It's a standard rock vs hard place situation. But
1) why should nVidia trust the attackers? nVdia might give in, and the files might still be leaked. The attackers should be able to guarantee they won't release the files AND nobody steals the files from them. Hard sell for the attackers, especially with a kid profile .
2) These files are legally toxic. You can't look at them and then publicly act on their content. So anything a third party can do has to happen at arm's length, parallel construction style. This also goes for open source devs, who can't permit nouveau gettibg kicked out of the legal repositories.
3)It is well possible the leak is not as damaging as it looks. People in the industry swap jobs all the time, and take knowledge with them. People accidentally do small leaks all the time, being sloppy with data entrusted to them. It seems reasonable for other big organizations to already have some level of knowledge of the content.
On the other side of the coin is the fully legal loss of control of their software. They also open themselves up to future ransomers ('Danegeld').
I'm not saying high level people at nVidia aren't swearing loudly right now, but a 'let the chips fall as they may' response seems most likely to me, especially combined with a 'we'll very publicly sue the attackers in the ground, as an example for all wannabes' response.