Many people already have Android smartphones, so there is already a Google microphone in your house. The big difference is that you know that it has a microphone.
A malicious actor could easily conceal their activity by making 24-hour-long recordings and sending them in the night (or whenever connected to WiFi and plugged into power).
Besides, the attack vector for a non-Google attacker to access this mic may be different than for accessing the mic on a phone
It might be reasonable to be concerned about this kind of thing in the tech crowd, but the vast majority of people aren't.
This should absolutely be the expectation. A note of "microphone (disabled in software)" at minimum. Since when is it OK for a company to sell you a product with hidden functionality that can be used to harm you by either the manufacturer or third parties?
(The obvious defense is that they're not selling it to you, they're renting it out. Such is the pathology of turning products into services. It's a sick market dynamic.)
Do I need to list all the capabilities of some SoC even if I don't take any advantage of them? If a component has thermal sensors I'm not using do I have to list every one of them on the box?
So, I agree no malicious intent is needed to make things turn very bad.