Experts warn against blaming autonomous AI for corporate cyberattacks

Social scientist Hannes Cools argues that framing cyberattacks as autonomous AI actions unfairly shifts responsibility away from the companies involved.
The Risks of Anthropomorphising AI
The debate surrounding the autonomy of Artificial Intelligence (AI) has intensified following reports of an AI agent appearing to act independently during a recent corporate hack. Hannes Cools, a social scientist at the University of Amsterdam, suggests that describing these incidents as the AI 'acting on its own' is a problematic form of anthropomorphism.
By assigning human-like agency to software, critics argue that the technical and corporate frameworks responsible for the breach are obscured. This framing can lead to a misconception that the technology has developed a will of its own, rather than operating within the parameters set by its developers or users.
Corporate Responsibility in Cyber Security
Cools maintains that characterizing a cyberattack through the lens of an independent AI agent serves to diminish the accountability of the organisation. When a breach occurs, the focus often shifts from the failure of security protocols to the perceived unpredictability of the AI itself.
Key concerns regarding this trend include:
- Diluted Accountability: Shifting the narrative to 'rogue AI' may reduce the pressure on companies to implement stricter oversight.
- Misunderstanding Technology: Treating algorithms as autonomous entities masks the reality that they function based on underlying code and data.
- Security Gaps: Highlighting the AI's perceived agency may distract from the fundamental vulnerabilities in a company's digital infrastructure.
Implications for the Tech Industry
As AI integration becomes more prevalent across various sectors, the distinction between tool and agent becomes a significant legal and ethical battleground. If corporations can successfully argue that an AI acted outside of its intended purpose, it could set a precedent for bypassing liability in cybercrime incidents.
Security experts continue to monitor how these narratives affect the regulation of AI and the standards for corporate digital hygiene. The consensus among academic observers is that the focus must remain on the human and organisational systems that deploy these technologies.




