Perhaps because your ISP can't see Tor usage (though bridges do that better), but now the VPN provider knows your real identity and that you're on Tor, a correlation choke point with payment records attached. Plain Tor never asks who you are. This is negated with some VPN provider though as not all require KYC. If you're using a private VPN and then from their connecting to Tor, you're most likely fine.
If you're connecting to Tor and then a VPN, that's bad. You're essentially negating Tor's random exit node. Tor exits rotate per circuit, a VPN exit doesn't, so the VPN becomes one persistent observer of all your traffic, defeating Tor Browser's per site circuit isolation.
It's also technically fragile: Tor only carries TCP, so UDP based WireGuard/OpenVPN won't tunnel over it without special config.
And this special configuration is very complicated for the average person that just what's some privacy.
My two sats.
That said, three letter agencies absolutely run Tor exit nodes. Why wouldn't they? They'd be terrible at their jobs if they didn't.