You actually couldn't do that with the original Pixel (which until recently, Android 11, these custom derivatives tended to support). You'd get a warning screen every boot about how the OS has been modified.
This was also possible on the Nexus devices, although the oldest I've tried it is the Nexus 6P.
It just worked slightly differently on those, nowadays you enroll the public key by flashing it to the device, on those (Pixel 1, Nexus) you used to have the public key embedded in the kernel.
When you lock the bootloader you block other keys, since fastboot is pretty much disabled when you do that, and the only way to install something would be via OTA updates which would have to be signed with your custom keys.
I guess maybe if you're able to get a root exploit and replace the boot image? Not exactly sure what would happen then, need to try.