It's probably built on systemd's Secure Boot + immutability support.
As said above, it's about who controls the keys. It's either building your own castle or having to live with the Ultimate TiVo.
We'll see.
Just to make it clear - on Android you don't have the keys. Even with avb_custom_key you can't modify many partitions.
We all know who controls the keys. It's the first party who puts their hands on the device.