The real risk is non auditability of open weight models (chinese or not). Open weight llms are not open source in the traditional sense - the "open" model is technically a bunch of matrices and numbers. Any hidden attack vectors even in open models is non discoverable, even if such a model operates in your own air gapped network. This applies to all models, open or closed. The extent of risk is measured by the history/behavior/laws of the place of origin.
This is a known problem and research is being done to solve it. But theres no solution yet. Thats the real risk (from a sovereign perspective) of open models. Its well documented in technical ai circles.