The only difference I see on the facts vs what I read so far is that OpenAI knew of the hack and decided not to intervene. I haven't read the report but I find it hard to believe that OpenAI deliberately let its agents hack a third party company during a training run. It would certainly attract a criminal liability, which would be surprising to admit in writing.