That sounds like a policy written by someone who doesn't understand how LLM's work...
Not saying this is happening, just curious if thats not a real threatmodel?
It’d be much easier to hide sketchy code in an agent harness, but “vendor adds spyware to their software” isn’t a novel issue.
I think the only sort of new issue is people “allow all”ing their agents tool calls, but that’s more or less the same issue as curl | bash
Pi/OpenCode seem pretty straight foward and widely used enough for this to be viable
OMP Does it's own vendoring of tools, so I assume it'd be a pain in the ass to audit, but that means you're even safe from base OS shenanigans
I imagine it would be very non trivial to do it in a way that that was reliable and obfuscated enough to prevent detection for any amount of time?
Hopefully this will change soon. But AI and China/US skepticism is very high. Even if the person you talk to isn't skeptic, his boss may be. And even if his boss isn't, his CFO or Legal department may use it as a political lever and therefore if you can say 'everything in europe' you dodge the tension entirely.
Yeah it's dumb.
Why use a Chinese product when a domestic or EU one is better and safer?