Apparently, it is a zero tolerance policy except for the provided apps even if you trust the app developer.. Which basically means you cannot truly replace the provided apps without rooting the phone.
Indeed. Which is why I say this represents another component of a strategy away from open systems, and towards the sort of proprietary walled-garden experience offered by Apple.
Not only is this a betrayal of many early Google evangelists - myself included - it's a fairly cynical exercise to build such a system on the Linux kernel.