Out of the box that's true.
The system firmware will ship with 3 boot modes selectable via the setup interface:
- Windows (this one has the Windows tcblauncher escalated to EL2 through Secure Launch)
- Linux (this one stays at EL1)
- Linux w/ KVM (which jumps to EL2 before kernel handover)