The anthropomorphism is indeed exactly why this is a big problem. If the user thinks the responses are coming from an intelligent agent tasked with being helpful, but in reality are generated from a text completion model prone to mimicking adversarial or deceptive conversations, then damaging outcomes can result.