

Are you talking about owner safety, or some bussiness security. Yes the device is ‘insecure’ if you are taking the point of view of DRM provider or software vendor who wants to make sure advertisements are displayed, etc. Or if your software actual security depends of taking control away from the user. But actual end user security does not have to depend on that.
Secure services should always have limited trust to user data and devices. Security built on ‘Google says the device is secure’ is broken. Yes, it is convenient fir service providers who do not care about their customer rights, but more for ‘intellectual property’ and liability.
Lots of apllications still work in web browsers without TPM-based, kernel level DRMs and many of them are still reasonably secure. They are built with the assumption user controls their device. This has always been possible and still is possible. Just inconvenient for corporations.