Earlier quoted context omitted.
It would probably be easy for any on-device model. But it would be illegal
What part of it is illegal? What if they reverse engineered the model, and then understood the fundamentals of how it worked, and implemented and trained the same architecture with different data? Or trained their own architecture with data sampled from the Google model? is it "stealing" data, the architecture, the parameters, or the act of reverse engineering and productizing the knowledge?
Models are also usually black boxes, and the techniques used are published.