They've added the following to the Q&A on the KrackAttack website which removes any doubt for those who were still unsure:
although an unpatched client can still connect to a patched AP, and vice versa, both the client and AP must be patched to defend against all attacks
In the modern world of BYOD this isn't going to be fun.