Every os update is signed, and protected against downgrades, queries to update servers only fetches metadata and only sends the device and current version to the server, this means the update server does not need to be trusted to the best of my knowledge
For users whom reside in regions where the GrapheneOS update servers are blocked, having an option to choose a mirror could potentially be helpful