I'm not sure that's true, actually. The ways that AFS hooks into the kernel, especially on kernels that don't have actual loadable module support (older commercial UNIXes) or on kernels that try to limit syscall hooking (e.g., Linux), are distressingly close to the ways that a rootkit hooks into the kernel.