Earlier quoted context omitted.
They could just MITM all connections and say 'for compatibility reasons, please install this root certificate'. With a fee, this requirement could then be waived. Dystopian but technically possible.
This type of hypothetical drives me batty, and I was tempted to be snarky. I'm not sure how to respond to the idea that there will ever be a time your ISP requires root cert installation for service, but I will be finding a way to launch a WISP of my own at that point.
http://www.csoonline.com/article/2865806/cloud-security/gogo...
Gogo didn't require installing a root cert, but they DID issue forged certificates to MitM connections to *.google.com (and others).
Also, remember "Superfish"? Their root cert was pre-installed by Lenovo.