Never trust user input. The users already can't modify the server.
And what actual applications did you have in mind that warrant throwing everybody under the bus? (by that I mean some applications (allegedly) need it, so it gets forced on everyone)
My banking app already trusts Face ID right now!
My banking app already trusts Face ID right now!