But that’s specifically for Secure Enclave work (disk encryption, biometric data). I don’t think they’d want to risk someone running arbitrary code there and breaking the sandbox. (The SEP is also separate from the A-series chip in the iPhone for a similar reason, IIRC).