I was confused by this as well, however I believe it is WORKING AS INTENDED.
If you look at the notes for Open, Open only allows network access if the VPN Gateway is not reachable.
If you want to allow users to bypass AnyConnect the only way seems to be to Automatic VPN Policy ON byt Always-On off.
You can toggle Always-On via DAP policies as well.
I don't like the way this works, but this is what I have found.