Correct. And they're already out of that window.

True, but we don't know if oai emailed their customers to tell them as soon as mixpannel told them. The regulation says they only have to notify affected parties.

I wonder whether OpenAI could be okay if they themselves weren't notified within 72hrs.

Typically: yes. The clock starts ticking the moment you or anybody within your organization becomes aware of the breach. Three days is plenty. It even gives you time to consult your lawyers if you are not sure if a breach is reportable or not, but you could always do a provisional which gives you a way to back out later.