Small correction: PowerShell script files are disabled by default for security reasons.
PowerShell is available with all Windows versions since Vista SP1.
On the latest Windows versions, remote command (part of Remote Management) is enabled by default. I.e. you can connect (given proper credentials) to a Server 2012R2 through PowerShell remoting and execute commands.
Indeed, the new "Server Nano" will not have any way to log in locally at all. There is no shell (as in operating system shell), and no local editor (like notepad). Only the remote command interface. PowerShell will be extended to allow remote file editing - i.e. use a local editor for a file residing on the remote computer (been missing that for the longest time now)
I think Microsoft envisions centrally-managed environments, rather than those with lots of Windows machines that aren't centrally managed.
Or through one group policy pushed to every machine.
So the company can push their CA and new PS policy in a single GPO, and then all internal PS scripts are signed using an internal CA generated code signing certificate.
This sounds complex but it is actually as simple as running Set-AuthenticodeSignature on each script using the code signing certificate.