When you boot into the "Startup Options" menu, you are booting into a special macOS partition in the internal SSD. M1 Macs use macOS as the moral equivalent of the UEFI setup menu. That boot picker that looks like the UEFI boot picker on Intel Macs? Yeah, that's a full-screen app on macOS made to look similar.
So how does external boot work?
The "blessing" process done by the Startup Options screen involves copying the entire macOS Preboot partition - iBoot2 OS loader, Darwin kernel, auxiliary CPU/device firmwares, device tree, and some additional stuff - to the internal SSD. It then creates a local, signed boot policy that allows system firmware to boot this macOS install.
You aren't booting from an external disk. You are booting from the internal SSD, with the root filesystem on the external disk.
Additionally, the integration of the macOS user credentials with the SEP means that you can't "just" take an install made on another machine and use it on a separate one. It involves importing user credentials into the local machine. This process isn't implemented properly yet.
As you might expect, this entire mechanism introduces a ton of corner cases around updates, boot selection, etc., and it is still very buggy and broken. The M1 launch was, when you look at details such as this, very obviously rushed.
Further reading for those interested:
https://github.com/AsahiLinux/docs/wiki/M1-vs.-PC-Boot https://github.com/AsahiLinux/docs/wiki/SW:Boot https://github.com/AsahiLinux/docs/wiki/SW%3AStorage
I'm actually eagerly waiting for Apple to fix this in future system firmware releases, because my plan for installing Asahi Linux for end users with a minimal amount of fuss is to abuse the mechanism to adopt foreign macOS installations. This elides the current need to have a completely wasted, 60+GB macOS install as a dummy to actually launch Linux (we could clean it up and resize it to get the space back, but it still makes for a very annoying install process that I'm hoping to avoid).
On the plus side, this dual-booting mechanism is very cleverly designed to separately secure different OSes, so you do not need to downgrade security on your machine to install an unsigned OS like Linux. It is a separate OS with a separate security policy. You can keep your macOS install fully secure, and capable of running iOS apps and other actions that require secureboot, and install Linux (or another macOS with a custom kernel, kexts, etc) in parallel, completely unintrusively. So kudos to Apple for designing this whole thing, and for opening it up for us to use :)