Negligence when you should have known better, and recklessness when you did know better but still did things that led to the crime occurring.
Given how long the leadership of these companies have been talking about alignment and safety and AI risk, it's hard to argue they, and the people working on the models more directly, didn't know what happened (Hugging Face, RubyGems, etc) was possible.
If more expensive and consequential incidents happen, it seems like the legal machinery to prosecute it already exists.