What about a custom ROM (fork) of Android, sans Google apps? Not an option for typical end-users, of course.
Disclaimer: I work at Google.
source: im another google engineer
How do you propose a custom rom can establish hardware root of trust without being signed by the device manufacturer?
I understand Verified Boot, but how would removing Google Play Services damage security? It would seem to reduce the attack surface.