If you get a certificate from a CA (DigiCert, AWS,Google...etc), they hand you the certificate after necessary verification but otherwise have nothing to do with how you use (TLS traffic) it.
The same with something like age verification. Once you have a certificate that attests to your age (as of certificate issue date), the issuer has nothing to do with how you use it, the receiver of signatures generated from that certificate (via private key) can verify it without any interaction with issuer.
As for misuse, that's certainly a concern but it can be addressed via the issuing process. Certisfy does address this issue.
A fundamental requirement for making a certificate scheme work is that certificates are anchored to IRL identity via identity anchor certificates in a privacy preserving manner. You can read up on the approach here: https://cipheredtrust.com/doc/#pki-id-anchoring
Yes you do have to trust someone and the CA is the trusted entity for doing the verification, but once they do the verification and in effect encode that verification onto a certificate, their role is done.
Of course they can be. That they aren't _necessarily_ centrally managed is a neat fact about the math, but has little bearing on what sort of system the political process will end up endorsing, and _that_ is what I'm saying has no chance of not being centrally managed.
The government will end up requiring that only Trusted Parties be permitted to handle loading the key material into Approved Devices, and that parties requiring age verification only permit use with Approved Devices. Mark my words, this is how it will hit the streets, if it ever does.