This argument can be made for most/all software vulnerabilities.
I the DAO case I am not aware of any regulations or laws that the "attacker" has broken.
No, it turns out that that's completely true, and that's the problem.
It is the same with Ethereum. If the DAO 'contract' does not include the terms, the 'lawyer' who wrote it just didn't do a very good job and it is open to taking advantage.