I think it's a combination of a fundamental distrust of the model makers and a history of them training on user data with and without consent.
The main players all allow some form of zero data retention but I'm sure the more cautious CISO/CIOs flat out don't trust it.