I agree fully with your assessment of USSR but basically any nation state with the power does such things.
Show me a COTS smartphone where the end-user can burn the OTP fuses for his personal public key, so they can have it boot their own custom signed firmware, and control exactly what runs in TrustZone's SW Secure World?