It would be good to be able to only trust CAs with some TLDs. That would limit the harm for adding a geographically useful CA to only a certain segment of the internet.
I'm guessing that for some TLDs it would make even more sense like for .gov or .google or similar.
It would be useful for internal CAs too, because they could be trusted for only a specific subdomain, eg *.intranet.acme.com.