On the topic of certs, last year, when Google announced they were now a root CA [1], I remarked that this made a lot of sense, because "who better to say that Google is indeed Google than Google itself?" [2]
I went on to write that not everyone runs a root CA because coordination of trust between various parties is difficult, and so are the mechanics and practices of running a CA, but if your browser (and/or OS) is the final gatekeeper of the trust anyway, why not just push trust towards the edges and out of the middle? Certainly, the most-visited websites could easily be in this boat.
As it stands today, the most-visited websites already don't use EV, because DV certs are good enough for their needs. People trust their website by fiat, simply by mental associations about their domain names, an imperfect process that makes plausibly-looking domain names such an effective tool for phishing. But users already fall for phishing conducted from ridiculous domain names too, so there's not much point.
[1] https://pki.goog/ [2] https://news.ycombinator.com/item?id=13495262