Tech and market pressure will make more capable processors affordable if security is prioritised.
For a small system like that, the shining ideal is probably a formally verified single program with no real OS to speak of.
I'd want to see a solid paper comparing the security of the approach you mention to a microkernel+app. Until then we have this.
But agreed, there are other ways, of varying practicality, to achieving security.
Tech and market pressure will make more capable processors affordable if security is prioritised.