As a policy thing, we also want to know what packages were updated when and broadly to control this, and we have enough machines that this information needs to be aggregated. Even if unattended-upgrades was totally safe, we'd want to only trigger it only on demand, see the package list in advance, and get an all-machines summary at the end.
Life would be a lot easier if apt-get updates could be more controlled, so for instance you could say 'only update this list of packages'. But apt-get doesn't want to do that; updates are global and using 'apt-get install' to update specific packages (normally) has side effects, like marking them as manually installed.
(I'm the author of the linked-to blog entry. For reference, we currently have 119 machines that get updated through this system.)