There is no technical requirement for Secure boot to allow enrolling your own keys. Also, have you ever actually tried to enroll your own keys? The process for each and every board is basically unique
Theoretically nothing, but there's even less stopping me from turning it off instead