@IsItMe,
Unfortunately, this behavior makes sense, and I don't think it can be done from a technical standpoint without a direct line of communication between the AP and main router.
Placing a device in AP mode essentially passes all networking functions off to the main router of the network, and the device essentially become just a wireless repeater for the network. Any kind of security measures or connectivity settings would have to go through the main router. This is where mesh and one mesh systems come into play, as the APs and REs in a Mesh Network, are able to understand and limit connectivity for devices based on the security and guest network options set on the main router.
I will however put forth the request that users would like to see some sort of AP isolation for just the Guest Network.