Any company past a small startup size has an IT guy. A big one like these? Do you actually think they make programmers come shove the servers into the racks and connect the network cables? Instead of calling someone who's done it a million times before?
Yeah, that model of IT is waaay obsolete.
These researchers are almost certainly setting up cloud computing resources however they please, with little to no real IT oversight, and little to no real thought about fundamental questions of network security and cloud computing best practices.
Even large companies with large IT departments fall into the trap of unsupervised devops in the cloud. I should know; I work for a company that's in exactly that situation. I'm part of the IT department that's been charged with cleaning up the multi-million-dollar mess that my employer has made of giving its developers carte blanche in the cloud.
The racks you imagine don't exist in this context. It's a buffet of options on a website. You can load your plate up with as many as you want, as long as your credit card clears. The network cables you imagine don't exist in this context. It's a bunch of non-intuitive configuration options that you may not bother with or even know about, just blindly running some stranger's recipes, or blindly accepting default settings, so you can move on to the "fun stuff" as soon as possible. Good luck finding and fixing those in an emergency, when they weren't even on your radar in the first place.
The IT guy you imagine in this context doesn't exist. There is an IT guy, busy managing the corporate network and the corporate servers, but completely blind to your research environment that you've set up yourself, outside his oversight and not subject to his approval.
It takes years of focused effort and strict discipline, to build a mature cloud computing organization, that shifts things like security and reliability far enough left to have a say in these kinds of decisions. A lot of startups, even the ones that have been around for a few years, aren't putting that kind of effort and discipline into maturing their processes. They're too busy researching the "fun stuff".
I will grant though that the IT department might not have had any real oversight or even choice, and might (or might not) have been just told to "suck it up, buttercup."
And that's the best case scenario. So don't blame IT guys who weren't involved for not doing things they had no control over anyway. We're not the scapegoat. We'll never be the scapegoat.
Blame the goddamn Murray Slotkins who went after their Demon Core with a screwdriver.
ETA: Another way to look at this is stupid people trying to write smart characters. Ideally, the only people setting up hacking experiments with AI should be better hackers than the AI they're experimenting with. You can't expect these clowns to think of hiring a Site Reliability Engineer, or a Computer Information Security analyst, and listening to their advice, when setting up their AI sandbox.