The pure, utilitarian calculation is rather simple. Anytime you beef up the security policy, it tends to decrease the (permanent) hijacking and increases the lockout. From the point of view of original owners access (i.e. availability), they are equivalent in terms of losing access to the account. Because the hijacking breaches the private information and it also gives hijacker further utility for other illegal activity, hijacking is worse in general.
Thus, as long as the total number of hijacking+lockout decreases, it is a useful policy from the utilitarian perspective. Of course, hijacked people don't cry for help as much, and neither they blame Google as much.
People think a better customer service would somehow solve the lockout problem, but they need to understand that customer service has the same hijacking vs lockout problem, and they can only help if they have better identity verification methods available to them - e.g. if Google asked for government ID for opening a Google account, this would work - but if Google did that, people would scream. Without properly established identity verification methods, the customer service can't improve the precision and the recall. Thus, the current choice for the users is to use a better identity verification method - like security keys and using Advanced Protection, as non-phishable auth does not need complex and elaborate heuristic based protection, and set up a chain of recovery accounts, with all accounts using the security keys and/or Advanced Protection.