Of course, if an instance is given the benefit of the doubt and they violate that trust, then they would be removed from the list. This is no worse than the status quo. But malicious instances will not get to participate unless they can convince someone to vouch for them. And there could be punishments for vouching for a malicious instance

If individual servers disagree with the collective allowlist, they can still have their own private list that they use that's catered to their own members