https://github.com/explainers-by-googlers/Web-Environment-Integrity
This was a proposal a few years ago for how to enforce "trusted web". Basically, a way for service providers to verify, at a per request basis, that the client is using an unmodified software stack, starting with an operating system signed by a trusted developer. Could absolutely be modified to enforce this shit.
That the fossil record is incomplete