HSTS removes the insecure choice after a browser has learned the policy, while preload can protect the first visit too

HSTS tells a browser never to connect to this site unencrypted again.

The gap is that the browser has to be told at least once, so the very first visit is still exposed to being downgraded. Preloading closes that by shipping the instruction inside the browser itself, before any visit happens. It is one of the few protections that is genuinely set and forget, with the caveat that removal is slow if you ever need it.

More on TLS and PKI