You are legally liable for the messages you send; the access rights you have etc;
This is why shared accounts are one of the first thing a CISO/CIO will try to kill. It makes liability lie with the company and not the individual.
You will not be able to hide behind the fact you refuse or fail to secure your devices if someone sends a threatening message from your email account or if someone deletes the prod database.
Where shared credentials are required there is usually an access log associated: which ties individual named accounts to shared access rights in the event of eDiscovery or forensics.
Some trust is good, but if we really believed in trust then we wouldn't even both having access accounts with our names on them.
I recommend Deviant Ollam’s YouTube channel for an entertaining way to expand your assumptions
The real reason for the policy is so when some dumbass sends a dick pic from their work computer and gets fired for it, they can't claim "it wasn't me" and expect to keep their job.