AI Can Help – But It Cannot Be Held Legally Liable
AI is being used more and more. Some people may be tempted to use AI increasingly carelessly and stop paying attention to the sources. In the worst case, errors can go unnoticed and cause financial damage. Keep in mind: A freelancer is liable to you, and if an appropriate problem arises, you can seek compensation from them. From AI, after financial damage has occurred, you can at most ask for a correction via a prompt. That is why it is always worth taking a sober look at the code and the approaches being used.
A Deliberate Approach
A human analyzes contextually and specifically based on the circumstances at hand and can actively think through situations and explain connections. AI analyzes what it knows from its algorithm and your prompt. Keep in mind: A human does not have a token limit and can follow a thread over a longer period while taking broader connections into account.
The Human Brain Instead of an AI Algorithm
A human is not dependent on an algorithm but thinks independently. As a result, the likelihood of long-lasting, unnoticed errors is generally lower. We correct, analyze, and identify connections without someone having to explicitly ask us to do so – even when something does not exactly match the given requirements. AI, on the other hand, often only sees what is explicitly provided. Whether an AI-generated solution complies with the guidelines or conflicts with other requirements usually has to be explicitly pointed out to it. A human, by contrast, can think outside the immediate context.
Cost Factor and Dependency
Working with AI instead of a freelancer/employee may save (employee-)costs, social security contributions, and other insurance expenses, but at the same time, responsibility is shifted to a tool over which you have no control. Pricing changes and token limits are outside your control. You can also come to a standstill when you reach your token limit.
Experience Matters
An experienced freelancer brings years of practical experience and also keeps obligations in mind that go beyond the code itself – without having to rely on potentially outdated AI-generated information.
Debugging in Complex Situations
A human forms an overall impression that enables them to investigate the real environment in a targeted way, rather than repeatedly suggesting plausible-sounding code changes and, in the worst case, missing the underlying concept entirely. AI is not able to automatically adapt to your needs.
The Limits of Vibe Coding
As a beginner, someone who relies exclusively on “vibe coding” or learns everything solely from AI can hardly assess reliably whether their approach is actually optimal – they often lack the ability to read documentation and independently develop pseudocode. And eventually, token limits are reached: At that point, the AI not only loses its context, but in the worst case, the chat may be unavailable for a while because the subscription is not sufficient. A developer, by contrast, generally follows a clear and consistent approach.
Risks of Unsupervised AI Use
Anyone who relies 100% on AI primarily faces two risks: data loss in the event of a leak – and the possibility that an AI may independently exploit security vulnerabilities.
AI is not human and cannot consciously take potential harm into account. That is why it is important to provide AI only with the details that are actually necessary and to have projects or code additionally reviewed from a security perspective – before damage occurs that could ultimately affect you as well.
How Can You Protect Yourself Against Data Leaks?
* Keys should never be shared in the first place. Keep demo and production access separate and actively maintain them. If you suspect a leak, rotate all keys first – this also applies if a .env file may have been affected.
* Only share the necessary code snippets instead of providing entire repositories or files without filtering.
* Keep an eye on the AI's profile and “memories” and delete them regularly so that sensitive context does not accumulate over time.
* Make sure that data is not used for training purposes – as an EU member, you can exercise your GDPR rights here, for example through the provider's privacy settings, to actively object to the use of your content for training.
* Code should be reviewed by a PR (Pull Request) at the latest. Although this costs some time and effort, an actual leak with potentially significant data protection consequences can be considerably more expensive.
* Pseudonymize messages sent to AI whenever possible and, in particular, do not provide customer data – this is generally covered by confidentiality agreements.
Conclusion
AI is a powerful tool, but it is no substitute for the human touch, experience, and a vigilant approach to security. By combining both – efficient use of AI and human oversight – you can get the best of both worlds without exposing yourself to unnecessary risks.



