All of this is interesting, but how easy is this to circumvent? When Apple changes their mind for whatever reason, don't they just return a key to a fake PCC node, which would bypass all of their listed protections? Furthermore, what prevents Apple from doing this for specific users?
If it appears in the transparency log, the whole world will be able to see that a suspicious node has started serving requests.
If Apple changes iOS to remove that restriction, the whole world will be able to see that change because it’s client side.
If Apple tries to deliver a custom version of iOS to a single user, the iOS hardware will refuse to run it unless it has a valid signature.
If it has a valid signature, that copy of the firmware is irrefutable evidence that Apple is deliberately breaking its privacy promises and spying on people in a way they specifically said they wouldn’t, which would be extremely harmful to their business.
Apple seems to be going all-out in binding themselves in a way that makes it as difficult as possible to do what you are suggesting.