Do we hold metasploit accountable when it leads to a hack? Why do we absolve the human actor in the case of AI?