1) Clouds (you mostly trust the provider, but maybe not fully. And you want to make sure they don’t have anything up their sleeves. Consider the FBI vs Apple encryption dispute)
2) Intra-corporation stuff as a mitigation against hacked users, malicious insiders, and malware (think crypto oracles for terminating SSL, requiring bootchain attestation before giving corporate credentials)
3) The more icky category: Places where you distrust your own customer (DRM, and probably eventually, game anticheat)
The userspace code being more privileged than kernel code has never really been true. Maybe arguably true for SGX, but even then, all you get is the ability to prove you were initialized in the “right” way. All the other TEEs have a kernel mode component (they are typically ways of running attestable VMs).