perhaps this will lead to better AppArmor and SELinux defaults?

People will just turn SELinux off rather than have to go through the horrible tooling when it breaks a regular use case.

I do think SELinux is a good example of how robust software with poor UX/DX gets undermined by that poor UX/DX. Although I do wonder if AI can help with it?

There is also the Android way, this is how it goes, fix your apps.

It is enabled by default on Android, and only developers can change it temporarly via an ADB session.