The same should apply to companies who build AI, if it’s used to hack someone or make CSAM.
Only if they host the model, if it’s a self hosted open source model, the entity hosting the model should be held accountable
Also to keep your analogy going, if I tell you how to make a grenade. You then go out to buy supplies, make the grenade and blow up your neighbour, should I be held accountable for sharing knowledgea? Because I’m yet to hear about anyone getting into trouble for distributing the anarchist’s cookbook