You are not quite the owner on GrapheneOS either, because of Android Key Attestation (which has functionality analogous to desktop TPMs). If you re-unlock your bootloader (say, to run a custom build of GrapheneOS), attestation will snitch on you and the subset of apps that use key attestation to require a locked bootloader and/or enforce an AVB key allowlist will not work properly. This is a very small subset of apps currently, but I don't see it getting any smaller.