This just exposes an API for sites to use. If they wanted to do the types of spying you're cynically suggesting, they could just add it without an API and you'd be none the wiser. Chrome contains closed source components so you wouldn't even know.
I appreciate you feel this is a cynical take. But have you seen the class action lawsuits against Google over the last 5 years? They exceed a billion dollars as far as I can remember and they are for more blatant things than this.
Why would adding a ML API or library require an EULA change?
It’s a totally valid question, and transparency is the only way this can work. On-device processing is an important core design goal of these APIs.
There are NO logs of the input / output interactions sent to any server, not even for training purposes. The only metrics we have are on performance, stability, and other generic API usage signals like any other APIs. These are all controlled by existing user preferences in Chrome.
Forgive my untrusting nature but I've been burned through several Google abuses of trust. I guess it doesn't matter much to me anymore I will never use chrome again, but maybe someone else is in the fence.