The two main protections are requiring multiple signoffs (for landing code) and requiring proof of physical presence (for various things, including any sort of access to prod). Having code exec on a large number of systems means the first is weakened significantly, and the strength of the second really depends to an extent on how much effort and patience the attacker is willing to put in (eg, alias a command that requires gnubby press to something under your control, use the press to do whatever you want, then trigger the real command - user ends up being prompted twice, but how many people would actually flag that as a security concern?). Someone with no understanding of how things work in Google would probably screw up in a way that got them noticed pretty quickly, but a well-skilled adversary who's not looking for a quick win could definitely circumvent many controls if they had code exec on a decent number of systems.
tl;dr - if I were still gLinux security, I might not be freaking out about this, but it would definitely fall into the set of stuff I'd be making space for in next quarter's OKRs.