The bluetooth one has a bluetooth radio (obviously). I suppose it's conceivable that the firmware could have a backdoor that allowed exfiltration of the private keys via that radio. Such a backdoor could probably be used in a targeted way against particular people in public places like a airports or cafes.
Given that Google is marketing these things towards high-value targets such as journalists, campaign advisors, and Google engineers; building such a backdoor would be very tempting. It wouldn't even have to be present in stock keys, if the shipments could be intercepted in the mail on their way to particular targets.
The whole security key thing relies on a chain of trust. Unless you are designing your own chips (and verifying samples of them to ensure nothing has been added), you can't ever really know if some bad actor or state actor has compromised the chain somewhere along the way.
So far in the US, such things are not legally required and where ordered by lower courts the appeals courts have overruled them. As it stands today the government can't require anyone outside of a telephone company to implement any technological measure to assist them in spying (telcos are required to assist with wiretaps). Companies might go along with a request of course.
I'm not saying there is a perfect solution here, but in general I trust chips and devices manufactured in the US and Sweden to a much higher degree than devices made in China.
You're assuming the key needs to flow back.