Because google actually cares about hardware and software security. Read the FAQ: https://grapheneos.org/faq#supported-devices
That statement might not have aged so well, especially consindering googles attempt to lock out apps from their devices, If the developers do not comply with being oficially registered.
The fact that the play store is not exactly known for exceptionally high standards w.r.t. malware, or that there are lots of valid concerns that come along with a company controlling who is allowed to supply apps for the device is a different topic.
It has nothing to do with devices. It has to do with OSes, most notably OSes certified by Google, which GrapheneOS isn't.
Also, it will be possible to bypass it even on certified OSes.