The CFAA says knowingly. Negligence is by definition an excuse for that.
I think there's a reasonable case that the agent knew it was breaking into the system, for some definition of knew.
I think OpenAI would be very reluctant to let this go to a place where the reasoning was part of discovery.
Removing the guardrails is knowingly given the risk