It's only a proof of concept at the moment and I don't know if it will see mass adoption but it's a step in the right direction to ending reliance on US-based Big Tech.
Regular release distros do security updates, backported if needed. Rolling release means introducing unknown security bugs until they are found and fixed. To me, the whole dilemma between regular and rolling is do I want old bugs or new bugs? But the security bugs get fixed on both.
if you're not paying it doesn't really matter. open source belongs to everyone; it's a disservice to put it in the same bag as, say, a Microsoft or Apple OS.
plus how far removed is enough? are we going to scrutinize what programming languages were used and where they originated as well?
Open source is free for everyone, I think the objection is more about an american company being able to directly influence the decisions, operating under US jurisdiction, etc.