I think that’s the scenario Google had in mind when designing this feature. For enterprise users, where the enterprise controls the hardware, the policy-level controls actually have teeth, because people don’t have root over the devices in their possession. For everyone else, it’s not “real security”, but rather just a gateway drug to get you used to the workflow that “real security” would provide in an enterprise context.
(Context: I used to work at IBM, and they had a very similar setup—company issued laptop, app that enforces MDM profile installation, VPN that checks with the app to ensure MDM is active before connecting, email servers only accessibly through said VPN, and, on top of all that, a policy-enforcing email app [IBM Notes] where you can delete already-sent things out of other enterprise-users’ inboxes, send expiring emails, etc.)