The EME spec only documents how to use a "Clear Key" scheme that is a complete trash defeated in 1 line of code, and of course not allowed by any website with DRM.
The EME spec says nothing about Widevine or any real-world DRM API. The CDM side, that does 99.99% of the actual work, is not documented in the EME spec. It's only a hypothetical construct alluded to in the spec, but not an actual API. The actual browser implementations don't even use the architecture outlined in the EME spec. Almost all of the EME spec is non-normative, or for the decoy Clear Key non-DRM.
EME is like a spec that says Adobe Flash is <object type="application/vnd.adobe.flash" />. There, Adobe Flash is now an open web standard. You have everything you need to handle .swf files without plug-ins, except the content playback module, which is a detail left for each vendor to figure out.