Because if /dev/kvm isn't accessible to unprivileged users, then people will start using `sudo` to run anything involving virtualization, which would be much worse for security overall.
Would they potentially be a solution to sudo's all-or-nothing granularity in this domain?
So as a responsible user I am slowly writing my own sandboxes, struggling with lack of documentation and designing workarounds.
Which is precisely why many kinds of kernel feature should be exposed as operations on device nodes, not as system calls usable out of thin air. UGO and ACL permissions work on device nodes!