it will not be a correct key, so you will fail during decryption, but it will take a lot of time to check and may not be easy to automate.
If you have any way to check the key validity offline (for example, you subpoena the encrypted data) then it's trivial to check and automate.
Of course not everybody is capable of this, but it's becoming less and less difficult to brute force it, and renting a few hours of GPU time to do it is within the means of small bad actors.