CAs have to prove they're not faking certs through the certificate transparency logs, there's no such limitation on Bluesky.
A more apt comparison is a shared host that does certificate management for you. Those are also often considered less secure, of course.