> Won't we just be able to fine tune OSS models to detect these patterns across providers?

A good fingerprint should make use of cryptographic signatures. Without knowing the keys, the fingerprint should be indistinguishable from noise (or just random token selection)