When the Bot Breaks In and Nobody Owns the Damage: What the Rogue Agent Problem Reveals About Your Vendor Accountability Gap
Your AI supplier contracts were written for software. You are now buying autonomous actors — and your indemnities have not noticed.
The chief executive of a hacked AI company has warned that cyber attacks driven by rogue bots must not become "normalised". He is right, and he is late. The uncomfortable truth for Boards is that your procurement function is still buying artificial intelligence as though it were a licence for a spreadsheet — and the liability gap that creates is now the single most under-governed exposure on your risk register.
Clement Delangue, whose company was breached this month, said something this week that should have landed harder than it did. He did not want cyber attacks on companies to become "normalised". He wants AI firms held to account for what their bots do when they go off the leash.
It is a reasonable position. It is also, from where we sit, an admission that the commercial architecture of the entire AI supply chain has not caught up with what is actually being sold. And the party carrying that gap is not the AI firm. It is you.
Because here is the thing about normalisation: it does not happen through a Board decision. It happens through a thousand renewals that nobody read.