MS imagines four different paths for a clean install to get the latest Windows Updates.
1. You're installing from the latest 25H2 MCT or MVS ISO (created every month), or from an user-updated ISO.
2. You installed Setup Dynamic Update, so in the beginning of each install it pulls the latest CU from the network and applies it to the image.
3. OOBE runs a mandatory update check. MS promised two years ago we could have a real config to block this, but apparently this only works for domain clients.
4. After the install, WU eventually runs and installs the current CU.
In the first three methods, the user isn't allowed to log on until you have a fully updated Windows. Enterprises with a formal security policy find this very beneficial. Not every IT admin will use Setup DU; you may prefer to refresh an ISO right before you want to install Windows so having Dynamic Update doesn't serve any function.
But with a mandatory OOBE update, MS fulfills a promise to enterprises that users can't touch an unpatched system. The real problem now is every CU includes over 1.25 GB of AI model sets. Which adds more forced delay for unhappy non-enterprise users.