Could be worded to either require the authorization endpoint be "publicly accessible" (for whatever "public" means tho that might be tricky), or to be accessible by the user agent with no other form of authentication needed, or specifically prohibit known lists of things like MTLS.
See this thread for context:
https://mailarchive.ietf.org/arch/msg/oauth/I9v_RvsGDHbfIpqwnH4vLXlTCls/
Could be worded to either require the authorization endpoint be "publicly accessible" (for whatever "public" means tho that might be tricky), or to be accessible by the user agent with no other form of authentication needed, or specifically prohibit known lists of things like MTLS.