* Security; allowing evaluation rather than a describing results.
* DDL; Data Structure and Types need to be learned out-of-band. Ideally we want a sort-of interactive INFORMATION_SCHEMA over http, so our tools can inform us about types/structure and we always have updated info as we write queries.
* Performance; Stored Procedures (server-side) protect against a client making poor joins; ORMs requesting too much data, etc...
* Info about Security: client side SQL doesn't know what rights it has, or you could say that a client account can't see the big picture of DDL. The understanding of rights is all communicated through non-API means.
* Info about Performance: clients don't know rate limits, current system load, what system admins consider reasonable data sizes or reasonable analytic calculations, etc...
I don't know what GraphQL does for each of those issues, but I'd love to hear.
[0] I recently setup InfluxDB which has a (private) web interface that takes raw SQL-ish, and it's so convenient.