Earlier quoted context omitted.
Who has ever said IP6 didn't need firewalling? That sounds insane... And where is this IP6 NAT you speak of??
All the enterprises that have deployed in RFC4193 space are using IPv6 NAT. It's been available in OpenBSD (a popular IPv6 Firewall/NAT device) for several years. If cisco hasn't deployed it yet in their ASAs, they will soon. Enterprise cannot leak their internal addresses, and, if they do, they want it to be something that nobody can make use of/route to.
So to hide IPv6 corporate network structure it is necessary to send outside all IPv6 packets with one global address. Is this an only option?
It should be possible to hide internal network structure with some address shuffling techniques.