The benefit with an ONT (or even DOCSIS dumb modem) managed by the ISP is that they can do fleet upgrades much quicker as they don't have to keep all old protocols running. For instance the GPON -> XGSPON upgrade that some ISPs are running right now (or DOCSIS 3 upgrade) really only works well if you can turn off the old protocol which requires swapping out all ONTs/DOCSIS modems.
If customers bring their own stuff then you're stuck with these things for much longer.
But in cases where the ONT just looks like a media converter and you have a separate router I really can’t see any reason for the customer to provide their own ONT. Especially given PON is a shared medium so a misbehaving ONT can affect other customers.
If you're paranoid, you may want to run an ONT that you control, just in case. I doubt it's something that matters to a lot of people, but even if it only matters to some, it shouldn't be made impossible for those that want to.
RE: misbehaving hardware: the same is very much true for cable internet and there are plenty of countries where people hook up their own modem without any trouble. If someone wanted to mess with the fiber network they could just disconnect the ONT and shine a laser pointer down there. All off-the-shelf devices are built to just work and follow the necessary standards, because there's nothing to be gained by messing with the PON network like that.
Sure, but so can the other endpoint. Even many AON installations these days are just hidden XPS-PON and similar, you just never see the ONT. (See a lot of ISPs in Switzerland)