Would they? The XZ utils backdoor was only discovered by what can only be described as an insanely attentive developer who happened to be testing something unrelated and who happened to notice a small increase in the startup time of the library, and was curious enough to go and figure out why.
Open does not mean “can’t be backdoored”.
Can you explain me why Linux waited till the very last moment of the Executive Order 14071’s grace period (the order is from April 2022!) to apply it? Obviously he trusted those people, or the verification system of the open system! Imagine you don’t like a political party for bad… fair enough, so you ban their representatives from voting table… don’t you think, that incentivizes the other party committing fraud? In these open system things, the more eyes the better, I don’t care if commies, libertarians, ultra-right or whatever, the diversity is what keep it in check…
Slow walking compliance is normal. It keeps assets liquid and processes & people in place as long as possible before making changes. It also prevents the cost of changing back and forth if a new rule is struck down before its final date.
What will happen often is that a compliant procedure will be developed as soon as possible, but no changes will be made until absolutely necessary. That gives the organization maximum time to figure out other routes of compliance, fight the rule and continue at pace before they change.