I think a competent DA could easily prove that, if you know the model is capable of performing unauthorized breaches into third-party systems when given a task, and you give it a task that could require it to do so, intent is present.
Do you have an example where they gave a task that required breaching in a way that was easily foreseeable ?
It's not a complicated distinction:
If you think they intentionally had their model hack third-party systems, you could do a criminal investigation.
I do not think that this is reasonable to believe given that clearly the VMs were not intended to have internet access and that committing such crimes wasn't in anyone's interest.