I always thought the use in Android of a full date to represent a security patch level was so misleading. Not only for normal people, but even to Android developers if they never read bout this in detail. Since GrapheneOS got early access to the security bulletins, I think this is now even worse because people will see a date in the future in the "Android security update" (?!).
Not only it is confusing but I think it can also by ambiguous. Does a full 2025-10-01 security patch level implies it also contains the 2025-09-05? Can it be the case that you get early access to the the Android patches of the next month, but still no patches for the (I guess proprietary) hardware patches for the current month? If that happens, would you keep the old date, even though some patches from the next month are already included?
Perhaps GrapheneOS can create a new less ambiguous and less confusing way to define the "Android security update". And who knows, if it makes sense, maybe Google copy that as well and stops using random YYYY-MM-01 and YYYY-MM-05 dates.