Even in the EU spyware use is prevalent (and i 'd guess everywhere else in the world). There have been many scandals of government authorized commercial spyware been deployed against journalists. Is it really that niche a mobile OS that tries to not be exploitable by them?
Graphene doesn't position itself against spyware.
For example, a user being able to inspect and edit the files written by an app, no matter where or how those files were written, would be an anti-spyware feature: you could better observe the behavior of a closed-source application.
Grapene opposes this feature because the app security model protects the app AGAINST the device user editing or reading protected files.
Graphene's philosophy is enforcing the Android security model. The Android security model gives guarantees to the app developer about how their app can behave, even where the device's owner wishes otherwise. See: Play Integrity.