I personally would like to see AI be able to review entire code bases and see the bigger picture because state sponsored lawful intercepts are rarely one piece of code but rather require multiple pieces of code and sometimes hardware to work in conjunction to form the back door.
The ability of the Russian government to lean on incredibly talented developers is extremely large.
The trust issues with software developed by Russians isn't that the engineers are Russian. It's that the engineers and their families are currently in Russia.
If you don't know, this is not even the first file compression related exploit. "Zip Slip"(0) for example, is just one year old, and there are many of them out there.
[Zip Slip]: https://nvd.nist.gov/vuln/detail/CVE-2022-21675
The original author Eugene Roshal (iirc) isn't.