Adversarial examples probably exist for humans too, they are just less easy to find since we can't easily backprop through human judgements like we can a bunch of array multiplications and dot products.
Doesn't mean that they are not "actually" learning any more than we are.