Can't you (as in the user) still just type `sudo spctl --master-disable` to get rid of the nonsense?

Yeah but this command sucks because AFAIK then it doesn’t even verify notarized apps anymore (for example if the certificate is invalid, if it was revoked, etc.)