This is the best guess if you take both the leaked documents and the companies' denials as accurate. They can use a real prism to duplicate the fiber traffic before/after Google/Apple/Facebook's servers and their root certs to take a peek within.
Do you have any more information about how viable this would be? It's a threat I hadn't considered before.