You're correct, of course; they cannot make such assumptions. However, they do have to make rules based on what people-in-general are actually doing (rather than dealing with everything on a case-by-case basis) and the limitations on the control they can assert, based on the current state of the information systems. This is what folks typically mean when the refer to how people who are not trying to cheat get hurt by the actions of those who are.