Final answer... ignore my second response. The first is what we'll stick with. The nonce field will be on the front end regardless of whether the user is logged in or not, but it will only be checked if they are logged in.
We may completely remove it after more research, but we'll need to determine which would be best.