To protect myself or my company, what about a pihole (or similar) that rejects any TLS connection attempted with certs signed by these root CA?
Of course there is still HSTS, but that's not supported by all tech using TLS.
Prediction: If this passes, users having to bypass cert errors will be the new cookie popup.