Yes, a rogue mirror or someone close to you could tamper with files, with DNS spoofing or other ways.
However, the issue with GPG is that it's huge, several megabytes, as well as slow. On size alone it can't be included in the base, and checking extensions on boot would be really slow on older hardware, which we support.
If you mean to only sign the .iso files for external validation, you could still be easily subverted via any extension. Just signing the isos would be snake oil.