To me, this is a non-issue. PEM is being developed in parallel by multiple
people, so it needs a carefully written spec and probably concensus on that
spec.
PGP was originally written by one person.
The group effort might have fewer gotchas, if it ever gets deployed. :-)
But seriously: I'm a fan of doing a prototype and getting it into service
before concensus is reached on an international spec. I'm delighted that
RIPEM was implemented before the spec was settled -- so that there was
something PEM-like for us to use to compare to PGP.