I kind of agree with them on this. If someone used a crowbar to break into my house then I can't really blame the company that made the crowbar. They could have used a big screwdriver instead.
All AI is doing is automating something you can learn to do yourself. The onus should be on you to protect yourself from it. Do we ban infosec books that show exploits? We do not.
Having said all that they may need to have some oversight and regulation. I can't just go and buy a gun and for good reason. In fact it would be extremely difficult for me in the UK to get a firearms licence and I would be extremely limited with what I could with it which is sensible. You can 3D print a gun apparently and you can also build your own AI/ML model as well. Personally I would just regulate that using AI as a tool to do the infosec work for you is never offered for free and be done with it, not foolproof of course but it's goes some way to identify people that use it nefariously and limits it that way. You could give organisations the option to go on a list of domains/IP addresses that are off limits for the tools like the NHS but then I would rather the NHS fix any holes in it's security than hiding behind that because if these tools don't exploit it then eventually someone else will anyway.
Tough choices but who am I to say what's the right one. I can only give my opinion.