A few things are going on.
Firstly you often don't need a PKI, and when you do need a PKI (which as I said is less often than people think) you often don't need a public one.
Take EMV ("Chip cards"). There's public key crypto securing your payment card transaction. There are multiple organisations involved. So we've got a PKI, but does it need to be a public PKI? Why not just let EMVco run everything, probably badly, and have them and their members (the banks and other big financial firms) eat it when inevitably they do a bad job? So that's what happens. If a CA in the EMV ecosystem does a bad job your bank will end up eating the cost of that, or maybe your country, the headline won't be "Obscure CA misissues certificate" it'll be "Huge Bank loses $500Bn in IT catastrophe" or something.
Secondly, the thing a PKI does relies upon is a common naming scheme. The standard actually used in the Web PKI, X.509 was designed for a world with a global directory of everything, the X.500 global directory system. That directory does not exist. What common naming schemes are there that we'd want digital certificates for?
The IETF published RFCs from the PKIX working group, defining how X.509 can be used for the Internet's names. That is, mostly ipAddresses, dnsNames, and emailAddresses.
The Web PKI concerns itself de facto with the first two. You could and some people do use IP addresses or DNS names in a context outside the Web PKI, but mostly they don't. "Don't roll your own". Even the successor to TCP, QUIC, was re-designed to have it just envelop TLS and thus depend upon the Web PKI, rather than inventing a new shiny public key crypto technology and associated PKI.
So the only use case we actually care about that didn't end up happening was email, S/MIME is what was attempted and... I have no doubt Thomas Ptacek can explain at considerable length how unlikely it is that anybody can get that to do what you'd expect it to do and deliver you any meaningful security if you're interested.
It should definitely give you pause when you see a system which really seems like it could only be secured by a PKI and it isn't the Web PKI. Is it a private PKI? Who has oversight? Or are they just going through the motions and the security is illusory? The answer is the latter pretty often. Stakes are often thought to be very low until they aren't...