(I'm a developer at Google, but I'm not on the Android team and am definitely not providing any sort of official response here - this is personal opinion and may be inaccurate)
If apps can download arbitrary code and then execute it, they can bypass the validation that's done as part of the Play Protect program. My understanding is that there's plenty of evidence of malware in the wild that presents as a harmless app and then downloads the actual payload after being installed on the user's device.