> End users have no good reason to trust Google with the cached data
I'd imagine that end users who don't trust Google aren't using Google.
> There's no real indication to an end user that that data is coming out of Google's caches rather than from the content provider.
Users who care can see the URL and the domain for which the cert is signed. Most users do not care.
> IMO this is very different than my company or ISP doing some edge caching. It's different because it is much more of an opt-in sort of relationship...
I don't see why I can't substitute "Google" and "Bing" for "Comcast" and "Verizon" in your example.
For that matter, at least in the U.S., it's a lot easier to switch out my search engine than my ISP if Comcast starts to muck with result content. FWIW, Verizon already redirects failures of domain name resolution to itself. I don't like it, and there's not much I can do about it if I want Internet around here.
> If Google takes advantage of their monopoly position and alters AMP content, nobody except the content providers will be the wiser.
That's a fair concern, but the day Google does that is the day a media firestorm blows AMP out of the water as a trustworthy tool.