Because you are unable to verify what the google play service binary is doing. It could potentially bypass any security built in to the app and allow google to read your messages.
And the answer to their question is that it depends on your threat model and the amount of risk you are willing to accept. There is no such thing as perfect security or a perfectly validated platform. At some point you have to accept good enough and get on with your life.