Indeed. Goggle is very hostile to anyone not wanting Google deep in their OS, running undisclosed code with the superuser privileges.

I think we all collectively should try the compliance / regulatory ways to force enough companies to have to adkit they know Google lies about security when talking about attestation, then force them into supporting alternative attestation methods.