Its called Mandatory Access Control. It has existed for over a decade in the mainline kernel. Ubutnu, Fedora, Suse - everyone but Arch, pretty much - supports one of its implementations.
The problem is more that I do not believe any distro is shipping a default-deny policy. Unknown programs are simply given the kitchen sink rather than having, say, user friendly prompts saying "this program has no access control and wants to open X or use Y, allow?"
But we definitely have the technology, and it does not take any heavy overhead isolation to do it.