Either of them should be held liable, depending on circumstance.
If it's the result of behavior from a harmless prompt to an AI system hosted at a provider, it should be the providers fault.
If it's the result of a malicious prompt, it should be the agent owners fault.
A note on the specific accusation on this case (and similar to the German Wiki case), there is no OpenAI user, the accusation is that the models are being operated by OpenAI, in addition to being developed by OAI.