My point was you can side-load apps. As for that specific API even the official docs seem a bit confused:
"Except when you use the NEHotspotHelper class, you do not need to obtain entitlements from Apple to use Network Extension classes. However, you still need to enable the Network Extension entitlement via the Developer portal."
My understanding is that you still need a developer certificate from apple which has a limited lifetime. So you're not given permanent control over your device in the sense of unshackling you from the manufacturer, which is a requirement for repairability.
They're merely handing out breadcrumbs to give the appearance of a way out which they can retract at any time.