Why does your trust model include "running a proprietary OS that can do anything at any time" but not "the OS explicitly requires a user account tied to an online account?" That doesn't make any sense.
To be clear: there are plenty of great reasons to dislike this change. But they all fall under "user-hostile" or "creeping surveillance capitalism," not "shady conspiracy to steal your encryption keys." They can already have the keys if they want them, and there's nothing you can do about it as-is.