I've seen this issue in Firefox Nightly when trying to perform the HSBC UK credit card verification, so it makes sense not to roll it out to the wider public yet.
Your only option is to use a _different_ browser which trusts the old certificate.
You are right, but there's always a chance that the various documented HSTS bypasses might filter down to normal people. People might be willing to find and use them if they /really/ need access to the site.
e.g. Typing "thisisunsafe" in Chrome on the error screen, or flushing the HSTS state in the browser.