GrapheneOS has largely worked around this by automating creating device support themselves using "adevtool". The current Pixels' hardware supports installing third-party OSes and will continue to do so, they will support those Pixels until EOL. For future Pixels (Pixel 10 series has not yet launched, only available for pre-order), it remains to be seen whether they still fully support installing third-party OSes. If they do, GrapheneOS will also support them, but it might take much longer to implement device support because they need to make this by themselves and this is more difficult doing it from scratch than being able to use the old Android device support for it as a base, like they could do for the existing devices when Google did their rugpull.
They have not really vendor locked themselves for the future. They have hardware requirements listed in their FAQ: https://grapheneos.org/faq#device-support
Google just happened to be the only company meeting those requirements, which weren't even that strict, becuase other OEMs just didn't prioritize security.
But, there is good news. GrapheneOS is currently in active talks with a major Android OEM right now in order to help them meet the security requirements for a subset of their future devices. They are very optimistic about that.