Not remotely true. Mens rea is a necessary precondition to establish criminal culpability for tons of crimes. Well before sentencing is ever considered. The far opposite, ‘strict liability’, where you’re guilty of a crime purely due to some action or inaction (the actus reus) is exceedingly rare in the US justice system.
Baloney, lots of people go to jail for DUIs, and that's the right analogy here.
People don't drink and drive with the intention to kill people. They drink because it's fun and then get behind the wheel because it's easy and convenient, even though they know the dangers they convince themselves nothing that bad will happen.
AI companies are creating these dangerous, powerful models (that they keep telling us are dangerous and powerful), then they take off all the safety guards to run them in woefully inadequate "sandboxes". Pure negligence.
It's certainly analogous to the behavior exhibited by these AI companies in deliberately performing dangerous actions and then letting other innocent people deal with the consequences.
Virtually all criminal law accounts for the perpetrator's state of mind. Drunk driving is a specific, rare carveout. The reason for this should be obvious: it is nearly impossible to prove a drunk person's state of mind beyond a reasonable doubt, so we passed laws so you can't say "Your Honor, I was too drunk to be responsible for my drunk driving".
So, no, this is not at all analogous to a totally routine question of whether someone was negligent in how they deployed some software.
There is a lot of good analysis of the Appeals process on this specific point - the CFAA as written required unauthorized access:
Section 1030(a)(5)(A), covers anyone who
(5) intentionally accesses a Federal interest computer without authorization, and by means of one or more instances of such conduct alters, damages, or destroys information in any such Federal interest computer, or prevents authorized use of any such computer or information, and thereby
(A) causes loss to one or more others of a value aggregating $1,000 or more during any one year period; ... [emphasis added].
The District Court concluded that the intent requirement applied only to the accessing and not to the resulting damage. Judge Munson found recourse to legislative history unnecessary because he considered the statute clear and unambiguous. However, the Court observed that the legislative history supported its reading of section 1030(a)(5)(A).
I'm not sure how you could categorize the Morris Worm as lacking mens rea based on that statute..
You think that Morris accidentally wrote the malware or that he accidentally released it (in a way specifically intended to obfuscate his connection to it)? lol