And yes, of course there's code that accesses the database. The problem is that if it's client code, that code must be trusted by the database.
A better approach is where there's code between the client and the database, also on the server (server estate, at least), that verifies data going into and out of the database.
That isolates client-side changes - malicious, unintentional or otherwise, that might impact the data, because there's a server-side gatekeeper.
So all of a sudden FAAS is more appealing than BAAS, and the FAAS API gateway doesn't just do routing, it does validation too. Guess what, you just created an application/business logic layer on a middle tier, and it's no longer serverless.
"...Why do you think that lambda functions cannot be in the second category..."
They can indeed be in the second category. The author, however, specifically calls out direct database access from the client without lambda functions.