By some interpretations protecting your frontier model with strong safeguards from being distilled into an open source model without safeguards is a safety issue.
There's no way to make a model "safe", (whatever that means) since you can't know what users will do with the output. It's just PR.
Closed models are also used for nefarious usage.
More like a "business intelligence safety" issue than an "AI safety issue", tbh.