I don’t get why this is an issue? You can run Claude/OpenAI SOTA models through Amazon bedrock. These weights have to live somewhere to run on Bedrock.
They won't sell/rent/license the weights to an end user at any price because they don't trust your security.
If the weights are physically encoded in hardware and the attacker owns the device, the problem becomes hardware extraction: decapping, probing, imaging, side channels, etc.
You can make that very expensive, but it’s still a very different security model from keeping the weights in a datacenter.