If most of the stuff the user cares about is inside the "Insecure World" bubble of the diagram, then this whole business is, like, for shit. It serves only the platform provider, who can decide which programs may or may not be installed based on whether they are aligned with or against their competitive interests.
This is just plainly false. Passkeys, biometrics, app permissions, and a suite of other user-centric privacy features have clear benefit from strong isolation from an "insecure world" kernel.
I tried to read the article, and know what all the words mean (sel4, enclaves, virtualization primitives, etc.).
It all seems very complicated and error prone, but I couldn’t figure out what the attack model is, or what the security objectives are.
Eg, what sorts of things run in exclaves, and under what circumstances will a persistent kernel level compromise on my laptop protect those things?