They’re talking about open-weight models you host yourself. Which are fundamentally incapable of spying on you unless you give them network access. We also haven’t seen any evidence of open-weight models exfiltrating data over side channels (DNS/steganography/etc) yet, so at this time internet access still seems safe enough to grant without worrying about spying.
I can imagine scenario. Let's say you tell open-weight model to generate kitten video. It uses piezoelectric effect of some ceramic capacitor on gpu as microphone and adds recorded audio to the generated video in non audible range. You post kitten video on social media where ai company collects it and extract what you were saying while the video was being generated.