For a variety of reasons.
* Many deployments are done via roles, not IAM users.
* That pesky "jenkins" user is not in fact "John Enkins" but is in fact a CI/CD system.
* The model breaks down entirely once you get past a certain level of complexity. Shared resources (CloudWatch Logs, CloudTrail events, oh god the NAT gateways) get really hard to slice up in easily agreeable ways; cross-account access becomes a nightmare to track costs across.
* Most relevant of all: the system wasn't designed to do this from the start, and there's a mountain of technical debt to dig out from under before it could be done.