Hi Michal,
When Azure Databricks gets created, it creates a Deny Assignment on the managed resource group created by Az Databricks. You can verify that by going to Access Control(IAM).
This Deny assignment does not allow users or even Azure policy to add/updated tags on the Azure resources which are inside that managed resource group. and not even on that managed resource as well.
The only tagging option available for Azure Databricks is mentioned here: https://learn.microsoft.com/en-us/azure/databricks/admin/account-settings/usage-detail-tags