But that's just it though - if bad actors gain control, you lose the ability to reject OAuth creds (which is what OpenID is). Things like social engineering or phishing of credentials, which happens at scale today.
They need a way to handle situations when bad actors take over, because other solutions handle this with centralized authorities who step in and rectify the issue.