(1) is premised on (2), which is not right. Some SQL RDBMSes are statically typed (e.g., PostgreSQL) while others are dynamically typed (e.g., SQLite3).
If you're building on SQLite3 then you're going to have to do run-time type checks anyways (even if you somehow disallow access to the DB that bypasses your application). So maybe don't build on SQLite3.
This is a shame. We really do need a SQLite3-like DB that is statically typed.