There is absolutely some horrible shit going down -- backbone sniffing and DPI, mass telephone metadata (and either OTA or carrier-delivered copies of content for "interesting" numbers and maybe areas), etc. And, there are serious future trust issues with cloud computing. But, at this time, I don't think NSA has pervasive access at Google -- I'm sure they (and the Chinese, Israel, and others) have Google staff who they know are likely to be "friendly" if they actually did need to do something (much much more applicable to non-US agencies), but even that doesn't need to be formalized until used.
Because NSA has so many other tools (legal and technical) to use, I don't think they do high-odds-of-being-detected stuff, certainly not on a widespread basis. Active MITM of connections, or really intrusive requests to companies, seems unlikely.
This is not the case for China, Israel, etc., so they are far far more likely to use external or internal attacks (other than legal) to get data from companies. And, guess what -- look at the news or your own networks -- lots of attacks from China, some quite sophisticated and successful.
I'd actually say there are higher odds of a given Google SRE being purely commercially evil and selling access to crime organizations than that NSA is doing this actively against Google.
This all means the threat is every bit as real as if NSA were doing it pervasively if you're likely to be a target. I don't think we ever thought NSA was using its pervasive monitoring for anything other than ultimately going after some specific targets, not for general law enforcement risk, so the situation is no different either way -- you can mostly trust Google if you blend in, but can't if you're "interesting".
Against some kind of pervasive secret program involving many people: The odds of a single Googler on any team being a "whistleblower" are far higher than the odds at NSA, and we've had a lot of espionage leaks over the years, plus actual leakers.
Occam's razor is that Google is telling the truth here.