I think the point is that all of this can be implemented purely in software that runs at the OS level, or even application level. There's no need to put this in a place where it's difficult to update/patch, and is entirely opaque and user-hostile to the point that the actual end-owner of the hardware can reasonably be sure they know what it does and can control what it does.
In other words: I don't want a backdoor into my system that I can't examine or disable.