That's about the least-private implementation one could think of; I wouldn't want to send scans of my iris to random Internet services either! This would be the equivalent raw-data implementation for Worldcoin.
> The actual problem - which is waiting for a solution - is undeniable
The solution is the government providing an oauth-like service. Internet services would only get a token and only a limited set of PII you were shown and agreed to while authenticating (e.g. your name, email address, and/or whether you're a minor/adult).
No one can attest your identity without keeping a record of it - public service or not. IMO, having private enterprise do this merely increases the attack surface.