I get a bunch of information through emails at work that Im not allowed to share outside the company, and tons of others that I need to send to people outside the company. If the people sending me the internal company emails mark them as such, I can be sure I never inadvertently forward the wrong emails to the wrong group.
I think the threat model is about catching your own mistakes, not preventing bad actors from acting.