I believe this is done partially to dissuade bad actors from gaining easy unverifiable access to hardware and software thus rendering anti theft technology ineffective. If you mandate all repairs to be done using a verifiable (and paid for) repair key which you supply to vetted people, it becomes that much harder to replace the anti theft module as a common thief. Even large scale operations would then be harder to run as they would require a fence of sorts to use as a repairman. Of course that fence would then risk their credentials and so on...