The transaction history, and thus the ballance of an address is held in the blockchain, in the ether.
To spend the coins, you must have at hand:
* the current blockchain
* the private key
* a connection to the network.
What is considered risky is spending only a fraction of the paper wallet, for the following reasons:
- you just used the private key for creating a transaction, so the chances of it being compromised increases
- the client you used might have sent the change to another address while you're thinking the remaining coins are still in the paper wallet
But if it's done well, yes, it's possible to spend a fraction of a paper wallet.
If I wanted to take it further, the "secure" machine could print that wallet onto paper or could robotically insert flash drives into a USB port (in such a way that removed keys were dropped into a bin the robot couldn't reach into.
This is only one of many ways I can think of that would allow the automatic creation of cold wallets ... the only way to attack such a system is to gain physical access.
TL;dr version: anything that is connected to the outside world, no matter how small, is an attack target.