It’s in their best interests to also use it for ad targeting (in a plausibly deniable way so they don’t get in trouble).
We’ve seen them using dark patterns to coerce users into opting into more data collection, and another advertising company got caught using phone numbers for ad purposes even if they originally promised to only use them for 2FA, so why should we trust them this time?
If it was being used for targeting it would be practical to run an external study demonstrating that.
I would be very curious as to how you’d prove this is or isn’t happening with a reasonable degree of accuracy considering all the factors involved in ad targeting. Unless you’re willing to give us access to all your source code and SSH access to the systems running it, it’s reasonable people have their doubts.
And surprisingly for most of HN readers, Google has been pretty transparent on the policy of its ads business. In fact, Google has pretty strong incentives for transparency in this area due to advertisers, who give all the money anyway.
An external study to evaluate whether Google is using fingerprinting would be some work, but pretty doable. Targeted advertising is generally very blunt: if someone thinks you're especially interested in a valuable category they'll often pay a lot to advertise to you. So you could set something up where test browsers visit pages related to high-value categories (mattresses, asbestos cancer, credit cards, ...), clear client-side data, and then visit a site that loads ad scripts only from Google (to make sure you're not getting someone else's fingerprinting) and see whether the ads differ from a control group that never visited those pages.
IMO, ads are probably the least worrisome way the data could be used. A boring but scary example is that aol search history leak (which is still searchable today):
This person is identified by name for example: https://searchids.com/user/19431784-joann_whitman