Seems like we're creating history here
It's a absolutely fantastic trade-off though: the reduction in security comes with privacy and convenience improvements. Even online, its useful for allowing instant transactions.
I'll make the idea even stronger: Once you support in-field loading, it should be possible to "refresh" the coins on the card by spending them and doing a new in-field load. If you successfully do that the coins you have refreshed are protected from double-spending by earlier holders.
Periodic refreshing would prevent a situation where someone runs a "spy card" that remembers a lot of private keys and does a lot of transactions and then suddenly one day captures up all the non-redeemed coins on the keys they've seen.