AWS and friends are very good at providing excellent enterprise grade security, but it’s literal child’s play for nation state threat actors to exfil these models.
TEMPEST / EMSEC alone is a wide open door for unclassified datacenters when the Mossad’s out to get you.
I'm sure if proprietary models continue to be a big thing, the methodology of their storage and loading on hardware will be obfuscated quite a bit.
Your hypothetical implies that there is a better alternative, but when those models are "restricted", in practice that means that the only people who have access to them are precisely those who can and will use them for the worst kind of shit. So yes, releasing them to the public is a better deal, ethically speaking, at least then the playing field will be slightly more equal.