You are understating the main difference a bit.
By using a bunker, the client can temporarily abuse the keys for things I explicitly allowed but bunker can still hold taps on things I never allowed or throttle the things I did allow in ways the client cannot know.
Bunkers so far are not that sophisticated but I anticipate them to profile behavior and require approval when dark patterns are detected. For example I might allow signing kind-1 events but future bunkers might totally lock up if that happens more than 20 times in a minute. The user could then investigate what happened and increase the threshold or remove the abusing client.
