No, Apple has made it a job of the OS. There's absolutely nothing fundamental to the problem that makes it a job of the OS.
A possible workaround would be a cumbersome two-way permissions system ("can app X access app Y?" [and, for purposes of apps asking the AI to ask follow-up questions] "can app Y access app X?", ad nauseam), but this is something of an impractical solution, because the AI would need to be granted permission every time the user installs a new app to access that app.
So yes, Apple makes it the job of the OS. This is a design compromise that mitigates the risk that the user is overburdened with confirmation dialogs, choice dialogs, and/or permission dialogs. And for an AI that just works, I would say this is pretty key.
Siri must be system-level because Apple has prevented other apps from being capable of assuming system default roles. It is an effect of iOS's design, not an inherent flaw in mobile OSes.
Security is just an excuse for not wanting to try and enable this.
Not when it comes to giving Google access to my personal data.