Sorry, but this just isn't true.
Plenty of other countries have negligent hacking coverage
Sorry, but such a thing is essentially nonexistent in cybercrime statutes. I can't say "entirely nonexistent", as I can't rule out that in the legal code of some country, like, say, Chad, that there may be an exception, but it is for all effective purposes basically nonexistent in law.
"Unauthorised access" in the UK sense doesn't require any intention, just that you don't access a system in a standard way with credentials assigned to you.
Completely false. In the UK, the statute governing hacking is the Computer Misuse Act 1990 (CMA). Under the CMA, section 1, a person commits an offense if and only they:
A person is guilty of an offence if—
(a)he causes a computer to perform any function with intent to secure access to any program or data held in any computer [F1, or to enable any such access to be secured];
(b)the access he intends to secure [F2, or to enable to be secured,] is unauthorised; and
(c)he knows at the time when he causes the computer to perform the function that that is the case.
(2)The intent a person has to have to commit an offence under this section need not be directed at—
(a)any particular program or data;
(b)a program or data of any particular kind; or
(c)a program or data held in any particular computer.
Stop trying to make "negligent hacking" into an actual crime. It doesn't exist in criminal law.
Re, Australia:
In Australia OpenAI would have most definitely broken the Criminal Code (1995) Part 10.7 - Computer access with multiple examples of it's antics except... the very first line of every subdivision of the law is: "A person commits an offence if:"
Once again, no. Just as in the US and the UK, Australia has no "negligent hacking" statute. Every relevent offense under Part 10.7, incl. Section 477.1, 477.2, and 478.1, requires a proof of fault element. 478.1 for example requires that the defendant knows the access is unauthorized and acts deliberately.
Under Chapter 2 (General Principles of Criminal Responsibility), if a statute does not expressly designate an offense as strict liability or absolute liability, the default fault elements are intention, knowledge, or recklessness. Negligence - which is defined in the code - is never a standard in Part 10.7 computer offenses. And if you want to upgrade from negligence to recklessness (something unusual in Australian cybercrime law, not found in US or UK cybercrime law), the person being charged has to have had prior knowledge of "a substantial risk that the result will occur" - not that "some arbitrary bad thing might occur in general because these things are dangerous, and our security is lax" (that's negligence, and not chargeable under part 10.7), but of the specific event being charged occurring. Unless you thought that OpenAI specifically thought, "If I run this benchmark, these bots are likely to specifically secretly convert our software repository into a messaging board and coordinate their actions to specifically hack HuggingFace (and our own servers) to steal answer keys", no, they do not meet that standard.
The reason OpenAI would not be charged is not because of some semantic trick around the word "person" (obviously you never charge tools), it's because they lack the mens rea for the crime. Intent. You have to have mens rea - in the US, in the UK, in Australia, and elsewhere.