Unfortunately the CA/B Forum has high requirements for constrained subordinate CA certificates[1], which to me sounds a lot like regulatory capture.

[1] https://community.letsencrypt.org/t/sub-ca-with-wildcard-cer...