Fortunately, those can run Linux. I recently installed Arch on an Intel T2. The only issue is that it does not have a TPM module, so the LUKS password needs to be manually entered at boot.
What's the alternative to typing in a LUKS password?
You can use TPM with secure boot to store the password. TPM checks that the firmware is the same and that the OS is signed by trusted (by _you_) keys, and if everything matches it makes the key available for reading by the OS.
So what stops other people turning on your computer?