I am not a security expert. This is my guess:
I would assume that hello only receives an encrypted image from the iris scanner (probably with a random code sent from hello) not from anywhere else, so that an app couldn't take, then send an image at will to unlock the phone.
This version of hello doesn't have the 3d scanner, just the cameras. So whether the camera is available to an app or not someone could take a printed physical IR picture and possibly use it to unlock the phone.
Hello works in the dark, so I don't think it is using the selfie camera for any kind of verification or parallax effect to make sure it is a physical face. Although the red led comes on, so who knows...
Tl;dr - hello should have encryption, so having the camera available to apps shouldn't be an issue.