For example, EAP-TLS, unlike the TLS used in HTTPS, requires a client to provide a X.509 certificate signed by an AP-side trusted authority. This is because people like Jouni Malinen (hostapd/wpa_supplicant), in all their wisdom, decided to spurn RFC 5216 ("While the EAP server SHOULD require peer authentication, this is not mandatory, since there are circumstances...") and completely disallow any and all configuration to disable the client-cert requirement, regardless of any circumstances (such as those behind HTTPS). NYC DoITT is no more equipped to provision X.509 certs for free wifi users than the NYS DMV is to provision X.509 certs for $80 DL/ID card holders (so people can securely prove their identity everywhere).
As trollian stated, Wi-Fi Alliance's "Passpoint" (Hotspot 2.0) does allow for such setups, technically. E.g., the vendor-specific WFA-UNAUTH-TLS version of EAP-TLS does not do client-side authentication at the WPA-level, as per RFC 5216. But WFA-UNAUTH-TLS, even among Passpoint-aware devices, is likely not widely supported.