(a) They're the Internet's foremost adopter and proponent of DHE ciphersuites, which drastically reduce the impact of losing the RSA key that underpins most site's TLS security, and, just as importantly, forces adversaries to actively MITM every connection in order to decrypt them.
(b) They're a pioneer in key pinning, which bakes the identity of their key into the Chrome browser binary, meaning that when your Chrome browser talks to Google's mail service, it's unlikely to trust any otherwise- valid- looking certificate presented by a MITM attacker.
Google's mail service is better encrypted than most banks.
But it's also engineered to give Google itself access to your data so they can improve their behavioral profile of you.
I think what people are suggesting is that if end user privacy was Google's priority rather than gaining access to user data for their own use, they could engineer a service that didn't place themselves as a man-in-the middle.
Chrome doesn't pin actual certificates, just public keys of CAs. If some organization had access to Verisign, Equifax or Geotrust keys, they could just create new certificates for *.google.com, which Chrome would accept.
Actually if someone sends an email to my Gmail account using his ISP SMTP server, is the connection between the two SMTP servers likely to be encrypted?
Google has a financial interest in having access to the content of mail messages, but (a) it's an interest "in the large", not in any specific account, and (b) it's a nonrivalrous interest.
You can't solve a legal problem with engineering. We're talking about the same agencies who had the ability to get all of the major phone carriers to install wiretapping services – there's no reason to believe they wouldn't do the same to anyone else of interest.
Google doesn't want the profile to be stored privately in your browser because then they can't use it to target you in other situations.
They are constantly pushing for access to more of your personal information, not less.