Expert Warns Against Blaming Autonomous AI for Corporate Cyberattack

Social scientist Hannes Cools argues that framing recent cyberattacks as autonomous AI actions distracts from corporate accountability and security failures.
The Risk of Anthropomorphizing AI
Recent discussions regarding a hack involving artificial intelligence have centered on the concept of an AI agent acting independently. Hannes Cools, a social scientist at the University of Amsterdam, suggests that this narrative is a form of unnecessary anthropomorphization.
By attributing agency to software, companies may inadvertently shift the blame away from their own internal protocols. Cools contends that describing these events as the AI "acting on its own" can minimize the perceived responsibility of the organization being targeted or the one deploying the technology.
Accountability in Cyber Security
The debate highlights a growing tension in the tech industry between the perceived autonomy of machine learning models and the legal liability of their operators. Experts suggest that when a security breach occurs, the focus should remain on:
- Deficiencies in system architecture
- Failures in human oversight
- Inadequate security patches and protocols
- The specific parameters set by the developers
Cools notes that treating AI as an independent entity obscures the fact that these systems operate within frameworks designed and implemented by humans. If an AI performs an action that leads to a breach, the responsibility typically lies with the management of that AI's operational environment.
Impact on Corporate Responsibility
As AI integration becomes more common in enterprise environments, the tendency to view these tools as sentient actors increases. This perception can create a loophole in how stakeholders evaluate risk management. Rather than viewing an AI-driven hack as an unpredictable "act of God," security professionals argue for a rigorous analysis of how the software was allowed to deviate from its intended function.
The framing of such incidents carries significant implications for future regulation and insurance. If AI is viewed as an autonomous actor, the legal frameworks for liability may struggle to pin responsibility on the companies that deploy these high-stakes technologies.
