It is intended, in the sense that this is how upstream AOSP has designed this change with Android 13.
GrapheneOS might want to change this in the future, but it's not a top priority. In the case where someone shuts off the VPN app, the block connections without VPN and always-on VPN settings (enabled by default in GrapheneOS - not the case in AOSP) will not result in leaks but loss of connectivity.
There is this open issue about it: https://github.com/GrapheneOS/os-issue-tracker/issues/1423