This worries me. Not because of the current usecase - this is already a common practice with cars from used-car dealers (at least in the US). It’s the “what’s next” usecase, where this is included by default, with other quasi-legal triggers.
Some potential triggers:
Attempts to root your phone. (For example, via a honeypot root mechanism released by the manufacturer)
Using an app store not approved by the manufacturer.
Visiting “blacklisted” websites.
etc.
We might not see these kinds of applications for months or years, but there’s no reason we wouldn’t see them, other than relying on Google’s good will.