Can you not simply enroll your own keys in your TPM and still boot with custom-signed drivers that circumvent all this? I mean, yeah, it's a lot more work but it would still work I guess?
The remote game server would then need to decide if it wants to let you connect given your inability to attest to running a trusted configuration.
I've seen this setup work in very controlled conditions. But given how diverse the ecosystem is, someone is going to put out a buggy system, and too many legitimate users will buy it for most games to be willing to blacklist it.