There is a phrase that is attributed to several thinkers and that circulates quite comfortably in the tech world: “we build the plane while we fly.” In the case of artificial intelligence, the metaphor is good but incomplete. We are not just building the plane in mid-flight: we are also not entirely clear who the pilot is, who is responsible if something goes wrong, and in some countries, not even who issued the certificate of airworthiness. That is not a cause for panic. It is exactly the normal state of all disruptive technology in its mass adoption phase. But it is an argument to pay attention.
In 2026, AI stops being a promise and becomes an infrastructure. It is in call centers, in contracting systems, in customer service platforms, in credit approval flows and in the assistants who write corporate emails. And like any infrastructure that is installed quickly, it comes with potholes that time (and regulation) will have to fill.
The problem of the legal vacuum: who signs? The regulatory vacuum around AI is not new, but in 2026 it will begin to have concrete consequences. In the United States, only 20 states have comprehensive data privacy laws, and federal regulation specific to AI remains fragmented. California moved forward in 2025 with 127 pages of new rules that include automated decision-making technology, but the federal Department of Justice has already formed a task force to block state regulations that it considers an obstacle to the country’s leadership in AI. In the European Union, the AI Act came into force, but its practical implementation, especially in “high-risk” systems, still has more questions than answers.
The core of the problem is old: legal frameworks were designed with human actors in mind. A company can be sued. A director can go to prison. A professional can lose his registration. But when the decision is made by a language model that received instructions from an external contractor, which in turn used data from a company in another country, in a system deployed by a third organization, the chain of responsibility becomes genuinely blurred. It is not malice: it is that the current legal categories do not contemplate this scenario.
Sturzenegger’s announcement and the question no one is asking. In this context comes Minister Federico Sturzenegger’s proposal to reform the Companies Law to create a new figure: “artificial intelligence companies.” Companies without partners, without directors, without any human inside. Only code that decides, operates and generates income. The announcement was made at ExpoEFI and the reasoning has a logic that is worth listening to: if in ten years AI agents are going to produce 90% of the world’s GDP, why not create the legal framework for these agents to pay taxes in Argentina? The model cited is Ireland, which captured Apple’s GDP by incorporating the company that owns the iPhone software.
The ambition is legitimate. The order in which it is built is what deserves discussion. Because the question that public debate is still not seriously asking is the same one that runs through the global legal vacuum: who is responsible when something goes wrong? An AI agent has no intention in any technical-legal sense. He cannot be an agent because he cannot be the owner of legal relations. When that AI company executes an erroneous transfer, activates a termination clause that no one decided to activate, or is used to structure a money laundering operation, the question has no clear answer under current law, much less without knowing the regulatory plan.
Sturzenegger is right to look far away. But the jurisdictions that will win this race are those that build the most solid liability frameworks, not those that offer the least regulatory friction. A corporate registry without an accountability framework is an opportunity for capital, not necessarily for the country that issues it.
Hacking and phishing: the AI on the other side of the counter. As companies debate how to use AI to be more efficient, malicious actors have already solved that question and are several steps ahead. The numbers from 2026 are difficult to ignore: 82.6% of phishing emails detected today are generated or assisted by AI, according to data consolidated by the FBI and various cybersecurity firms. That’s a 53% jump from the previous year. And the FBI recorded more than one million cybercrime reports in 2025 for the first time in its history, with phishing and spoofing leading the ranking.
What changed is not just the volume: it is the quality. Language models generate perfectly written communications, personalized by recipient, with references to the real context of the target company and in the corresponding language and tone. The FBI explicitly warned that malicious actors are using AI to orchestrate highly targeted phishing campaigns that result in devastating financial losses. It is not alarmism: it is the current state of the problem.
The situation became even more complex with the appearance on dark markets of tools such as WormGPT and FraudGPT: versions of language models specifically trained to write malware, scam emails and exploit code, without the ethical restrictions of commercial models. Put another way: the barrier to entry for executing sophisticated attacks dropped dramatically. What once required a team of 50 people with specialized technical knowledge can today be replicated by a single person with access to the right tools.
The reputational challenge of the corporate chatbot. There is one risk that companies that have adopted customer-facing conversational agents are still underestimating: jailbreaking as a vector of reputational damage.
Jailbreaking in AI is not the same as hacking a system in the traditional sense. Does not require advanced technical knowledge. It is basically the manipulation of the conversation context so that the model does or says things it should not. And the numbers here are uncomfortable: according to data published by NeuralTrust researchers and verified against multiple state-of-the-art models, multi-round attacks—where the attacker gradually builds context until the model lowers its defenses—achieve success rates of 92.78% in corporate environments. Jailbreak attacks in general have an average success rate of 20% according to IBM, and data from more than 60% of scenarios expose sensitive company information.
What does this mean in practice? That a company’s customer service chatbot can be manipulated to reveal internal instructions, offer unauthorized discounts, generate inappropriate content on behalf of the brand, or simply contradict the company’s official position on any issue. A video of the exchange goes up on social media and the reputational damage occurs before the communications team wakes up.
This is not an argument against conversational agents: they are a genuinely valuable tool. It is an argument for companies that deploy them to incorporate into their security architecture something that traditional firewalls do not contemplate: visibility at the level of intent and not just keywords. Detection tools based on banned word lists are, to put it bluntly, playing in a different league.
What to do while the road is paved? It is worth clarifying, because it would be unfair not to, that AI is not only the new threat vector: it is also the most effective defense available. Google blocks approximately 100 million phishing emails per day using language models. Microsoft checks around 5 billion emails a day with AI systems. Gartner projects that companies that combine generative AI with structured security culture programs will experience 40% fewer incidents caused by human error by the end of 2026. Defense-side AI is no longer optional: it is the only mechanism capable of operating at the speed and scale that today’s attacks require.
So what do we do? There are no perfect answers yet. It would be dishonest to offer them. But there are some attitudes that distinguish organizations that are navigating this moment well from those that are going to have problems.
The first is to stop treating the security of AI systems as an extension of traditional cybersecurity. They are related problems, but not identical. An AI system is not hacked in the same way as a server. It requires specific network-teaming, adversary testing, real-time output monitoring and, this is non-negotiable, a human in the loop for high-impact decisions.
The second is to actively participate in the construction of the regulatory framework, instead of waiting for it. Legal loopholes do not resolve themselves: they are resolved when the industries that know the problem best contribute to the debate with judgment and responsibility. Sturzenegger’s proposal, for example, is an opportunity for the Argentine technology sector to contribute not only enthusiasm but also the questions that the project still does not answer.
The third is to invest in training. Most attacks still depend on the human factor: a person clicking, sharing a credential, believing the CFO’s audio is real. The difference between the collaborator who falls and the one who doesn’t, today, is education. Not necessarily technical: conceptual. Knowing that phishing no longer sounds like spam, but rather a perfectly worded email from the company’s accountant.
We are, effectively, paving as we walk. That is not a defect of this moment: it is the nature of any significant technological transformation. The difference between those who come out well and those who don’t usually comes down to something simple: the former are aware that they are in that process. The seconds believe they have already arrived.
* Graduated in Marketing and Master in Artificial Intelligence. He has more than 15 years of experience in the field of technology, digital marketing, product marketing, survey and sale of computer solutions, software and middleware.
by Eduardo Laens

