First that costs too much for many.
Second, you don't just want to prevent MITM, you (hopefully) also care about site's tracking you. For example, you have a Linux/Firefox user-agent and you are browsing HN in private mode, you close the window and start over. No cookies or other artifacts of the previous session remains but your user-agent and IP combibation is unique enough to identify your device. Now if you are using a VPN service there might be at least a handful of Linux/Firefox users out of millions that share the same IP.
Third, most VPN users like the geoip flexibility it allows them (bypass filtering or access different content).
Fourth, a VPS dedicated to this one service means you are now the admin of one more server that needs to be patched and supported by you (admin overhead)
Fivth, some sites block you if you use cloud provider IPs
Sixth, some VPN providers specifically host their infra in privacy friendly jurisdictions and take precautions cloud/vps providers might not (legally and technically).
Seventh, reputation. No one will bat an eye if Microsoft let some country's law enforcement have logs of your traffic in Azure. But by design, outbound VPN traffic can only be logged on the VPN server and it would ruin their reputation if they disclosed logs or tampered with traffic which translates to monetary loss.
VPN services are far from perfect but they hardly have any replacement. Just pick one with a good reputation.
For example with PIA, they are incorporated in the great surveillance kingdom of the UK, which is why I avoided them. They did not take the neccessary legal precautions and their freenode aquisition made little sense from a profit perspective which all in all suggests a grand scheme/vision not obvious to customers.