The AI Legal Minefield: Why You Still Need a Human Behind the Wheel
We are in a gold rush of AI-generated code, but as ImmuniWeb CEO Dr. Ilia Kolochenko makes clear on Techstrong TV, the idea of “perfect AI” is a dangerous illusion. Dr. Kolochenko—who uniquely navigates the intersection of cybersecurity and complex cyber law—warns that because LLMs are trained on vulnerable open-source data, relying solely on AI for penetration testing or legal contracts is the fastest way to end up in court. We’re facing a watershed moment in application security where AI must be used for “intelligent automation,” but if you take the human expert out from behind the wheel, you’re setting yourself up for an unrecoverable crash.
Transcript
Hey, everyone. Welcome back here to Techstrong tv. Let me introduce you to Dr.
Ilya Chenko. Uh, Dr. Chenko is the CEO of Immuno Web.
That's I-M-M-U-N-I, Webb, WEB, Dr. Chenko Ilya. Welcome to Text on tv.
It's great to have you on here. Thank you very much, and thank you for having me here today. Absolutely.
Um, let's start off with little bit Ilia, if you, I'm gonna call you ia, if it's okay. Ilya, let's start off with a little bit about you, right? Your PhD, CEO of immuno web thought leader in sp in the space.
Tell us a little bit about, about your story, your life story, if you don't mind. Certainly, Sarah, probably my, uh, story is not very usual because I'm a cybersecurity professional. I've been in cybersecurity practice for about 20 years.
That's another way to say that. I'm an old man, uh, and I got you beat, so go easy, Uh, right, and, uh, actually, when, um, I was in my, uh, thirties, I, uh, decided, uh, to start studying law and I became a lawyer. Uh, and, uh, basically speaking today, uh, I'm an attorney.
Uh, my practice is mostly focused on complex, uh, cyber law cases or cases that involve, um, cyber crime investigations, and also have a pleasure and privilege to all lead the amazing technical teams at mwe. Uh, in the nutshell what we do, we are a global application security company, headquartered in Gene Switzerland. We also have regional offices in London, Washington, DC and Dubai.
And, uh, we provide, uh, cybersecurity services, uh, to more than 1000 enterprise customers from 50 plus countries. Really? That's interesting.
Um, so I did the opposite. I went to law first, hated it, and then got into technology, and that was about Jesus, 35, maybe years ago, maybe more. And, um, never looked back though.
You know, what you learned in law, it always stays with you, right? It's the way of looking at things, a way of thinking about things, way of approaching problems. Um, but it, you know, cybersecurity has become one of those areas where having a law degree is a good thing, right?
Because the between legal illegal wrong, you know, morally wrong versus legally wrong, is, is often there's a wider gulf than one would think, right? Um, so it, it's an interesting thing. So you didn't found immuno web, or you did, I did You found an muni web to kind of be the vehicle around this, this whole law thing?
Or, or did the law thing come after? I would say probably it happened simultaneously, but at the Muni web, we're certainly not the law firm. So we don't, uh, provide legal services, right?
However, we have a lot of different products where we help our customers to better understand, uh, for example, their regulatory duties relating to cybersecurity, data protection, privacy, incident response. Now, we have a lot of different, uh, products relating to security and safety of artificial intelligence products and technologists. Uh, so basically speaking, we are a pure tech firm, but we try to provide some additional insights to our customers.
We're not competing with lawyers, not at all, but we try to bring in a certain areas that, uh, usually stay in darkness and nobody cares till they have a lawsuit. We try to bring them to our customer, say, listen, probably you, you, you should look at this specific item because it's might trigger an issue and probably talk to your general counsel. So we try to put the cherry on the cake.
Got it. Excellent. You know, you mentioned artificial intelligence, ai, ai, I mean, these last couple weeks have just been historic in what we're seeing at the AI starting to do now, probably application security.
AppSec has been one of the most, uh, impacted domains, uh, from ai, you know, the release of Claude Opus and finding all these vulnerabilities and open source projects, the idea that not only is AI helping you generate the code, but it's actually testing code. It's testing code as good as some of the best, you know, SaaS or, or, or, you know, I don't wanna say das yet, but certainly static tests out there, and a lot of people are, you know, foretelling and, and contemplating and pontificating maybe is a better word, on what the future of application security is in, in an AI world here, right? Where not only does it write the code, but test the code and potentially fixes the code, right?
And, and that's a lot of, it's a lot of responsibility to put in front of what's still a pretty unproven, I think, uh, to technology. I'm wondering from where you sit, where do you see that Dr. Chenko?
So, I believe that, uh, my position, uh, and my view on the future, uh, of artificial intelligence, um, uh, have been consistent since 2019. Uh, this is actually when, uh, 10 web, we received our first, uh, international award for practical use of machine learning and ai. So it was, uh, before the lounge of chat, GPT, and basically speaking, my opinion is still the same.
So AI is an amazing tool for lawyers, for engineers, for penetration testers, for many other people. It is an amazing tool, but that's it. I don't think that, uh, artificial intelligence will ever be able to fully replace human experts.
Uh, I acknowledge that in many organizations we had too many people doing redundant tasks for some good or bad reasons. And currently we also see what we call AI washing when a lot of people are being fired, uh, uh, under the pretext of, uh, AI automation. But in reality, organizations truly never needed this kind of roles internally.
And, uh, with this AI trend, they start rethinking, reviewing, and actually deciding, saying, well, if we can do this task, uh, with a team of two, why actually we had 25 people, seven supervisors, uh, three additional supervisors, and, uh, entire team of technical support. We just don't need it. And, um, talking about practical implications, uh, of, uh, artificial intelligence.
Some people say that AI will replace virtually everybody, alright, but the, but the challenge is that if you don't understand an output of AI tool or solution being at the complicated m and day contract, for example, or source code of a sufficiently complicated, sufficiently sophisticated, uh, suer, if you as a lawyer or non-lawyer or as an engineer or non IT person, you don't understand that you'll probably have a contract that will do exactly the opposite of what you initially contemplated, uh, to do. Same with the software. If you just copy paste, uh, output from chat GPT or Claude, you'll probably create unreliable software to put it mild.
Uh, so we still need, uh, human experts to understand, to utilize AI because we cannot just say, listen, I want to create a Microsoft office. Uh, we will not have it. We may have a beautiful web user interface, uh, or things like that.
But the, the truth is that behind Microsoft Office, we have millions of hours of, uh, qualified, uh, human labor and work, and we cannot just, uh, uh, create it with, by coding or however we call it now, right? Same with the contract, AI may create a one size fits all contract. In my experience, that's the best way to end up in court.
And, uh, as a practicing lawyer, what I see now, uh, steadily growing number of incoming clients saying, listen, we used AI to, you insert something to draft the contract to create an agreement to settle, and now we are being sued or we are willing to sue. So, uh, amusingly, I'm using the use of AI to fully replace lawyers, actually brings more work to lawyers. So I would suggest, uh, using ai, uh, if you're a lawyer, if you are an engineer, if you're a penetration tester, it'll certainly accelerate a lot of things.
It'll certainly intelligently automate many, uh, time consuming, but not very, uh, exciting tasks and process. It'll boost your productivity, but it's not here to replace you. And last thing, probably, you know, from the technical viewpoint, we simply cannot have perfect ai.
By perfect, I mean AI that will always produce secure, uh, privacy friendly and reliable code. Why? Because AI was trained, I mean, all large language models, they were trained on, uh, different types of data, right?
Including vulnerable code, including publicly available code, including open source software. So all these code inevitably contains some vulnerabilities or even back doors. So when we have this kind of data in our training data set, inevitably sooner or later, our AI generated code will contain vulnerability or even a backdoor.
So hypothetically, uh, we could create a perfect LLM model that would write, you know, flawless AI code or, or perfect, uh, from a legal viewpoint contracts. But we don't have training data because in order to generate contracts, LLM models, uh, were trained on all kind of poorly written contracts. Uh, in order to create software, AI was trained on all kind of pri uh, insecurely written code.
So we cannot really take it out. And I believe that AI is great. AI is here to stay, AI is awesome, and I personally use AI for many different, uh, types of tasks, but it's not here to replace any of us all the time.
Big, at least I don't disagree with you. I, I, you know, I tell my people here, AI's not gonna take your job. Someone who uses AI better than you is gonna take your job.
And, um, I, and I think it's particularly true even in law, quite frankly, right? I mean, yes, law was based on, you know, precedents and, and and studied decisis and so forth, but, um, a good lawyer using AI will be a better lawyer. AI trying to be a lawyer is not a very good lawyer, do you?
Do you understand what I'm saying? Absolutely. And, and, and I think the same thing is true for coding.
I think the same thing is true for marketing. I think the same thing is true for, you know, pick, pick a use case with ai. I think having that human, um, expertise and leveraging AI with it is, is at least for the, as you say, foreseeable future, I think is where we're going.
Um, however, it is turning up a lot of vulnerabilities, but it's a funny thing about these vulnerabilities that it's finding, I don't wanna say they're not real because who's, who's to say what a real vulnerability is, right? But it's, it, it doesn't distinguish between something that's exploitable reachable, you know, truly, you know, when we look at the criticality, whether you want to use CVE or something else, it it, I think it has a harder time distinguishing that, and that's still sort of the human purview there. But, you know, I, I don't wanna poo poh it either.
That's a a, a very famous word there, poo poh. Uh, but I don't wanna poo poh it in that it's, it's trivial. It's certainly not trivial, right?
It, it is gonna be a, a big part of it. I guess my question to you then, IA, is as the CEO, what, what's immuno web's view on ai? Is it a tool you're using to help your customers?
Is it something you're still looking at at this point? How do you see it as the CEO of a company? How do you see it playing out for you?
Uh, so basically our strategy, uh, has been consistent since 2019. So we've been always transparently telling our customers that list. And we, uh, use machine learning and artificial intelligence for intelligent automation and acceleration of different tasks and processes.
For example, web application, pausing, crawling, uh, vulnerability verification, many other things. Uh, but AI is no magic. And when we talk about penetration testing, we always say, listen, uh, practically and also from a legal viewpoint, you cannot have fully automated or AI powered, AI enabled penetration testing.
You still need a human expert behind the will. And, uh, we've been always, uh, transparently saying, listen, yes, with our AI technology, you'll probably have, uh, better results compared to fully automated software in terms of quality and quantity of fines. But it's certainly not a replacement of a qualified human penetration tester.
And if you need penetration testing, you still need human brain here. Yeah, agreed. Look, I, I, I, I also think that at least for the short-term future, we're gonna be very much in a sort of uncharted waters kinda way where, and you know, as a lawyer, the law is usually not a leading indicator.
We're more of a trailing indicator. It's gonna take time for the legal system to catch up with what is going on in the marketplace here, right? I mean, cases will have to work their way through the system.
They'll have to be reasoned out and stuff like that. Um, and, and so in this, in between time, if you will, we will see more uncertainty. We probably will see more lawsuits, incidents as, you know, as we kind of map out if you will, you know, where, where we're going.
And so it's gonna be interesting times. Ia, we're almost out of time though, but for people who want to get more information on Immuno web, where do you, where can they go? com and we have have all the information transparently available there.
All righty. Hey, come back on. We always talk about AI and how this is affecting us, so I'd love to have you back on if we could get you in with one of the panels we're doing on this.
'cause they're fascinating conversations. Lovely. Thank you so much.
All right, Dr. IA Chenko, CEO Immuno Web here on Text Drunk tv. We're gonna take a break.
We'll be back in a moment.