-They still support playback on devices with no TEE. Kinda defeats the point of implementing it until this is the case.
- They are wary of moving more functionality into their TEE as it increases the attack surface.
- If the platform is already "attested" and locked down as it is the case today, moving the playback to the TEE provides only a little bit of extra security.
- They are banking on the ARM Realm Management Extension[0] coming to their chips. This would be more of a "catch all" solution to fuck over the owners of their machines in new and exciting ways.
[0]: https://fuse.wikichip.org/news/5699/arm-introduces-its-confi...
https://en.wikipedia.org/wiki/Software_Guard_Extensions#SGX_...
EDIT: thinking about secure enclave.. maybe (still an hypothesis) the chip does not have the bandwidth to perform decryption just in time. Probably it's a huge cost for Apple to apply something like that.
Windows has a similar approach, but it's easier to get attacker's code into kernel space there, and PCs can't properly remotely attest so the whole thing doesn't really work (too many possible legit configurations).