It looks like as part of the process, they delegate the prefix in global DNS and see how much traffic it currently gets; if it gets too much it will be classified as "high-risk" which at least makes things harder. Which is to say, we want as much leakage as possible to hopefully make ICANN think twice about approving this.
https://icannwiki.org/Name_Collision_Risk_Management_Framewo...
Do we know if leakage is currently under test?
This test is poorly designed for .lan because the opposite problem is more likely: that many people using .lan will have any resolution attempts swallowed by their routers. This is certainly true for OpenWrt and GL.iNet. It may be true for Unifi AmpliFi, which reserves .lan by default. It's potentially true for other vendors when .lan is configured as the local domain (which many online guides suggest people do).