The only reason I don't think the big players are doing this _is_ the potential for scandal. Random apps on the app store that ask for a million permissions, on the other hand, are probably doing this.
It only takes one clever hacker looking to make a name for themselves. With that said, there are plenty of cases where companies _were_ caught spying, so maybe it's not so cut and dry.
Also: people seem to be looking at modern speech recognizers on their phones and wrongly concluding that speech recognition in general is very compute-intensive. It isn't, if you're willing to make some sacrifices on accuracy and generality, and to do it locally instead voice data off to a cloud somewhere. A proper benchmark here isn't Siri or Google Assistant - it's Microsoft Speech API, as shipped with Windows 12+ years ago.
I disagree - even shitty, low CPU on-device transcription could give a signal to advertising algos.
I doubt this is being done, but it is definitely within the range of possibility and wouldn't even drain your phone battery that much.