Isn't Microsoft already doing that on a default Windows installation?
Edit: Yes, SmartScreen, enabled by default, seems to send:
Hash, name and signature for executables. (Also hashes of urls you visit (though I guess only in Edge?))
That sounds like most of what you need to build a system that can enforce what executables you're allowed to load and prevent you from attaching a debugger.
That's a different use case (chip-to-cloud). It can also not prevent you from attaching a debugger when all you need to do is to go offline.
In fact, the whole point is that you can run anything without compromising the security of the data in the secure enclave. That's what Zero-Trust is all about.
If it goes into client chips, and someone uses it for DRM, that's awful.
I guess we'll see?