The hint worked! It mentioned to enable csm, but for windows 11 is useless as it doesn’t support booting in legacy mode. But it was loading a loader from Rufus before Windows, so I tried to check if it was interfering with that. I checked secure boot. It was enabled but with custom keys by default. Why the F would they create a default with invalid secure boot keys??
Once restored to Microsoft keys, the USB booted without showing the Rufus UEFI loader and the setup recognized the drive.