IIRC, even GW-BASIC allowed direct access to the hardware via peek/poke/inp/out. When you turned on the PC, it loaded the first 512 byte sector from floppy or hard disk into memory and transferred control to that. In theory, you could use the tools it came with to write a complete replacement for the operating system and install it so that after the BIOS loads that first sector, not a single machine instruction that you haven't written yourself runs.

I'm genuinely asking everyone here: How can I do this on a smartphone or tablet? Not just "root it", or install an "alternative OS" that is really just a tweaked Android, and "also you first have to buy this particular device it works on". Preferably without having to solder SMD components.

But from all I've read, I'm expecting the answer is "you can't". Which is too bad, since I have a couple of old devices from family laying around and would like to tinker with them. I'm not connecting them to any network as long as I don't have that level of control over what they do. Wouldn't do it with a new, "secure" device either -- the problem for me is what the built-in software does when working as intended by Goo666le + Shenzhen (I don't trust Apple either, and their devices seem even less hackable).