https://www.chromium.org/Home/chromium-security/security-faq...
I can't remember what Firefox does in this situation
The real thing you seem to be upset about is that Chrome even allows you to MITM TLS connections at all at any level, whether or not the "actor" is your boss or a rogue adversary. It's debatable whether or not this is a good policy[1]. It's also a completely separate debate from whether HPKP is "neutered" or not.
[1] Realistically, it mostly doesn't matter what you think, because here's what will usually happen: Chrome doesn't allow MITM. Your business then enforces a network policy that bans Chrome from all devices. The alternative browser still allows MITM, and you still have to use them, and thus it still happens to you and everyone else. The end.
If Chrome enforced pinning with local roots, then the outcome would be:
1. Those sites simply become unaccessible 2. Those networks require you to use a different browser 3. Those networks deploy a modified version of the browser which disable that behavior 4. Websites avoid using HPKP in the first place because it may cause problems
or some combination. Those outcomes seem worse than Chrome obeying the desires of the network admins.
Is there some risk that malware or other bad actors could abuse this? Sure. But Chrome's devs considered that and decided any other number of bad things could be done with the same access.