You are conflating many things here. A locked bootloader does not imply you cannot run unsigned software in user space. There are also many phones that do allow you to unlock the bootloader. I have a drawer full of them.
Finally, the ability to allow you to unlock your phone bootloader or to run custom firmware has nothing to do with the silicon. It's a software choice. The trusted software could most certainly decide to disable these safeguards.
It most certainly could, but will it? I have that same drawer. There is absolutely custom silicon dedicated to putting up those safeguards. The problem is the trusted software decides wether or not to disable those safeguards is what makes it special.