Where legally appropriate, remuneration arrangements should provide for adjustment or recovery linked to materially misstated performance or proven misconduct. TCC Article 393 requires attention to conflicted deliberations. Litigation-response procedures should preserve relevant records and facilitate independent assessment of claims against management. D&O insurance should be reviewed against its actual wording, including exclusions and derivative-action provisions, without assuming that every alleged liability or restitutionary payment is insured. [11]

The governing objective is demonstrable, proportionate decision-making. A company should be able to explain who was responsible, what information was available, why the decision was taken and how a material legal concern was addressed. That record supports lawful innovation and provides the foundation for a defence if corporate exposure later becomes a claim against the individuals who governed it.

Asutay Duhan Meydan

Attorney at Law | Meydan AI & Tech Law

Authorities and sources

[1] Gray v. Nadella et al., No. 2:26-cv-03215 (W.D. Wash.), filed 8 September 2026. Docket.

[2] Gray, shareholder derivative complaint, Document 1, particularly paragraphs 1–12, 43–58, 67–75, 86–109, 114–119 and 140–160, and prayer for relief. References to earlier copyright actions identify pleaded warning signs, not adjudicated infringement. Complaint.

[3] Microsoft, 2025 Proxy Statement, sections on risk oversight and the board’s response to Shareholder Proposal 7 concerning training-data sources. Company publication.

[4] Federal Rule of Civil Procedure 23.1; Kamen v. Kemper Financial Services, Inc., 500 U.S. 90 (1991).

[5] United Food & Commercial Workers Union v. Zuckerberg, 262 A.3d 1034, 1058–59 (Del. 2021). Supreme Court opinion.

[6] Trimm v. Kelly, No. 86734-2-I (Wash. Ct. App.), unpublished opinion, pp. 3–6 and 10 n.6, discussing F5 Networks and Zuckerberg. Court opinion. See also RCW 23B.07.400.

[7] 15 U.S.C. § 78n(a); 17 C.F.R. § 240.14a-9.

[8] Mills v. Electric Auto-Lite Co., 396 U.S. 375 (1970). Supreme Court opinion.

[9] Bartz v. Anthropic PBC, No. 3:24-cv-05417-WHA, Document 231, Order on Fair Use, 23 June 2025, especially pp. 31–32. District court order.

[10] Law No. 5718, Articles 2, 9(4), 23, 34 and 40. Consolidated statutory text.

[11] Turkish Commercial Code No. 6102, particularly Articles 54–56, 340, 367, 369, 375, 393, 437–439 and 553–557. Statutory text hosted by the Ministry of Trade. The AI governance applications in this article are the author’s analysis.

[12] Law No. 5846, Articles 22, 25, 35, 38, 52, 54, 66, 68–72 and 76, and Additional Article 8. WIPO Lex legislative record and consolidated text.

[13] Turkish Code of Obligations No. 6098, Articles 49, 61 and 112. Statutory text.

[14] Turkish Criminal Code No. 5237, Article 20. Statutory text.

[15] Law No. 6698, Articles 3–6, 9–12 and 18. Official guidance on processing conditions and the amended international transfer regime.

[16] Capital Markets Law No. 6362, Articles 14, 15 and 32. Statutory text.

[17] Code of Civil Procedure No. 6100, Articles 190, 194, 199, 219–221, 266 and 400. Statutory text.