The title should strike the word "agents" from the title. If OpenAI hacked someone, who cares if it was an agent or a human actor. They're accountable for what their software does.
At the very least this amounts to culpable negligence. (In the sense that their lack of precautions here has clearly exposed other organizations to risk of harm. I can't speak for the legal sense.)
So if I set up a company and accidentally hack random organizations that's OK? But if I do it as an individual user that's not? If they directed anyone or anything to "hack" and that was the outcome that they could not control within the confines of their sandbox then they are responsible for all damages and computer crimes.
I mean, why is OpenAI allowed to continue running public infrastructure? Maybe someone should sue their upstream providers for aiding and abetting felons with massive Internet interconnects.
There’s several billion difference I can think of between you as an individual, and an organisation courting the Australian government with proposed billions of dollars of investment building data centres.
I agree with you right up until “end of story”. Absolutely they should be held accountable, but stories provide details and there is nothing wrong with including details in the title.
Or could we take your original statement to its logical conclusion and change the title to just “OpenAI commits crime”?