Request for a new header: State-Of-The-Art
medium.com
medium.com
If the same header automatically adds that meaning as well, your site can break essentially randomly, unless you keep tabs on the new stuff and adapt the site to handle them - in which case, you don't really need this header, you can just add the new stuff as it comes up.
If the header is fixed in meaning ("best practices as of 03/2017"), then what value was really gained over simply copy-pasting a list of the recommended headers as of that date?
It just seems like it's either mostly useless, or too dangerous to use.
Then a couple years later, you add State-Of-The-Art-Plus-Plus.
Then a couple years after that...
If the website works from a user perspective, and it's not being actively attacked in a way that leaves obvious signs in normal operations monitoring, then a lot of IT orgs simply won't have the mandate or the budget to go Googling to find out the very latest recommended HTTP headers.
By the way, there are already such lists and tools:
https://www.owasp.org/index.php/OWASP_Secure_Headers_Project (OWASP in general, though I hear the crypto stuff is weak)
You make people turn off safety features manually and the rest of us are fine.
That'd be a great way to make CSRF attacks from any domain a default setting.