Basically the point is rather than keeping the absolute minimum in the kernel, you keep the minimum needed to multiplex the hardware with the fewest abstractions possible. So stick a network driver in there, sure. But does the TCP stack need to be in there? Stick a disk driver in there, but does the VFS need to be in there?
Then you add security so that the fast path doesn't need to go to a user space abstraction service. You have something like bpf so that processes only get the packets that correspond to the ports they've opened, directly from the kernel device driver. Your FS service gives out revocable capabilities to the disk blocks corresponding to files a process was able to successfully open, etc.