Because they think you’re going to try to sell them life insurance or something like that, when the reality is nothing could ...
Any data that enters your system from outside a trust boundary should be treated as untrusted until proven otherwise. That includes form fields, API payloads, file uploads, headers, cookies, queue ...