Earlier quoted context omitted.
Yes it does, all of this is to make Java fully safe by default, in the age of cybersecurity laws, hence all loopholes are being closed down, in reflection, JNI and Panama. The security model was deprected, just like .NET dropped CAS in .NET Core, because it wasn't sound, and without applets, the OS security model was the right way.
If there's no security model then who are you protecting from who?
Supply chain attacks from misbehaving libraries using reflection or JNI/Panama, that is what secure by default is protecting from.