My university has a public IP for every computer, but you could still only connect to the servers, not random computers, from the outside. Because they had a firewall.
NAT/port forwarding, for all their faults make it rather difficult to write rules allowing traffic to a machine you didn't intend to expose to the world.
This is not in any way a benefit of NAT.
Just because NAT accidentally achieves some good outcomes doesn't in any way imply that said good outcomes are somehow exclusive to NAT.
Obviously, those average people have a suitable firewall provided by default on their routers.
Tailscale doesn't strictly need NAT traversal. They can run only their DERP servers and still continue to work. If your firewall tries to block two devices from communicating and yet allows both devices internet access, you have already lost.