This eeprom, being security relevant, should be signed by the TPM, read into RAM, and if the signature check fails then the machine should consider itself stolen.
The only recovery method should be to replace the EEPROM contents with another valid image, also signed by the TPM. And that image should be available from the manufacturer for anyone able to show they are the device owner.