Private Access Control Tokens (PACT) are designed to allow sites with strong knowledge of “personhood” to issue anonymous tokens.
A centralization of authorization. So that's why Google and Microsoft are interested.
If it's open enough, could still be a net-positive.
Depends on the mechanism though. Too weak and it can be automated and misused, losing "it's a human". Too strong and there's more concerns about privacy, control, and centralization of the selected auth providers and browsers making the selection.
Maybe hosters could use their own trust lists, like Firefox does for certs. But most will just go with the big and common default set.
I'd prefer skipping the anti-ai guards. But having to give a passwort to Google for it? I don't know. They'd have enough data on me to know I'm a human without it.
This is a press release. Is there more technical or concise information?