So, in the case of an unauthorized, unimplemented request you can only pick one response code: A 5xy unimplemented tells the client that the server is in a state where repeated requests will never be satisfied unless the server code changes. A 4wz type error tells the client that they may be able to run the request later, without changes to server code, and the request could succeed (depending on the changes made). Now, in this case, if the client gains all the permissions (so, authorized to execute any action supported by the server) the request still won't be implemented. So, the bigger issue is the (non-)implementation of the action that the client is requesting the server to perform, not the client's authorization level.
Also, a friendly reminder to everyone: authentication is not authorization.
Oh, and I haven't checked the RFCs, but this rationale makes sense to me...
Sure, but note that 401 Unauthorized is explicitly a failure of authentication. The error for an unauthorized request is 403 Forbidden.
Usually a client retrying a 500 error is the expected behavior, since over time that 500 error will tend to become some other status once the problem is addressed.
FOOBAR /my/path HTTP 1.1