My read of the announcement is that they are now hiring vulnerability researchers to work on arbitrary targets, the way security product companies do to staff their research labs.
Starting back in the 1990s, companies like ISS and McAfee staffed teams of bugfinders to comb through high-profile software for vulnerabilities, and kept score with advisories (and with IDS/IPS signatures and scanner checks for those bugs, which they'd have a semi-proprietary interest in, since they found them). They'd use this to market their expensive products. The researchers generally had a long leash so long as they were (a) looking at software that customers might care about and (b) were actually finding things.
What Google seems to be doing is starting a lab like that, but without the hooks into products and marketing; instead: Google has cash, wants to retain security researchers, and so will throw money at a vulnerability lab run for the common good, partially for the PR win, partially for the knock-on benefits to Google of having lots of good security people, and yes, partially for the good of humanity.
(FWIW: I worked at what I think was the industry's first vulnerability lab, at SNI, which eventually became McAfee's vulnerability team).