I reported this bug after SP1 launched. Basically it doesn't matter if you have a policy set on the assembly unless you place the site it comes from into the trusted sites. Until that time it doesn't even look at your policy I found...
You can read messages from the DOTNET archive, unsubscribe from DOTNET, or subscribe to other DevelopMentor lists at http://discuss.develop.com.