I am very pro open source models - I use them every single day.. But we obviously don't want everyone to have capabilities like and beyond what caused the huggingface incident in every domain, so it's not like it all comes from bottom line cynicism.
You can say you don't want the bad guys to get the capability until and after the reality hits you. But this arrogant hope stands in the way of developing an effective response. The handlers of closed models would like you to be dependent on them for protection, this much is clear.