The middle ground of course is for all government agencies and companies to set up their own Anycast root DNS servers to participate in the global authoritative DNS clusters [1] and put their own caching DoT/DoH non-authoritative servers in front of them to keep their queries from traversing untrusted networks. i.e. all queries traverse government and corporate VPN's and the query terminates on the in-house DoT/DoH servers and finally terminates on the in-house root DNS Anycast replicas.
3 days before Trump replaced Biden. No offense, but I suspect that implementation won't be a priority for the new administration.