The idea, within regulated circles, is that it lacks provenance - there’s no vendor to sue. Many open source licenses also carry an explicit disclaimer of merchantability and fitness for purpose. These are taken seriously, and open-source software is viewed akin to car parts found on the side of the road. They could work but it’s better to let someone else verify.
But in the context of privacy it makes no sense though right? Open source and close source models (depending on vendor) both can be configured in a way that protects privacy of the user. The entire quote is wonky despite your point about companies preferring vendor-based system rather than raw dog oss