Maybe I missed it, but assuming GrapheneOS doesn't adhere to this verification, or provides some OS-level way to disable it, what makes Graphene worse after this change?
GrapheneOS is only allowed to live because google lets it. This signals a wider ecosystem change that tells us that GrapheneOS is going to stop being usable when this generation of hardware dies. This generation or maybe the one after it.
What do you mean with "Google lets it"? GrapheneOS is based on AOSP.
GrapheneOS only runs on the Google Pixels, and Google may decide to render future Pixels unusable for GrapheneOS (e.g. by preventing to unlock/relock the bootloader).
But another Android manufacturer could get to the point where GrapheneOS endorses them. It feels like it shouldn't be that hard for an Android manufacturer, and they would immediately get quite some attention. Maybe not mainstream attention, but largely profitable, I think.
GrapheneOS exists only because the Pixel's bootloader can be unlocked. Google could remove that option anytime, making it impossible to install GrapheneOS.