Skip to content
Menu
vAndu
  • Home
  • Home Lab
  • AI/ML & vGPU
  • Snapshot
  • The Lab Floor
vAndu

Who Is the Bigger Criminal: Cybercriminals or Companies and People Breaking Laws and Rules With AI?

Posted on October 5, 2026October 5, 2026

Not knowing the law, IT systems, or cybersecurity does not free you from following the rules/laws or taking responsibility. The same applies to AI.

AI is not an excuse.

If you use AI to make a decision, build a system, process data, configure security, write code, or perform any other work, you are responsible for the result. Not ChatGPT, Claude, Copilot, or any other AI service.

If AI gives you a wrong answer and you use it without checking, you made that decision. If you upload sensitive information to a cloud AI service without knowing whether you are allowed to send that data there, you sent it. AI did not force you to do it.

The same basic principle already applies everywhere in IT and cybersecurity. If you do not know how to configure a system securely, that does not make an insecure configuration acceptable. If you do not know what data you are allowed to process, where it can be stored, or which third parties can receive it, that does not give you permission to do whatever is convenient.

AI can help you work faster. It can analyze information, generate documentation, help troubleshoot problems, write code, and suggest solutions. None of that removes the requirement to understand and verify what you are doing. If you do not have the required knowledge, learn it or involve someone who does.

The real problem is not AI. The problem is people using systems they do not understand and blindly trusting the output. Even worse are people and companies that know the rules and deliberately ignore them because following them is inconvenient.

Companies already hold enormous amounts of information that belongs to customers, employees, partners, and other organizations. Customer records, employee information, emails, contracts, financial information, source code, internal documents, credentials, business secrets, and other confidential information.

That data did not suddenly become free to use because AI became popular.

Much of it was collected for specific purposes and under specific conditions. There may be contracts, confidentiality agreements, privacy requirements, internal security policies, regulatory requirements, or restrictions on where the information can be processed and who can access it.

Those requirements still exist.

If you were not allowed to send customer data to another company before AI, you are not suddenly allowed to send it to an AI provider. If information was required to remain within a specific country or region, putting AI in the middle does not remove that requirement. If a customer allowed their information to be processed for one purpose, that does not automatically give you permission to use it for another purpose.

Yet this is exactly what is happening.

Companies are connecting databases, document repositories, email systems, customer platforms, development environments, and internal systems to external AI services. Employees copy confidential information into AI tools without checking where the information goes, how it is processed, how long it is retained, who can access it, or whether they have the legal or contractual right to send it there in the first place.

Some people genuinely do not understand the problem. Others understand it perfectly well and do it anyway.

That second group is the bigger problem.

Laws, contracts, confidentiality agreements, security requirements, and internal policies are being ignored because AI is useful and convenient. Calling something AI adoption does not make an existing requirement disappear. Calling it innovation does not give a company permission to ignore its contracts. Calling it digital transformation does not change who owns the data or what you are allowed to do with it.

If you are not allowed to process data in a certain way, then you are not allowed to process it that way. It really is that simple.

We also need to stop pretending that every case is just a small privacy concern. Connecting entire databases, customer records, mailboxes, document repositories, source code, and internal business systems to external services without proper control is data exposure. If you do it at scale, it becomes massive data exposure.

Giving it a nice AI project name does not change what is technically happening.

The same applies to responsibility.

If a company connects an AI system to customer data, somebody approved that connection. If an AI agent receives access to production infrastructure, somebody granted the permissions. If confidential information is uploaded to an external service, somebody allowed it. If AI generated code reaches production, somebody accepted that code and deployed it.

Automation does not remove responsibility.

This becomes especially important with AI agents because they can perform actions instead of only generating text. Giving an AI agent access to production systems, customer information, cloud infrastructure, source code, email, or internal applications is still an access control decision. Somebody decided what the agent could access and what permissions it received.

If those permissions are excessive or the system performs an action it should never have been allowed to perform, blaming the AI is nonsense. The access should not have been granted in the first place.

AI cannot become a place where responsibility disappears. Otherwise it becomes the perfect excuse for companies and individuals to do things they already know they should not be doing. They can automate the process, benefit from it, and then point at AI when something goes wrong.

No.

AI did not decide to connect your customer database to an external service. AI did not sign your customer agreements. AI did not decide which confidential information could leave the company. AI did not decide to ignore your security requirements. AI did not grant itself access to your production environment.

People made those decisions. Companies made those decisions.

AI is a tool. You decide where it is deployed, what information it receives, what systems it can access, what permissions it gets, which recommendations you follow, and which generated output you actually use.

If you make the decision, you are responsible for it. If your company deploys the system, the company is responsible for how it is used. If you give an AI system access to data or infrastructure, you are responsible for understanding and controlling that access.

Using AI does not transfer responsibility to AI.

Home Labber who likes to build things and push it to the limits. vSphere is like Lego for adults.

“The fastest way to learn IT is 80% labbing and 20% studying theory. Just do it and have fun.” – vAndu

“If you wish to achieve worthwhile things in your personal and career life, you must become a worthwhile person in your own self-development” – Brian Tracy

VMware vExpert 2023
VMware vExpert NSX
VMware vExpert Pro
©2026 vAndu | Powered by SuperbThemes!