Anyone who has lived through the windows PC era knows it's a legitimate problem. Google has tons of data to show malware exists for Android as well. Being able to prevent that malware from affecting the lives of Android users is a moral imperative for Google. I understand why folks are skeptical, but it's worth trying to dig into the fact rather than just react blindly.
To the extent that this is true, the lesson is very much not that Microsoft should have had total control over what users were allowed to run.