this is 100% an already solved problem.
the idiocy here is the stupid psudo "AGI" marketing around the services.
its really simple. Whoever run the service to do the task requested is responsible. If OpenAI sent an agent out to train their AI then the directors are to be held responsible, if a user of the service used the service and it inadvertently "hacked" someone then both are held responsible.
throwing AI into the mix changes nothing about how the law is applied. its a tool, like a car or a gun. The user of the tool is responsible for how its used, the manufacturer is also responsible for the safety of it.