It looks to me that while Asylo is agnostic about the specific TEE used, it is primarily targeted at Intel SGX [1]. Instead of having to trust Google to run your code correctly and not read your data, you'd have to trust Intel to manufacture a secure enclave and essentially bake in a private key that cannot be read. You could use the public key to encrypt your code and workload, and it would run in a part of the processor that Google presumably cannot access (or measure [2]).
A good further introduction might be this paper [3] (especially the diagram on page 2), or this answer [4].
I'll repeat my main concern with this system: you will reinforce Intel's position as 'feudal lord' in this model [5].
[1] https://github.com/google/asylo/tree/master/asylo/identity/s...
[2] https://arxiv.org/abs/1702.08719
[3] https://eprint.iacr.org/2016/086.pdf
[4] https://security.stackexchange.com/questions/175749/what-are...