To be honest, this fits in Apple’s security approach known from iOS... the walled garden. If it’s Apple’s intention to bring the same approach to its larger devices... it’s evolutionary. Apple has made installing unsigned software harder and harder over the years. I can see how they will justify it: “we care about your security”.
But creating a whole new API for it, not accessible by other apps, is not “break things”. It is not just sneaky but evil.
!ENGAGE 25