Even if there is N% possibly that a three-letter agency can find an identity correlated to a Tor client in M time, VPNs are much more likely to either be malicious or compromised. And worse, most if not all VPNs don't onion or scatter-route traffic; every single network request goes directly to the VPN provider whom I must explicitly trust.
Granted, this isn't a problem if you run your own WireGuard/IPSec/OVPN instance on your own hardware, but for most people in unfree countries this simply isn't possible.
What's worse is that now not only do governments possibly collect your data, but a random third-party entity as well. Because of this, I only use VPNs when the alternative is nothing at all (like airport wifi that blocks Tor connections).