> How do we know all of the traffic isn't deanonymized due to a big company or government having control of a large number of nodes?
It absolutely is. This is known and explicitely called out in Tor's design:
> A global passive adversary is the most commonly assumed threat when analyzing theoretical anonymity designs. But like all practical low-latency systems, Tor does not protect against such a strong adversary. Instead, we assume an adversary who can observe some fraction of network traffic; who can generate, modify, delete, or delay traffic […]