ARCH Teknoloji · Article
The Legitimacy of Automation: The Legal Status of RPA and a Liability Framework Distinct From AI
The position of rule-based automation under the AI Act, GDPR Art. 22, and KVKK
Abstract
RPA is rule-based and deterministic: the AI Act excludes it from scope at the definition stage, and it stays aligned with the threshold of GDPR Art. 22 and KVKK Art. 11/1-g.
Software robots that enter the same invoices in the same order every month in an accounting department, copy customer instructions from system to system in a bank, or match policy data in an insurance company have become an ordinary business reality. The name given to these robots is usually "Robotic Process Automation" (RPA). Yet in recent years, the debate shaped around AI regulation has tended to place RPA in the same category. The moment a company says "we use automation," it can face legal suspicion, as if it were operating an algorithmic decision-maker or an opaque "black box." RPA, however, works in a rule-based and deterministic way; it executes steps predefined by humans, under human supervision, in a manner that humans can change at any moment. This structural difference shows that most of the debates about accountability, transparency, and unpredictability triggered by AI do not apply to RPA. This study will first clarify the academic and technical definition of RPA, and then set out the legal status and liability framework that distinguish this technology from AI.
Robotic process automation was first systematically defined in the academic literature in the field of business information systems. van der Aalst, Bichler, and Heinzl define RPA as an umbrella term for software tools that interact with other computer systems through the user interface, the way a human would, and emphasize a fundamental difference between this technology and classic workflow management: RPA works "outside-in," without changing the underlying information system. According to the Gartner definition cited in the same study, RPA tools execute operations that run on "if… then… else" logic over structured data, through user interface interactions or API connections. The element at the center of this definition is clear: RPA is bound to rules previously coded by humans and does not infer on its own from input data. Indeed, a systematic literature review also states that RPA is a supporting framework aimed at automating long-tail processes involving routine tasks, structured data, and deterministic outcomes, and it specifically notes that these systems rely on explicit rule and configuration coding, have no self-learning capability, and cannot understand on their own which action belongs to which process or which processes are suitable for automation. This technical framework forms the basis of the legal analysis addressed in the following sections: it is not "what" a system does but "how it works" that determines its legal characterization.
What distinguishes RPA from AI is often not the "level of automation," as is commonly thought, but the way the system produces output. AI, and especially systems based on machine learning, produce results by drawing statistical inferences from input data; this inference process is not fully traceable even for the engineers who design the system. Burrell explains this through three different types of opacity: opacity as intentional corporate or state secrecy, opacity arising from technical illiteracy, and opacity arising from the characteristics of machine learning algorithms and the scale required to apply them usefully. This third type of opacity does not apply to RPA, because RPA executes "if-then-else" logic, and every step of that logic has been written in advance by the person who configures it. This difference is not merely technical; it has direct legal consequences: if a system's behavior can be foreseen and audited in advance, the question of who is responsible for the outcomes it produces can also be answered with classic legal tools. With AI, establishing this chain of liability becomes harder, because sometimes even the developer cannot fully explain "why" the system made a given decision.
RPA's deterministic structure does not limit its legal advantage to transparency alone; it also makes a fundamental difference in terms of data security and data locality. An AI system, especially one based on a large language model, usually performs inference by sending data to a provider operating in the cloud; this data flow may count as a "cross-border data transfer" under Article 9 of KVKK as amended in 2024 and the Regulation based on it, and requires additional conditions to be met, such as an adequacy decision, appropriate safeguards, or explicit consent. In the banking sector, this picture becomes even more rigid: BDDK's Regulation on Internal Systems requires banks' primary and secondary information systems to be kept within the country, even if these systems are accessed through outsourcing or cloud computing, and Article 73 of Banking Law No. 5411 strictly limits the sharing of information qualifying as customer secrets with third parties. Within this framework, having a cloud-based AI service read data from a bank's core system is practically impossible; RPA, by contrast, falls outside these restrictions, since it reads and moves the very screen that a human employee is already authorized to view, at code level and without sending data outside the system. Moreover, the rule-based nature of RPA does not carry the "hallucination" risk documented in AI language models: as defined in the comprehensive survey by Ji and colleagues, hallucination is the generation of information that is not supported by the source or that contradicts reality, even though the generated content appears fluent and coherent; RPA, however, does not "generate" anything, it simply executes a predefined mapping.
The most practical element behind RPA's legal reliability is perhaps the least discussed: every operation is recorded step by step. When an RPA robot reads an invoice, copies a field into a system, or clicks on an approval screen, each of these actions is kept as a time-stamped log: which data was processed at which step, which rule was triggered, and what the result was. Huang and Vasarhelyi tie RPA's potential in auditing precisely to this feature: the processes run by robots produce a record chain that human auditors can trace directly, which allows the source of errors to be identified quickly. This is a critical difference compared with AI systems. When a model makes a prediction, it is often impossible to explain retrospectively and with complete clarity "why" that prediction came out the way it did; this is why explainable AI has developed as a separate field of research. RPA needs no such research field, because the explanation is already in the code: it is there when the rule is written, there when it runs, and there when something goes wrong. A company can answer the question "why did our automation carry out this operation this way" within seconds by looking at the logs, which greatly facilitates both internal and external audit processes. That automation is so far from being a "black box" shows that the legal suspicion directed at it is also largely misplaced.
RPA being deterministic and auditable does not automatically make it error-free; the truly critical variable is how well the person designing the robot understands the business process. A study by Denagama Vitharanage and colleagues published in Computers in Industry identified 32 critical success factors specific to RPA, based on interviews with 19 experts and a systematic literature review, and highlighted "early involvement of business unit and IT experts in the process" as an RPA-specific, technology-related condition for success. Similarly, another study published in the Business Process Management Journal draws attention to the risk of "loss of process knowledge" among the disadvantages of RPA and argues that a successful RPA implementation must be treated as a whole of human, organizational, and technical factors. The legal side of this should not be overlooked either: an RPA robot cannot know more than how the person coding it understood the process. A developer who misunderstands the process can produce automation that technically "works" but is legally flawed. This differs from the risk of "algorithmic bias" often stressed in AI debates; here the problem lies not in the nature of the system but in the quality of the process design. This strengthens the thesis in defense of RPA one step further, because in RPA the legal risk stems not from the technology itself but from the business knowledge of the person who builds it; this is a classic, well-known, and manageable human resources matter, not the kind of structural uncertainty debated with AI.
To understand why RPA should be subject to different legal treatment, we must first look at where the core concern of AI law comes from. In her study of public administration's shift to automated decision systems, Citron showed how these systems erode traditional procedural safeguards; in her view, automated systems combine the functions of individual dispute resolution and general rulemaking while lacking the procedural safeguards of both, because code now determines the decision, and programmers can change these rules in ways that the public, elected officials, and courts cannot oversee. In their study extending this debate to private sector applications such as credit scoring, Citron and Pasquale argued that procedural regularity is essential for individuals stigmatized by opaque scoring systems, and that regulators must be able to test the fairness and accuracy of these systems. The common denominator of these two studies is that the source of the problem is not "automation" but the opacity of automation: that neither the regulator nor the affected person can trace how the system reached its result. This is precisely a feature RPA structurally lacks: in RPA, the decision is already visible and open to debate when the code is written; the robot does not "learn" the rule, it simply applies it. The accountability crisis identified by Citron and Citron-Pasquale therefore points, by definition, not to rule-based systems but to systems that infer.
The approach of European data protection law to automation actually contains a threshold that largely protects RPA. Article 22 of the GDPR prohibits decisions that produce legal effects concerning a person or similarly significantly affect them from being taken "based solely on automated processing"; according to guidance from the UK Information Commissioner's Office (ICO), for a process to count as "solely automated," there must be no human involvement in the decision-making process. It is further required that this human involvement be "meaningful": the person reviewing the decision must have the authority to override it and the knowledge to assess all relevant data; a merely formal approval does not meet this threshold. As Veale and colleagues emphasize in the HCI literature, regulatory guidance defines this "meaningful" involvement as someone with authority and competence not "routinely" applying the model's output. From the perspective of RPA, this threshold is advantageous in two ways: first, RPA is mostly positioned as a tool that supports a human decision or executes a human decision already taken, and does not itself produce a new "decision"; second, even when a fully automated process is chosen, RPA's rule-based structure technically facilitates the exercise of the rights guaranteed in Article 22(3), "to obtain human intervention, to express one's point of view and to contest the decision," because which rule was executed is already recorded. In Turkish law, the "right to object to the occurrence of a result against the person by analyzing the data exclusively through automated systems" set out in KVKK Art. 11/1-g works on the same logic, and RPA's transparent structure ensures that this right to object can be exercised in practice.
Regulation (EU) 2024/1689, the European Union's comprehensive regulation on artificial intelligence, is the clearest example of carrying the distinction this article defends directly into positive law. Article 3(1) of the Regulation defines an "AI system" as "a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs." Recital 12 of the Regulation clarifies this definition further: the purpose of the AI system concept is to distinguish these systems from "simpler traditional software systems or programming approaches," and the concept does not cover "systems that are based on the rules defined solely by natural persons to automatically execute operations." The European Commission's official guidelines on this definition also emphasize that the capability to "infer" is the indispensable element that sets an AI system apart. For the legal position of RPA, this provision amounts to a direct exclusion from scope: by definition, an RPA robot relies on "rules predefined by natural persons" and does not itself infer how to generate output from input; it already knows the way. RPA therefore falls outside the system at the definition stage, before it could enter any of the risk categories envisaged by even the EU's most comprehensive AI regulation.
Legal defensibility aside, companies largely adopt this technology for concrete operational gains. Field studies by Lacity, Willcocks, and Craig in the Outsourcing Unit research group at the London School of Economics (case analyses examining real implementations at organizations such as Telefónica O2, Xchanging, Royal DSM, and SEB Bank) showed that RPA shortens processing time, lowers error rates, and reduces staff workload in frequently repeated, rule-based, high-volume operations. In the academic literature, the benefits promised by RPA are systematically grouped under process performance, efficiency, scalability, auditability, security, and compliance, and it is stressed that these benefits can be obtained quickly and at low cost compared with classic business process automation projects. Lacity and Willcocks's study published in MIT Sloan Management Review argues that this gain is not limited to cost savings, and that robots also free human employees from tedious, repetitive tasks, allowing them to turn to higher value-added work. A study specific to the banking sector showed that RPA enables more effective allocation of resources by reducing processing times and operational costs, and strengthens compliance and reporting processes by increasing data accuracy and consistency.
The reliability and auditability advantage that the academic literature attributes to RPA is also consistent with the experience of the entrepreneurship and technology investment world. A sectoral view has emerged that "wrapper" startups, which package generative AI models as a thin interface around an API call, lose value quickly as the underlying model itself improves or as competitors gain access to the same model, whereas automation solutions that are deeply integrated into a company's existing processes and run predictably and reliably provide a more lasting competitive advantage. This observation also confirms the article's thesis from a technology investment perspective: the market values the question "how reliably and repeatably does it work" far more than "how smart does it look."
The findings set out so far converge on a single point: the legal suspicion directed at RPA stems not from the technology itself but from the word "automation" being confused with artificial intelligence. At the level of academic definition, RPA runs on deterministic rules previously coded by humans and does not infer; this keeps it outside the crisis of opacity and unaccountability described by Citron and Citron-Pasquale. At the regulatory level, the EU's AI Act places RPA outside the scope of an "AI system" at the definition stage; the "solely automated decision" threshold of GDPR Art. 22 and KVKK Art. 11/1-g also aligns easily with RPA's transparent, auditable structure, which is open to human intervention. At the level of liability law, an RPA error reduces to a traceable rule design problem, which makes it manageable with classic, well-known legal tools. At the operational level, academic field studies and the industry's own experience show that RPA produces concrete, measurable, and lasting value. When all these layers are stacked together, the picture that emerges is this: RPA is a technology that structurally does not carry the problems AI regulation seeks to answer; viewing it through the same legal framework as AI both creates an unnecessary regulatory burden and obscures the real risk (humans designing the process incorrectly).
Türkiye's approach to AI regulation rests not on a settled statute but on several complementary regulatory moves, and none of them has so far targeted rule-based automation of the RPA type. The National Artificial Intelligence Strategy 2024-2025 Action Plan, prepared under the coordination of the Presidency's Digital Transformation Office, focuses mainly on topics such as the development of generative AI technologies, Turkish large language models, high-performance computing infrastructure, and workforce transformation; in other words, strategic interest is shaped around systems that infer and generate. The Artificial Intelligence Bill submitted to the Grand National Assembly in September 2025 moves along the same axis: the bill envisages banning the use of discriminatory datasets based on personal characteristics such as race, gender, and ethnic origin in the data on which AI systems are trained, making the labeling of deepfake content mandatory, and granting BTK emergency intervention powers against AI content that threatens public order; all of these point to systems that infer from data or generate content, and RPA robots, whose rules are written in advance by humans and which generate no content, do not naturally fall within these definitions. The information document titled "Use of Generative AI Tools in the Workplace," published by the Personal Data Protection Authority in March 2026, is likewise specific to the workplace use of third-party, publicly available generative AI tools, and leaves outside its scope in-house automation tools that work with human-defined rules. This picture shows that the definition centered on "systems that infer," seen in the EU's AI Act, is repeated on the Turkish regulatory agenda as well; for Türkiye-based companies adopting RPA, the regulatory risk in the present and foreseeable future therefore remains limited to KVKK's provisions on data processing and cross-border transfer, and does not fall within the scope of new-generation AI regulations.
The thesis defended throughout this article can be reduced to a single sentence: weighing automation on the same legal scale as artificial intelligence is a mistake that stems from misunderstanding the nature of both. By its academic definition, RPA is rule-based and deterministic; it does not learn or infer, it simply executes steps previously written by a human. This structural characteristic renders the problems of opacity, unaccountability, and unpredictability at the heart of AI law largely meaningless for RPA. This is no coincidence: the EU's AI Act excludes RPA from scope at the definition stage, the "solely automated decision" threshold of GDPR Art. 22 and KVKK Art. 11/1-g aligns easily with RPA's transparent structure, and Türkiye's current regulatory agenda is moving along the same axis. In terms of liability law, an RPA error reduces to a traceable design problem and can be managed with classic tools. At the operational level, both academic field studies and the industry's own experience confirm that RPA produces concrete, measurable, and lasting value. The common conclusion of all this is that the right question for companies and regulators to ask when assessing RPA is not "is this automation?" but "does this system determine for itself how to generate output from input, or does it apply a predefined rule?" Defending RPA is not belittling AI; it is recognizing that two different technologies require two different legal treatments.
References
- Aguirre, S., & Rodriguez, A. (2017). Automation of a Business Process Using Robotic Process Automation (RPA): A Case Study. In Applied Computer Sciences in Engineering (WEA 2017). Springer.
- Banking Regulation and Supervision Agency (BDDK). Regulation on Banks' Information Systems and Electronic Banking Services, Official Gazette 15.3.2020/31069.
- Burrell, J. (2016). How the machine ‘thinks’: Understanding opacity in machine learning algorithms. Big Data & Society, 3(1), 1-12.
- Citron, D. K. (2008). Technological Due Process. Washington University Law Review, 85(6), 1249-1313.
- Citron, D. K., & Pasquale, F. A. (2014). The Scored Society: Due Process for Automated Predictions. Washington Law Review, 89(1), 1-33.
- Presidency of the Republic of Türkiye Digital Transformation Office. (2024). National Artificial Intelligence Strategy 2024-2025 Action Plan.
- Denagama Vitharanage, I., Bandara, W., Syed, R., & Toman, D. (2023). The Critical Success Factors for Robotic Process Automation. Computers in Industry, 145, 103646.
- European Commission. (2025). Commission Guidelines on the definition of an artificial intelligence system established by Regulation (EU) 2024/1689 (AI Act).
- Hofmann, P., Samp, C., & Urbach, N. (2020). Robotic process automation. Electronic Markets, 30, 99-106.
- Huang, F., & Vasarhelyi, M. A. (2019). Applying robotic process automation (RPA) in auditing: A framework. International Journal of Accounting Information Systems, 35, 100433.
- Information Commissioner’s Office (ICO). Rights related to automated decision making including profiling. UK GDPR Guidance.
- Ji, Z., Lee, N., Frieske, R., Yu, T., Su, D., Xu, Y., Ishii, E., Bang, Y. J., Madotto, A., & Fung, P. (2023). Survey of Hallucination in Natural Language Generation. ACM Computing Surveys, 55(12), 1-38.
- Kişisel Verileri Koruma Kurumu. (2025). Kişisel Verilerin Yurt Dışına Aktarılması Rehberi.
- Kişisel Verileri Koruma Kurumu. (2026, March 5). İş Yerlerinde Üretken Yapay Zekâ Araçlarının Kullanımı (Bilgilendirme Dokümanı).
- Lacity, M., & Willcocks, L. P. (2016). A New Approach to Automating Services. MIT Sloan Management Review, 58(1).
- Lacity, M., Willcocks, L. P., & Craig, A. (2015). Robotic Process Automation at Telefónica O2. The Outsourcing Unit Working Research Paper Series, 15(2).
- Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation), Article 22.
- Regulation (EU) 2024/1689 of the European Parliament and of the Council (Artificial Intelligence Act), Article 3(1) and Recital 12.
- Türkiye Büyük Millet Meclisi. (2025, September 3). Yapay Zekâ Kanun Teklifi, Esas No. 2/2234.
- van der Aalst, W. M. P., Bichler, M., & Heinzl, A. (2018). Robotic Process Automation. Business & Information Systems Engineering, 60(4), 269-272.
- Veale, M., Binns, R., & Van Kleek, M. (2018). Some HCI Priorities for GDPR-Compliant Machine Learning. arXiv:1803.06174.
- Banking Law No. 5411, Art. 73.
- Personal Data Protection Law No. 6698 (KVKK), Art. 9, Art. 11/1-g.