Good post man.
You're right, it's based off UID only, so if it can read long enough to give the failed read sound then it'll still unlock cos it'll have the UID. I played around with it for ages doing that, making sure that it wasn't just unlocking for any old device.
Something you can do that's interesting and bypasses the empty tag message is to encode an action for the ring, like in my case I read a lot so I have a good selection of ebooks and my reader of choice. Setting up the ring as both unlock-allowed and also to trigger the ebook I'm currently reading lets me unlock the tablet or phone with a quick swipe and the "failed read" sound, and with a longer "successful" read it'll both unlock and launch my book.
It's fiddly for a start but after practice it's second nature.