Because the priority is not making secure apps, the priority is not being responsible for security incidents. The lawyers at the company making shitty apps (e.g.: your bank) want to be able to say "We followed industry best practices, which is whatever Google said to do".
That being said: root, unlocked bootloader, and custom ROMs can all be big security problems. But if your bank's app will not work on GrapheneOS, your bank just sucks.