I think it would just give CEOs who want to do the right thing (and not pay) legal cover to tell the board of directors "Nope, not paying — the company is going to be shut down for a month. Deal with it, I'm not going to jail."
And it would give CEOs who want to do the wrong thing an avenue to destroy competitors under the table.
You could always hire a bunch of shadowrunners to destroy your competitor's computer system, but I don't know what that has to do with ransomware.
But hey, I guess you could use cryptocurrency to pay the runners.
This has always been true... and always been illegal.
What if it was more than a month? What if it was.. permanent?
Then they totally failed at continuity planning, backups... a whole lot of things.