Groups are pretty essential to controlling access on AGOL and therefore the ability to create them is something that should not be given out lightly in an organization. I think in general all permissions need to be separated out more finely with roles, there are too many things that are grouped into a single permissions but this is probably the lowest hanging fruit.