My only complaint about the tradeoffs made in Google's current implementation of Advanced Protection is that I can't (even if awkwardly and with difficulty) allowlist any given third party OAuth.
So, if I want to, say, authenticate my Gmail account with Fastmail or ProtonMail, I can't also be using Advanced Protection. [0]
With Google Workspace, admins can allowlist OAuth applications registered with Google APIs for users who use Advanced Protection. Consumer accounts have no such feature.
I am not arguing the logic; I understand it. I just wish it were different. I suspect that passkeys are one stepping stone on the road to increasing account security baselines to be more like Advanced Protection, which may ultimately give me what I want one day. Wishful thinking, perhaps.
[0] These are OTOH examples, which may not be accurate as of this writing.