Presumably you need to trust servers you use in both cases.
But not necessarily allow them to impersonate you (e.g if the messages are signed in your client).
Servers all need the same degree of trust.
The difference is, with #ActivityPub you can't take your identity (followers have to be sought out and notified the new ID), in #Zot you can (the ID is host-independent).
But I would defer to people like @strypey who seem to have studied #Zot closer than I.