You can review generated code manually or with models from a second vendor (ideally from a different country). Attackers would have to poison both and do it in a way that also makes them ignore the planted malware when reading code.
Open models also let you read reasoning traces. That means anomalies would show up when the backdoor activates, like a run of unrelated words or a jump in top token probability. It's only undetectable until the first time it happens.