Foggy TBF that applies equally to the stock 4a, ie the OP is in no worse a situation than they were before.
This is complicated. Due to Google's current Play Integrity policies, a 4a running stock may be less secure than a 4a running EOL GrapheneOS, but banking apps and other apps that demand a pass from Integrity will still work (regardless of how insecure the situation is).
Foggy (the same goes for any other phone out of support, this isn't GOS specific)
In a way it is, since security and privacy are primary goals for GrapheneOS. That is not true for other Android variants, such as DivestOS. And it is quite possible that in roughly a month GrapheneOS will entirely stop shipping releases for 4a devices, whereas DivestOS may continue, which would likely include some security patches to the high-level parts of the OS.
What makes sense depends on a user's goals. If somebody wants a cheap device to serve as a strictly-offline music player, out-of-support GrapheneOS could be fine, but also arguably other Android variants. As you point out, somebody might want a cheap device to experiment with GrapheneOS on, and 4a devices are likely cheap now -- though GrapheneOS on 4a devices is frozen at A13, so the experimental results will suffer from some fidelity loss.