So every country or block needs to run their own models to avoid opening a security hole for other countries.
This should be done regardless of which model was used - American or otherwise.
A hosted model is different because you could prompt inject specific customers, but I assume from this question you mean a malicious open source model being hosted by an honest provider.