I clearly have been living under a rock, but in the case where it's just text in/out of their API, and a customer uses this on their own to do nefarious things, I don't see why they would be liable?
If they knowingly allowed use of their services for illegal purposes then yes, but in so far that they provide a service that can be used for useful things (including cyber security research) and did a best effort attempt at abuse, I don't see why it should make sense to hold them liable. This is especially the case now that frontier LLMs are almost a commodity that can be used without restrictions from providers outside of your legal jurisdiction.